Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 39: FEDORA-2024-c395d8fef4 moderate: FreeRADIUS Forgery Threat

Update to upstream release 3.2.5. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c395d8fef4 2024-07-18 04:05:28.192702 -------------------------------------------------------------------------------- Name : freeradius Product : Fedora 39 Version : 3.2.5 Release : 1.fc39 URL : http://www.freeradius.org/ Summary : High-performance and highly configurable free RADIUS server Description : The FreeRADIUS Server Project is a high performance and highly configurable GPL'd free RADIUS server. The server is similar in some respects to Livingston's 2.0 server. While FreeRADIUS started as a variant of the Cistron RADIUS server, they don't share a lot in common any more. It now has many more features than Cistron or Livingston, and is much more configurable. FreeRADIUS is an Internet authentication daemon, which implements the RADIUS protocol, as defined in RFC 2865 (and others). It allows Network Access Servers (NAS boxes) to perform authentication for dial-up users. There are also RADIUS clients available for Web servers, firewalls, Unix logins, and more. Using RADIUS allows authentication and authorization for a network to be centralized, and minimizes the amount of re-configuration which has to be done when adding or deleting new users. -------------------------------------------------------------------------------- Update Information: Update to upstream release 3.2.5 -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 9 2024 Antonio Torres - 3.2.5-1 - Update to upstream release 3.2.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2296625 - CVE-2024-3596 freeradius: forgery attack [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2296625 -------------------------------------------------------------------------------- This update can beinstalled with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c395d8fef4' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Updated FreeRADIUS server for Fedora 39 enhances security against impersonation risks with version 3.2.5.. Freeradius, Fedora updates, Security advisory, Network authentication. . LinuxSecurity.com Team

Calendar 2 Jul 18, 2024 Fedora
89

Fedora 36 Samba 2022-7f9021ead1 Critical: Elevation And Forgery Risks

Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7f9021ead1 2022-12-21 01:17:10.825705 --------------------------------------------------------------------------------Name : samba Product : Fedora 36 Version : 4.16.8 Release : 0.fc36 URL : Summary : Server and Client software to interoperate with Windows machines Description : Samba is the standard Windows interoperability suite of programs for Linux and Unix. --------------------------------------------------------------------------------Update Information: Security fixes for CVE-2022-37966, CVE-2022-37967 and CVE-2022-38023 --------------------------------------------------------------------------------ChangeLog: * Fri Dec 16 2022 Guenther Deschner - 4.16.8-0 - resolves: #2154303, #2154304 - Security fixes for CVE-2022-37966 - resolves: #2154320, #2154322 - Security fixes for CVE-2022-37967 - resolves: #2154362, #2154363 - Security fixes for CVE-2022-38023 --------------------------------------------------------------------------------References: [ 1 ] Bug #2154303 - CVE-2022-37966 samba: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability. https://bugzilla.redhat.com/show_bug.cgi?id=2154303 [ 2 ] Bug #2154320 - CVE-2022-37967 samba: Kerberos constrained delegation ticket forgery possible against Samba AD DC https://bugzilla.redhat.com/show_bug.cgi?id=2154320 [ 3 ] Bug #2154362 - CVE-2022-38023 samba: RC4/HMAC-MD5 NetLogon Secure Channel is weak and should be avoided https://bugzilla.redhat.com/show_bug.cgi?id=2154362 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7f9021ead1' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The latest Samba update for Fedora 36 resolves multiple security vulnerabilities, notably in terms of privilege escalation and insufficient secure channel protections.. Fedora Samba Security, Privilege Escalation, Kerberos Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 21, 2022 Critical Fedora
203

Mageia 7 gnuPG2 Update: MGASA-2019-0348 Critical SHA-1 Fix

gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created . MGASA-2019-0348 - Updated gnupg2 packages fix security vulnerability Publication date: 30 Nov 2019 URL: https://advisories.mageia.org/MGASA-2019-0348.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14855 gnupg2 is updated to 2.2.18 and fix security vulnerability: Web of Trust forgeries using collisions in SHA-1 signatures (CVE-2019-14855) * Note that this change removes all SHA-1 based key signature newer than 2019-01-19 from the web-of-trust. This includes all key signature created with dsa1024 keys. The new option --allow-weak-key-signatues can be used to override the new and safer behaviour. For other fixes in this update, see the gnupg-announce reference. References: - https://bugs.mageia.org/show_bug.cgi?id=25749 - https://lists.gnupg.org/pipermail/gnupg-announce/2019q4/000442.html - https://www.cve.org/CVERecord?id=CVE-2019-14855 SRPMS: - 7/core/gnupg2-2.2.18-1.mga7 . Update MGASA-2019-0349 addresses vulnerabilities in openssl regarding certificate validation. The amendments enhance cryptographic security by disabling weak ciphers and algorithms.. gnupg2 security, Mageia security update, SHA-1 collision, Web of Trust, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 30, 2019 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here