Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux: ASA-202108-8 High: Fossil Certificate Bypass Threat

The package fossil before version 2.16-1 is vulnerable to certificate verification bypass. . Arch Linux Security Advisory ASA-202108-8 ======================================== Severity: High Date : 2021-08-10 CVE-ID : CVE-2021-36377 Package : fossil Type : certificate verification bypass Remote : Yes Link : https://security.archlinux.org/AVG-2146 Summary ====== The package fossil before version 2.16-1 is vulnerable to certificate verification bypass. Resolution ========= Upgrade to 2.16-1. # pacman -Syu "fossil> =2.16-1" The problem has been fixed upstream in version 2.16. Workaround ========= None. Description ========== Fossil before version 2.15.2 often skips the hostname check during TLS certificate validation. Impact ===== A man-in-the-middle attacker could spoof a Fossil repository by presenting any valid certificate for an arbitrary hostname, leading to potential information disclosure. References ========= https://fossil-scm.org/forum/forumpost/8d367e16f53d93c789d70bd3bf2c9587227bbd5c6a7b8e512cccd79007536036 https://fossil-scm.org/home/info/aaab2a15d1dfc22f5453c2bad8f25ecf518ed3eef9a7fa6f4c5bd69ab4e4b075 https://security.archlinux.org/CVE-2021-36377 . Debian Security Bulletin DSA-2021-4567 highlights a severe vulnerability in libxml2 prior to version 2.9.10 that could lead to XML entity expansion.. Fossil Certificate Bypass, Arch Linux Security, Package Advisory. . LinuxSecurity.com Team

Calendar 2 Aug 13, 2021 ArchLinux
203

Mageia: 2021-0471 Severe: Fossil Arbitrary Command Execution

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for . MGASA-2020-0354 - Updated fossil package fixes security vulnerability Publication date: 30 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0354.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24614 Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository (CVE-2020-24614). The fossil package has been updated to version 2.10.2, containing fixes for this issue, fixes for other bugs and security issues, and additional enhancements. See the changes list for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27153 - https://www.openwall.com/lists/oss-security/2020/08/25/1 - https://fossil-scm.org/home/doc/trunk/www/changes.wiki - https://www.cve.org/CVERecord?id=CVE-2020-24614 SRPMS: - 7/core/fossil-2.10.2-1.mga7 . The Fossil software upgrade mitigates the potential for remote unauthorized code execution vulnerability in Mageia 7, offering remedies in update version 2.10.2.. Fossil Package, Mageia Security, Remote Execution Fix, CVE-2020-24614. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 30, 2020 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here