Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 11.10 LTS USN-1197-7 Critical: ca-certificates-java Fraudulent Issue

A certificate authority mis-issued fraudulent certificates.. =========================================================================Ubuntu Security Notice USN-1197-7 March 27, 2012 ca-certificates-java vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: A certificate authority mis-issued fraudulent certificates. Software Description: - ca-certificates-java: Common CA certificates (JKS keystore) Details: USN-1197-5 addressed an issue in ca-certificates pertaining to the Dutch Certificate Authority DigiNotar mis-issuing fraudulent certificates. This update provides the corresponding update for ca-certificates-java. Original advisory details: It was discovered that Dutch Certificate Authority DigiNotar had mis-issued multiple fraudulent certificates. These certificates could allow an attacker to perform a "man in the middle" (MITM) attack which would make the user believe their connection is secure, but is actually being monitored. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: ca-certificates-java 20110912ubuntu3.1 Ubuntu 11.04: ca-certificates-java 20100412ubuntu0.11.04.1 Ubuntu 10.10: ca-certificates-java 20100412ubuntu0.10.10.1 Ubuntu 10.04 LTS: ca-certificates-java 20100406ubuntu1.1 After a standard system update you need to restart any application using ca-certificates-java to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1197-7 https://ubuntu.com/security/notices/USN-1197-1 https://bugs.launchpad.net/ubuntu/+source/ca-certificates-java/+bug/920758 Package Information: https://launchpad.net/ubuntu/+source/ca-certificates-java/20110912ubuntu3.1 https://launchpad.net/ubuntu/+source/ca-certificates-java/20100412ubuntu0.11.04.1 https://launchpad.net/ubuntu/+source/ca-certificates-java/20100412ubuntu0.10.10.1 https://launchpad.net/ubuntu/+source/ca-certificates-java/20100406ubuntu1.1 . Enhance the security of your Ubuntu environment by applying updates to fix the ca-certificates-java issue associated with counterfeit certificates.. Linux Security, Certificate Authority, Authentication Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 27, 2012 Critical Ubuntu
98

Red Hat Enterprise Linux 4, 5, 6: RHSA-2011:1282-01 Important: NSS Update

Updated nss and nspr packages that fix one security issue are now available for Red Hat Enterprise Linux 4, 5, and 6. The Red Hat Security Response Team has rated this update as having important security impact.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: nss and nspr security update Advisory ID: RHSA-2011:1282-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1282.html Issue date: 2011-09-12 ==================================================================== 1. Summary: Updated nss and nspr packages that fix one security issue are now available for Red Hat Enterprise Linux 4, 5, and 6. The Red Hat Security Response Team has rated this update as having important security impact. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: Network Security Services (NSS) is a set of libraries designed to support the cross-platform development of security-enabled client andserver applications. Netscape Portable Runtime (NSPR) provides platform independence for non-GUI operating system facilities. It was found that a Certificate Authority (CA) issued fraudulent HTTPS certificates. This update renders any HTTPS certificates signed by that CA as untrusted. This covers all uses of the certificates, including SSL, S/MIME, and code signing. (BZ#734316) Note: This fix only applies to applications using the NSS Builtin Object Token. It does not render the certificates untrusted for applications that use the NSS library, but do not use the NSS Builtin Object Token. These updated packages upgrade NSS to version 3.12.10 on Red Hat Enterprise Linux 4 and 5. As well, they upgrade NSPR to version 4.8.8 on Red Hat Enterprise Linux 4 and 5, as required by the NSS update. The packages for Red Hat Enterprise Linux 6 include a backported patch. All NSS and NSPR users should upgrade to these updated packages, which correct this issue. After installing the update, applications using NSS and NSPR must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 734316 - Fraudulent certificates signed by DigiNotar CA certificate (MFSA 2011-34) 6. Package List: Red Hat Enterprise Linux AS version4: Source: i386: nspr-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-devel-4.8.8-1.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-devel-3.12.10-4.el4.i386.rpm nss-tools-3.12.10-4.el4.i386.rpm ia64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.ia64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.ia64.rpm nspr-devel-4.8.8-1.el4.ia64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.ia64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.ia64.rpm nss-devel-3.12.10-4.el4.ia64.rpm nss-tools-3.12.10-4.el4.ia64.rpm ppc: nspr-4.8.8-1.el4.ppc.rpm nspr-4.8.8-1.el4.ppc64.rpm nspr-debuginfo-4.8.8-1.el4.ppc.rpm nspr-debuginfo-4.8.8-1.el4.ppc64.rpm nspr-devel-4.8.8-1.el4.ppc.rpm nss-3.12.10-4.el4.ppc.rpm nss-3.12.10-4.el4.ppc64.rpm nss-debuginfo-3.12.10-4.el4.ppc.rpm nss-debuginfo-3.12.10-4.el4.ppc64.rpm nss-devel-3.12.10-4.el4.ppc.rpm nss-tools-3.12.10-4.el4.ppc.rpm s390: nspr-4.8.8-1.el4.s390.rpm nspr-debuginfo-4.8.8-1.el4.s390.rpm nspr-devel-4.8.8-1.el4.s390.rpm nss-3.12.10-4.el4.s390.rpm nss-debuginfo-3.12.10-4.el4.s390.rpm nss-devel-3.12.10-4.el4.s390.rpm nss-tools-3.12.10-4.el4.s390.rpm s390x: nspr-4.8.8-1.el4.s390.rpm nspr-4.8.8-1.el4.s390x.rpm nspr-debuginfo-4.8.8-1.el4.s390.rpm nspr-debuginfo-4.8.8-1.el4.s390x.rpm nspr-devel-4.8.8-1.el4.s390x.rpm nss-3.12.10-4.el4.s390.rpm nss-3.12.10-4.el4.s390x.rpm nss-debuginfo-3.12.10-4.el4.s390.rpm nss-debuginfo-3.12.10-4.el4.s390x.rpm nss-devel-3.12.10-4.el4.s390x.rpm nss-tools-3.12.10-4.el4.s390x.rpm x86_64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.x86_64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.x86_64.rpm nspr-devel-4.8.8-1.el4.x86_64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.x86_64.rpm nss-devel-3.12.10-4.el4.x86_64.rpm nss-tools-3.12.10-4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version4: Source: i386: nspr-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-devel-4.8.8-1.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-devel-3.12.10-4.el4.i386.rpm nss-tools-3.12.10-4.el4.i386.rpm x86_64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.x86_64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.x86_64.rpm nspr-devel-4.8.8-1.el4.x86_64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.x86_64.rpm nss-devel-3.12.10-4.el4.x86_64.rpm nss-tools-3.12.10-4.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: nspr-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-devel-4.8.8-1.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-devel-3.12.10-4.el4.i386.rpm nss-tools-3.12.10-4.el4.i386.rpm ia64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.ia64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.ia64.rpm nspr-devel-4.8.8-1.el4.ia64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.ia64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.ia64.rpm nss-devel-3.12.10-4.el4.ia64.rpm nss-tools-3.12.10-4.el4.ia64.rpm x86_64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.x86_64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.x86_64.rpm nspr-devel-4.8.8-1.el4.x86_64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.x86_64.rpm nss-devel-3.12.10-4.el4.x86_64.rpm nss-tools-3.12.10-4.el4.x86_64.rpm Red Hat Enterprise Linux WS version4: Source: i386: nspr-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-devel-4.8.8-1.el4.i386.rpm nss-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-devel-3.12.10-4.el4.i386.rpm nss-tools-3.12.10-4.el4.i386.rpm ia64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.ia64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.ia64.rpm nspr-devel-4.8.8-1.el4.ia64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.ia64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.ia64.rpm nss-devel-3.12.10-4.el4.ia64.rpm nss-tools-3.12.10-4.el4.ia64.rpm x86_64: nspr-4.8.8-1.el4.i386.rpm nspr-4.8.8-1.el4.x86_64.rpm nspr-debuginfo-4.8.8-1.el4.i386.rpm nspr-debuginfo-4.8.8-1.el4.x86_64.rpm nspr-devel-4.8.8-1.el4.x86_64.rpm nss-3.12.10-4.el4.i386.rpm nss-3.12.10-4.el4.x86_64.rpm nss-debuginfo-3.12.10-4.el4.i386.rpm nss-debuginfo-3.12.10-4.el4.x86_64.rpm nss-devel-3.12.10-4.el4.x86_64.rpm nss-tools-3.12.10-4.el4.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: nspr-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nss-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-tools-3.12.10-4.el5_7.i386.rpm x86_64: nspr-4.8.8-1.el5_7.i386.rpm nspr-4.8.8-1.el5_7.x86_64.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.x86_64.rpm nss-3.12.10-4.el5_7.i386.rpm nss-3.12.10-4.el5_7.x86_64.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.x86_64.rpm nss-tools-3.12.10-4.el5_7.x86_64.rpm RHEL Desktop Workstation (v. 5client): Source: i386: nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-devel-4.8.8-1.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm x86_64: nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.x86_64.rpm nspr-devel-4.8.8-1.el5_7.i386.rpm nspr-devel-4.8.8-1.el5_7.x86_64.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.x86_64.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nss-devel-3.12.10-4.el5_7.x86_64.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: nspr-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-devel-4.8.8-1.el5_7.i386.rpm nss-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm nss-tools-3.12.10-4.el5_7.i386.rpm ia64: nspr-4.8.8-1.el5_7.i386.rpm nspr-4.8.8-1.el5_7.ia64.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.ia64.rpm nspr-devel-4.8.8-1.el5_7.ia64.rpm nss-3.12.10-4.el5_7.i386.rpm nss-3.12.10-4.el5_7.ia64.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.ia64.rpm nss-devel-3.12.10-4.el5_7.ia64.rpm nss-pkcs11-devel-3.12.10-4.el5_7.ia64.rpm nss-tools-3.12.10-4.el5_7.ia64.rpm ppc: nspr-4.8.8-1.el5_7.ppc.rpm nspr-4.8.8-1.el5_7.ppc64.rpm nspr-debuginfo-4.8.8-1.el5_7.ppc.rpm nspr-debuginfo-4.8.8-1.el5_7.ppc64.rpm nspr-devel-4.8.8-1.el5_7.ppc.rpm nspr-devel-4.8.8-1.el5_7.ppc64.rpm nss-3.12.10-4.el5_7.ppc.rpm nss-3.12.10-4.el5_7.ppc64.rpm nss-debuginfo-3.12.10-4.el5_7.ppc.rpm nss-debuginfo-3.12.10-4.el5_7.ppc64.rpm nss-devel-3.12.10-4.el5_7.ppc.rpm nss-devel-3.12.10-4.el5_7.ppc64.rpm nss-pkcs11-devel-3.12.10-4.el5_7.ppc.rpm nss-pkcs11-devel-3.12.10-4.el5_7.ppc64.rpm nss-tools-3.12.10-4.el5_7.ppc.rpm s390x: nspr-4.8.8-1.el5_7.s390.rpm nspr-4.8.8-1.el5_7.s390x.rpm nspr-debuginfo-4.8.8-1.el5_7.s390.rpm nspr-debuginfo-4.8.8-1.el5_7.s390x.rpm nspr-devel-4.8.8-1.el5_7.s390.rpm nspr-devel-4.8.8-1.el5_7.s390x.rpm nss-3.12.10-4.el5_7.s390.rpm nss-3.12.10-4.el5_7.s390x.rpm nss-debuginfo-3.12.10-4.el5_7.s390.rpm nss-debuginfo-3.12.10-4.el5_7.s390x.rpm nss-devel-3.12.10-4.el5_7.s390.rpm nss-devel-3.12.10-4.el5_7.s390x.rpm nss-pkcs11-devel-3.12.10-4.el5_7.s390.rpm nss-pkcs11-devel-3.12.10-4.el5_7.s390x.rpm nss-tools-3.12.10-4.el5_7.s390x.rpm x86_64: nspr-4.8.8-1.el5_7.i386.rpm nspr-4.8.8-1.el5_7.x86_64.rpm nspr-debuginfo-4.8.8-1.el5_7.i386.rpm nspr-debuginfo-4.8.8-1.el5_7.x86_64.rpm nspr-devel-4.8.8-1.el5_7.i386.rpm nspr-devel-4.8.8-1.el5_7.x86_64.rpm nss-3.12.10-4.el5_7.i386.rpm nss-3.12.10-4.el5_7.x86_64.rpm nss-debuginfo-3.12.10-4.el5_7.i386.rpm nss-debuginfo-3.12.10-4.el5_7.x86_64.rpm nss-devel-3.12.10-4.el5_7.i386.rpm nss-devel-3.12.10-4.el5_7.x86_64.rpm nss-pkcs11-devel-3.12.10-4.el5_7.i386.rpm nss-pkcs11-devel-3.12.10-4.el5_7.x86_64.rpm nss-tools-3.12.10-4.el5_7.x86_64.rpm Red Hat Enterprise Linux Desktop (v. 6): Source: i386: nss-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-sysinit-3.12.9-12.el6_1.i686.rpm nss-tools-3.12.9-12.el6_1.i686.rpm x86_64: nss-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.x86_64.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-sysinit-3.12.9-12.el6_1.x86_64.rpm nss-tools-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm x86_64: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: nss-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.x86_64.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-sysinit-3.12.9-12.el6_1.x86_64.rpm nss-tools-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: nss-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-sysinit-3.12.9-12.el6_1.i686.rpm nss-tools-3.12.9-12.el6_1.i686.rpm ppc64: nss-3.12.9-12.el6_1.ppc.rpm nss-3.12.9-12.el6_1.ppc64.rpm nss-debuginfo-3.12.9-12.el6_1.ppc.rpm nss-debuginfo-3.12.9-12.el6_1.ppc64.rpm nss-devel-3.12.9-12.el6_1.ppc.rpm nss-devel-3.12.9-12.el6_1.ppc64.rpm nss-sysinit-3.12.9-12.el6_1.ppc64.rpm nss-tools-3.12.9-12.el6_1.ppc64.rpm s390x: nss-3.12.9-12.el6_1.s390.rpm nss-3.12.9-12.el6_1.s390x.rpm nss-debuginfo-3.12.9-12.el6_1.s390.rpm nss-debuginfo-3.12.9-12.el6_1.s390x.rpm nss-devel-3.12.9-12.el6_1.s390.rpm nss-devel-3.12.9-12.el6_1.s390x.rpm nss-sysinit-3.12.9-12.el6_1.s390x.rpm nss-tools-3.12.9-12.el6_1.s390x.rpm x86_64: nss-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.x86_64.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.x86_64.rpm nss-sysinit-3.12.9-12.el6_1.x86_64.rpm nss-tools-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): Source: i386: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm ppc64: nss-debuginfo-3.12.9-12.el6_1.ppc.rpm nss-debuginfo-3.12.9-12.el6_1.ppc64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.ppc.rpm nss-pkcs11-devel-3.12.9-12.el6_1.ppc64.rpm s390x: nss-debuginfo-3.12.9-12.el6_1.s390.rpm nss-debuginfo-3.12.9-12.el6_1.s390x.rpm nss-pkcs11-devel-3.12.9-12.el6_1.s390.rpm nss-pkcs11-devel-3.12.9-12.el6_1.s390x.rpm x86_64: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: nss-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-sysinit-3.12.9-12.el6_1.i686.rpm nss-tools-3.12.9-12.el6_1.i686.rpm x86_64: nss-3.12.9-12.el6_1.i686.rpm nss-3.12.9-12.el6_1.x86_64.rpm nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-devel-3.12.9-12.el6_1.i686.rpm nss-devel-3.12.9-12.el6_1.x86_64.rpm nss-sysinit-3.12.9-12.el6_1.x86_64.rpm nss-tools-3.12.9-12.el6_1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): Source: i386: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm x86_64: nss-debuginfo-3.12.9-12.el6_1.i686.rpm nss-debuginfo-3.12.9-12.el6_1.x86_64.rpm nss-pkcs11-devel-3.12.9-12.el6_1.i686.rpm nss-pkcs11-devel-3.12.9-12.el6_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFObmMCXlSAg2UNWIIRAsOpAKClRezYsW2oGvhx2V2LFfqs7JWNaQCfaNsv AeVVmhXAEE6j2w4f1quEIks=xkFl -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Acquire the critical security patch for the Red Hat nss and nspr packages that addresses counterfeit certificates affecting SSL functionality.. Red Hat Enterprise,nss security update,NSPR package fix,important security advisory,SSL certificate trust. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 12, 2011 Important Red Hat
172

Ubuntu 11.04 USN-1197-3 Moderate: DigiNotar Fraudulent Certificates Threat

A certificate authority issued fraudulent certificates.. =========================================================================Ubuntu Security Notice USN-1197-3 September 07, 2011 firefox, xulrunner-1.9.2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: A certificate authority issued fraudulent certificates. Software Description: - firefox: Mozilla Open Source web browser - xulrunner-1.9.2: Mozilla Gecko runtime environment Details: USN-1197-1 partially addressed an issue with Dutch Certificate Authority DigiNotar mis-issuing fraudulent certificates. This update actively distrusts the DigiNotar root certificate as well as several intermediary certificates. Also included in this list of distrusted certificates are the Staat der Nederlanden root certificates. Original advisory details: It was discovered that Dutch Certificate Authority DigiNotar, had mis-issued multiple fraudulent certificates. These certificates could allow an attacker to perform a "man in the middle" (MITM) attack which would make the user believe their connection is secure, but is actually being monitored. For the protection of its users, Mozilla has removed the DigiNotar certificate. Sites using certificates issued by DigiNotar will need to seek another certificate vendor. We are currently aware of a regression that blocks one of two Staat der Nederlanden root certificates which are believed to still be secure. This regression is being tracked at https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/838322. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.04: firefox 6.0.2+build2+nobinonly-0ubuntu0.11.04.1 Ubuntu 10.10: firefox 3.6.22+build2+nobinonly-0ubuntu0.10.10.1 xulrunner-1.9.2 1.9.2.22+build2+nobinonly-0ubuntu0.10.10.1 Ubuntu 10.04 LTS: firefox 3.6.22+build2+nobinonly-0ubuntu0.10.04.1 xulrunner-1.9.2 1.9.2.22+build2+nobinonly-0ubuntu0.10.04.1 After a standard system upgrade you need to restart Firefox and any applications that use Xulrunner to effect the necessary changes. References: https://ubuntu.com/security/notices/USN-1197-1 https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/838322 Package Information: https://launchpad.net/ubuntu/+source/firefox/6.0.2+build2+nobinonly-0ubuntu0.11.04.1 https://launchpad.net/ubuntu/+source/firefox/3.6.22+build2+nobinonly-0ubuntu0.10.10.1 https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.22+build2+nobinonly-0ubuntu0.10.10.1 https://launchpad.net/ubuntu/+source/firefox/3.6.22+build2+nobinonly-0ubuntu0.10.04.1 https://launchpad.net/ubuntu/+source/xulrunner-1.9.2/1.9.2.22+build2+nobinonly-0ubuntu0.10.04.1 . Ensure your Ubuntu installations are up to date to defend against deceptive DigiNotar certificates, which could lead to vulnerability and potential man-in-the-middle (MITM) assaults.. DigiNotar Security Issue, Firefox Update, Xulrunner Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 07, 2011 Important Ubuntu
87

Ubuntu: USN-1234-1 Critical: Security Updates for Firefox Released

This update for the Iceape internet suite, an unbranded version of Seamonkey, updates the certificate blacklist for several fraudulent HTTPS certificates. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2199-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 23, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : iceape Vulnerability : none in iceape Problem type : none in iceape Debian-specific: no CVE ID : not available This update for the Iceape internet suite, an unbranded version of Seamonkey, updates the certificate blacklist for several fraudulent HTTPS certificates. More details can be found in a blog posting by Jacob Appelbaum of the Tor project: The oldstable distribution (lenny) is not affected. The iceape package only provides the XPCOM code. For the stable distribution (squeeze), this problem has been fixed in version 2.0.11-4. For the unstable distribution (sid), this problem has been fixed in version 2.0.13-1. We recommend that you upgrade your iceape packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . New release of the Snowfall package introduces a blocklist for deceptive SSL websites. Critical updates for Ubuntu distributions.. Iceape Internet Suite, HTTPS Certificates, Debian Security Advisory, Software Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 23, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here