Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 77 articles for you...
91

Gentoo: GLSA-202505-02 high: Mozilla Firefox multiple issues

Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202505-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Firefox: Multiple Vulnerabilities Date: May 12, 2025 Bugs: #951563, #953021 ID: 202505-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Mozilla Firefox, the worst of which can lead to arbitrary code execution. Background ========== Mozilla Firefox is a popular open-source web browser from the Mozilla project. Affected packages ================= Package Vulnerable Unaffected ---------------------- ---------------- ----------------- www-client/firefox < 128.9.0:esr > = 128.9.0:esr < 137.0.1:stable > = 137.0.1:stable www-client/firefox-bin < 128.9.0:esr > = 128.9.0:esr < 137.0.1:stable > = 137.0.1:stable Description =========== Multiple vulnerabilities have been discovered in Mozilla Firefox. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Mozilla Firefox users should upgrade to the latest version in their release channel: # emerge --sync # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-137.0.1:rapid" # emerge --ask --oneshot --verbose "> =www-client/firefox-bin-128.9.0:esr" All Mozilla Firefox users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-client/firefox-137.0.1:rapid" # emerge --ask --oneshot --verbose "> =www-client/firefox-128.9.0:esr" References ========== [ 1 ] CVE-2024-43097 https://nvd.nist.gov/vuln/detail/CVE-2024-43097 [ 2 ] CVE-2025-1931 https://nvd.nist.gov/vuln/detail/CVE-2025-1931 [ 3 ] CVE-2025-1932 https://nvd.nist.gov/vuln/detail/CVE-2025-1932 [ 4 ] CVE-2025-1933 https://nvd.nist.gov/vuln/detail/CVE-2025-1933 [ 5 ] CVE-2025-1934 https://nvd.nist.gov/vuln/detail/CVE-2025-1934 [ 6 ] CVE-2025-1935 https://nvd.nist.gov/vuln/detail/CVE-2025-1935 [ 7 ] CVE-2025-1936 https://nvd.nist.gov/vuln/detail/CVE-2025-1936 [ 8 ] CVE-2025-1937 https://nvd.nist.gov/vuln/detail/CVE-2025-1937 [ 9 ] CVE-2025-1938 https://nvd.nist.gov/vuln/detail/CVE-2025-1938 [ 10 ] CVE-2025-1941 https://nvd.nist.gov/vuln/detail/CVE-2025-1941 [ 11 ] CVE-2025-1942 https://nvd.nist.gov/vuln/detail/CVE-2025-1942 [ 12 ] CVE-2025-1943 https://nvd.nist.gov/vuln/detail/CVE-2025-1943 [ 13 ] CVE-2025-3028 https://nvd.nist.gov/vuln/detail/CVE-2025-3028 [ 14 ] CVE-2025-3029 https://nvd.nist.gov/vuln/detail/CVE-2025-3029 [ 15 ] CVE-2025-3030 https://nvd.nist.gov/vuln/detail/CVE-2025-3030 [ 16 ] CVE-2025-3031 https://nvd.nist.gov/vuln/detail/CVE-2025-3031 [ 17 ] CVE-2025-3032 https://nvd.nist.gov/vuln/detail/CVE-2025-3032 [ 18 ] CVE-2025-3034 https://nvd.nist.gov/vuln/detail/CVE-2025-3034 [ 19 ] CVE-2025-3035 https://nvd.nist.gov/vuln/detail/CVE-2025-3035 [ 20 ] MFSA2025-14 [ 21 ] MFSA2025-16 [ 22 ] MFSA2025-18 [ 23 ] MFSA2025-20 [ 24 ] MFSA2025-22 [ 25 ] MFSA2025-23 [ 26 ] MFSA2025-24 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202505-02 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Several security flaws identified in Mozilla Firefox could allow for unauthorized code execution. It is advisable to update for enhanced protection.. Gentoo Mozilla Firefox vulnerabilities, security advisory high severity, browser security updates. . LinuxSecurity.com Team

Calendar%202 May 12, 2025 Gentoo
91

Gentoo: GLSA-202501-09 critical: QtWebEngine multiple issues

Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202501-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: QtWebEngine: Multiple Vulnerabilities Date: January 23, 2025 Bugs: #944807 ID: 202501-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in QtWebEngine, the worst of which could lead to arbitrary code execution. Background ========== QtWebEngine is a library for rendering dynamic web content in Qt5 and Qt6 C++ and QML applications. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------------- -------------------- dev-qt/qtwebengine < 5.15.16_p20241115 > = 5.15.16_p20241115 Description =========== Multiple vulnerabilities have been discovered in QtWebEngine. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All QtWebEngine users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-qt/qtwebengine-5.15.16_p20241115" References ========== [ 1 ] CVE-2024-4058 https://nvd.nist.gov/vuln/detail/CVE-2024-4058 [ 2 ] CVE-2024-4059 https://nvd.nist.gov/vuln/detail/CVE-2024-4059 [ 3 ] CVE-2024-4060 https://nvd.nist.gov/vuln/detail/CVE-2024-4060 [ 4 ] CVE-2024-4558 https://nvd.nist.gov/vuln/detail/CVE-2024-4558 [ 5 ] CVE-2024-4559 https://nvd.nist.gov/vuln/detail/CVE-2024-4559 [ 6 ]CVE-2024-4761 https://nvd.nist.gov/vuln/detail/CVE-2024-4761 [ 7 ] CVE-2024-5157 https://nvd.nist.gov/vuln/detail/CVE-2024-5157 [ 8 ] CVE-2024-5158 https://nvd.nist.gov/vuln/detail/CVE-2024-5158 [ 9 ] CVE-2024-5159 https://nvd.nist.gov/vuln/detail/CVE-2024-5159 [ 10 ] CVE-2024-5160 https://nvd.nist.gov/vuln/detail/CVE-2024-5160 [ 11 ] CVE-2024-5830 https://nvd.nist.gov/vuln/detail/CVE-2024-5830 [ 12 ] CVE-2024-5831 https://nvd.nist.gov/vuln/detail/CVE-2024-5831 [ 13 ] CVE-2024-5832 https://nvd.nist.gov/vuln/detail/CVE-2024-5832 [ 14 ] CVE-2024-5833 https://nvd.nist.gov/vuln/detail/CVE-2024-5833 [ 15 ] CVE-2024-5834 https://nvd.nist.gov/vuln/detail/CVE-2024-5834 [ 16 ] CVE-2024-5835 https://nvd.nist.gov/vuln/detail/CVE-2024-5835 [ 17 ] CVE-2024-5836 https://nvd.nist.gov/vuln/detail/CVE-2024-5836 [ 18 ] CVE-2024-5837 https://nvd.nist.gov/vuln/detail/CVE-2024-5837 [ 19 ] CVE-2024-5838 https://nvd.nist.gov/vuln/detail/CVE-2024-5838 [ 20 ] CVE-2024-5839 https://nvd.nist.gov/vuln/detail/CVE-2024-5839 [ 21 ] CVE-2024-5840 https://nvd.nist.gov/vuln/detail/CVE-2024-5840 [ 22 ] CVE-2024-5841 https://nvd.nist.gov/vuln/detail/CVE-2024-5841 [ 23 ] CVE-2024-5842 https://nvd.nist.gov/vuln/detail/CVE-2024-5842 [ 24 ] CVE-2024-5843 https://nvd.nist.gov/vuln/detail/CVE-2024-5843 [ 25 ] CVE-2024-5844 https://nvd.nist.gov/vuln/detail/CVE-2024-5844 [ 26 ] CVE-2024-5845 https://nvd.nist.gov/vuln/detail/CVE-2024-5845 [ 27 ] CVE-2024-5846 https://nvd.nist.gov/vuln/detail/CVE-2024-5846 [ 28 ] CVE-2024-5847 https://nvd.nist.gov/vuln/detail/CVE-2024-5847 [ 29 ] CVE-2024-6290 https://nvd.nist.gov/vuln/detail/CVE-2024-6290 [ 30 ] CVE-2024-6291 https://nvd.nist.gov/vuln/detail/CVE-2024-6291 [ 31 ] CVE-2024-6292 https://nvd.nist.gov/vuln/detail/CVE-2024-6292 [ 32 ] CVE-2024-6293 https://nvd.nist.gov/vuln/detail/CVE-2024-6293 [ 33 ] CVE-2024-6988 https://nvd.nist.gov/vuln/detail/CVE-2024-6988 [ 34 ] CVE-2024-6989 https://nvd.nist.gov/vuln/detail/CVE-2024-6989 [ 35 ] CVE-2024-6991 https://nvd.nist.gov/vuln/detail/CVE-2024-6991 [ 36 ] CVE-2024-6994 https://nvd.nist.gov/vuln/detail/CVE-2024-6994 [ 37 ] CVE-2024-6995 https://nvd.nist.gov/vuln/detail/CVE-2024-6995 [ 38 ] CVE-2024-6996 https://nvd.nist.gov/vuln/detail/CVE-2024-6996 [ 39 ] CVE-2024-6997 https://nvd.nist.gov/vuln/detail/CVE-2024-6997 [ 40 ] CVE-2024-6998 https://nvd.nist.gov/vuln/detail/CVE-2024-6998 [ 41 ] CVE-2024-6999 https://nvd.nist.gov/vuln/detail/CVE-2024-6999 [ 42 ] CVE-2024-7000 https://nvd.nist.gov/vuln/detail/CVE-2024-7000 [ 43 ] CVE-2024-7001 https://nvd.nist.gov/vuln/detail/CVE-2024-7001 [ 44 ] CVE-2024-7003 https://nvd.nist.gov/vuln/detail/CVE-2024-7003 [ 45 ] CVE-2024-7004 https://nvd.nist.gov/vuln/detail/CVE-2024-7004 [ 46 ] CVE-2024-7005 https://nvd.nist.gov/vuln/detail/CVE-2024-7005 [ 47 ] CVE-2024-7532 https://nvd.nist.gov/vuln/detail/CVE-2024-7532 [ 48 ] CVE-2024-7533 https://nvd.nist.gov/vuln/detail/CVE-2024-7533 [ 49 ] CVE-2024-7534 https://nvd.nist.gov/vuln/detail/CVE-2024-7534 [ 50 ] CVE-2024-7535 https://nvd.nist.gov/vuln/detail/CVE-2024-7535 [ 51 ] CVE-2024-7536 https://nvd.nist.gov/vuln/detail/CVE-2024-7536 [ 52 ] CVE-2024-7550 https://nvd.nist.gov/vuln/detail/CVE-2024-7550 [ 53 ] CVE-2024-7964 https://nvd.nist.gov/vuln/detail/CVE-2024-7964 [ 54 ] CVE-2024-7965 https://nvd.nist.gov/vuln/detail/CVE-2024-7965 [ 55 ] CVE-2024-7966 https://nvd.nist.gov/vuln/detail/CVE-2024-7966 [ 56 ] CVE-2024-7967 https://nvd.nist.gov/vuln/detail/CVE-2024-7967 [ 57 ] CVE-2024-7968 https://nvd.nist.gov/vuln/detail/CVE-2024-7968 [ 58 ] CVE-2024-7969 https://nvd.nist.gov/vuln/detail/CVE-2024-7969 [ 59 ] CVE-2024-7971 https://nvd.nist.gov/vuln/detail/CVE-2024-7971 [ 60 ] CVE-2024-7972 https://nvd.nist.gov/vuln/detail/CVE-2024-7972 [61 ] CVE-2024-7973 https://nvd.nist.gov/vuln/detail/CVE-2024-7973 [ 62 ] CVE-2024-7974 https://nvd.nist.gov/vuln/detail/CVE-2024-7974 [ 63 ] CVE-2024-7975 https://nvd.nist.gov/vuln/detail/CVE-2024-7975 [ 64 ] CVE-2024-7976 https://nvd.nist.gov/vuln/detail/CVE-2024-7976 [ 65 ] CVE-2024-7977 https://nvd.nist.gov/vuln/detail/CVE-2024-7977 [ 66 ] CVE-2024-7978 https://nvd.nist.gov/vuln/detail/CVE-2024-7978 [ 67 ] CVE-2024-7979 https://nvd.nist.gov/vuln/detail/CVE-2024-7979 [ 68 ] CVE-2024-7980 https://nvd.nist.gov/vuln/detail/CVE-2024-7980 [ 69 ] CVE-2024-7981 https://nvd.nist.gov/vuln/detail/CVE-2024-7981 [ 70 ] CVE-2024-8033 https://nvd.nist.gov/vuln/detail/CVE-2024-8033 [ 71 ] CVE-2024-8034 https://nvd.nist.gov/vuln/detail/CVE-2024-8034 [ 72 ] CVE-2024-8035 https://nvd.nist.gov/vuln/detail/CVE-2024-8035 [ 73 ] CVE-2024-8193 https://nvd.nist.gov/vuln/detail/CVE-2024-8193 [ 74 ] CVE-2024-8194 https://nvd.nist.gov/vuln/detail/CVE-2024-8194 [ 75 ] CVE-2024-8198 https://nvd.nist.gov/vuln/detail/CVE-2024-8198 [ 76 ] CVE-2024-8636 https://nvd.nist.gov/vuln/detail/CVE-2024-8636 [ 77 ] CVE-2024-8637 https://nvd.nist.gov/vuln/detail/CVE-2024-8637 [ 78 ] CVE-2024-8638 https://nvd.nist.gov/vuln/detail/CVE-2024-8638 [ 79 ] CVE-2024-8639 https://nvd.nist.gov/vuln/detail/CVE-2024-8639 [ 80 ] CVE-2024-9120 https://nvd.nist.gov/vuln/detail/CVE-2024-9120 [ 81 ] CVE-2024-9121 https://nvd.nist.gov/vuln/detail/CVE-2024-9121 [ 82 ] CVE-2024-9122 https://nvd.nist.gov/vuln/detail/CVE-2024-9122 [ 83 ] CVE-2024-9123 https://nvd.nist.gov/vuln/detail/CVE-2024-9123 [ 84 ] CVE-2024-9602 https://nvd.nist.gov/vuln/detail/CVE-2024-9602 [ 85 ] CVE-2024-9603 https://nvd.nist.gov/vuln/detail/CVE-2024-9603 [ 86 ] CVE-2024-10229 https://nvd.nist.gov/vuln/detail/CVE-2024-10229 [ 87 ] CVE-2024-10230 https://nvd.nist.gov/vuln/detail/CVE-2024-10230 [ 88 ] CVE-2024-10231 https://nvd.nist.gov/vuln/detail/CVE-2024-10231 [ 89 ] CVE-2024-10826 https://nvd.nist.gov/vuln/detail/CVE-2024-10826 [ 90 ] CVE-2024-10827 https://nvd.nist.gov/vuln/detail/CVE-2024-10827 [ 91 ] CVE-2024-45490 https://nvd.nist.gov/vuln/detail/CVE-2024-45490 [ 92 ] CVE-2024-45491 https://nvd.nist.gov/vuln/detail/CVE-2024-45491 [ 93 ] CVE-2024-45492 https://nvd.nist.gov/vuln/detail/CVE-2024-45492 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202501-09 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Several flaws in QtWebEngine could pose significant security threats. Urgent measures advised for all individuals.. security advisory, Gentoo, QtWebEngine, arbitrary code execution, high severity. . LinuxSecurity.com Team

Calendar%202 Jan 23, 2025 Gentoo
91

Gentoo 202408-06 Advisory: PostgreSQL Privilege Escalation And DoS Risks

Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to privilege escalation or denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PostgreSQL: Multiple Vulnerabilities Date: August 07, 2024 Bugs: #903193, #912251, #917153, #924110, #931849 ID: 202408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in PostgreSQL, the worst of which could lead to privilege escalation or denial of service. Background ========== PostgreSQL is an open source object-relational database management system. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------- -------------- dev-db/postgresql < 12.19:12 > = 12.19:12 < 13.14:13 > = 13.14:13 < 14.12-r1:14 > = 14.12-r1:14 < 15.7-r1:15 > = 15.7-r1:15 < 16.3-r1:16 > = 16.3-r1:16 < 12 > = 12.19 Description =========== Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All PostgreSQL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-16.3-r1:16" Or update an older slot if that is still in use. References ========== [ 1 ] CVE-2023-5868 https://nvd.nist.gov/vuln/detail/CVE-2023-5868 [ 2 ]CVE-2023-5869 https://nvd.nist.gov/vuln/detail/CVE-2023-5869 [ 3 ] CVE-2023-5870 https://nvd.nist.gov/vuln/detail/CVE-2023-5870 [ 4 ] CVE-2024-0985 https://nvd.nist.gov/vuln/detail/CVE-2024-0985 [ 5 ] CVE-2024-4317 https://nvd.nist.gov/vuln/detail/CVE-2024-4317 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202408-06 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Gentoo has released PostgreSQL vulnerability advisories under GLSA 202408-06, detailing severity levels and providing guidance for necessary mitigation actions. PostgreSQL Updates,Gentoo Security Advisory,Privilege Escalation,Denial of Service,Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Aug 07, 2024 Gentoo
91

Gentoo: GLSA 202407-23 Normal Severity Denial of Service Advisory

Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LIVE555 Media Server: Multiple Vulnerabilities Date: July 09, 2024 Bugs: #732598, #807622 ID: 202407-23 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in LIVE555 Media Server, the worst of which could lead to a denial of service. Background ========== LIVE555 Media Server is a set of libraries for multimedia streaming. Affected packages ================= Package Vulnerable Unaffected ------------------ ------------ ------------- media-plugins/live < 2021.08.24 > = 2021.08.24 Description =========== Multiple vulnerabilities have been discovered in LIVE555 Media Server. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All LIVE555 Media Server users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-plugins/live-2021.08.24" References ========== [ 1 ] CVE-2020-24027 https://nvd.nist.gov/vuln/detail/CVE-2020-24027 [ 2 ] CVE-2021-38380 https://nvd.nist.gov/vuln/detail/CVE-2021-38380 [ 3 ] CVE-2021-38381 https://nvd.nist.gov/vuln/detail/CVE-2021-38381 [ 4 ] CVE-2021-38382 https://nvd.nist.gov/vuln/detail/CVE-2021-38382 [ 5 ] CVE-2021-39282 https://nvd.nist.gov/vuln/detail/CVE-2021-39282 [ 6 ] CVE-2021-39283 https://nvd.nist.gov/vuln/detail/CVE-2021-39283 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-23 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . The LIVE555 Media Server was revealed to have vulnerabilities prompting the Gentoo Security Advisory to take action to prevent exploitation by attackers. LIVE555 Media Server, Gentoo Linux Advisory, Security Updates. . LinuxSecurity.com Team

Calendar%202 Jul 09, 2024 Gentoo
91

Gentoo: GLSA 202407-04 Critical: Gnome-shell Privilege Escalation

A vulnerability has been discovered in Liferea, which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202407-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Liferea: Remote Code Execution Date: July 01, 2024 Bugs: #901085 ID: 202407-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Liferea, which can lead to remote code execution. Background ========== Liferea is a feed reader/news aggregator that brings together all of the content from your favorite subscriptions into a simple interface that makes it easy to organize and browse feeds. Its GUI is similar to a desktop mail/news client, with an embedded web browser. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ net-news/liferea < 1.12.10 > = 1.12.10 Description =========== A vulnerability has been discovered in Liferea. Please review the CVE identifier referenced below for details. Impact ====== A vulnerability was found in liferea. Affected by this issue is the function update_job_run of the file src/update.c of the component Feed Enrichment. The manipulation of the argument source can lead to os command injection. The attack may be launched remotely. Workaround ========== There is no known workaround at this time. Resolution ========== All Liferea users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-news/liferea-1.12.10" References ========== [ 1 ] CVE-2023-1350 https://nvd.nist.gov/vuln/detail/CVE-2023-1350 Availability ============ This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202407-03 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . A flaw in Liferea may allow for remote code execution. Update to version 1.12.10 to reduce potential threats.. Liferea Security Advisory, Gentoo Remote Execution, Linux Vulnerability Management. . LinuxSecurity.com Team

Calendar%202 Jul 01, 2024 Gentoo
91

Gentoo: GLSA-202405-12 High: Pillow Arbitrary Code Threat

Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Pillow: Multiple Vulnerabilities Date: May 05, 2024 Bugs: #889594, #903664, #916907, #922577 ID: 202405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in Pillow, the worst of which can lead to arbitrary code execution. Background ========== The friendly PIL fork. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ dev-python/pillow < 10.2.0 > = 10.2.0 Description =========== Multiple vulnerabilities have been discovered in Pillow. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Pillow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pillow-10.2.0" References ========== [ 1 ] CVE-2023-44271 https://nvd.nist.gov/vuln/detail/CVE-2023-44271 [ 2 ] CVE-2023-50447 https://nvd.nist.gov/vuln/detail/CVE-2023-50447 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202405-12 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should beaddressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5 . Several security flaws in Pillow may permit the execution of arbitrary code. It is crucial to upgrade to the most recent version without delay.. Pillow Security, Gentoo Linux Advisory, Arbitrary Code Threats, Security Updates. . LinuxSecurity.com Team

Calendar%202 May 05, 2024 Gentoo
91

Gentoo: GLSA-202402-27 Normal Severity: Glade Denial of Service

A vulnerability has been discovered in Glade which can lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Glade: Denial of Service Date: February 19, 2024 Bugs: #747451 ID: 202402-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Glade which can lead to a denial of service. Background ========== Glade is a RAD tool to enable quick & easy development of user interfaces for the GTK+ toolkit (Version 3 only) and the GNOME desktop environment. Affected packages ================= Package Vulnerable Unaffected -------------- ------------ ------------ dev-util/glade < 3.38.2 > = 3.38.2 Description =========== A vulnerability has been found in Glade which can lead to a denial of service when working with specific glade files. Impact ====== A crafted file may lead to crashes in Glade. Workaround ========== There is no known workaround at this time. Resolution ========== All Glade users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/glade-3.38.2" References ========== [ 1 ] CVE-2020-36774 https://nvd.nist.gov/vuln/detail/CVE-2020-36774 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-27 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bugat https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A Glade security flaw in Gentoo leads to potential service disruption; fixing this issue requires updating to version 3.38.2 or later.. Gentoo Linux, Glade Tool, Denial of Service Issue, Security Fix. . LinuxSecurity.com Team

Calendar%202 Feb 19, 2024 Gentoo
91

Gentoo: GLSA-202402-12 High: GNU Tar Out Of Bounds Read Threat

A vulnerability has been discovered in GNU Tar which may lead to an out of bounds read.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: GNU Tar: Out of Bounds Read Date: February 18, 2024 Bugs: #898176 ID: 202402-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in GNU Tar which may lead to an out of bounds read. Background ========== The GNU Tar program provides the ability to create tar archives, as well as various other kinds of manipulation. Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ app-arch/tar < 1.34-r3 > = 1.34-r3 Description =========== A vulnerability have been discovered in GNU Tar. Please review the CVE identifier referenced below for details. Impact ====== GNU Tar has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs via a V7 archive in which mtime has approximately 11 whitespace characters. Workaround ========== There is no known workaround at this time. Resolution ========== All GNU Tar users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/tar-1.34-r3" References ========== [ 1 ] CVE-2022-48303 https://nvd.nist.gov/vuln/detail/CVE-2022-48303 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-12 Concerns? ========= Security is a primary focus of Gentoo Linux andensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical alert for GNU Tar on Arch Linux. Immediate update necessary to address the buffer overflow vulnerability.. Gentoo Advisory,GNU Tar Security,Out Of Bounds,High Severity Threat. . LinuxSecurity.com Team

Calendar%202 Feb 18, 2024 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200