Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
100

SUSE: 2022:2876-1 Important Security Update for gfbgraph TLS Issues

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for gfbgraph ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2876-1 Rating: important References: #1189850 Cross-References: CVE-2021-39358 CVSS scores: CVE-2021-39358 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2021-39358 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Storage 7.1 SUSE Linux Enterprise Workstation Extension 15-SP3 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gfbgraph fixes the following issues: - CVE-2021-39358: Fixed missing TLS certificate verification (bsc#1189850). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-2876=1 - SUSE Linux Enterprise Workstation Extension 15-SP3: zypper in -t patch SUSE-SLE-Product-WE-15-SP3-2022-2876=1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3: zypper in -t patchSUSE-SLE-Module-Packagehub-Subpackages-15-SP3-2022-2876=1 Package List: - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): gfbgraph-debugsource-0.2.3-150000.3.5.1 gfbgraph-devel-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-debuginfo-0.2.3-150000.3.5.1 typelib-1_0-GFBGraph-0_2-0.2.3-150000.3.5.1 - SUSE Linux Enterprise Workstation Extension 15-SP3 (x86_64): gfbgraph-debugsource-0.2.3-150000.3.5.1 gfbgraph-devel-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-debuginfo-0.2.3-150000.3.5.1 typelib-1_0-GFBGraph-0_2-0.2.3-150000.3.5.1 - SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP3 (aarch64 ppc64le s390x): gfbgraph-debugsource-0.2.3-150000.3.5.1 gfbgraph-devel-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-0.2.3-150000.3.5.1 libgfbgraph-0_2-0-debuginfo-0.2.3-150000.3.5.1 typelib-1_0-GFBGraph-0_2-0.2.3-150000.3.5.1 References: https://www.suse.com/security/cve/CVE-2021-39358.html https://bugzilla.suse.com/1189850 . Crucial SUSE Security Patch for gfbgraph Issued to Address TLS Authentication Issues. gfbgraph Security Update,TLS Verification Issue,SUSE Updates,Important Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 23, 2022 Important SuSE
98

Red Hat Enterprise Linux 8 RHSA-2022:1801-01 Moderate gfbgraph TLS Issue

An update for gfbgraph is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: gfbgraph security update Advisory ID: RHSA-2022:1801-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:1801 Issue date: 2022-05-10 CVE Names: CVE-2021-39358 ==================================================================== 1. Summary: An update for gfbgraph is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 8) - ppc64le, x86_64 3. Description: GLib/GObject wrapper for the Facebook Graph API that integrates with GNOME Online Accounts. The following packages have been upgraded to a later upstream version: gfbgraph (0.2.4). (BZ#1997941) Security Fix(es): * gfbgraph: missing TLS certificate verification (CVE-2021-39358) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.6 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1997139 - CVE-2021-39358 gfbgraph: missing TLS certificate verification 6. Package List: Red Hat Enterprise Linux AppStream (v. 8): Source: gfbgraph-0.2.4-1.el8.src.rpm ppc64le: gfbgraph-0.2.4-1.el8.ppc64le.rpm gfbgraph-debuginfo-0.2.4-1.el8.ppc64le.rpm gfbgraph-debugsource-0.2.4-1.el8.ppc64le.rpm x86_64: gfbgraph-0.2.4-1.el8.i686.rpm gfbgraph-0.2.4-1.el8.x86_64.rpm gfbgraph-debuginfo-0.2.4-1.el8.i686.rpm gfbgraph-debuginfo-0.2.4-1.el8.x86_64.rpm gfbgraph-debugsource-0.2.4-1.el8.i686.rpm gfbgraph-debugsource-0.2.4-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-39358 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.6_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIUAwUBYnqQo9zjgjWX9erEAQgBCg/1Fwf2mE6gsvv5JooolTYZOkhFOP2ReTUV M1pJ1CvEQSNS+InSGyG/k8PFkpVBqZyvAha6W4bcpDR7bJ509QahOh9dXo66KITM BOxdCKQ1tM/gNVr21fGCsT49OAOHmPavDSOEpddjNQxS3heF3nt+QeqYuSTjO6/u u0fMDVYc53dIbspqL14NYyDLyOj3dYEU4dKhcfwPgCKN/vZ/wJYx/54G0eHK1oAI 9+aSTPi8MvsJ3P459Bi2FM+Isw3sNK1xRs18MizPddV88CeCnu+TzdnvTkWF8eqJ FslIpL+x4fbcWxQnsG+l4pMwQtmK+B9wnlRy2MuCRxi/ldFi8RZFkzxPF2DS2tXN rlReCPS9LdhwOVK6jwj4k5+kGp/EBi6/0ArBOmfaAn0RF2FRXwV3dJ/GsTlQHbLc BvM0vSUOp2B26R+9L5nwAMXR0Lby8cdCffBJf7zmy64A39HF1v4I97pCJVpQOvY6 0lI268pnhOqMLW09TSrkckkmS3/Y7SaHDTmtkLsgma6R48KlZocpRfKJ2ITxhHTY L+wx53DdqqKhZZx/gHiu09brDuNYBQnboNY+rXYsaAM/DEfraKeGR/atxgeI3Lk0 npJWsdbGlQs1Oqgrljrog0YSGu87XPwHLNtB1s9qpTLn/wag3y9d0zVvEWbxuMgk SUeerZn01g==ih+e -----END PGP SIGNATURE----- -- RHSA-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. . Oracle Linux announces a critical security patch for appdb addressing buffer overflow vulnerabilities.. gfbgraph Update, Red Hat Security, Moderate Security Advisories. . LinuxSecurity.com Team

Calendar 2 May 10, 2022 Red Hat
203

Mageia 8: MGASA-2021-0530 Moderate: gfbgraph TLS Issue Mitigated

In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. . MGASA-2021-0530 - Updated gfbgraph packages fix security vulnerability Publication date: 02 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0530.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-39358 In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011. References: - https://bugs.mageia.org/show_bug.cgi?id=29577 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/UYI47UX6S5PAOWVWQ2KID64MCTXTH7SE/ - https://www.cve.org/CVERecord?id=CVE-2021-39358 SRPMS: - 8/core/gfbgraph-0.2.4-1.1.mga8 . Mageia 2021-0540 enhances gfbgraph to resolve the TLS certificate validation vulnerability to mitigate MITM threats.. Mageia Update, gfbgraph Security, TLS Issues, Network Security. . LinuxSecurity.com Team

Calendar 2 Dec 02, 2021 Mageia
89

Fedora 35: FEDORA-2021-743a0aafa0 Critical: gfbgraph TLS Security Issue

Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-743a0aafa0 2021-10-29 22:48:33.392435 --------------------------------------------------------------------------------Name : gfbgraph Product : Fedora 35 Version : 0.2.4 Release : 1.fc35 URL : https://wiki.gnome.org/Projects/GFBGraph Summary : GLib/GObject wrapper for the Facebook Graph API Description : GLib/GObject wrapper for the Facebook Graph API that integrates with GNOME Online Accounts. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 12 2021 Debarshi Ray - 0.2.4-1 - Update to 0.2.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1997139 - CVE-2021-39358 gfbgraph: missing TLS certificate verification https://bugzilla.redhat.com/show_bug.cgi?id=1997139 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-743a0aafa0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . This Fedora 35 release addresses CVE-2021-39359 and resolves stability and validation concerns for the gfbutils module.. Fedora Software Update,gfbgraph Security Fix,TLS Verification Fix,Critical Update,Memory Issue Resolution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 29, 2021 Critical Fedora
89

Fedora 33: 2021-9c737bb848 Critical: gfbgraph TLS Verification Issue

Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-9c737bb848 2021-10-20 19:26:10.134732 --------------------------------------------------------------------------------Name : gfbgraph Product : Fedora 33 Version : 0.2.4 Release : 1.fc33 URL : https://wiki.gnome.org/Projects/GFBGraph Summary : GLib/GObject wrapper for the Facebook Graph API Description : GLib/GObject wrapper for the Facebook Graph API that integrates with GNOME Online Accounts. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 12 2021 Debarshi Ray - 0.2.4-1 - Update to 0.2.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1997139 - CVE-2021-39358 gfbgraph: missing TLS certificate verification https://bugzilla.redhat.com/show_bug.cgi?id=1997139 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-9c737bb848' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 33 has received a key security update for gfbgraph, addressing critical vulnerabilities to enhance system integrity and user data protection. gfbgraph Fedora security fix TLS verification memory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 20, 2021 Critical Fedora
89

Fedora 34 FEDORA-2021-7cccd2784c Moderate gfbgraph Memory Issue

Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-7cccd2784c 2021-10-20 19:22:32.242211 --------------------------------------------------------------------------------Name : gfbgraph Product : Fedora 34 Version : 0.2.4 Release : 1.fc34 URL : https://wiki.gnome.org/Projects/GFBGraph Summary : GLib/GObject wrapper for the Facebook Graph API Description : GLib/GObject wrapper for the Facebook Graph API that integrates with GNOME Online Accounts. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-39358, and many other memory, assertion, etc. fixes. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 12 2021 Debarshi Ray - 0.2.4-1 - Update to 0.2.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1997139 - CVE-2021-39358 gfbgraph: missing TLS certificate verification https://bugzilla.redhat.com/show_bug.cgi?id=1997139 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-7cccd2784c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The vulnerabilities CVE-2021-39358 in the gfbgraph package for Fedora 34 have been fixed in the latest updates. Follow these steps to update your system. Fedora Update,gfbgraph,memory Fixes,security Patch,CVE Fixes. . LinuxSecurity.com Team

Calendar 2 Oct 20, 2021 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here