Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 9 MGASA-2024-0314 Critical gnome-shell JavaScript Threat

In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the . MGASA-2024-0314 - Updated gnome-shell packages fix security vulnerability Publication date: 27 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0314.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-36472 In GNOME Shell through 45.7, a portal helper can be launched automatically (without user confirmation) based on network responses provided by an adversary (e.g., an adversary who controls the local Wi-Fi network), and subsequently loads untrusted JavaScript code, which may lead to resource consumption or other impacts depending on the JavaScript code's behavior. (CVE-2024-36472) References: - https://bugs.mageia.org/show_bug.cgi?id=33434 - https://lists.suse.com/pipermail/sle-updates/2024-July/036098.html - https://ubuntu.com/security/notices/USN-6963-1 - https://www.cve.org/CVERecord?id=CVE-2024-36472 SRPMS: - 9/core/gnome-shell-44.2-1.2.mga9 . Revised gnome-shell updates for Mageia address security vulnerabilities and resource concerns. Release date: 27 Sep 2024.. Gnome Shell Security,Mageia Advisory,JavaScript Threats,Network Vulnerabilities,Resource Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 27, 2024 Critical Mageia
203

Mageia 9 MGASA-2023-0311 Critical: Gnome Shell Local Access Risk

The updated packages fix a security vulnerability: GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. . MGASA-2023-0311 - Updated gnome-shell packages fix a security vulnerability Publication date: 09 Nov 2023 URL: https://advisories.mageia.org/MGASA-2023-0311.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-43090 The updated packages fix a security vulnerability: GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. (CVE-2023-43090) References: - https://bugs.mageia.org/show_bug.cgi?id=32320 - https://ubuntu.com/security/notices/USN-6395-1 - https://www.cve.org/CVERecord?id=CVE-2023-43090 SRPMS: - 9/core/gnome-shell-44.2-1.1.mga9 . Revised gnome-shell installations address a vulnerability affecting local session entry. Important specifics outlined.. Gnome Shell Security Update, Mageia Security Advisory, Local User Access Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 09, 2023 Critical Mageia
172

Ubuntu 23.04 USN-6395-1 Low Severity: GNOME Shell Local Threat

GNOME Shell could be made to expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-6395-1 September 21, 2023 gnome-shell vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 Summary: GNOME Shell could be made to expose sensitive information. Software Description: - gnome-shell: graphical shell for the GNOME desktop Details: Mickael Karatekin discovered that GNOME Shell incorrectly allowed the screenshot tool to view open windows when a session was locked. A local attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: gnome-shell 44.3-0ubuntu1.1 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6395-1 CVE-2023-43090 Package Information: https://launchpad.net/ubuntu/+source/gnome-shell/44.3-0ubuntu1.1 . The Ubuntu Security Advisory USN-6396-1 highlights a vulnerability in the GNOME Desktop environment that may lead to unauthorized data exposure, necessitating immediate updates.. GNOME Shell, Security Update, Sensitive Information, Local Attack, Ubuntu Security Notice. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Sep 21, 2023 Low Ubuntu
91

Gentoo: GLSA-202208-33 Normal: Gnome Shell Denial Of Service

A vulnerability has been found in libcroco which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Gnome Shell, gettext, libcroco: Multiple Vulnerabilities Date: August 21, 2022 Bugs: #722752, #755848, #769998 ID: 202208-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in libcroco which could result in denial of service. Background ========= GNOME Shell provides core user interface functions for the GNOME desktop, like switching to windows and launching applications. gettext contains the GNU locale utilities. libcroco is a standalone CSS2 parsing and manipulation library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libcroco < 0.6.13 > = 0.6.13 2 gnome-base/gnome-shell < 3.36.7 > = 3.36.7 3 sys-devel/gettext < 0.21 > = 0.21 Description ========== The cr_parser_parse_any_core function in libcroco's cr-parser.c does not limit recursion, leading to a denial of service via a stack overflow when trying to parse crafted CSS. Gnome Shell and gettext bundle libcroco in their own sources and thus are potentially vulnerable as well. Impact ===== An attacker with control over the input to the library can cause a denial of service. Workaround ========= There is no known workaround at this time. Resolution ========= All gettext users should upgrade tothe latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-devel/gettext-0.21" All Gnome Shell users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =gnome-base/gnome-shell-3.36.7" All libcroco users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libcroco-0.6.13" References ========= [ 1 ] CVE-2020-12825 https://nvd.nist.gov/vuln/detail/CVE-2020-12825 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-33 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Alert: Critical security flaws discovered in Gnome Shell, gettext, and libcroco pose risks of denial of service to Gentoo users.. Gentoo Security Advisory, Gnome Shell, libcroco, denial of service, gettext. . LinuxSecurity.com Team

Calendar 2 Aug 20, 2022 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here