Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9: DLA-2348-1 Critical: php-horde-core XSS Threat

In Horde Groupware, there has been an XSS vulnerability in two components via the Color field in a Create Task List action. For Debian 9 stretch, this problem has been fixed in version . -------------------------------------------------------------------------Debian LTS Advisory DLA-2348-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Mike Gabriel August 29, 2020 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : php-horde-core Version : 2.27.6+debian1-2+deb9u1 CVE ID : CVE-2017-16907 Debian Bug : 909800 In Horde Groupware, there has been an XSS vulnerability in two components via the Color field in a Create Task List action. For Debian 9 stretch, this problem has been fixed in version 2.27.6+debian1-2+deb9u1. We recommend that you upgrade your php-horde-core packages. For the detailed security status of php-horde-core please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-horde-core Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Debian LTS Advisory DLA-2350-1 addresses a critical SQL injection flaw in php-horde-db. Make sure to upgrade your installation promptly.. Debian LTS, php-horde-core, XSS Risk, Task List Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Critical Debian LTS
89

Fedora 21: Vital Security Alert on Zarafa 7.1.12 File Replacement Threat

- Upgrade to 7.1.12 (re-released) - Backported patch from Zarafa 7.2 to fix CVE-2015-3436. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8487 2015-05-19 11:38:29 -------------------------------------------------------------------------------- Name : zarafa Product : Fedora 21 Version : 7.1.12 Release : 2.fc21 URL : https://www.kopano.cloud/ Summary : Open Source Edition of the Zarafa Collaboration Platform Description : The Zarafa Collaboration Platform is a Microsoft Exchange replacement. The Open Source Collaboration provides an integration with your existing Linux mail server, native mobile phone support by ActiveSync compatibility and a webaccess with 'Look & Feel' similar to Outlook using Ajax. Including an IMAP and a POP3 gateway as well as an iCal/CalDAV gateway, the Zarafa Open Source Collaboration can combine the usability with the stability and the flexibility of a Linux server. The proven Zarafa groupware solution is using MAPI objects, provides a MAPI client library as well as programming interfaces for C++, PHP and Python. The other Zarafa related packages need to be installed to gain all features and benefits of the Zarafa Collaboration Platform (ZCP). -------------------------------------------------------------------------------- Update Information: - Upgrade to 7.1.12 (re-released) - Backported patch from Zarafa 7.2 to fix CVE-2015-3436 -------------------------------------------------------------------------------- ChangeLog: * Mon May 18 2015 Robert Scheck 7.1.12-2 - Upgrade to 7.1.12 (re-released) - Backported patch from Zarafa 7.2 to fix CVE-2015-3436 (#1222151) * Tue Apr 7 2015 Robert Scheck 7.1.12-1 - Upgrade to 7.1.12 - Added multiple minor enhancement and bugfix patches - Added patch to fix CVE-2014-0103 for PHP < 5.3 (#1073618) - Handle "su" option in logrotate > = 3.8.0 to avoid errors* Sat Oct 25 2014 Kevin Kofler 7.1.11-2 - Rebuild for reference-counting-enabledclucene09 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1222151 - CVE-2015-3436 zarafa: Overwrite arbitrary files in filesystem https://bugzilla.redhat.com/show_bug.cgi?id=1222151 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update zarafa' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Enhance Zarafa to version 7.1.12, incorporating a backported fix from version 7.2 that addresses the file overwrite vulnerability.. Zarafa Update, Fedora Security, Open Source Collaboration, Linux Mail Server. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 05, 2015 Important Fedora
89

Fedora: 2005-338 Moderate Update: Evolution Groupware Tool

Updated packages.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-338 2005-04-22 ---------------------------------------------------------------------Product : Fedora Core 3 Name : evolution Version : 2.0.4 Release : 4 Summary : GNOME's next-generation groupware suite Description : Evolution is the GNOME mailer, calendar, contact manager and communications tool. The tools which make up Evolution will be tightly integrated with one another and act as a seamless personal information-management tool. ---------------------------------------------------------------------* Fri Apr 22 2005 David Malcolm - 2.0.4-4 - Added the correct patch this time * Wed Apr 20 2005 David Malcolm - 2.0.4-3 - Added patch for #155378 (CAN-2005-0806) - Updated mozilla_build_version from 1.7.6 to 1.7.7 ---------------------------------------------------------------------This update can be downloaded from: d1d9f7e91d2dcabe95b96f17dbc6e955 SRPMS/evolution-2.0.4-4.src.rpm de9c927756f2e3c416c1e90173d64cac x86_64/evolution-2.0.4-4.x86_64.rpm 056c4eec55e773f143426867c488352c x86_64/evolution-devel-2.0.4-4.x86_64.rpm 53767f18bfc52fcac846f1b4f6bde00a x86_64/debug/evolution-debuginfo-2.0.4-4.x86_64.rpm 683dad62220397672ef9449dbb77950a i386/evolution-2.0.4-4.i386.rpm 49a25ecfc03f69b2b218da9a69dc4adb i386/evolution-devel-2.0.4-4.i386.rpm b33c58c7f38880d075352bba8e66e7fc i386/debug/evolution-debuginfo-2.0.4-4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Stay informed on the newest enhancements for Fedora Core 3’s evolution platform, designed to improve your personal data handling and communication capabilities.. Evolution Update,Fedora Core 3,Groupware Suite,Communication Tool,SecurityAdvisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 22, 2005 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here