Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
197

Debian: DLA-3745-1 Critical: gSOAP DoS and Code Execution Risks

Multiple vulnerabilities have been fixed in the gSOAP toolkit for developing Web services. CVE-2020-13574 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3745-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk February 29, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : gsoap Version : 2.8.75-1+deb10u1 CVE ID : CVE-2020-13574 CVE-2020-13575 CVE-2020-13576 CVE-2020-13577 CVE-2020-13578 Debian Bug : 983596 Multiple vulnerabilities have been fixed in the gSOAP toolkit for developing Web services. CVE-2020-13574 WS-Security plugin denial-of-service CVE-2020-13575 WS-Addressing plugin denial-of-service CVE-2020-13576 WS-Addressing plugin code execution CVE-2020-13577 WS-Security plugin denial-of-service CVE-2020-13578 WS-Security plugin denial-of-service For Debian 10 buster, these problems have been fixed in version 2.8.75-1+deb10u1. We recommend that you upgrade your gsoap packages. For the detailed security status of gsoap please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/gsoap Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Recent security threats linked to the gSOAP toolkit could result in serious service disruptions and heightened risks. Urgent updates for Debian systems are essential. gSOAP Security Update, Debian LTS Advisory, Denial of Service, Code Execution Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 29, 2024 Critical Debian LTS
203

Mageia: 2021-0263 Moderate: gSOAP Denial Of Service and Remote Execution

A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13574). . MGASA-2021-0263 - Updated gsoap packages fix security vulnerabilities Publication date: 16 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0263.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-13574, CVE-2020-13575, CVE-2020-13576, CVE-2020-13577, CVE-2020-13578 A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13574). A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13575). A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13576). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13577). A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability (CVE-2020-13578). References: - https://bugs.mageia.org/show_bug.cgi?id=29015 - https://www.cve.org/CVERecord?id=CVE-2020-13574 - https://www.cve.org/CVERecord?id=CVE-2020-13575 -https://www.cve.org/CVERecord?id=CVE-2020-13576 - https://www.cve.org/CVERecord?id=CVE-2020-13577 - https://www.cve.org/CVERecord?id=CVE-2020-13578 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/SMTJ3SJJ22SFLBLPKFADV7NVBH7UFA23/ - https://www.cve.org/CVERecord?id=CVE-2020-13574 - https://www.cve.org/CVERecord?id=CVE-2020-13575 - https://www.cve.org/CVERecord?id=CVE-2020-13576 - https://www.cve.org/CVERecord?id=CVE-2020-13577 - https://www.cve.org/CVERecord?id=CVE-2020-13578 SRPMS: - 8/core/gsoap-2.8.104-1.1.mga8 - 7/core/gsoap-2.8.67-2.1.mga7 . Mageia 2021-0299 releases updates for libcurl to mitigate potential vulnerabilities related to unauthorized access and data breaches.. Denial Of Service, Gsoap, Security Update, Mageia Advisory, Remote Execution. . LinuxSecurity.com Team

Calendar 2 Jun 16, 2021 Mageia
202

openSUSE: 2021:0665-1 Critical gsoap Vulnerability Remedy

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gsoap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0664-1 Rating: important References: #1182098 Cross-References: CVE-2020-13576 CVSS scores: CVE-2020-13576 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gsoap fixes the following issues: - CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-664=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): gsoap-devel-2.8.102-bp152.2.4.1 libgsoap-2_8_102-2.8.102-bp152.2.4.1 - openSUSE Backports SLE-15-SP2 (noarch): gsoap-doc-2.8.102-bp152.2.4.1 References: https://www.suse.com/security/cve/CVE-2020-13576.html https://bugzilla.suse.com/1182098 . This software patch for gsoap resolves a significant remote exploitation vulnerability in openSUSE Backports.. openSUSE Security,gsoap Update,Critical Flaw Fix,Remote Code Execution. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 04, 2021 Important OpenSUSE
202

openSUSE Leap 15.2 OpenSUSE-SU-2021:0632-1 Critical: gsoap Remote Code Exec

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for gsoap ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0632-1 Rating: important References: #1182098 Cross-References: CVE-2020-13576 CVSS scores: CVE-2020-13576 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for gsoap fixes the following issues: - CVE-2020-13576: Fixed a remote code execution via specially crafted SOAP request inside the WS-Addressing plugin (boo#1182098) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-632=1 Package List: - openSUSE Leap 15.2 (x86_64): gsoap-debuginfo-2.8.102-lp152.2.3.1 gsoap-debugsource-2.8.102-lp152.2.3.1 gsoap-devel-2.8.102-lp152.2.3.1 gsoap-devel-debuginfo-2.8.102-lp152.2.3.1 libgsoap-2_8_102-2.8.102-lp152.2.3.1 libgsoap-2_8_102-debuginfo-2.8.102-lp152.2.3.1 - openSUSE Leap 15.2 (noarch): gsoap-doc-2.8.102-lp152.2.3.1 References: https://www.suse.com/security/cve/CVE-2020-13576.html https://bugzilla.suse.com/1182098 . A vital security patch for gsoap on openSUSE addresses a remote code execution flaw recognized as CVE-2020-13576.. openSUSE Security,gsoap Remote Code Execution,Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 30, 2021 Important OpenSUSE
89

Fedora 34: 2021-1da151722e Critical: gSOAP Multiple Fixes Report

Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1da151722e 2021-03-19 19:51:22.366602 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 34 Version : 2.8.104 Release : 4.fc34 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 8 2021 Mattias Ellert - 2.8.104-4 - Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1da151722e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Unveil the Fedora 34 gSOAP security bulletin, addressing several vulnerabilities to ensure improved protection.. gSOAP Update,Fedora Advisory,Software Fixes,Security Updates,Threat Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 19, 2021 Critical Fedora
89

Fedora 33: 2021-faea36a9c3 Critical: gsoap Security Fix

Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-faea36a9c3 2021-03-17 02:17:03.380896 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 33 Version : 2.8.104 Release : 4.fc33 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 --------------------------------------------------------------------------------ChangeLog: * Mon Mar 8 2021 Mattias Ellert - 2.8.104-4 - Backporting upstream fixes - Fixes CVE: CVE-2020-13574 CVE-2020-13575 CVE-2020-13577 CVE-2020-13578 - Fixes CVE: CVE-2020-13576 * Tue Jan 26 2021 Fedora Release Engineering - 2.8.104-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-faea36a9c3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Essential security patch for Fedora 33 gsoap library resolves several vulnerabilities. Update immediately to maintain protection.. Fedora Security Update,gSOAP Toolkit Fixes,SOAP/XML Development,Security Patch Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 16, 2021 Critical Fedora
89

Fedora 27 gSOAP Critical Update: DIME Protocol Receiver Fix

This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b7a613ea5d 2018-04-27 23:35:59.891088 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 27 Version : 2.8.49 Release : 4.fc27 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html --------------------------------------------------------------------------------ChangeLog: * Wed Apr 18 2018 Mattias Ellert - 2.8.49-4 - Fix issue with DIME protocol receiver and malformed DIME headers --------------------------------------------------------------------------------References: [ 1 ] Bug #1568930 - gsoap: Infinite loop on malformed DIME protocol messages [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1568930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-b7a613ea5d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential gSOAP upgrade for Fedora resolves DIME protocol vulnerabilities to avert receiver hang-ups. Discover further details here.. gsoap,Fedora Updates,DIME Protocol,Critical Fix,Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 27, 2018 Critical Fedora
89

Fedora 27: FEDORA-2018-b7a613ea5d Critical: gsoap DIME Issue

This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b7a613ea5d 2018-04-27 23:35:59.891088 --------------------------------------------------------------------------------Name : gsoap Product : Fedora 27 Version : 2.8.49 Release : 4.fc27 URL : https://www.genivia.com/dev.html Summary : Generator Tools for Coding SOAP/XML Web Services in C and C++ Description : The gSOAP Web services development toolkit offers an XML to C/C++ language binding to ease the development of SOAP/XML Web services in C and C/C++. --------------------------------------------------------------------------------Update Information: This patch addresses a critical issue with the DIME protocol receiver that may cause the receiver to become unresponsive when a malformed DIME protocol message is received. -- https://www.genivia.com/advisory.html --------------------------------------------------------------------------------ChangeLog: * Wed Apr 18 2018 Mattias Ellert - 2.8.49-4 - Fix issue with DIME protocol receiver and malformed DIME headers --------------------------------------------------------------------------------References: [ 1 ] Bug #1568930 - gsoap: Infinite loop on malformed DIME protocol messages [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1568930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-b7a613ea5d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential gsoap update for Fedora 27 tackling DIME protocol handling problems and risk of freezing.. gsoap security update,DIME receiver issue,Fedora software fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 27, 2018 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here