Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 33: Critical Update Released for Chromium Heap and Stack Issues

Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa764a8531 2021-02-28 17:25:31.286237 --------------------------------------------------------------------------------Name : chromium Product : Fedora 33 Version : 88.0.4324.182 Release : 1.fc33 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Update to 88.0.4324.182. Fixes CVE-2021-21149 CVE-2021-21150 CVE-2021-21151 CVE-2021-21152 CVE-2021-21153 CVE-2021-21154 CVE-2021-21155 CVE-2021-21156 CVE-2021-21157 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 17 2021 Tom Callaway - 88.0.4234.182-1 - update to 88.0.4234.182 --------------------------------------------------------------------------------References: [ 1 ] Bug #1929523 - CVE-2021-21149 chromium-browser: Stack overflow in Data Transfer https://bugzilla.redhat.com/show_bug.cgi?id=1929523 [ 2 ] Bug #1929524 - CVE-2021-21150 chromium-browser: Use after free in Downloads https://bugzilla.redhat.com/show_bug.cgi?id=1929524 [ 3 ] Bug #1929525 - CVE-2021-21151 chromium-browser: Use after free in Payments https://bugzilla.redhat.com/show_bug.cgi?id=1929525 [ 4 ] Bug #1929526 - CVE-2021-21152 chromium-browser: Heap buffer overflow in Media https://bugzilla.redhat.com/show_bug.cgi?id=1929526 [ 5 ] Bug #1929527 - CVE-2021-21153 chromium-browser: Stack overflow in GPU Process https://bugzilla.redhat.com/show_bug.cgi?id=1929527 [ 6 ] Bug #1929528 - CVE-2021-21154 chromium-browser: Heap bufferoverflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929528 [ 7 ] Bug #1929529 - CVE-2021-21155 chromium-browser: Heap buffer overflow in Tab Strip https://bugzilla.redhat.com/show_bug.cgi?id=1929529 [ 8 ] Bug #1929530 - CVE-2021-21156 chromium-browser: Heap buffer overflow in V8 https://bugzilla.redhat.com/show_bug.cgi?id=1929530 [ 9 ] Bug #1929531 - CVE-2021-21157 chromium-browser: Use after free in Web Sockets https://bugzilla.redhat.com/show_bug.cgi?id=1929531 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa764a8531' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The Fedora team has released an update for Chromium version 88.0.4324.182, which mitigates various security vulnerabilities found in the browser.. Fedora Update, Chromium Update, Open Source Browser Version, Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 28, 2021 Critical Fedora
89

Fedora 23: 2016-54f85ec6e8 Critical: nghttp2 Heap Use-After-Free Fix

- update to nghttp2-1.6.0 (fixes CVE-2015-8659). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-54f85ec6e8 2016-01-07 16:45:29.292971 -------------------------------------------------------------------------------- Name : nghttp2 Product : Fedora 23 Version : 1.6.0 Release : 1.fc23 URL : https://nghttp2.org/ Summary : Experimental HTTP/2 client, server and proxy Description : This package contains the HTTP/2 client, server and proxy programs. -------------------------------------------------------------------------------- Update Information: - update to nghttp2-1.6.0 (fixes CVE-2015-8659) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1295351 - CVE-2015-8659 nghttp2: heap-use-after-free flaw in idle stream handling code https://bugzilla.redhat.com/show_bug.cgi?id=1295351 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update nghttp2' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Debian patch 2023-64g5hjk7l1 rectifies buffer issue in libcurl, improving performance and safety for HTTP requests.. nghttp2 Update, Fedora Security, HTTP/2 Client, Software Fix, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 07, 2016 Critical Fedora
200

Scientific Linux: Important Netpbm Security Alert for Buffer Overflow

Important: netpbm security update. Date: Tue, 13 Dec 2011 08:14:57 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 5x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: acpid-1.0.4-12.el5.i386.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm sos-1.7-9.54.el5_7.1.noarch.rpm x86_64: acpid-1.0.4-12.el5.x86_64.rpm gtk2-2.10.4-21.el5_7.7.i386.rpm gtk2-2.10.4-21.el5_7.7.x86_64.rpm gtk2-devel-2.10.4-21.el5_7.7.i386.rpm gtk2-devel-2.10.4-21.el5_7.7.x86_64.rpm sos-1.7-9.54.el5_7.1.noarch.rpm Date: Tue, 13 Dec 2011 11:08:42 -0600 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: netpbm on SL4.x, SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Important: netpbm security update Issue Date: 2011-12-12 CVE Numbers: CVE-2009-4274 CVE-2011-4516 The netpbm packages contain a library of functions which support programs for handling various graphics file formats, including.pbm (Portable Bit Map),.pgm (Portable Gray Map),.pnm (Portable Any Map),.ppm (Portable Pixel Map), and others. Two heap-based buffer overflow flaws were found in the embedded JasPer library, which is used to provide support for Part 1 of the JPEG 2000 image compression standard in the jpeg2ktopam and pamtojpeg2k tools. An attacker could create a malicious JPEG 2000 compressed image file that could cause jpeg2ktopam to crash or, potentially, execute arbitrary code with the privileges of the user running jpeg2ktopam. These flaws do not affect pamtojpeg2k. (CVE-2011-4516, CVE-2011-4517) A stack-based buffer overflow flaw was found in the way the xpmtoppm tool processed X PixMap (XPM) image files. An attacker could create a malicious XPM file that would cause xpmtoppm to crash or, potentially, execute arbitrary code with the privileges of the user runningxpmtoppm. (CVE-2009-4274) All users of netpbm are advised to upgrade to these updated packages, which contain backported patches to correct these issues. SL4: i386 netpbm-10.35.58-8.el4.i386.rpm netpbm-debuginfo-10.35.58-8.el4.i386.rpm netpbm-devel-10.35.58-8.el4.i386.rpm netpbm-progs-10.35.58-8.el4.i386.rpm x86_64 netpbm-10.35.58-8.el4.i386.rpm netpbm-10.35.58-8.el4.x86_64.rpm netpbm-debuginfo-10.35.58-8.el4.i386.rpm netpbm-debuginfo-10.35.58-8.el4.x86_64.rpm netpbm-devel-10.35.58-8.el4.x86_64.rpm netpbm-progs-10.35.58-8.el4.x86_64.rpm SL5: i386 netpbm-10.35.58-8.el5_7.3.i386.rpm netpbm-debuginfo-10.35.58-8.el5_7.3.i386.rpm netpbm-devel-10.35.58-8.el5_7.3.i386.rpm netpbm-progs-10.35.58-8.el5_7.3.i386.rpm x86_64 netpbm-10.35.58-8.el5_7.3.i386.rpm netpbm-10.35.58-8.el5_7.3.x86_64.rpm netpbm-debuginfo-10.35.58-8.el5_7.3.i386.rpm netpbm-debuginfo-10.35.58-8.el5_7.3.x86_64.rpm netpbm-devel-10.35.58-8.el5_7.3.i386.rpm netpbm-devel-10.35.58-8.el5_7.3.x86_64.rpm netpbm-progs-10.35.58-8.el5_7.3.x86_64.rpm - Scientific Linux Development Team . Urgent netpbm security patch released for Scientific Linux to mitigate buffer overflow vulnerabilities jeopardizing JPEG handling.. netpbm security update, Scientific Linux netpbm, buffer overflow vulnerability, heap and stack flaws. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 13, 2011 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here