Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
217

Oracle Linux 8 perl-XML-LibXML Important Out of Bounds Read ELSA-2026-39878

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-39878 http://linux.oracle.com/errata/ELSA-2026-39878.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: perl-XML-LibXML-2.0132-3.el8_10.x86_64.rpm aarch64: perl-XML-LibXML-2.0132-3.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/perl-XML-LibXML-2.0132-3.el8_10.src.rpm Related CVEs: CVE-2026-8177 Description of changes: [1:2.0132-3] - Fix out-of-bounds heap read via truncated UTF-8 in node name validation (CVE-2026-8177) - Resolves: RHEL-186519 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux updates include important security fix for perl-XML-LibXML addressing out-of-bounds read issues.. Oracle Linux, perl XML Library, Security Patch, Important Update, Heap Read Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Important Oracle
203

Mageia Perl-Socket Important Out-of-Bounds Read Risk CVE-2026-12087

Security update. Publication date: 14 Jul 2026 URL: https://advisories.mageia.org/MGASA-2026-0251.html Type: security Affected Mageia releases: 10, 9 CVE: CVE-2026-12087 Description: Socket versions before 2.041 for Perl have an out-of-bounds heap read. (CVE-2026-12087) References: - https://bugs.mageia.org/show_bug.cgi?id=35708 - https://www.openwall.com/lists/oss-security/2026/06/15/10 - https://www.cve.org/CVERecord?id=CVE-2026-12087 SRPMS: - 10/core/perl-Socket-2.41.0-1.mga10 - 9/core/perl-Socket-2.36.0-1.1.mga9 . Perl-Socket update for Mageia fixes out-of-bounds read issue, enhancing system security against potential exploits.. Perl-Socket Security, Mageia Advisory, Out-of-Bounds Read, Heap Issue, System Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important Mageia
202

openSUSE 15.4: 2023:3440-1 Low Severity: Gawk Heap Read Issue

This update for gawk fixes the following issues: CVE-2023-4156: Fix a heap out of bound read by validating the index into argument list. (bsc#1214025). # Security update for gawk Announcement ID: SUSE-SU-2023:3440-1 Rating: low References: * #1214025 Cross-References: * CVE-2023-4156 CVSS scores: * CVE-2023-4156 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP4 * Basesystem Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * openSUSE Leap Micro 5.3 * openSUSE Leap Micro 5.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for gawk fixes the following issues: * CVE-2023-4156: Fix a heap out of bound read by validating the index into argument list. (bsc#1214025) ## Patch Instructions: To install this SUSE Low update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3440=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3440=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3440=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2023-3440=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3440=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2023-3440=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-3440=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2023-3440=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-3440=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-3440=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-3440=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-3440=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3440=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-3440=1 * openSUSE Leap Micro 5.3 zypper in -t patch openSUSE-Leap-Micro-5.3-2023-3440=1 * openSUSE Leap Micro 5.4 zypper in -t patch openSUSE-Leap-Micro-5.4-2023-3440=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Manager Proxy 4.2 (x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Manager Server 4.2 (ppc64le s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro 5.1 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 * openSUSE Leap Micro 5.3 (aarch64 x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 *gawk-debugsource-4.2.1-150000.3.3.1 * openSUSE Leap Micro 5.4 (aarch64 s390x x86_64) * gawk-4.2.1-150000.3.3.1 * gawk-debuginfo-4.2.1-150000.3.3.1 * gawk-debugsource-4.2.1-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-4156.html * https://bugzilla.suse.com/show_bug.cgi?id=1214025 . The curl security patch resolves a significant buffer overflow vulnerability with modifications to enhance data integrity and prevent unauthorized access.. openSUSE Security Update,gawk Patch,Low Severity Vulnerability,Heap Out of Bounds Fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Aug 28, 2023 Low OpenSUSE
202

openSUSE: 2023:3190-1 Minor Issue ImageMagick Buffer Overflow Patch

This update for ImageMagick fixes the following issues: CVE-2023-3745: Fixed heap out of bounds read in PushCharPixel() in quantum- private.h (bsc#1213624).. # Security update for ImageMagick Announcement ID: SUSE-SU-2023:3186-1 Rating: low References: * #1213624 Cross-References: * CVE-2023-3745 CVSS scores: * CVE-2023-3745 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-3745 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2023-3745: Fixed heap out of bounds read in PushCharPixel() in quantum- private.h (bsc#1213624). ## Patch Instructions: To install this SUSE Low update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3186=1 ## Package List: * openSUSE Leap 15.4 (x86_64) * libMagick++-7_Q16HDRI4-32bit-debuginfo-7.0.7.34-150200.10.51.1 * libMagickCore-7_Q16HDRI6-32bit-7.0.7.34-150200.10.51.1 * libMagickWand-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-150200.10.51.1 * libMagick++-7_Q16HDRI4-32bit-7.0.7.34-150200.10.51.1 * libMagickWand-7_Q16HDRI6-32bit-7.0.7.34-150200.10.51.1 * libMagickCore-7_Q16HDRI6-32bit-debuginfo-7.0.7.34-150200.10.51.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI6-debuginfo-7.0.7.34-150200.10.51.1 * libMagick++-7_Q16HDRI4-7.0.7.34-150200.10.51.1 * libMagickCore-7_Q16HDRI6-7.0.7.34-150200.10.51.1 * libMagickWand-7_Q16HDRI6-7.0.7.34-150200.10.51.1 * libMagickCore-7_Q16HDRI6-debuginfo-7.0.7.34-150200.10.51.1 * libMagick++-7_Q16HDRI4-debuginfo-7.0.7.34-150200.10.51.1 ## References: * https://www.suse.com/security/cve/CVE-2023-3745.html *https://bugzilla.suse.com/show_bug.cgi?id=1213624 . The recent ImageMagick patch addresses vulnerabilities linked to buffer overflow errors, bolstering security for Fedora.. ImageMagick Security Fix, openSUSE Update, Heap Read Issue. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Aug 03, 2023 Low OpenSUSE
89

Fedora 29: FEDORA-2019-3377813d18 Moderate: sqlite Out Of Bounds Read

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-3377813d18 2019-08-08 01:53:05.822701 --------------------------------------------------------------------------------Name : sqlite Product : Fedora 29 Version : 3.26.0 Release : 4.fc29 URL : https://sqlite.org/index.html Summary : Library that implements an embeddable SQL database engine Description : SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of use. Applications that link against SQLite can enjoy the power and flexibility of an SQL database without the administrative hassles of supporting a separate database server. Version 2 and version 3 binaries are named to permit each to be installed on a single host --------------------------------------------------------------------------------Update Information: Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting. --------------------------------------------------------------------------------ChangeLog: * Wed Jun 26 2019 Ondrej Dubaj - 3.26.0-4 - Fixed CVE-2019-8457 (#1719121) * Thu May 16 2019 Petr Kubat - 3.26.0-3 - Fixed CVE-2019-9937 (#1692358) - Fixed CVE-2019-9936 (#1692366) * Thu May 16 2019 Petr Kubat - 3.26.0-2 - Fixed CVE-2019-5827 (#1710212) * Mon Dec 17 2018 Petr Kubat - 3.26.0-1 - Updated to version 3.26.0 (https://sqlite.org/releaselog/3_26_0.html) Fixes fts3/4 corrupt database exploit(#1659677) --------------------------------------------------------------------------------References: [ 1 ] Bug #1719121 - CVE-2019-8457 sqlite: sqlite3: heap out-of-bound read in function rtreenode() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1719121 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-3377813d18' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora patch for libpng fixes buffer overflow vulnerability in png_set_filter_function; improves memory management and debugging outputs.. Fedora, SQLite, heap reading, rtreenode function. . LinuxSecurity.com Team

Calendar%202 Aug 07, 2019 Fedora
89

Fedora 30: FEDORA-2019-02b81266b7 Critical: sqlite Heap Read Issue

Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-02b81266b7 2019-07-27 01:39:06.745657 --------------------------------------------------------------------------------Name : sqlite Product : Fedora 30 Version : 3.26.0 Release : 6.fc30 URL : https://sqlite.org/index.html Summary : Library that implements an embeddable SQL database engine Description : SQLite is a C library that implements an SQL database engine. A large subset of SQL92 is supported. A complete database is stored in a single disk file. The API is designed for convenience and ease of use. Applications that link against SQLite can enjoy the power and flexibility of an SQL database without the administrative hassles of supporting a separate database server. Version 2 and version 3 binaries are named to permit each to be installed on a single host --------------------------------------------------------------------------------Update Information: Fixed out of bounds heap read in function rtreenode() Enhance the rtreenode() function of rtree (used for testing) so that it uses the newer sqlite3_str object for better performance and improved error reporting. --------------------------------------------------------------------------------ChangeLog: * Wed Jun 26 2019 Ondrej Dubaj - 3.26.0-6 - Fixed CVE-2019-8457 (#1719121) * Thu May 16 2019 Petr Kubat - 3.26.0-5 - Fixed CVE-2019-9937 (#1692358) - Fixed CVE-2019-9936 (#1692366) * Thu May 16 2019 Petr Kubat - 3.26.0-4 - Fixed CVE-2019-5827 (#1710212) --------------------------------------------------------------------------------References: [ 1 ] Bug #1719121 - CVE-2019-8457 sqlite: sqlite3: heap out-of-bound read in function rtreenode()[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1719121 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-02b81266b7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Correction of out-of-range heap read within sqlite's rtreenode() function to boost efficiency. Update now accessible for Fedora 30 users.. Fedora Update, sqlite Heap Fix, Security Advisory, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 26, 2019 Critical Fedora
202

openSUSE Leap 15.0: 2019:1210-1 Important: Clamav Out-Of-Bounds Fix

An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for clamav ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1210-1 Rating: important References: #1130721 Cross-References: CVE-2019-1787 CVE-2019-1788 CVE-2019-1789 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for clamav to version 0.100.3 fixes the following issues: Security issues fixed (bsc#1130721): - CVE-2019-1787: Fixed an out-of-bounds heap read condition which may occur when scanning PDF documents. - CVE-2019-1789: Fixed an out-of-bounds heap read condition which may occur when scanning PE files (i.e. Windows EXE and DLL files). - CVE-2019-1788: Fixed an out-of-bounds heap write condition which may occur when scanning OLE2 files such as Microsoft Office 97-2003 documents. This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1210=1 Package List: - openSUSE Leap 15.0 (x86_64): clamav-0.100.3-lp150.2.10.1 clamav-debuginfo-0.100.3-lp150.2.10.1 clamav-debugsource-0.100.3-lp150.2.10.1 clamav-devel-0.100.3-lp150.2.10.1 libclamav7-0.100.3-lp150.2.10.1 libclamav7-debuginfo-0.100.3-lp150.2.10.1 libclammspack0-0.100.3-lp150.2.10.1 libclammspack0-debuginfo-0.100.3-lp150.2.10.1 References: https://www.suse.com/security/cve/CVE-2019-1787.html https://www.suse.com/security/cve/CVE-2019-1788.html https://www.suse.com/security/cve/CVE-2019-1789.html https://bugzilla.suse.com/1130721 -- . New update released for clamav on openSUSE Leap 15.0, addressing severe heap read vulnerabilities & improving overall security.. clamav Update, OpenSUSE Security, Heap Read Fix, Out-Of-Bounds Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 16, 2019 Important OpenSUSE
89

Fedora 27: 2017-77f991e537 Moderate: bluez Heap Read Issue

Security fix for CVE-2017-1000250 ---- - This update adds support for cable pairing for PlayStation 3 and 4 controllers. - Add scripts to automatically btattach serial-port / uart connected Broadcom HCIs found on some Atom based x86 hardware. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-77f991e537 2017-09-30 05:57:53.246725 --------------------------------------------------------------------------------Name : bluez Product : Fedora 27 Version : 5.46 Release : 6.fc27 URL : Summary : Bluetooth utilities Description : Utilities for use in Bluetooth applications: - hcitool - hciattach - hciconfig - bluetoothd - l2ping - rfcomm - sdptool - bccmd - bluetoothctl - btmon - hcidump - l2test - rctest - gatttool - start scripts (Red Hat) - pcmcia configuration files The BLUETOOTH trademarks are owned by Bluetooth SIG, Inc., U.S.A. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-1000250 ---- - This update adds support for cable pairing for PlayStation 3 and 4 controllers. - Add scripts to automatically btattach serial-port / uart connected Broadcom HCIs found on some Atom based x86 hardware --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1489446 - CVE-2017-1000250 bluez: Out-of-bounds heap read in service_search_attr_req function https://bugzilla.redhat.com/show_bug.cgi?id=1489446 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bluez' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Significant patch for Fedora 27 addressing a heap leak vulnerability in bluez. Introduces compatibility for PlayStation gamepads.. Fedora 27 Update,Bluetooth Utilities,Security Fix,PlayStation Controllers. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 30, 2017 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200