Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for go1.19-openssl fixes the following issues: Update to version 1.19.13 (bsc#1200441).. # Security update for go1.19-openssl Announcement ID: SUSE-SU-2023:3841-1 Rating: important References: * #1200441 * #1213229 * #1213880 * #1215090 Cross-References: * CVE-2023-29406 * CVE-2023-29409 CVSS scores: * CVE-2023-29406 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2023-29406 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2023-29409 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-29409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP4 * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities and has two security fixes can now be installed. ## Description: This update for go1.19-openssl fixes the following issues: Update to version 1.19.13 (bsc#1200441). * CVE-2023-29409: Fixed unrestricted RSA keys in certificates (bsc#1213880). * CVE-2023-29406: Fixed insufficient sanitization of Host header (bsc#1213229). The following non-security bug was fixed: * Add missing directory pprof html asset directory to package (bsc#1215090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-3841=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-3841=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-3841=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-3841=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * go1.19-openssl-doc-1.19.13.1-150000.1.8.1 * go1.19-openssl-1.19.13.1-150000.1.8.1 * go1.19-openssl-race-1.19.13.1-150000.1.8.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * go1.19-openssl-doc-1.19.13.1-150000.1.8.1 * go1.19-openssl-1.19.13.1-150000.1.8.1 * go1.19-openssl-race-1.19.13.1-150000.1.8.1 * Development Tools Module 15-SP4 (aarch64 ppc64le s390x x86_64) * go1.19-openssl-doc-1.19.13.1-150000.1.8.1 * go1.19-openssl-1.19.13.1-150000.1.8.1 * go1.19-openssl-race-1.19.13.1-150000.1.8.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * go1.19-openssl-doc-1.19.13.1-150000.1.8.1 * go1.19-openssl-1.19.13.1-150000.1.8.1 * go1.19-openssl-race-1.19.13.1-150000.1.8.1 ## References: * https://www.suse.com/security/cve/CVE-2023-29406.html * https://www.suse.com/security/cve/CVE-2023-29409.html * https://bugzilla.suse.com/show_bug.cgi?id=1200441 * https://bugzilla.suse.com/show_bug.cgi?id=1213229 * https://bugzilla.suse.com/show_bug.cgi?id=1213880 * https://bugzilla.suse.com/show_bug.cgi?id=1215090 . The recent release of go1.19-openssl addresses severe vulnerabilities, such as improper key management and inadequate host header validation.. SUSE OpenSSL Fixes, Security Update, Development Tools Module, Go1.19 OpenSSL, SUSE Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-Twisted ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4000-1 Rating: low References: #1204781 Cross-References: CVE-2022-39348 CVSS scores: CVE-2022-39348 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2022-39348 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.3 SUSE Manager Retail Branch Server 4.3 SUSE Manager Server 4.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Twisted fixes the following issues: - CVE-2022-39348: Fixed NameVirtualHost Host header injection (bsc#1204781). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-4000=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-4000=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): python-Twisted-doc-22.2.0-150400.5.7.1 python3-Twisted-22.2.0-150400.5.7.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (aarch64 ppc64le s390x x86_64): python3-Twisted-22.2.0-150400.5.7.1 References: https://www.suse.com/security/cve/CVE-2022-39348.html https://bugzilla.suse.com/1204781 . Resolving a vulnerability in python-Twisted, this revision improves the security of SUSE environments.. SUSE Update, python-Twisted, Host Header Injection, Security Fix. . Severity: Low. LinuxSecurity.com Team
Several security issues were fixed in Django.. =========================================================================Ubuntu Security Notice USN-1757-1 March 07, 2013 python-django vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: James Kettle discovered that Django did not properly filter the Host HTTP header when processing certain requests. An attacker could exploit this to generate and display arbitrary URLs to users. Although this issue had been previously addressed in USN-1632-1, this update adds additional hardening measures to host header validation. This update also adds a new ALLOWED_HOSTS setting that can be set to a list of acceptable values for headers. (CVE-2012-4520) Orange Tsai discovered that Django incorrectly performed permission checks when displaying the history view in the admin interface. An administrator could use this flaw to view the history of any object, regardless of intended permissions. (CVE-2013-0305) It was discovered that Django incorrectly handled a large number of forms when generating formsets. An attacker could use this flaw to cause Django to consume memory, resulting in a denial of service. (CVE-2013-0306) It was discovered that Django incorrectly deserialized XML. An attacker could use this flaw to perform entity-expansion and external-entity/DTD attacks. This updated modified Django behaviour to no longer allow DTDs, perform entity expansion, or fetch external entities/DTDs. (CVE-2013-1664, CVE-2013-1665) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: python-django 1.4.1-2ubuntu0.3 Ubuntu12.04 LTS: python-django 1.3.1-4ubuntu1.6 Ubuntu 11.10: python-django 1.3-2ubuntu1.6 Ubuntu 10.04 LTS: python-django 1.1.1-2ubuntu1.8 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1757-1 CVE-2012-4520, CVE-2013-0305, CVE-2013-0306, CVE-2013-1664, CVE-2013-1665 Package Information: https://launchpad.net/ubuntu/+source/python-django/1.4.1-2ubuntu0.3 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.6 https://launchpad.net/ubuntu/+source/python-django/1.3-2ubuntu1.6 https://launchpad.net/ubuntu/+source/python-django/1.1.1-2ubuntu1.8 . Django has released security patches that rectify several vulnerabilities. The update guidelines are provided for numerous Ubuntu distributions.. Django Security Updates, Python-Django Issues, Ubuntu Vulnerability Fixes. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.