Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 7 MGASA-2020-0314 Security Advisory: glib-networking TLS Issue

The updated packages fix a security vulnerability: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected . MGASA-2020-0314 - Updated glib-networking packages fix security vulnerability Publication date: 16 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0314.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13645 The updated packages fix a security vulnerability: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server identity, including Balsa before 2.5.11 and 2.6.x before 2.6.1, accept a TLS certificate if the certificate is valid for any host. (CVE-2020-13645) References: - https://bugs.mageia.org/show_bug.cgi?id=26819 - https://www.cve.org/CVERecord?id=CVE-2020-13645 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/TQEQJQ4XFMFCFJTEXKL2ZO3UELBPCKSK/ - https://ubuntu.com/security/notices/USN-4405-1 - https://www.cve.org/CVERecord?id=CVE-2020-13645 SRPMS: - 7/core/glib-networking-2.60.2-1.1.mga7 . Security alert MGASA-2020-0314 has been issued regarding a glib-networking vulnerability impacting Mageia 7 that raises concerns about TLS certificate management.. glib-networking vulnerability,Mageia TLS certificate,security update,Mageia security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 16, 2020 Critical Mageia
203

Mageia: 2020-0263 Moderate: Axel TLS Implementation Missing Hostname Check

Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification (CVE-2020-13614). The axel package has been updated to version 2.17.8, fixing this issue and other bugs. . MGASA-2020-0263 - Updated axel packages fix security vulnerability Publication date: 15 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0263.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13614 Updated axel package fixes security vulnerability: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification (CVE-2020-13614). The axel package has been updated to version 2.17.8, fixing this issue and other bugs. References: - https://bugs.mageia.org/show_bug.cgi?id=26754 - https://github.com/axel-download-accelerator/axel/releases/ - - https://www.cve.org/CVERecord?id=CVE-2020-13614 SRPMS: - 7/core/axel-2.17.8-2.mga7 . Revised xylophone components resolve a security flaw involving certificate hostname checks. Launched on July 20, 2021.. Mageia Package Update, Axel Security Fix, TLS Hostname Verification, Software Vulnerability Resolution. . LinuxSecurity.com Team

Calendar 2 Jun 15, 2020 Mageia
89

Fedora 22 FEDORA-2015-10235 Critical: OpenSAML Java Hostname Verification

* OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-10235 2015-06-20 13:37:02 -------------------------------------------------------------------------------- Name : opensaml-java-openws Product : Fedora 22 Version : 1.5.5 Release : 2.fc22 URL : / Summary : Java OpenWS library Description : The OpenWS library provides a growing set of tools to work with web services at a low level. These tools include classes for creating and reading SOAP messages, transport-independent clients for connecting to web services, and various transports for use with those clients. -------------------------------------------------------------------------------- Update Information: * OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification -------------------------------------------------------------------------------- ChangeLog: * Tue Jun 16 2015 Marek Goldmann - 1.5.5-2 - Use mvn BR for tomcat API * Fri May 8 2015 Marek Goldmann - 1.5.5-1 - Upstream release 1.5.5 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1131823 - CVE-2014-3603 OpenSAML Java: HTTPS Connections Via HTTP Resources Do Not Perform Hostname Verification https://bugzilla.redhat.com/show_bug.cgi?id=1131823 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update opensaml-java-openws' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . This modification resolves the OpenSAML Java concern regarding the absence of hostname verification for HTTPS connections stemming from HTTP resources.. OpenSAML, Fedora 22, Java, hostname, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 07, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here