It was discovered that the uv_getaddrinfo() function in libuv, an asynchronous event notification library, incorrectly truncated certain hostnames, which may result in bypass of security measures on internal APIs or SSRF attacks. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5638-1
e2guardian did not validate TLS hostnames (CVE-2021-44273) References: - https://bugs.mageia.org/show_bug.cgi?id=29811 - https://www.openwall.com/lists/oss-security/2021/12/23/2 . MGASA-2021-0594 - Updated e2guardian packages fix security vulnerability Publication date: 30 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0594.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-44273 e2guardian did not validate TLS hostnames (CVE-2021-44273) References: - https://bugs.mageia.org/show_bug.cgi?id=29811 - https://www.openwall.com/lists/oss-security/2021/12/23/2 - https://www.cve.org/CVERecord?id=CVE-2021-44273 SRPMS: - 8/core/e2guardian-5.3.4-1.1.mga8 . The recent e2guardian release addresses a critical TLS hostname validation vulnerability, bolstering the security of Mageia 8. For further details, refer to our advisory.. Mageia Security Update, e2guardian TLS Fix, Mageia Advisory 2021, Hostname Validation, Security Patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.