Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 33 Kiwix-Desktop Moderate HTTP Security Patch FEDORA-2021-aa347d2b99

Always use HTTPS for the catalog downloads.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-aa347d2b99 2021-02-19 01:13:24.060184 --------------------------------------------------------------------------------Name : kiwix-desktop Product : Fedora 33 Version : 2.0.5 Release : 3.fc33 URL : https://github.com/kiwix/kiwix-desktop Summary : Kiwix desktop application Description : The Kiwix-desktop is a view/manager of zim files for GNU/Linux and Windows. You can download and view your zim files as you which. --------------------------------------------------------------------------------Update Information: Always use HTTPS for the catalog downloads. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 10 2021 Vitaly Zaitsev - 2.0.5-3 - Always use HTTPS for the catalog downloads. * Tue Jan 26 2021 Fedora Release Engineering - 2.0.5-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1927413 - kiwix: library catalog downloaded over HTTP https://bugzilla.redhat.com/show_bug.cgi?id=1927413 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-aa347d2b99' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Kiwix-desktop update for Fedora 33 boosts security for users by enhancing HTTPS for catalog downloads. Discover more!. Kiwix Update,Fedora 33 Security,HTTPS Downloads. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Feb 18, 2021 moderate Fedora
200

Scientific Linux SL4: Important Security Update for SeaMonkey

Important: seamonkey security update. Date: Thu, 8 Sep 2011 09:57:46 -0500 Reply-To: "Tyler L. Parsons" Sender: Security Errata for Scientific Linux From: "Tyler L. Parsons" Subject: Security ERRATA Important: seamonkey on SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Important: seamonkey security update Issue Date: 2011-09-06 SeaMonkey is an open source web browser, email and newsgroup client, IRC chat client, and HTML editor. A previous SeaMonkey update rendered HTTPS certificates signed by a certain Certificate Authority (CA) as untrusted, but made an exception for a select few. This update removes that exception, rendering every HTTPS certificate signed by that CA as untrusted. All SeaMonkey users should upgrade to these updated packages, which correct this issue. After installing the update, SeaMonkey must be restarted for the changes to take effect. SL4: i386 seamonkey-1.0.9-75.el4.i386.rpm seamonkey-mail-1.0.9-75.el4.i386.rpm seamonkey-js-debugger-1.0.9-75.el4.i386.rpm seamonkey-dom-inspector-1.0.9-75.el4.i386.rpm seamonkey-devel-1.0.9-75.el4.i386.rpm seamonkey-debuginfo-1.0.9-75.el4.i386.rpm seamonkey-chat-1.0.9-75.el4.i386.rpm x86_64 seamonkey-js-debugger-1.0.9-75.el4.x86_64.rpm seamonkey-dom-inspector-1.0.9-75.el4.x86_64.rpm seamonkey-devel-1.0.9-75.el4.x86_64.rpm seamonkey-debuginfo-1.0.9-75.el4.x86_64.rpm seamonkey-chat-1.0.9-75.el4.x86_64.rpm seamonkey-1.0.9-75.el4.x86_64.rpm seamonkey-mail-1.0.9-75.el4.x86_64.rpm - Scientific Linux Development Team . Crucial SeamMonkey security patch for Scientific Linux SL4 resolves HTTPS certificate validity concerns.. SeaMonkey Security Update, Scientific Linux, HTTPS Trust Issues, SL4 Errata. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 08, 2011 Important Scientific Linux
87

Debian: DSA-2203-1 Moderate: NSS HTTPS Certificates Untrusted

This update for the Network Security Service libraries marks several fraudulent HTTPS certificates as unstrusted. For the oldstable distribution (lenny), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2203-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 26, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss Vulnerability : none in nss Problem type : none in nss Debian-specific: no CVE ID : not available This update for the Network Security Service libraries marks several fraudulent HTTPS certificates as unstrusted. For the oldstable distribution (lenny), this problem has been fixed in version 3.12.3.1-0lenny4. For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 3.12.9.with.ckbi.1.82-1. We recommend that you upgrade your nss packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest NSS libraries now classify fake HTTPS certificates as untrustworthy. To improve security, please update your Debian package installations.. Debian Security,NSS Updates,HTTPS Certificates. . LinuxSecurity.com Team

Calendar%202 Mar 26, 2011 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200