Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
87

Debian DSA-4922-1 Moderate: Hyperkitty Import Visibility Issue

Amir Sarabadani and Kunal Mehta discovered that the import functionality of Hyperkitty, the web user interface to access Mailman 3 archives, did not restrict the visibility of private archives during the import, i.e. that during the import of a private Mailman 2 archive the archive was . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4922-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 29, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hyperkitty CVE ID : CVE-2021-33038 Amir Sarabadani and Kunal Mehta discovered that the import functionality of Hyperkitty, the web user interface to access Mailman 3 archives, did not restrict the visibility of private archives during the import, i.e. that during the import of a private Mailman 2 archive the archive was publicly accessible until the import completed. For the stable distribution (buster), this problem has been fixed in version 1.2.2-1+deb10u1. We recommend that you upgrade your hyperkitty packages. For the detailed security status of hyperkitty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hyperkitty Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Delve into the security update for Hyperkitty addressing the visibility issues in confidential archive imports on Debian. Discover more now!. Hyperkitty Security, Debian Security Advisory, Archive Import Security. . LinuxSecurity.com Team

Calendar%202 May 29, 2021 Debian
89

Fedora 26: FEDORA-2018-58b0c6a60e Moderate: Anki Security Issue

Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use correct shebang for python2 * upstream changelog: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-58b0c6a60e 2018-04-25 18:15:46.098220 --------------------------------------------------------------------------------Name : anki Product : Fedora 26 Version : 2.0.50 Release : 1.fc26 URL : https://apps.ankiweb.net/ Summary : Flashcard program for using space repetition learning Description : Anki is a program designed to help you remember facts (such as words and phrases in a foreign language) as easily, quickly and efficiently as possible. Anki is based on a theory called spaced repetition. --------------------------------------------------------------------------------Update Information: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use correct shebang for python2 * upstream changelog: --------------------------------------------------------------------------------ChangeLog: * Mon Apr 9 2018 Christian Krause - 2.0.50-1 - Update to new upstream version 2.0.50 (BZ 1436178, BZ 1529540, BZ 1529541) - Disable internal CA store in favor of global one (BZ 1497504) - Use correct shebang for python2 (BZ 1478302) - Use %autosetup --------------------------------------------------------------------------------References: [ 1 ] Bug #1529540 - anki: Security issue in .apkg imports fixed in 2.0.47 https://bugzilla.redhat.com/show_bug.cgi?id=1529540 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-58b0c6a60e' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . A recent security patch for Anki in the Fedora 26 distribution resolves vulnerabilities related to .apkg file imports and the downloading of plugins.. Anki Security Update,Fedora 26,Software Update. . LinuxSecurity.com Team

Calendar%202 Apr 25, 2018 Fedora
89

Fedora 26: Anki Import Issue Addressed in Update 2018-58b0c6a60e

Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use correct shebang for python2 * upstream changelog: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-58b0c6a60e 2018-04-25 18:15:46.098220 --------------------------------------------------------------------------------Name : anki Product : Fedora 26 Version : 2.0.50 Release : 1.fc26 URL : https://apps.ankiweb.net/ Summary : Flashcard program for using space repetition learning Description : Anki is a program designed to help you remember facts (such as words and phrases in a foreign language) as easily, quickly and efficiently as possible. Anki is based on a theory called spaced repetition. --------------------------------------------------------------------------------Update Information: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use correct shebang for python2 * upstream changelog: --------------------------------------------------------------------------------ChangeLog: * Mon Apr 9 2018 Christian Krause - 2.0.50-1 - Update to new upstream version 2.0.50 (BZ 1436178, BZ 1529540, BZ 1529541) - Disable internal CA store in favor of global one (BZ 1497504) - Use correct shebang for python2 (BZ 1478302) - Use %autosetup --------------------------------------------------------------------------------References: [ 1 ] Bug #1529540 - anki: Security issue in .apkg imports fixed in 2.0.47 https://bugzilla.redhat.com/show_bug.cgi?id=1529540 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-58b0c6a60e' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Anki 2.0.50 update enhances security protocols while addressing bugs related to .apkg file imports and plugin installations on Ubuntu.. Fedora 26, Anki security, import vulnerability, software update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 25, 2018 Important Fedora
89

Fedora 28 Anki: FEDORA-2018-50039f6b61 Critical: .apkg Import Issue

Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-50039f6b61 2018-04-17 00:11:16.755305 --------------------------------------------------------------------------------Name : anki Product : Fedora 28 Version : 2.0.50 Release : 1.fc28 URL : https://apps.ankiweb.net/ Summary : Flashcard program for using space repetition learning Description : Anki is a program designed to help you remember facts (such as words and phrases in a foreign language) as easily, quickly and efficiently as possible. Anki is based on a theory called spaced repetition. --------------------------------------------------------------------------------Update Information: Update to new upstream release 2.0.50. * fix a security issue in .apkg imports * fix a problem with plugin download * use python send2trash module from system * use correct shebang for python2 * upstream changelog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1529540 - anki: Security issue in .apkg imports fixed in 2.0.47 https://bugzilla.redhat.com/show_bug.cgi?id=1529540 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade anki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Anki update, version 2.0.50, resolves security vulnerabilities in .apkg file imports and corrects issues related to downloading plugins.. Fedora Updates, Anki Security, Software Patches, Flashcard Software. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2018 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200