Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

Scientific Linux: CVE-2013-0169 Critical Risk in java-1.6.0-openjdk

Critical: java-1.6.0-openjdk security update. Date: Wed, 20 Feb 2013 13:16:30 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Critical: java-1.6.0-openjdk on SL6.x i386/x86_64 Synopsis: Critical: java-1.6.0-openjdk security update Issue Date: 2013-02-20 CVE Numbers: CVE-2013-0169 CVE-2013-1486 -- An improper permission check issue was discovered in the JMX component in OpenJDK. An untrusted Java application or applet could use this flaw to bypass Java sandbox restrictions. (CVE-2013-1486) It was discovered that OpenJDK leaked timing information when decrypting TLS/SSL protocol encrypted records when CBC-mode cipher suites were used. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a TLS/SSL server as a padding oracle. (CVE-2013-0169) Note: If the web browser plug-in provided by the icedtea-web package was installed, CVE-2013-1486 could have been exploited without user interaction if a user visited a malicious website. This erratum also upgrades the OpenJDK package to IcedTea6 1.11.8. All running instances of OpenJDK Java must be restarted for the update to take effect. -- SL6 x86_64 java-1.6.0-openjdk-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm java-1.6.0-openjdk-src-1.6.0.0-1.56.1.11.8.el6_3.x86_64.rpm i386 java-1.6.0-openjdk-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm java-1.6.0-openjdk-debuginfo-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm java-1.6.0-openjdk-demo-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm java-1.6.0-openjdk-devel-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm java-1.6.0-openjdk-javadoc-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm java-1.6.0-openjdk-src-1.6.0.0-1.56.1.11.8.el6_3.i686.rpm - Scientific Linux DevelopmentTeam . Stay informed about essential patches for java-1.6.0-openjdk on Scientific Linux to address potential vulnerabilities and bolster security measures.. Scientific Linux, java update, remote access risk, security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 20, 2013 Critical Scientific Linux
89

Fedora 8: 2023:0011-1 Critical: Postfix Privilege Escalation and DoS

New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-8595 2008-10-09 04:48:12 --------------------------------------------------------------------------------Name : postfix Product : Fedora 8 Version : 2.5.5 Release : 1.fc8 URL : http://www.postfix.org Summary : Postfix Mail Transport Agent Description : Postfix is a Mail Transport Agent (MTA), supporting LDAP, SMTP AUTH (SASL), TLS --------------------------------------------------------------------------------Update Information: New upstream patch level version 2.5.5, including multiple security fixes detailed in upstream announcements: http://www.postfix.org/announcements/20080814.html http://www.postfix.org/announcements/20080902.html --------------------------------------------------------------------------------ChangeLog: * Wed Sep 17 2008 Thomas Woerner 2:2.5.5-1 - new version 2.5.5 fixes CVE-2008-2936, CVE-2008-2937 and CVE-2008-3889 (rhbz#459101) * Thu Aug 28 2008 Tom "spot" Callaway 2:2.5.1-4 - fix license tag * Thu Aug 14 2008 Thomas Woerner 2:2.5.1-3 - fixed postfix privilege problem with symlinks in the mail spool directory (CVE-2008-2936) (rhbz#459101) * Wed Mar 12 2008 Thomas Woerner 2:2.5.1-2 - fixed fix for enabling IPv6 support (rhbz#437024) - added new postfix data directory (rhbz#437042) * Thu Feb 21 2008 Thomas Woerner 2:2.5.1-1 - new verison 2.5.1 * Wed Feb 20 2008 Fedora Release Engineering - 2:2.4.6-3 - Autorebuild for GCC 4.3 * Thu Dec 6 2007 Release Engineering - 2.4.6-2 - Rebuild for deps * Wed Nov 28 2007 Thomas Woerner 2:2.4.6-1 - new verison 2.4.6 - added virtual server(smtp) provide (rhbz#380631) - enabling IPv6 support (rhbz#197105) - made the MYSQL andPGSQL defines overloadable as build argument * Wed Nov 7 2007 Thomas Woerner 2:2.4.5-3 - fixed multilib conflict for makedefs.out: rename to makedefs.out-ppc (rhbz#342941) - enabled mysql support --------------------------------------------------------------------------------References: [ 1 ] Bug #456314 - CVE-2008-2936 postfix privilege escalation flaw https://bugzilla.redhat.com/show_bug.cgi?id=456314 [ 2 ] Bug #456347 - CVE-2008-2937 postfix improper mailbox permissions https://bugzilla.redhat.com/show_bug.cgi?id=456347 [ 3 ] Bug #460906 - CVE-2008-3889 postfix: local DoS via leaked file descriptor https://bugzilla.redhat.com/show_bug.cgi?id=460906 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update postfix' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest update for Fedora 8 Postfix delivers crucial security enhancements. Upgrade to version 2.5.5 to ensure improved safety and system robustness.. Postfix Update, Secure MTA, Fedora 8 Patch, Mail Security, Update Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 09, 2008 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here