Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
87

Debian: Dovecot Critical Authentication Flaw DSA-6019-1

A flaw with the authentication cache management was discovered in the Dovecot email server, which could result in users being logged in as the wrong user in certain configurations. For the stable distribution (trixie), this problem has been fixed in version 1:2.4.1+dfsg1-6+deb13u1.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6019-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 05, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dovecot Debian Bug : 1115474 1115964 A flaw with the authentication cache management was discovered in the Dovecot email server, which could result in users being logged in as the wrong user in certain configurations. For the stable distribution (trixie), this problem has been fixed in version 1:2.4.1+dfsg1-6+deb13u1. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/dovecot Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical flaw in Dovecot's authentication cache could log users as incorrect accounts. Update recommended for stability.. Dovecot security flaw, Debian notification, user login issue, authentication fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 05, 2025 Critical Debian
202

openSUSE Leap 15.6 SUSE-SU-2024:3882-1 important: kernel live patch

This update for the Linux Kernel 6.4.0-150600_23_14 fixes several issues. The following security issues were fixed:. # Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP6) Announcement ID: SUSE-SU-2024:3882-1 Release Date: 2024-11-04T06:33:41Z Rating: important References: * bsc#1225819 * bsc#1228349 * bsc#1228786 * bsc#1231419 Cross-References: * CVE-2023-52752 * CVE-2024-40909 * CVE-2024-40954 * CVE-2024-42133 CVSS scores: * CVE-2023-52752 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-52752 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40954 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-40954 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-42133 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-42133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 6.4.0-150600_23_14 fixes several issues. The following security issues were fixed: * CVE-2024-42133: Bluetooth: Ignore too large handle values in BIG (bsc#1231419) * CVE-2023-52752: smb: client: fix use-after-free bug in cifs_debug_data_proc_show() (bsc#1225819). * CVE-2024-40954: net: do not leave a dangling sk pointer, when socket creation fails (bsc#1227808) * CVE-2024-40909: bpf: Fix a potential use-after-free in bpf_link_free() (bsc#1228349). ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-3882=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2024-3882=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_2-debugsource-4-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-4-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_14-default-4-150600.13.6.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_2-debugsource-4-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_14-default-debuginfo-4-150600.13.6.1 * kernel-livepatch-6_4_0-150600_23_14-default-4-150600.13.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-52752.html * https://www.suse.com/security/cve/CVE-2024-40909.html * https://www.suse.com/security/cve/CVE-2024-40954.html * https://www.suse.com/security/cve/CVE-2024-42133.html * https://bugzilla.suse.com/show_bug.cgi?id=1225819 * https://bugzilla.suse.com/show_bug.cgi?id=1228349 * https://bugzilla.suse.com/show_bug.cgi?id=1228786 * https://bugzilla.suse.com/show_bug.cgi?id=1231419 . New enhancements tackle significant challenges with essential improvements for Linux Kernel Live Patch on openSUSE. Grab it today!. openSUSE Kernel Patch, Security Update, Linux Kernel Security, Critical Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 04, 2024 Important OpenSUSE
172

Ubuntu 21.10: 5380-2 Urgent: Django Cross-Site Scripting Vulnerabilities

Several security issues were fixed in Django.. =========================================================================Ubuntu Security Notice USN-5373-1 April 11, 2022 python-django vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: It was discovered that Django incorrectly handled certain certain column aliases in the QuerySet.annotate(), aggregate(), and extra() methods. A remote attacker could possibly use this issue to perform an SQL injection attack. (CVE-2022-28346) It was discovered that Django incorrectly handled certain option names in the QuerySet.explain() method. A remote attacker could possibly use this issue to perform an SQL injection attack. This issue only affected Ubuntu 20.04 LTS, and Ubuntu 21.10. (CVE-2022-28347) It was discovered that the Django URLValidator function incorrectly handled newlines and tabs. A remote attacker could possibly use this issue to perform a header injection attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2021-32052) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: python3-django 2:2.2.24-1ubuntu1.4 Ubuntu 20.04 LTS: python3-django 2:2.2.12-1ubuntu0.11 Ubuntu 18.04 LTS: python-django 1:1.11.11-1ubuntu1.17 python3-django 1:1.11.11-1ubuntu1.17 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5373-1 CVE-2021-32052, CVE-2022-28346, CVE-2022-28347 Package Information: https://launchpad.net/ubuntu/+source/python-django/2:2.2.24-1ubuntu1.4 https://launchpad.net/ubuntu/+source/python-django/2:2.2.12-1ubuntu0.11 https://launchpad.net/ubuntu/+source/python-django/1:1.11.11-1ubuntu1.17 . Uncover solutions for various security flaws within Django affecting numerous Ubuntu versions and follow the outlined upgrade steps.. Django Vulnerabilities, SQL Injection, Python Django Security, Ubuntu Security Notice, System Update Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 11, 2022 Important Ubuntu
98

Red Hat Virtualization: RHSA-2021-3477-01 Critical RHV-H Security Threat

An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: RHV-H security update (redhat-virtualization-host) 4.3.18 Advisory ID: RHSA-2021:3477-01 Product: Red Hat Virtualization Advisory URL: https://access.redhat.com/errata/RHSA-2021:3477 Issue date: 2021-09-09 CVE Names: CVE-2021-3621 CVE-2021-3715 CVE-2021-22555 CVE-2021-31535 CVE-2021-32399 ==================================================================== 1. Summary: An update for redhat-release-virtualization-host and redhat-virtualization-host is now available for Red Hat Virtualization 4 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: RHEL 7-based RHEV-H for RHEV 4 (build requirements) - noarch, x86_64 Red Hat Virtualization 4 Hypervisor for RHEL 7 - noarch 3. Description: The redhat-virtualization-host packages provide the Red Hat Virtualization Host. These packages include redhat-release-virtualization-host. Red Hat Virtualization Hosts (RHVH) are installed using a special build of Red Hat Enterprise Linux with only the packages required to host virtual machines. RHVH features a Cockpit user interface for monitoring the host's resources and performing administrative tasks. Security Fix(es): * sssd: shell command injection in sssctl (CVE-2021-3621) * kernel: use-after-free in route4_change() in net/sched/cls_route.c (CVE-2021-3715) *kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c (CVE-2021-22555) * libX11: missing request length checks (CVE-2021-31535) * kernel: race condition for removal of the HCI controller (CVE-2021-32399) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/2974891 5. Bugs fixed (https://bugzilla.redhat.com/): 1961822 - CVE-2021-31535 libX11: missing request length checks 1970807 - CVE-2021-32399 kernel: race condition for removal of the HCI controller 1975142 - CVE-2021-3621 sssd: shell command injection in sssctl 1980101 - CVE-2021-22555 kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c 1993988 - CVE-2021-3715 kernel: use-after-free in route4_change() in net/sched/cls_route.c 6. Package List: Red Hat Virtualization 4 Hypervisor for RHEL 7: Source: redhat-virtualization-host-4.3.18-20210903.0.el7_9.src.rpm noarch: redhat-virtualization-host-image-update-4.3.18-20210903.0.el7_9.noarch.rpm RHEL 7-based RHEV-H for RHEV 4 (build requirements): Source: redhat-release-virtualization-host-4.3.18-1.el7ev.src.rpm redhat-virtualization-host-4.3.18-20210903.0.el7_9.src.rpm noarch: redhat-virtualization-host-image-update-4.3.18-20210903.0.el7_9.noarch.rpm redhat-virtualization-host-image-update-placeholder-4.3.18-1.el7ev.noarch.rpm x86_64: redhat-release-virtualization-host-4.3.18-1.el7ev.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2021-3621 https://access.redhat.com/security/cve/CVE-2021-3715 https://access.redhat.com/security/cve/CVE-2021-22555 https://access.redhat.com/security/cve/CVE-2021-31535 https://access.redhat.com/security/cve/CVE-2021-32399 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYTnSd9zjgjWX9erEAQiz5A//Ts2JvzwTT3hGdLSq+8URB3Iax5bNtKA/ I/Wy+C3N6dxtnv3Zi6SlPN2zkurCvSpEI5QotrqT2WUVsTDs4gvnjxIb1MGOzuFm zYFw+QoiViyIssZ1q4MiPAMLgJmYwn/J5tNR8ads0zV6RwJRAatwEsfMKnCNxG1z 9PQb0xHzwbH2bdBZjO/8h+rCI2IyUljX8f+jtG4FiMpCyPHIrDrSb5XSgpqmDmWo OH613TmS62rLF0s0OoLn/kc0N9n3r2+NnCe1qy56rIXXMDkDlN3+nRE2V6sOYwuV kW7Y23zBdavs5AhtwQJdYKrvFjppsVfSFz0+thFw5N7y93ZNoELfwTcczECgGr+M LVk/2YrATtyGFAg3Ot7NmlYYuB8Zy5+0+n7pKZwbhRWF1oHh0fA+yapXeZ+MntJ8 Zn8+zNkluiMRqyd/2cTgBX2tucFQTr3FBATW80bhtl4PEEmTXvXHWpLc3RqgdSqe EFdWlwg6seU47XmQjMd8zufxbJXcCPj21Xc6TbkWUCPv0LQ9h168M7KHHAllTy8D iSDpvQUyvVCosPhD+TsbF3qnlMAWkHb+IMJgKvfag0HwIdYr4qgSgTtU2Dtb3UBc Wc8sB6uyVB7GHzqJaPc3wfWJ55LuNeDkH1SxTxOrfF3nw9aCnxoQo1z04q7pMUe3 C3aC+Aa64Dc=d7rO -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important RHV-H security patch for Red Hat Virtualization 4 tackling several major vulnerabilities.. Red Hat Virtualization, RHV Update, Security Patch, Virtualization Impact. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 09, 2021 Important Red Hat
89

Fedora 33 Kernel 5.9.10 Advisory: Critical Fixes Addressing Security Flaws

The 5.9.10 stable kernel update contains a number of important fixes across the tree.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8c15928d23 2020-11-25 01:34:42.404045 --------------------------------------------------------------------------------Name : kernel Product : Fedora 33 Version : 5.9.10 Release : 200.fc33 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: The 5.9.10 stable kernel update contains a number of important fixes across the tree. --------------------------------------------------------------------------------ChangeLog: * Mon Nov 23 2020 Justin M. Forbes - 5.9.10-200 - Linux v5.9.10 - Fix CVE-2020-28941 (rhbz 1899985 1899986) - Fix CVE-2020-4788 (rhbz 1888433 1900437) --------------------------------------------------------------------------------References: [ 1 ] Bug #1888433 - CVE-2020-4788 kernel: speculation on incompletely validated data on IBM Power9 https://bugzilla.redhat.com/show_bug.cgi?id=1888433 [ 2 ] Bug #1899985 - CVE-2020-28941 kernel: NULL pointer dereference in spk_ttyio_ldisc_close function in drivers/accessibility/speakup/spk_ttyio.c https://bugzilla.redhat.com/show_bug.cgi?id=1899985 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8c15928d23' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The release of Kernel 5.9.10 in Fedora 33 tackles significant vulnerabilities while improving overall system reliability and performance.. Fedora 33 Kernel Security Fixes, Fedora Update Notification, Kernel Update Information. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 24, 2020 Critical Fedora
98

RedHat: RHSA-2019-2980-01 Important: Python Information Disclosure Issue

An update for python is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: python security update Advisory ID: RHSA-2019:2980-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:2980 Issue date: 2019-10-08 CVE Names: CVE-2019-9636 ==================================================================== 1. Summary: An update for python is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.5) - ppc64, ppc64le, s390x, x86_64 3. Description: Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): * python: Information Disclosure due to urlsplit improper NFKC normalization (CVE-2019-9636) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the Referencessection. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1688543 - CVE-2019-9636 python: Information Disclosure due to urlsplit improper NFKC normalization 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5): Source: python-2.7.5-70.el7_5.src.rpm x86_64: python-2.7.5-70.el7_5.x86_64.rpm python-debuginfo-2.7.5-70.el7_5.i686.rpm python-debuginfo-2.7.5-70.el7_5.x86_64.rpm python-devel-2.7.5-70.el7_5.x86_64.rpm python-libs-2.7.5-70.el7_5.i686.rpm python-libs-2.7.5-70.el7_5.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.5): x86_64: python-debug-2.7.5-70.el7_5.x86_64.rpm python-debuginfo-2.7.5-70.el7_5.x86_64.rpm python-test-2.7.5-70.el7_5.x86_64.rpm python-tools-2.7.5-70.el7_5.x86_64.rpm tkinter-2.7.5-70.el7_5.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.5): Source: python-2.7.5-70.el7_5.src.rpm ppc64: python-2.7.5-70.el7_5.ppc64.rpm python-debuginfo-2.7.5-70.el7_5.ppc.rpm python-debuginfo-2.7.5-70.el7_5.ppc64.rpm python-devel-2.7.5-70.el7_5.ppc64.rpm python-libs-2.7.5-70.el7_5.ppc.rpm python-libs-2.7.5-70.el7_5.ppc64.rpm ppc64le: python-2.7.5-70.el7_5.ppc64le.rpm python-debuginfo-2.7.5-70.el7_5.ppc64le.rpm python-devel-2.7.5-70.el7_5.ppc64le.rpm python-libs-2.7.5-70.el7_5.ppc64le.rpm s390x: python-2.7.5-70.el7_5.s390x.rpm python-debuginfo-2.7.5-70.el7_5.s390.rpm python-debuginfo-2.7.5-70.el7_5.s390x.rpm python-devel-2.7.5-70.el7_5.s390x.rpm python-libs-2.7.5-70.el7_5.s390.rpm python-libs-2.7.5-70.el7_5.s390x.rpm x86_64: python-2.7.5-70.el7_5.x86_64.rpm python-debuginfo-2.7.5-70.el7_5.i686.rpm python-debuginfo-2.7.5-70.el7_5.x86_64.rpm python-devel-2.7.5-70.el7_5.x86_64.rpm python-libs-2.7.5-70.el7_5.i686.rpm python-libs-2.7.5-70.el7_5.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v.7.5): ppc64: python-debug-2.7.5-70.el7_5.ppc64.rpm python-debuginfo-2.7.5-70.el7_5.ppc64.rpm python-test-2.7.5-70.el7_5.ppc64.rpm python-tools-2.7.5-70.el7_5.ppc64.rpm tkinter-2.7.5-70.el7_5.ppc64.rpm ppc64le: python-debug-2.7.5-70.el7_5.ppc64le.rpm python-debuginfo-2.7.5-70.el7_5.ppc64le.rpm python-test-2.7.5-70.el7_5.ppc64le.rpm python-tools-2.7.5-70.el7_5.ppc64le.rpm tkinter-2.7.5-70.el7_5.ppc64le.rpm s390x: python-debug-2.7.5-70.el7_5.s390x.rpm python-debuginfo-2.7.5-70.el7_5.s390x.rpm python-test-2.7.5-70.el7_5.s390x.rpm python-tools-2.7.5-70.el7_5.s390x.rpm tkinter-2.7.5-70.el7_5.s390x.rpm x86_64: python-debug-2.7.5-70.el7_5.x86_64.rpm python-debuginfo-2.7.5-70.el7_5.x86_64.rpm python-test-2.7.5-70.el7_5.x86_64.rpm python-tools-2.7.5-70.el7_5.x86_64.rpm tkinter-2.7.5-70.el7_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-9636 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXZxeudzjgjWX9erEAQg3gw/9GEK2wEg4asdGexTv7+96qP4EdJUKoKL1 k9D/2HGQGVooT+arEBxXJqny+6an7/JwBc1cTeG3qpAxLdfGO3JE8oBhjtU7uMH3 J0NvXXOUTxmv7zXYReseEgZQd7yG8JFXaOtGqXsqwXHF0+2hqcSTLlfhufWC2gzU SIUnr2pC9tr1ExpXSVjjBPvpI3O/1B8rfHM5+eBMO+zQf8EYErFkBnuUUSs/19LN 3EbtMpV8DjCL2CGVhAZqb1ku80CvHJZ8kpbs8yTQ2BiUbNUa9s7g0zNqNi/QHpxL 77EjWKEiyu2i0zSRZWUcpbZ2aaNC773is61+1jWc13ZPA595R3HlNUwnV4g/z2gy D4GgQkfzs0ZScJZsyC8g1Skv3gpYfzbC8pn8Zsq8iTS14bt5YQuf+pQEufqixzK4 2DdERDsKQM9uzayuRS5sEtUVNiwsdgHjDqkImjEhpjaraLK1TDWDHEszbC0wuBVm f7u2h3D1LT6UGm5++RLKVc50TaJiVFj5TnIeGfI+RSjoGxHsXMF+fSIav11Xcf8I vQpy0JwjZgHtF0xdcpqRRIRueyqtNTcky/DIRYK/7WphFz6wpAK/mbySDbaDnAne qx0pVs7JCG1ztTo/mh8VrLNxy7dfShnKIa+9ZNykGopAALxJ6A51rddh0m+Mgsr5 jTf36Ic54Ag=tTgl -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important python security patch for Red Hat Enterprise Linux 7.5 aimed at resolving major data leakage vulnerabilities.. Python Security Update, Red Hat Advisory, Information Disclosure, Linux Update, RedHat Enterprise. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 08, 2019 Important Red Hat
89

Fedora 28: GnuPG Security Update 2018-4ef71d3525 Critical Fix

- doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-4ef71d3525 2018-06-15 15:48:22.929912 --------------------------------------------------------------------------------Name : gnupg Product : Fedora 28 Version : 1.4.22 Release : 7.fc28 URL : http://www.gnupg.org/ Summary : A GNU utility for secure communication and data storage Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). --------------------------------------------------------------------------------Update Information: - doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020] --------------------------------------------------------------------------------ChangeLog: * Fri Jun 8 2018 Brian C. Lane - 1.4.22-7 - doc Remove documentation for future option faked sys - build Don't use dev srandom on OpenBSD - Do not use C99 feature - g10 Fix regexp sanitization - g10 Push compress filter only if compressed - gpg Sanitize diagnostic with the original file name [CVE-2018-12020] --------------------------------------------------------------------------------This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-4ef71d3525' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/ECER26OJWTXJCGF7LEUAPMF4ZR6ZORMH/ . The latest patch notes outline improvements and bug corrections in GnuPG for Fedora 28, boosting both security measures and user experience for the community.. GnuPG Update,Fedora 28 Security,Fedora Update Notification,Data Encryption,Secure Communication. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 15, 2018 Critical Fedora
89

Fedora 26: Security Update for Globus-Net-Manager - Critical Issues

globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Remove checksum data from public. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0eea793538 2017-07-14 11:45:23.814507 --------------------------------------------------------------------------------Name : globus-net-manager Product : Fedora 26 Version : 0.17 Release : 1.fc26 URL : http://toolkit.globus.org/ Summary : Globus Toolkit - Network Manager Description : The Globus Toolkit is an open source software toolkit used for building Grid systems and applications. It is being developed by the Globus Alliance and many others all over the world. A growing number of projects and companies are using the Globus Toolkit to unlock the potential of grids for their cause. The globus-net-manager package contains: Network Manager The Globus Net Manager library is a plug-in point for network management tasks, such as: - selectively open ports in a firewall and allow these ports to be closed when transfers are complete - configure a virtual circuit based on a site policy and route traffic over this circuit - route network traffic related to a task over a particular network --------------------------------------------------------------------------------Update Information: globus-ftp-client * Adapt to Perl 5.26 - POSIX::tmpnam() no longer available * Remove some redundant tests to reduce test time globus-gass-cache-program * GT6 update globus-gass-copy * Don't attempt sshftp data protection without creds (9.24) * Checksum verification based on contribution from IBM (9.24) * Fix uninitialized field related crash (9.25) * Removechecksum data from public handle (9.26) * Prevent some race conditions (9.27) globus-gram-client * GT6 update globus-gram-job-manager * Default to running personal gatekeeper on an ephemeral port globus-gram-job-manager-condor * Make noarch build arch independent globus-gridftp-server * New error message format (12.0) * Configuration database (12.0) * Better delay for end of session ref check (12.1) * Fix tests when getgroups() does not return effective gid (12.2) globus-gssapi-gsi * Don't unlock unlocked mutex (12.14) * Remove legacy SSLv3 support (12.15) * Test fixes (12.16/12.17) * Drop patch globus-gssapi-gsi-mutex-unlock.patch (fixed upstream 12.14) globus-io * Remove legacy SSLv3 support globus-net-manager * Fix .pc typo * Drop patch globus-net-manager-pkgconfig.patch (fixed upstream) globus-xio * Don't rely on globus_error_put(NULL) to be GLOBUS_SUCCESS (5.15) * Fix crash in error handling in http driver (5.16) globus-xio-gsi-driver * Fix crash when checking for anonymous GSS name when name comparison fails globus-xio-pipe-driver * Fix .pc typo globus-xio-udt-driver * Don't force --static flag to pkg-config * Drop some BuildRequires no longer needed with above change * Fix undefined symbols during linking myproxy * Fix error check (6.1.26) * Remove legacy SSLv3 support (6.1.27) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade globus-net-manager' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Stay informed about all the latest enhancements and patches for globus-net-manager in Fedora to bolster security measures and optimize network administration.. Globas Net Manager, Fedora Update, Network Toolkit, System Security, Open Source Tools. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 14, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here