Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 33: FEDORA-2021-535596f062 Critical Injection Flaw in nbdkit

New upstream stable version 1.24.6; fixes CVE-2021-3716.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-535596f062 2021-08-29 01:13:10.120208 --------------------------------------------------------------------------------Name : nbdkit Product : Fedora 33 Version : 1.24.6 Release : 1.fc33 URL : https://github.com/libguestfs/nbdkit Summary : NBD server Description : NBD is a protocol for accessing block devices (hard disks and disk-like things) over the network. nbdkit is a toolkit for creating NBD servers. The key features are: * Multithreaded NBD server written in C with good performance. * Minimal dependencies for the basic server. * Liberal license (BSD) allows nbdkit to be linked to proprietary libraries or included in proprietary code. * Well-documented, simple plugin API with a stable ABI guarantee. Lets you to export "unconventional" block devices easily. * You can write plugins in C or many other languages. * Filters can be stacked in front of plugins to transform the output. 'nbdkit' is a meta-package which pulls in the core server and a useful subset of plugins and filters with minimal dependencies. If you want just the server, install 'nbdkit-server'. To develop plugins, install the 'nbdkit-devel' package and start by reading the nbdkit(1) and nbdkit-plugin(3) manual pages. --------------------------------------------------------------------------------Update Information: New upstream stable version 1.24.6; fixes CVE-2021-3716. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 20 2021 Eric Blake - 1.24.6-1 - New upstream stable version 1.24.6; fixes CVE-2021-3716. --------------------------------------------------------------------------------References: [ 1 ] Bug #1994695 - CVE-2021-3716 nbdkit: NBD_OPT_STRUCTURED_REPLY injection on STARTTLS https://bugzilla.redhat.com/show_bug.cgi?id=1994695 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-535596f062' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora Security Alert for nbdkit v1.24.6 mitigates severe injection vulnerability CVE-2021-3716 safeguarding system stability.. Fedora 33 Update, nbdkit Injection Flaw, Block Device Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 28, 2021 Critical Fedora
89

Fedora 27: Bibutils Security Update - Critical Injection Flaws Addressed

Update to 6.6. ---- Version 6.5 - address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 - fix injection of Fedora LDFLAGS. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-9ec3061fc8 2018-08-01 17:54:21.486173 --------------------------------------------------------------------------------Name : bibutils Product : Fedora 27 Version : 6.6 Release : 1.fc27 URL : Summary : Bibliography conversion tools Description : The bibutils package converts between various bibliography formats using a common MODS-format XML intermediate. --------------------------------------------------------------------------------Update Information: Update to 6.6. ---- Version 6.5 - address CVE-2018-10773, CVE-2018-10774, CVE-2018-10775 - fix injection of Fedora LDFLAGS --------------------------------------------------------------------------------ChangeLog: * Mon Jul 23 2018 Vasiliy N. Glazov 6.6-1 - Update to 6.6 - Drop patch - Clean spec * Fri Jun 29 2018 Jens Petersen - 6.5-1 - update to version 6.5 - build with LDFLAGS (#1541039) * Wed Jun 6 2018 Jens Petersen - 6.3-1 - update to 6.3 which addresses CVE-2018-10773 CVE-2018-10774 CVE-2018-10775 (#1577259) * Mon Feb 19 2018 Jens Petersen - 6.2-4 - BR gcc * Wed Feb 14 2018 Jens Petersen - 6.2-3 - fix the build with CFLAGS and LDFLAGS * Fri Feb 2 2018 Jens Petersen - 6.2-2 - using distro LDFLAGS (#1541039) * Sat Jan 13 2018 Jens Petersen - 6.2-1 - update to 6.2 --------------------------------------------------------------------------------References: [ 1 ] Bug #1577280 - CVE-2018-10775 bibutils: NULL pointer dereference in _fields_add function in fields.c in libbibcore.a https://bugzilla.redhat.com/show_bug.cgi?id=1577280 [ 2 ] Bug #1577268 - CVE-2018-10774 bibutils: Out-of-bounds Read in isiin_keyword function in isiin.c in libbibutils.a https://bugzilla.redhat.com/show_bug.cgi?id=1577268 [ 3 ]Bug #1577258 - CVE-2018-10773 bibutils: NULL pointer deference in addsn function in serialno.c in libbibcore.a https://bugzilla.redhat.com/show_bug.cgi?id=1577258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-9ec3061fc8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/DKQ7A6ZKXW3JBJTXB5BIF3HQHBR62IDZ/ . Ubuntu releases urgent patches for libxml addressing various cross-site scripting vulnerabilities and additional improvements.. Fedora Updates,Bibutils Security,Injection Flaws,Fedora Software Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 01, 2018 Critical Fedora
89

Fedora 24: FEDORA-2016-1b042a79bd Critical Kf5-Kontactinterface Issues

KDE PIM Applications 16.08.2, https://kde.org/announcements/announce-applications-16.08.2/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-1b042a79bd 2016-10-30 14:09:06.179463 -------------------------------------------------------------------------------- Name : kf5-kontactinterface Product : Fedora 24 Version : 16.08.2 Release : 1.fc24 URL : Summary : The Kontact Interface Library Description : The Kontact Interface library provides API to integrate other applications with Kontact. -------------------------------------------------------------------------------- Update Information: KDE PIM Applications 16.08.2, https://kde.org/announcements/announce-applications-16.08.2/ -------------------------------------------------------------------------------- References: [ 1 ] Bug #1382288 - CVE-2016-7967 kdepim: JavaScript access to local and remote URLs in Kmail https://bugzilla.redhat.com/show_bug.cgi?id=1382288 [ 2 ] Bug #1382286 - CVE-2016-7966 kdepim: HTML injection in plain text viewer of KMail https://bugzilla.redhat.com/show_bug.cgi?id=1382286 [ 3 ] Bug #1382293 - CVE-2016-7968 kdepim: JavaScript execution in HTML Mails https://bugzilla.redhat.com/show_bug.cgi?id=1382293 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kf5-kontactinterface' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep informed about the Fedora 24 security updates for kf5-kontactinterface that tackle serious API vulnerabilities and injection issues.. Kontact Interface, Kf5-Kontactinterface, Security Patch, KDE PIM Applications, API Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 30, 2016 Critical Fedora
89

Fedora Core 6: 2007-415 Critical PHP Denial Of Service And Injection

This update fixes a number of security issues in PHP. A denial of service flaw was found in the way PHP processed a deeply nested array. A remote attacker could cause the PHP interpreter to crash by submitting an input variable with a deeply nested array. (CVE-2007-1285) . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-415 2007-04-17 ---------------------------------------------------------------------Product : Fedora Core 6 Name : php Version : 5.1.6 Release : 3.5.fc6 Summary : The PHP HTML-embedded scripting language. (PHP: Hypertext Preprocessor) Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated webpages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The php package contains the module which adds support for the PHP language to Apache HTTP Server. ---------------------------------------------------------------------Update Information: This update fixes a number of security issues in PHP. A denial of service flaw was found in the way PHP processed a deeply nested array. A remote attacker could cause the PHP interpreter to crash by submitting an input variable with a deeply nested array. (CVE-2007-1285) A flaw was found in the way the mbstring extension set global variables. A script which used the mb_parse_str() function to set global variables could be forced to enable the register_globals configuration option, possibly resulting in global variable injection. (CVE-2007-1583) A flaw was discovered in the way PHP's mail() function processed header data. If a script sent mail using a Subject header containing a string from an untrusted source, a remote attacker could send bulk e-mail tounintended recipients. (CVE-2007-1718) A heap based buffer overflow flaw was discovered in PHP's gd extension. A script that could be forced to process WBMP images from an untrusted source could result in arbitrary code execution. (CVE-2007-1001) A buffer over-read flaw was discovered in PHP's gd extension. A script that could be forced to write arbitrary strings using a JIS font from an untrusted source could cause the PHP interpreter to crash. (CVE-2007-0455) ---------------------------------------------------------------------* Thu Apr 5 2007 Joe Orton 5.1.6-3.5.fc6 - add security fixes for CVE-2007-0455, CVE-2007-1001, CVE-2007-1285, CVE-2007-1583, CVE-2007-1718 (#235364) - package /usr/share/php (#225434) ---------------------------------------------------------------------This update can be downloaded from: ba011afdd624305632629e3f4605817f8bc47ae3 SRPMS/php-5.1.6-3.5.fc6.src.rpm ba011afdd624305632629e3f4605817f8bc47ae3 noarch/php-5.1.6-3.5.fc6.src.rpm 6a69d4c8085e24c8148052a2b096d6115b9f39a8 ppc/php-xml-5.1.6-3.5.fc6.ppc.rpm a447279cb67aaf5e73fc17cde4915e3e78acee86 ppc/php-xmlrpc-5.1.6-3.5.fc6.ppc.rpm 45cdc53d7ad2ff799b0d8c7b8cd55152358eb624 ppc/php-mbstring-5.1.6-3.5.fc6.ppc.rpm 091868a36729e28571baeb2d16155add417c7c9f ppc/php-odbc-5.1.6-3.5.fc6.ppc.rpm 8092df89f00e5199a9411a265e2b408fe77b457d ppc/php-bcmath-5.1.6-3.5.fc6.ppc.rpm 99494ff22c6456475a901d8db21f18d6eb67e65f ppc/php-cli-5.1.6-3.5.fc6.ppc.rpm 8df407db61f53929a0be070af9929b2564449dc9 ppc/php-pgsql-5.1.6-3.5.fc6.ppc.rpm 2ef92a9fff750f61710b9c0f384244b87f4d9242 ppc/php-snmp-5.1.6-3.5.fc6.ppc.rpm be4779e02b0d0be468b7b1c532798256891c6a61 ppc/php-pdo-5.1.6-3.5.fc6.ppc.rpm f8b1a756826f64add7b03a6fdd202e8ae7a31ace ppc/php-dba-5.1.6-3.5.fc6.ppc.rpm da137c91ce49913eefd07f6bff216fd0305b6dc9 ppc/php-devel-5.1.6-3.5.fc6.ppc.rpm 2788c003fac688b1b4a0a76c6f431dc1ef7bbb63 ppc/php-soap-5.1.6-3.5.fc6.ppc.rpm 27017879491266d0d3738b2470d6b1814d1547ac ppc/php-mysql-5.1.6-3.5.fc6.ppc.rpm 9660ed6e6eb74a41e65e4b8979fe696afba7276a ppc/debug/php-debuginfo-5.1.6-3.5.fc6.ppc.rpm 5cecd491edf5871c3943cec7fe33bfb57664098c ppc/php-ldap-5.1.6-3.5.fc6.ppc.rpm 17011e6a2ffb4481326c282dd976620690abb4f0 ppc/php-ncurses-5.1.6-3.5.fc6.ppc.rpm 176eebec3e1c9fcbd563dd44e1c1628b3d05daa4 ppc/php-5.1.6-3.5.fc6.ppc.rpm bb79b8bfaff6d8a9f1e300102c26dde4291ab030 ppc/php-imap-5.1.6-3.5.fc6.ppc.rpm c2eef96d1d0b0fdc65feda4f5810a34455b7a3a8 ppc/php-common-5.1.6-3.5.fc6.ppc.rpm c986d51cf133c82e5f98bd8acdbc24760cf05893 ppc/php-gd-5.1.6-3.5.fc6.ppc.rpm c5cf959505453323834e669eb26ea853372c632e x86_64/php-common-5.1.6-3.5.fc6.x86_64.rpm ac85bca1403a6d064428647f9323312853b5ae03 x86_64/php-cli-5.1.6-3.5.fc6.x86_64.rpm 6555217a974ccd1c7e7ff9ef1e1d310082441a03 x86_64/php-xml-5.1.6-3.5.fc6.x86_64.rpm 143d0711da94e0b0bfe218942e7e15b1955467d8 x86_64/debug/php-debuginfo-5.1.6-3.5.fc6.x86_64.rpm abcc482d25c4e09bed05a62f916f9eff31dbcbd1 x86_64/php-gd-5.1.6-3.5.fc6.x86_64.rpm 16bdeba1a640677b54f87e573624726506196d01 x86_64/php-5.1.6-3.5.fc6.x86_64.rpm 369bb74f995633beee49a20df9f26282ee3c92e5 x86_64/php-imap-5.1.6-3.5.fc6.x86_64.rpm caad40c6edea6caa3889617663bb7c4233e90d62 x86_64/php-snmp-5.1.6-3.5.fc6.x86_64.rpm cadef18d28fdd3dce9962a453438a9820b9aab5e x86_64/php-bcmath-5.1.6-3.5.fc6.x86_64.rpm d903f3cfbe25bc6af7fd366fd1ab2e1d2c262062 x86_64/php-soap-5.1.6-3.5.fc6.x86_64.rpm 78bb21621fa9d467d0e23b99ec91ee8fa388ad09 x86_64/php-xmlrpc-5.1.6-3.5.fc6.x86_64.rpm d4a8e552d867028fffccfd69b19fe4a79e217319 x86_64/php-pgsql-5.1.6-3.5.fc6.x86_64.rpm f9a79bcb2cf6fb1040a133de146bfd416060c168 x86_64/php-odbc-5.1.6-3.5.fc6.x86_64.rpm 35df5d9f454872ef4aba17d0fbb05805bd13915f x86_64/php-devel-5.1.6-3.5.fc6.x86_64.rpm a526508c539c96332c4032c64056c6dc05a1907d x86_64/php-pdo-5.1.6-3.5.fc6.x86_64.rpm 2b46cbf4e45ccdbb0b9e07d7a8e4addded58c580 x86_64/php-ncurses-5.1.6-3.5.fc6.x86_64.rpm 43d04dc9e504fa7a4100fafd9ab49b7a6c567860 x86_64/php-dba-5.1.6-3.5.fc6.x86_64.rpm faa041477091e854580c6fa31790e7a734bc4f16 x86_64/php-mbstring-5.1.6-3.5.fc6.x86_64.rpm 9441985700ff3b54298371e172c1a1ed44324315 x86_64/php-mysql-5.1.6-3.5.fc6.x86_64.rpm a2b9b64b37d12fd1f82028af68b6983a23260fec x86_64/php-ldap-5.1.6-3.5.fc6.x86_64.rpm 5367195a555f989eb1ddbc5bd705ed162682f9f8 i386/php-pgsql-5.1.6-3.5.fc6.i386.rpm 4cc47437ac53309cb89dfea123a7e850c969b78a i386/php-snmp-5.1.6-3.5.fc6.i386.rpm bad2b66597bbd28074ace741872ae97d0398b099 i386/php-mysql-5.1.6-3.5.fc6.i386.rpm 4817d6b666313082214c1ac38d8ddd3970d749e5 i386/php-ncurses-5.1.6-3.5.fc6.i386.rpm 54fc6912d36132f2a3eae853707242256fcb0a05 i386/php-imap-5.1.6-3.5.fc6.i386.rpm 384bce7e76e014016e3a9a20fa7b56d36f973f38 i386/debug/php-debuginfo-5.1.6-3.5.fc6.i386.rpm 1f05cab5925291969629a4631c6a10fc932975f5 i386/php-odbc-5.1.6-3.5.fc6.i386.rpm aa81faf2a78f217fb17396fb6e72a7c41a230b81 i386/php-devel-5.1.6-3.5.fc6.i386.rpm b59307c9ffe18a51e6ea21437d44d42fbd9d8077 i386/php-common-5.1.6-3.5.fc6.i386.rpm 39d16e0c60d11c0155e76e0726f0b7fb6078d9f8 i386/php-xml-5.1.6-3.5.fc6.i386.rpm 958b379478fa4356c6d7d292d3ba20f257926794 i386/php-dba-5.1.6-3.5.fc6.i386.rpm 2cf9fe08fc9a24e30ec74886782012dfb1e6392f i386/php-5.1.6-3.5.fc6.i386.rpm f6cdca4e0297e2b14282d8d6f57cc76d537d284f i386/php-ldap-5.1.6-3.5.fc6.i386.rpm 76cbaf17f6f3dfc806386615f34e3acf43ea9234 i386/php-pdo-5.1.6-3.5.fc6.i386.rpm 7e422ba0219af41bd67dfb6ca12024c0cc16df47 i386/php-xmlrpc-5.1.6-3.5.fc6.i386.rpm f643d304b5e6c1a8f7869f812425e20e91c52e43 i386/php-soap-5.1.6-3.5.fc6.i386.rpm be77b675d2d0d5c6b4a0e6792a0349d580ee02b9 i386/php-gd-5.1.6-3.5.fc6.i386.rpm c6f2474f043d5e8ed6a86fb8f11f55c47d4ca3e7 i386/php-bcmath-5.1.6-3.5.fc6.i386.rpm 9e9ccbd388fad93fff8c94ffe124c2bc516c7455 i386/php-mbstring-5.1.6-3.5.fc6.i386.rpm 294389ebf2e45c7a2bc36cb5c9a29ecfe74b3379 i386/php-cli-5.1.6-3.5.fc6.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For moreinformation, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Keep informed about patches for the Fedora Core 6 PHP software that tackle various issues and security vulnerabilities.. Fedora Core, PHP Update, Denial Of Service, Injection Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 17, 2007 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here