Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 38: FEDORA-2023-c746c8gfab Urgent Awstats Cross-Site Scripting Patch

Security fix for CVE-2022-46391. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-b645c7feda 2023-01-18 01:38:16.785686 --------------------------------------------------------------------------------Name : awstats Product : Fedora 37 Version : 7.8 Release : 9.fc37 URL : https://awstats.sourceforge.io/ Summary : Advanced Web Statistics Description : Advanced Web Statistics is a powerful and full-featured tool that generates advanced web server graphical statistics. This server log analyzer works from the command line or as a CGI and shows all information your log contains, in graphical web pages. It can analyze a lot of web/wap/proxy servers such as Apache, IIS, Weblogic, Webstar, Squid, ... but also mail or FTP servers. This program can measure visits, unique visitors, authenticated users, pages, domains/countries, OS busiest times, robot visits, type of files, search engines/keywords used, visit duration, HTTP errors and more... Statistics can be updated from a browser or your scheduler. The program also supports virtual servers, plugins and a lot of features. With the default configuration, the statistics are available at: --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-46391 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 9 2023 Tim Jackson - 7.8-9 - Fix CVE-2022-46391 (rhbz #2150632) - Clean up spec file, removing conditionals for now-obsolete releases --------------------------------------------------------------------------------References: [ 1 ] Bug #2150632 - CVE-2022-46391 awstats: XSS due to improper input checks https://bugzilla.redhat.com/show_bug.cgi?id=2150632 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnfupgrade --advisory FEDORA-2023-b645c7feda' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . System enhancement for awstats in Fedora tackles CVE-2022-46391 by implementing crucial input validation upgrades.. Awstats Security Update, Fedora Security Advisory, Input Validation Improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 18, 2023 Critical Fedora
100

SUSE: 2022:4293-1 Moderate: Freerdp Division By Zero Threat

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for freerdp ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:4293-1 Rating: moderate References: #1205563 #1205564 Cross-References: CVE-2022-39318 CVE-2022-39319 CVSS scores: CVE-2022-39318 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-39318 (SUSE): 4.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H CVE-2022-39319 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2022-39319 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:H Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for freerdp fixes the following issues: - CVE-2022-39318: Fixed division by zero in urbdrc (bsc#1205563). - CVE-2022-39319: Fixed missing input buffer length check in urbdrc (bsc#1205564). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-4293=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-4293=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): freerdp-2.1.2-12.32.1 freerdp-debuginfo-2.1.2-12.32.1 freerdp-debugsource-2.1.2-12.32.1 freerdp-proxy-2.1.2-12.32.1 freerdp-server-2.1.2-12.32.1 libfreerdp2-2.1.2-12.32.1 libfreerdp2-debuginfo-2.1.2-12.32.1 libwinpr2-2.1.2-12.32.1 libwinpr2-debuginfo-2.1.2-12.32.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): freerdp-debuginfo-2.1.2-12.32.1 freerdp-debugsource-2.1.2-12.32.1 freerdp-devel-2.1.2-12.32.1 libfreerdp2-2.1.2-12.32.1 libfreerdp2-debuginfo-2.1.2-12.32.1 libwinpr2-2.1.2-12.32.1 libwinpr2-debuginfo-2.1.2-12.32.1 winpr2-devel-2.1.2-12.32.1 References: https://www.suse.com/security/cve/CVE-2022-39318.html https://www.suse.com/security/cve/CVE-2022-39319.html https://bugzilla.suse.com/1205563 https://bugzilla.suse.com/1205564 . SUSE Security Notice: Freerdp addresses critical flaws including zero division errors and input buffer size vulnerabilities. Urgent update needed.. SUSE Linux, Freerdp, Moderate Security Fix, Update Information. . LinuxSecurity.com Team

Calendar 2 Nov 29, 2022 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here