Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
202

openSUSE: Moderate CVE-2025-6069 Input Processing Issue in Python310

An update that solves one vulnerability can now be installed.. # Security update for python310 Announcement ID: SUSE-SU-2025:02597-1 Release Date: 2025-08-01T15:14:37Z Rating: moderate References: * bsc#1244705 Cross-References: * CVE-2025-6069 CVSS scores: * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python310 fixes the following issues: * CVE-2025-6069: Avoid worst case quadratic complexity when processing certain crafted malformed inputs with HTMLParser (bsc#1244705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-2597=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-2597=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * python310-3.10.18-150400.4.85.1 * python310-dbm-debuginfo-3.10.18-150400.4.85.1 * python310-curses-3.10.18-150400.4.85.1 * python310-testsuite-debuginfo-3.10.18-150400.4.85.1 * python310-dbm-3.10.18-150400.4.85.1 * python310-doc-devhelp-3.10.18-150400.4.85.1 * libpython3_10-1_0-3.10.18-150400.4.85.1 * python310-base-3.10.18-150400.4.85.1 * python310-core-debugsource-3.10.18-150400.4.85.1 * python310-curses-debuginfo-3.10.18-150400.4.85.1 * python310-debuginfo-3.10.18-150400.4.85.1 * python310-debugsource-3.10.18-150400.4.85.1 * python310-devel-3.10.18-150400.4.85.1 * python310-doc-3.10.18-150400.4.85.1 * python310-tk-debuginfo-3.10.18-150400.4.85.1 *python310-testsuite-3.10.18-150400.4.85.1 * python310-idle-3.10.18-150400.4.85.1 * python310-base-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-debuginfo-3.10.18-150400.4.85.1 * python310-tk-3.10.18-150400.4.85.1 * python310-tools-3.10.18-150400.4.85.1 * openSUSE Leap 15.4 (x86_64) * python310-32bit-3.10.18-150400.4.85.1 * libpython3_10-1_0-32bit-3.10.18-150400.4.85.1 * python310-base-32bit-3.10.18-150400.4.85.1 * python310-32bit-debuginfo-3.10.18-150400.4.85.1 * python310-base-32bit-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-32bit-debuginfo-3.10.18-150400.4.85.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-base-64bit-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-64bit-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-64bit-3.10.18-150400.4.85.1 * python310-base-64bit-3.10.18-150400.4.85.1 * python310-64bit-debuginfo-3.10.18-150400.4.85.1 * python310-64bit-3.10.18-150400.4.85.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python310-3.10.18-150400.4.85.1 * python310-dbm-debuginfo-3.10.18-150400.4.85.1 * python310-curses-3.10.18-150400.4.85.1 * python310-testsuite-debuginfo-3.10.18-150400.4.85.1 * python310-dbm-3.10.18-150400.4.85.1 * python310-doc-devhelp-3.10.18-150400.4.85.1 * libpython3_10-1_0-3.10.18-150400.4.85.1 * python310-base-3.10.18-150400.4.85.1 * python310-core-debugsource-3.10.18-150400.4.85.1 * python310-curses-debuginfo-3.10.18-150400.4.85.1 * python310-debuginfo-3.10.18-150400.4.85.1 * python310-debugsource-3.10.18-150400.4.85.1 * python310-devel-3.10.18-150400.4.85.1 * python310-doc-3.10.18-150400.4.85.1 * python310-testsuite-3.10.18-150400.4.85.1 * python310-tk-debuginfo-3.10.18-150400.4.85.1 * python310-idle-3.10.18-150400.4.85.1 * python310-base-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-debuginfo-3.10.18-150400.4.85.1 * python310-tk-3.10.18-150400.4.85.1 *python310-tools-3.10.18-150400.4.85.1 * openSUSE Leap 15.6 (x86_64) * python310-32bit-3.10.18-150400.4.85.1 * libpython3_10-1_0-32bit-3.10.18-150400.4.85.1 * python310-base-32bit-3.10.18-150400.4.85.1 * python310-32bit-debuginfo-3.10.18-150400.4.85.1 * python310-base-32bit-debuginfo-3.10.18-150400.4.85.1 * libpython3_10-1_0-32bit-debuginfo-3.10.18-150400.4.85.1 ## References: * https://www.suse.com/security/cve/CVE-2025-6069.html * https://bugzilla.suse.com/show_bug.cgi?id=1244705 . A significant announcement regarding python310 has been made, highlighting a moderate risk flaw associated with input handling complications.. python310 update, security patch, openSUSE advisory, moderate risk CVE, input processing bug. . LinuxSecurity.com Team

Calendar 2 Aug 01, 2025 OpenSUSE
100

SUSE: 2025:0512-1 important: libtasn1 input processing threat

* bsc#1236878 Cross-References: * CVE-2024-12133 . # Security update for libtasn1 Announcement ID: SUSE-SU-2025:0512-1 Release Date: 2025-02-13T11:47:14Z Rating: important References: * bsc#1236878 Cross-References: * CVE-2024-12133 CVSS scores: * CVE-2024-12133 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-12133 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12133 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libtasn1 fixes the following issues: * CVE-2024-12133: the processing of input DER data containing a large number of SEQUENCE OF or SET OF elements takes quadratic time to complete. (bsc#1236878) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2025-512=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-512=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libtasn1-6-debuginfo-4.9-3.16.1 * libtasn1-4.9-3.16.1 * libtasn1-debugsource-4.9-3.16.1 * libtasn1-debuginfo-4.9-3.16.1 * libtasn1-6-4.9-3.16.1 * libtasn1-devel-4.9-3.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libtasn1-6-32bit-4.9-3.16.1 * libtasn1-6-debuginfo-32bit-4.9-3.16.1 * SUSE LinuxEnterprise Server 12 SP5 LTSS Extended Security (x86_64) * libtasn1-6-debuginfo-4.9-3.16.1 * libtasn1-4.9-3.16.1 * libtasn1-6-debuginfo-32bit-4.9-3.16.1 * libtasn1-debugsource-4.9-3.16.1 * libtasn1-debuginfo-4.9-3.16.1 * libtasn1-6-32bit-4.9-3.16.1 * libtasn1-6-4.9-3.16.1 * libtasn1-devel-4.9-3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12133.html * https://bugzilla.suse.com/show_bug.cgi?id=1236878 . Crucial libtasn1 security patch for SUSE resolves input handling vulnerabilities to bolster system security.. libtasn1 update, SUSE security fix, important security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 13, 2025 Important SuSE
172

Ubuntu 22.10: 5907-1 Serious Risk of c-ares Denial Of Service Attack

c-ares could be made to crash or run programs if it processed specially crafted input.. =========================================================================Ubuntu Security Notice USN-5907-1 March 02, 2023 c-ares vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: c-ares could be made to crash or run programs if it processed specially crafted input. Software Description: - c-ares: library for asynchronous name resolution Details: It was discovered that c-ares incorrectly handled certain sortlist strings. A remote attacker could use this issue to cause c-ares to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: libc-ares2 1.18.1-1ubuntu0.22.10.1 Ubuntu 22.04 LTS: libc-ares2 1.18.1-1ubuntu0.22.04.1 Ubuntu 20.04 LTS: libc-ares2 1.15.0-1ubuntu0.2 Ubuntu 18.04 LTS: libc-ares2 1.14.0-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5907-1 CVE-2022-4904 Package Information: https://launchpad.net/ubuntu/+source/c-ares/1.18.1-1ubuntu0.22.10.1 https://launchpad.net/ubuntu/+source/c-ares/1.18.1-1ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/c-ares/1.15.0-1ubuntu0.2 https://launchpad.net/ubuntu/+source/c-ares/1.14.0-1ubuntu0.2 . Ensure your Ubuntu installation is updated to mitigate the c-ares vulnerability, which could lead to system crashes or unauthorized code execution upon receiving specially designed input.. Ubuntu Security, c-ares Issue, Security Update, Denial of Service, Remote Execution. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Mar 02, 2023 Critical Ubuntu
87

Debian 3.0: DSA-720-1 Critical Remote Exploit in Smartlist

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 720-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze May 3rd, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : smartlist Vulnerability : wrong input processing Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-0157 Jeroen van Wolffelaar noticed that the confirm add-on of SmartList, the listmanager used on lists.debian.org, which is used on that host as well, could be tricked to subscribe arbitrary addresses to the lists. For the stable distribution (woody) this problem has been fixed in version 3.15-5.woody.1. For the unstable distribution (sid) this problem has been fixed in version 3.15-18. We recommend that you upgrade your smartlist package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 591 3876af4dd42b57ffe3a442936050e2e0 Size/MD5 checksum: 18960 72c921048d0aae96ba993e0431a2ac3b Size/MD5 checksum: 276652 105cb4a2bf22324afc10654236926f45 Alpha architecture: Size/MD5 checksum: 100100 b747b361beeec6828168fd28b5e2a9bf ARM architecture: Size/MD5 checksum: 97380 c89d5ecf5bf17c6defe1ccd0ea5cf91e Intel IA-32 architecture: Size/MD5 checksum: 97346 1d3c7ae8e0a4972beccaaa2af5fdfa3c Intel IA-64 architecture: Size/MD5 checksum: 103260 ed3fea87f7329abcb807ae85fc77323e HP Precision architecture: Size/MD5 checksum: 99270 fed594324e9e63416b2b0b64f060e5ec Motorola 680x0 architecture: Size/MD5 checksum: 96684 eb186656e073b848ce8135d9bc21a471 Big endian MIPS architecture: Size/MD5 checksum: 97736 4e9951dab3a2f10203b228a04b7f6eb1 Little endian MIPS architecture: Size/MD5 checksum: 97798 1d572809bb860c0ddc8aa6e2be027758 PowerPC architecture: Size/MD5 checksum: 97570 bdcf89fe0d8619942278be852db8493e IBM S/390 architecture: Size/MD5 checksum: 98268 e839fc7457330bf46bad0e00b2329778 Sun Sparc architecture: Size/MD5 checksum: 97280 dc87465a7fe50d5ca2567038a4636ad5 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance the smartlist software in Debian to resolve unauthorized subscription vulnerabilities. Urgent security patch accessible immediately.. Debian Security Update, Smartlist Exploit, Remote Access Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 03, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here