Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
89

Fedora 28: FEDORA-2018-f513267ac5 Critical: Matrix-Synapse DoS Issue

Update to latest upstream. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f513267ac5 2018-05-15 20:03:56.911926 --------------------------------------------------------------------------------Name : matrix-synapse Product : Fedora 28 Version : 0.28.1 Release : 1.fc28 URL : https://github.com/matrix-org/synapse Summary : A Matrix reference homeserver written in Python using Twisted Description : Matrix is an ambitious new ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix from the core development team at matrix.org, written in Python/Twisted. It is intended to showcase the concept of Matrix and let folks see the spec in the context of a coded base and let you run your own homeserver and generally help bootstrap the ecosystem. --------------------------------------------------------------------------------Update Information: Update to latest upstream --------------------------------------------------------------------------------ChangeLog: * Tue May 1 2018 Jeremy Cline - 0.28.1-1 - Update to the latest upstream release. --------------------------------------------------------------------------------References: [ 1 ] Bug #1567107 - matrix-synapse-0.28.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1567107 [ 2 ] Bug #1574780 - CVE-2018-10657 matrix-synapse: Injection of malicious events with a depth size of 2^63-1 can cause a denial of service to making rooms unusable [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1574780 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-f513267ac5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html Allpackages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This patch fixes an important vulnerability found in Matrix Synapse for Fedora 28. Discover how to perform the upgrade process.. Matrix Synapse Update,Fedora 28 Security,DoS Prevention,Instant Messaging Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2018 Critical Fedora
89

Fedora 25: Critical Jabberd 2.6.1 Security Fix Advisory

updated to 2.6.1 (security bugfix release). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-9dd1004ad8 2017-07-14 11:44:22.390822 --------------------------------------------------------------------------------Name : jabberd Product : Fedora 25 Version : 2.6.1 Release : 1.fc25 URL : https://jabberd2.org/ Summary : OpenSource server implementation of the Jabber protocols Description : The jabberd project aims to provide an open-source server implementation of the Jabber protocols for instant messaging and XML routing. The goal of this project is to provide a scalable, reliable, efficient and extensible server that provides a complete set of features and is up to date with the latest protocol revisions. jabberd2 is the next generation of the jabberd server. It has been rewritten from the ground up to be scalable, architecturally sound, and to support the latest protocol extensions coming out of the JSF. This package defaults to use pam and sqlite. --------------------------------------------------------------------------------Update Information: updated to 2.6.1 (security bugfix release) --------------------------------------------------------------------------------References: [ 1 ] Bug #1468568 - CVE-2017-10807 jabberd: CVE-2017-10807 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1468568 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade jabberd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Jabberd security patch improves stability and addresses significant vulnerabilities. Discover the details of this update.. Jabberd Bugfix, Fedora Security Update, Jabber Protocols Server. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 14, 2017 Critical Fedora
89

Fedora: 2017-8840ec0204 Critical: Empathy Instant Messaging Update

Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8840ec0204 2017-04-01 16:46:19.662323 -------------------------------------------------------------------------------- Name : empathy Product : Fedora 26 Version : 3.12.13 Release : 2.fc26 URL : Summary : Instant Messaging Client for GNOME Description : Empathy is powerful multi-protocol instant messaging client which supports Jabber, GTalk, MSN, IRC, Salut, and other protocols. It is built on top of the Telepathy framework. -------------------------------------------------------------------------------- Update Information: Fix certificate validation to work without legacy CAs. ---- empathy 3.12.13 release. For details, see https://mail.gnome.org/archives/ftp-release-list/2017-March/msg00077.html -------------------------------------------------------------------------------- References: [ 1 ] Bug #1381671 - Fails to connect to Google, with legacy CAs disabled, or with ca-certificates version 2.10 https://bugzilla.redhat.com/show_bug.cgi?id=1381671 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade empathy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolves certificate verification issues in compassion for Fedora 26, eliminating outdated CAs in the newest security patch.. Empathy Update,Fedora Security,Certificate Validation,Instant Messaging,Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 01, 2017 Critical Fedora
89

Fedora 23: Latest Security Update Released For Mcabber Chat Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-7da97a3914 2016-12-11 16:19:11.675039 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 23 Version : 1.0.4 Release : 1.fc23 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora's mcabber console messaging client receives a security patch improving chat functionalities and strengthening SSL integration.. Fedora Update, mcabber Client, Console Messaging, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Important Fedora
89

Fedora 24: Security Update on Mcabber Instant Messaging Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-30f68ec06b 2016-12-11 16:19:33.990660 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 24 Version : 1.0.4 Release : 1.fc24 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Delve into the Fedora 24 security patch for mcabber, enhancing your messaging application with essential improvements and repairs.. Fedora 24, mcabber, security updates, instant messaging client. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Important Fedora
89

Fedora 25 Mcabber Security Advisory: Updates for Instant Messaging Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e865601498 2016-12-11 16:19:57.246617 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 25 Version : 1.0.4 Release : 1.fc25 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Mcabber release for Fedora 25 enhances security mechanisms and fixes associated vulnerabilities. Update now for optimal functionality.. Fedora Updates, Mcabber Client, Security Enhancements, Instant Messaging App. . LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Fedora
89

Fedora 23: Jabberd Security Advisory for Dialback PRNG Fix

fixes "Dialback secrets are generated using a non-cryptographically secure PRNG". -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-ba6fd98830 2016-02-29 02:06:34.731967 -------------------------------------------------------------------------------- Name : jabberd Product : Fedora 23 Version : 2.3.3 Release : 7.fc23 URL : https://jabberd2.org/ Summary : OpenSource server implementation of the Jabber protocols Description : The jabberd project aims to provide an open-source server implementation of the Jabber protocols for instant messaging and XML routing. The goal of this project is to provide a scalable, reliable, efficient and extensible server that provides a complete set of features and is up to date with the latest protocol revisions. jabberd2 is the next generation of the jabberd server. It has been rewritten from the ground up to be scalable, architecturally sound, and to support the latest protocol extensions coming out of the JSF. This package defaults to use pam and sqlite. -------------------------------------------------------------------------------- Update Information: fixes "Dialback secrets are generated using a non-cryptographically secure PRNG" -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update jabberd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Debian 9 updates prosody torectify weak random number generator for authentication tokens, enhancing overall security measures.. Jabberd Update,Fedora 23 Security,PRNG Fix,Open Source Messaging,Jabber Protocol Improvements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 29, 2016 Critical Fedora
89

CentOS 7: 2023-b5a4f2a6c3 Critical: Signal-CLI Vulnerability Patch

telegram-cli-1.3.1-7.20150730git2052f4.fc22 - Hardened builds on

Calendar 2 Nov 16, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here