Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia: 2020-0313 Critical: Php-PhpMailer Insufficient Escaping Issue

Fix insufficient output escaping bug in file attachment names (CVE-2020-13625). References: - https://bugs.mageia.org/show_bug.cgi?id=26760 . MGASA-2020-0313 - Updated php-phpmailer packages fix security vulnerability Publication date: 01 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0313.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-13625 Fix insufficient output escaping bug in file attachment names (CVE-2020-13625). References: - https://bugs.mageia.org/show_bug.cgi?id=26760 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/OBRDMEV3CB44CAAF5BOHFNV23JVRO6PZ/ - https://github.com/advisories/GHSA-f7hx-fqxw-rvvj - https://www.cve.org/CVERecord?id=CVE-2020-13625 SRPMS: - 7/core/php-phpmailer-6.1.6-1.mga7 . Mageia security advisory MGASA-2020-0313 resolves an issue with php-phpmailer regarding inadequate escaping of filenames for attachments.. Mageia php-phpmailer security update, critical security patch, insufficient escaping, file attachments. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 01, 2020 Critical Mageia
89

Fedora 25: 2017-f85c37ae3d moderate: Squirrelmail Insufficient Escaping

fix insufficient escaping of user-supplied data (CVE-2017-7692). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f85c37ae3d 2017-06-02 17:35:06.903270 --------------------------------------------------------------------------------Name : squirrelmail Product : Fedora 25 Version : 1.4.22 Release : 19.fc25 URL : https://www.squirrelmail.org/ Summary : webmail client written in php Description : SquirrelMail is a basic webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no JavaScript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. --------------------------------------------------------------------------------Update Information: fix insufficient escaping of user-supplied data (CVE-2017-7692) --------------------------------------------------------------------------------References: [ 1 ] Bug #1445165 - CVE-2017-7692 squirrelmail: Insufficient escaping of user-supplied data https://bugzilla.redhat.com/show_bug.cgi?id=1445165 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade squirrelmail' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Addresses a vulnerabilityrelated to inadequate escaping in SquirrelMail for Fedora 25. Implemented improvements to bolster security measures.. Fedora Updates, Squirrelmail Security, PHP Webmail Protection. . LinuxSecurity.com Team

Calendar 2 Jun 03, 2017 Fedora
87

Debian Sarge DSA-1251-1 Critical Netrik Remote Command Execution

Updated package.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1251-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp January 21, 2007 - ------------------------------------------------------------------------Package : netrik Vulnerability : insufficient escaping Problem type : remote Debian-specific: no CVE Id(s) : CVE-2006-6678 Debian Bug : 404233 It has been discovered that netrik, a text mode WWW browser with vi like keybindings, doesn't properly sanitize temporary filenames when editing textareas which could allow attackers to execute arbitrary commands via shell metacharacters. For the stable distribution (sarge), this problem has been fixed in version 1.15.4-1sarge1. For the upcoming stable distribution (etch) this problem has been fixed in version 1.15.3-1.1. For the unstable distribution (sid) this problem has been fixed in version 1.15.3-1.1. We recommend that you upgrade your netrik package. Upgrade instructions - --------------------Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 620 31e1673b4ac99919469faf3dc9c54a08 Size/MD5 checksum: 22821 7a55e2a9d74a24cb891afd4e9a44c703 Size/MD5 checksum: 216160 1d0a41153b93b07b8cdaa9e7e9556848 Alpha architecture: Size/MD5 checksum: 278212 a6b2f7f278cfe2f30d3f0fd954ad3e53 AMD64 architecture: Size/MD5 checksum: 273334 b6b7826f7d876a963ce423bee53121b3 ARM architecture: Size/MD5 checksum: 270014 dc2dfdb7e203515859391e57207a224c HP Precision architecture: Size/MD5 checksum: 275476 8184e4e6ea4f08cb6ce7d9a2350860af Intel IA-32 architecture: Size/MD5 checksum: 276780 a8ed3c443444e5090d58c7d422825381 Intel IA-64 architecture: Size/MD5 checksum: 292688 7efd26ab39d1056f6c520498fdf352a1 Motorola 680x0 architecture: Size/MD5 checksum: 264084 2ebb4ec950c7bb92fe8c257f70905ba0 Big endian MIPS architecture: Size/MD5 checksum: 272624 9764fbbb151dcd282582c163c2457aeb Little endian MIPS architecture: Size/MD5 checksum: 272788 9007ba43c4539f3620509a51889729c8 PowerPC architecture: Size/MD5 checksum: 272240 4700e9b69cd678582ccfc29e5ab05633 IBM S/390 architecture: Size/MD5 checksum: 271492 dd41604dce1d89ec3b3dfec99a56a5b2 Sun Sparc architecture: Size/MD5 checksum: 269562 bb4650deeda9ee6089bc9021e54a3e86 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade netrik dependencies to mitigate risks of unintended command execution due to inadequate escaping, thus ensuring the security of remote operations.. Remote Command Execution, Security Advisory, Debian Netrik Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 21, 2007 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here