Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
203

Mageia: 2021-0492 Moderate: Opencryptoki Invalid Curve Attack

It was discovered that openCryptoki incorrectly handled certain EC keys. An attacker could possibly use this issue to cause a invalid curve attack. References: - https://bugs.mageia.org/show_bug.cgi?id=29328 . MGASA-2021-0492 - Updated opencryptoki packages fix security vulnerability Publication date: 27 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0492.html Type: security Affected Mageia releases: 8 It was discovered that openCryptoki incorrectly handled certain EC keys. An attacker could possibly use this issue to cause a invalid curve attack. References: - https://bugs.mageia.org/show_bug.cgi?id=29328 - https://ubuntu.com/security/notices/USN-5031-1 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/FLP3UNIVGYENSFGVADMQ2IYP4A3TDYJC/ SRPMS: - 8/core/opencryptoki-3.15.1-1.1.mga8 . OpenCryptoki upgrade mitigates EC key management issue enabling possible flawed curve exploitation. Discover further insights for specifics.. Mageia Security Update, OpenCryptoki Vulnerability, EC Key Issue, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Oct 27, 2021 Mageia
172

Ubuntu 21.04 USN-5031-1: Addressing openCryptoki Invalid Curve Attack

openCryptoki could be made to allow invalid curve attacks if it received a specially crafted key.. =========================================================================Ubuntu Security Notice USN-5031-1 August 04, 2021 opencryptoki vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 Summary: openCryptoki could be made to allow invalid curve attacks if it received a specially crafted key. Software Description: - opencryptoki: PKCS#11 implementation (daemon) Details: It was discovered that openCryptoki incorrectly handled certain EC keys. An attacker could possibly use this issue to cause a invalid curve attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libopencryptoki0 3.15.1+dfsg-0ubuntu1.2 opencryptoki 3.15.1+dfsg-0ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5031-1 https://bugs.launchpad.net/ubuntu/+source/opencryptoki/+bug/1928780 Package Information: https://launchpad.net/ubuntu/+source/opencryptoki/3.15.1+dfsg-0ubuntu1.2 . The Ubuntu Security Announcement USN-5032-1 warns of a vulnerability in the openCryptoki package that may allow exploitation of invalid signatures. Update your system now!. openCryptoki Vulnerability, Invalid Curve Attack, Ubuntu Update Advisories. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 04, 2021 Important Ubuntu
203

Mageia: 2019-0176 Critical: FreeRADIUS Authentication Issues

An attacker can reflect the received scalar and element from the server in it's own commit message, and subsequently reflect the confirm value as well. This causes the adversary to successfully authenticate as the victim (CVE-2019-11234). . MGASA-2019-0176 - Updated freeradius packages fix security vulnerability Publication date: 18 May 2019 URL: https://advisories.mageia.org/MGASA-2019-0176.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-11234, CVE-2019-11235 An attacker can reflect the received scalar and element from the server in it's own commit message, and subsequently reflect the confirm value as well. This causes the adversary to successfully authenticate as the victim (CVE-2019-11234). An invalid curve attack allows an attacker to authenticate as any user (without knowing the password). The problem is that on the reception of an EAP-PWD Commit frame, FreeRADIUS doesn't verify whether the received elliptic curve point is valid (CVE-2019-11235). References: - https://bugs.mageia.org/show_bug.cgi?id=24762 - https://bugzilla.redhat.com/show_bug.cgi?id=1695748 - https://bugzilla.redhat.com/show_bug.cgi?id=1695783 - https://access.redhat.com/errata/RHSA-2019:1131 - https://www.cve.org/CVERecord?id=CVE-2019-11234 - https://www.cve.org/CVERecord?id=CVE-2019-11235 SRPMS: - 6/core/freeradius-3.0.15-1.1.mga6 . Mageia 2023-0045 addresses security flaws in OpenSSH, introducing essential enhancements to safeguard connections.. freeradius update,mageia security,authentication fix,critical security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 18, 2019 Critical Mageia
200

SciLinux 7 Important: SLSA-2019-1131-1 Freeradius Authentication Bypass

freeradius: eap-pwd: authentication bypass via an invalid curve attack (CVE-2019-11235) * freeradius: eap-pwd: fake authentication using reflection (CVE-2019-11234) SL7 x86_64 freeradius-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.1 [More...]. Synopsis: Important: freeradius security update Advisory ID: SLSA-2019:1131-1 Issue Date: 2019-05-09 CVE Numbers: CVE-2019-11235 CVE-2019-11234 -- Security Fix(es): * freeradius: eap-pwd: authentication bypass via an invalid curve attack (CVE-2019-11235) * freeradius: eap-pwd: fake authentication using reflection (CVE-2019-11234) -- SL7 x86_64 freeradius-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.13-10.el7_6.x86_64.rpm freeradius-doc-3.0.13-10.el7_6.x86_64.rpm freeradius-krb5-3.0.13-10.el7_6.x86_64.rpm freeradius-ldap-3.0.13-10.el7_6.x86_64.rpm freeradius-mysql-3.0.13-10.el7_6.x86_64.rpm freeradius-perl-3.0.13-10.el7_6.x86_64.rpm freeradius-postgresql-3.0.13-10.el7_6.x86_64.rpm freeradius-python-3.0.13-10.el7_6.x86_64.rpm freeradius-sqlite-3.0.13-10.el7_6.x86_64.rpm freeradius-unixODBC-3.0.13-10.el7_6.x86_64.rpm freeradius-utils-3.0.13-10.el7_6.x86_64.rpm - Scientific Linux Development Team . Important freeradius update addressing authentication bypass issues from invalid curve attacks.. freeradius, authentication bypass, invalid curve, security update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 09, 2019 Important Scientific Linux
87

Debian DSA-3417-1 High: Bouncy Castle Invalid Curve Attack

Tibor Jager, Jörg Schwenk, and Juraj Somorovsky, from Horst Görtz Institute for IT Security, published a paper in ESORICS 2015 where they describe an invalid curve attack in Bouncy Castle Crypto, a Java library for cryptography. An attacker is able to recover private Elliptic Curve . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3417-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Luciano Bello December 14, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : bouncycastle CVE ID : CVE-2015-7940 Debian Bug : 802671 Tibor Jager, Jörg Schwenk, and Juraj Somorovsky, from Horst Görtz Institute for IT Security, published a paper in ESORICS 2015 where they describe an invalid curve attack in Bouncy Castle Crypto, a Java library for cryptography. An attacker is able to recover private Elliptic Curve keys from different applications, for example, TLS servers. More information: https://web-in-security.blogspot.com/2015/09/practical-invalid-curve-attacks.html Practical Invalid Curve Attacks on TLS-ECDH: For the oldstable distribution (wheezy), this problem has been fixed in version 1.44+dfsg-3.1+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 1.49+dfsg-3+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 1.51-2. We recommend that you upgrade your bouncycastle packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian security notice DSA-3418-2 highlights severe vulnerabilities in the libssl package, recommending prompt action for software updates.. Bouncycastle Security,Invalid Curve Attack,Debian Update,JavaCryptography,Security Advisory. . LinuxSecurity.com Team

Calendar 2 Dec 14, 2015 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here