Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 40: 2024-129d8ca6fc High: Beust-JCommander Type Confusion

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : beust-jcommander Product : Fedora 40 Version : 1.82 Release : 9.fc40 URL : http://jcommander.org/ Summary : Java framework for parsing command line parameters Description : JCommander is a very small Java framework that makes it trivial to parse command line parameters (with annotations). -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.82-9 - Rebuilt for java-21-openjdk as system jdk * Fri Mar 1 2024 Jiri Vanek - 1.82-8 - bump of release for for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora patch for jcommander-beust tackles critical vulnerabilities involving Type Confusion in the V8 engine and enhances JDK.. fedora update,type confusion,java framework,jdk 21,command line parsing. . LinuxSecurity.com Team

Calendar%202 Mar 07, 2024 Fedora
197

Debian 10: DLA-3656-1 Moderate: Netty Denial Of Service Threat

A flaw was discovered in Netty, a Java NIO client/server socket framework. The HTTP/2 protocol implementation allowed a denial of service (server resource consumption) because request cancellation can reset many streams quickly. This problem is also known as Rapid Reset Attack. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3656-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany November 19, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : netty Version : 1:4.1.33-1+deb10u4 CVE ID : CVE-2023-44487 Debian Bug : 1054234 A flaw was discovered in Netty, a Java NIO client/server socket framework. The HTTP/2 protocol implementation allowed a denial of service (server resource consumption) because request cancellation can reset many streams quickly. This problem is also known as Rapid Reset Attack. For Debian 10 buster, this problem has been fixed in version 1:4.1.33-1+deb10u4. We recommend that you upgrade your netty packages. For the detailed security status of netty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/netty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A notice concerning the Rapid Reset Attack on Netty for Debian LTS has been issued. It's advised to apply the latest updates to mitigate the risks of service disruption.. Debian LTS,Netty Security Update,Rapid Reset Attack,Java NIO Framework,Network Protocol Security. . LinuxSecurity.com Team

Calendar%202 Nov 19, 2023 Debian LTS
87

Debian Security Advisory DSA-4532-2 Critical: Libxml2-Java Data Leak

It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3536-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond March 31, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libstruts1.2-java CVE ID : CVE-2015-0899 It was discovered that libstruts1.2-java, a Java framework for MVC applications, contains a bug in its multi-page validation code. This allows input validation to be bypassed, even if MPV is not used directly. For the oldstable distribution (wheezy), this problem has been fixed in version 1.2.9-5+deb7u2. We recommend that you upgrade your libstruts1.2-java packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Libstruts1.2-java security patch resolves data sanitation issues on Ubuntu installations.. libstruts1.2, Java Framework, Input Issue, Debian Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 31, 2016 Critical Debian
89

Fedora 21 FEDORA-2015-11184 Critical: Springframework DoS Fix

Security fix for CVE-2015-3192. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-11184 2015-07-04 17:45:37 -------------------------------------------------------------------------------- Name : springframework Product : Fedora 21 Version : 3.2.14 Release : 1.fc21 URL : https://spring.io/projects/spring-framework/ Summary : Spring Java Application Framework Description : Spring is a layered Java/J2EE application framework, based on code published in Expert One-on-One J2EE Design and Development by Rod Johnson (Wrox, 2002). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3192 -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2015 Michal Srb - 0:3.2.14-1 - Update to 3.2.14 - Resolves: CVE-2015-3192 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1239002 - CVE-2015-3192 Spring Framework: denial-of-service attack with XML input https://bugzilla.redhat.com/show_bug.cgi?id=1239002 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update springframework' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora Update Notification FEDORA-2015-11184 2015-07-04 17:45:37 Name : springframework Product : Fe. security,cve-2015-3192, ---------------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 16, 2015 Critical Fedora
89

Fedora Core 5 glib-java Update: FEDORA-2006-739 Medium Severity

Make current version of frysk available to FC5 users.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-739 2006-06-21 ---------------------------------------------------------------------Product : Fedora Core 5 Name : glib-java Version : 0.2.5 Release : 0.FC5 Summary : Base Library for the Java-GNOME libraries Description : Glib-java is a base framework for the Java-GNOME libraries. Allowing the use of GNOME through Java. ---------------------------------------------------------------------Update Information: Make current version of frysk available to FC5 users. ---------------------------------------------------------------------* Wed Jun 14 2006 Stepan Kasal - 0.2.5-0 - New version. * Wed May 24 2006 Ben Konrath - 0.2.4-4 - Change mod time of all java source files for the src zip. * Thu May 18 2006 Ben Konrath - 0.2.4-3 - Ensure Config.java has the same mod time accross rebuilds (needed for multilib). * Wed May 10 2006 Ben Konrath - 0.2.4-2 - Add -X option when zipping up the sources. This is needed for multilib. * Fri Apr 28 2006 Stepan Kasal - 0.2.4-1 - New version. ---------------------------------------------------------------------This update can be downloaded from: 128970ad158a14120a875cd1e577ecb6c2cbbbd1 SRPMS/glib-java-0.2.5-0.FC5.src.rpm 128970ad158a14120a875cd1e577ecb6c2cbbbd1 noarch/glib-java-0.2.5-0.FC5.src.rpm ff8ea72a1c813c53f781b19118382d3f1f4cf84e ppc/glib-java-devel-0.2.5-0.FC5.ppc.rpm 0b4068ec1e26759702e4db8d78d15b6484eaac67 ppc/glib-java-0.2.5-0.FC5.ppc.rpm 23690a7cd2728f6f046dc445db18e30f79ded767 ppc/debug/glib-java-debuginfo-0.2.5-0.FC5.ppc.rpm cd5c04833a0098d8580b16004db61eb8667a3e3c x86_64/glib-java-devel-0.2.5-0.FC5.x86_64.rpm 4af58f42b6d0a7caac9fac10491ac4a5e4112256 x86_64/debug/glib-java-debuginfo-0.2.5-0.FC5.x86_64.rpm 5c34a90ff91c72dd1be02f1fa99e739e3fd3f6ef x86_64/glib-java-0.2.5-0.FC5.x86_64.rpm f8828b971ed6b24366a086d47d36e55aa9d6c9ec i386/glib-java-devel-0.2.5-0.FC5.i386.rpm 99d69bdb3b9ba86b30db7d874b6125ac44c82716 i386/glib-java-0.2.5-0.FC5.i386.rpm 3c24f8d9de804a948fab64452bcb7b6322279ae4 i386/debug/glib-java-debuginfo-0.2.5-0.FC5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Be informed about the release of glib-java 0.2.5 in Fedora Core 5, which enhances Java-GNOME connectivity for improved performance.. Fedora Core 5, glib-java update, Java GNOME library, software update, framework release. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 21, 2006 Medium Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200