Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE: 2024:0327-1 Important: Jsch and Bouncycastle Security Issue

* bsc#1218134 Cross-References: * CVE-2023-48795 . # Security update for bouncycastle, jsch Announcement ID: SUSE-SU-2024:0327-1 Rating: important References: * bsc#1218134 Cross-References: * CVE-2023-48795 CVSS scores: * CVE-2023-48795 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-48795 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * Development Tools Module 15-SP5 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 Module 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for bouncycastle, jsch fixes the following issues: * Updated jsch to version 0.2.15: * CVE-2023-48795: Fixed a prefix truncation issue that could leadto disclosure of sensitive information (bsc#1218134). * Updated bouncycastle to version 1.77. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-327=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-327=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-327=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-327=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-327=1 * SUSE Manager Server 4.3 Module 4.3 zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2024-327=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-327=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-327=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-327=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-327=1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-327=1 * SUSE Linux Enterprise Server for SAPApplications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-327=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Enterprise Storage 7.1 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * openSUSE Leap 15.5 (noarch) * bouncycastle-mail-1.77-150200.3.24.1 * bouncycastle-1.77-150200.3.24.1 * bouncycastle-tls-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-jmail-1.77-150200.3.24.1 * bouncycastle-javadoc-1.77-150200.3.24.1 * jsch-javadoc-0.2.15-150200.11.13.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * jsch-demo-0.2.15-150200.11.13.1 * Development Tools Module 15-SP5 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Manager Server 4.3 Module 4.3 (noarch) * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS 15-SP4 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * bouncycastle-1.77-150200.3.24.1 * bouncycastle-util-1.77-150200.3.24.1 * bouncycastle-pkix-1.77-150200.3.24.1 * bouncycastle-pg-1.77-150200.3.24.1 * jsch-0.2.15-150200.11.13.1 ##References: * https://www.suse.com/security/cve/CVE-2023-48795.html * https://bugzilla.suse.com/show_bug.cgi?id=1218134 . An important announcement pertains to the resolution of a prefix cutting problem in jsch and bouncycastle. Discover further details.. jsch Security Patch, bouncycastle Fix, SUSE Important Update, Linux Software Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 05, 2024 Important SuSE
100

SUSE: 2024:0057-1 important: eclipse-jgit jsch file overwrite

* bsc#1209646 * bsc#1211955 * bsc#1215298 * jsc#PED-6376 * jsc#PED-6377 . # Security update for eclipse-jgit, jsch Announcement ID: SUSE-SU-2024:0057-1 Rating: important References: * bsc#1209646 * bsc#1211955 * bsc#1215298 * jsc#PED-6376 * jsc#PED-6377 Cross-References: * CVE-2023-4759 CVSS scores: * CVE-2023-4759 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-4759 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Development Tools Module 15-SP4 * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 Module 4.3 An update that solves one vulnerability, contains two features and has two security fixes can now be installed. ## Description: This update for eclipse-jgit, jsch fixes thefollowing issues: Security fix: \- CVE-2023-4759: Fixed an arbitrary file overwrite which might have occurred with a specially crafted git repository and a case-insensitive filesystem. (bsc#1215298) Other fixes: jsch was updated to version 0.2.9: \- Added support for various algorithms \- Migrated from `com.jcraft:jsch` to `com.github.mwiede:jsch` fork (bsc#1211955): * Alias to the old artifact since the new one is drop-in replacement * Keep the old OSGi bundle symbolic name to avoid extensive patching of eclipse stack \- Updated to version 0.2.9: * For the full list of changes please consult the upstream changelogs below for each version updated: \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.9 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.8 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.7 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.6 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.5 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.4 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.3 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.2 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.1 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.2.0 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.71 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.70 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.69 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.68 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.67 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.66 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.65 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.64 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.63 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.62 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.61 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.60 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.59\+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.58 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.57 \+ https://github.com/mwiede/jsch/releases/tag/jsch-0.1.56 eclipse-jgit: * Craft the jgit script from the real Main class of the jar file instead of using a jar launcher (bsc#1209646) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2024-57=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-57=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2024-57=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2024-57=1 * SUSE Manager Server 4.3 Module 4.3 zypper in -t patch SUSE-SLE-Module-SUSE-Manager-Server-4.3-2024-57=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-57=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2024-57=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-57=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-57=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-57=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-57=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-57=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-57=1 ## Package List: * openSUSE Leap 15.4 (noarch) * jsch-demo-0.2.9-150200.11.10.1 *jsch-javadoc-0.2.9-150200.11.10.1 * jgit-javadoc-5.11.0-150200.3.15.2 * eclipse-jgit-5.11.0-150200.3.15.2 * jgit-5.11.0-150200.3.15.2 * jsch-0.2.9-150200.11.10.1 * openSUSE Leap 15.5 (noarch) * eclipse-jgit-5.11.0-150200.3.15.2 * jsch-demo-0.2.9-150200.11.10.1 * jsch-javadoc-0.2.9-150200.11.10.1 * jsch-0.2.9-150200.11.10.1 * Development Tools Module 15-SP4 (noarch) * jsch-0.2.9-150200.11.10.1 * Development Tools Module 15-SP5 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Manager Server 4.3 Module 4.3 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * jsch-0.2.9-150200.11.10.1 * SUSE Enterprise Storage 7.1 (noarch) * jsch-0.2.9-150200.11.10.1 ## References: * https://www.suse.com/security/cve/CVE-2023-4759.html * https://bugzilla.suse.com/show_bug.cgi?id=1209646 * https://bugzilla.suse.com/show_bug.cgi?id=1211955 * https://bugzilla.suse.com/show_bug.cgi?id=1215298 * * . SUSE announces a crucial security update for eclipse-jgit and jsch addressing a critical flaw.. SUSE Linux,Eclipse JGit,JSCH,Security Update,Threat Mitigation. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 08, 2024 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here