Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 22.04 LTS: USN-7464-1 critical: Jupyter Notebook ReDoS

Jupyter Notebook could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-7464-1 April 28, 2025 jupyter-notebook vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Jupyter Notebook could be made to crash if it received specially crafted input. Software Description: - jupyter-notebook: Jupyter interactive notebook Details: It was discovered that Jupyter Notebook did not properly parse HTML comments under certain circumstances. An attacker could possibly use this issue to cause a regular expression denial of service (ReDoS). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 jupyter-notebook 6.4.13-5ubuntu0.1 python3-notebook 6.4.13-5ubuntu0.1 Ubuntu 24.10 jupyter-notebook 6.4.13-2ubuntu0.1 python3-notebook 6.4.13-2ubuntu0.1 Ubuntu 24.04 LTS jupyter-notebook 6.4.12-2.2ubuntu1+esm1 Available with Ubuntu Pro python3-notebook 6.4.12-2.2ubuntu1+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS jupyter-notebook 6.4.8-1ubuntu0.1+esm1 Available with Ubuntu Pro python3-notebook 6.4.8-1ubuntu0.1+esm1 Available with Ubuntu Pro In general, a standard system updatewill make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7464-1 CVE-2022-25887 Package Information: https://launchpad.net/ubuntu/+source/jupyter-notebook/6.4.13-5ubuntu0.1 https://launchpad.net/ubuntu/+source/jupyter-notebook/6.4.13-2ubuntu0.1 . A significant vulnerability in Jupyter Notebook permits system crashes triggered by specially designed input. Ensure you update your Ubuntu packages without delay.. jupyter notebook security, ubuntu vulnerabilities, denial of service, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2025 Critical Ubuntu
198

Arch Linux: 201812-1 Medium Severity: Jupyter Notebook Cross-Site Scripting

The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting. . Arch Linux Security Advisory ASA-201812-1 ======================================== Severity: Medium Date : 2018-12-06 CVE-ID : CVE-2018-19351 CVE-2018-19352 Package : jupyter-notebook Type : cross-site scripting Remote : No Link : https://security.archlinux.org/AVG-820 Summary ====== The package jupyter-notebook before version 5.7.2-1 is vulnerable to cross-site scripting. Resolution ========= Upgrade to 5.7.2-1. # pacman -Syu "jupyter-notebook> =5.7.2-1" The problems have been fixed upstream in version 5.7.2. Workaround ========= None. Description ========== - CVE-2018-19351 (cross-site scripting) A security issue has been found in Jupyter Notebook versions prior to 5.7.1, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files. It allowed nbconvert endpoints (such as Print Preview) to render untrusted HTML and javascript with access to the notebook server. - CVE-2018-19352 (cross-site scripting) A security issue has been found in Jupyter Notebook versions prior to 5.7.2, where untrusted javascript could be executed if malicious files could be delivered to the users system and the user takes specific actions with those malicious files. It allowed maliciously crafted directory names to execute javascript when opened in the tree view. Impact ===== A remote attacker is able to execute javascript and create html content by tricking users into opening and interacting with maliciously crafted notebook files. References ========= https://bugs.archlinux.org/task/60910 https://security.archlinux.org/CVE-2018-19351 https://security.archlinux.org/CVE-2018-19352 . Follow these steps to update Jupyter Notebook on Arch Linux and address cross-site scripting vulnerabilities effectively and securely. Arch Linux Security,Jupyter Notebook Update,Cross-Site Scripting. . Severity: Medium.LinuxSecurity.com Team

Calendar 2 Dec 06, 2018 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here