Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
202

openSUSE: 2019:1259-1 Moderate: libqt5-qtvirtualkeyboard Keylogging Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libqt5-qtvirtualkeyboard ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1259-1 Rating: moderate References: #1118593 Cross-References: CVE-2018-19865 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libqt5-qtvirtualkeyboard fixes the following issues: Security issue fixed: - CVE-2018-19865: Fixed an issue with verbose keypress logging (boo#1118593). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1259=1 Package List: - openSUSE Leap 15.0 (x86_64): libqt5-qtvirtualkeyboard-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-debuginfo-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-debugsource-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-devel-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-examples-5.9.4-lp150.2.3.1 libqt5-qtvirtualkeyboard-examples-debuginfo-5.9.4-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-19865.html https://bugzilla.suse.com/1118593 -- . openSUSE Security Patch for libqt5-qtvirtualkeyboard resolves key input tracking vulnerability (CVE-2018-19865) successfully.. openSUSE Update, Linux Security, Keylogging Fix, libqt5 Security, Vulnerability Management. . LinuxSecurity.com Team

Calendar 2 Apr 23, 2019 OpenSUSE
198

Arch Linux 11.2.202.440-1 Critical: Flashplugin Remote Code Execution

The package flashplugin before version 11.2.202.440-1 is vulnerable to multiple issues including remote code execution, denial of service, keylogging and memory leaks. . Arch Linux Security Advisory ASA-201501-22 ========================================= Severity: Critical Date : 2015-01-23 CVE-ID : CVE-2015-0311 CVE-2015-0301 CVE-2015-0302 CVE-2015-0303 CVE-2015-0304 CVE-2015-0305 CVE-2015-0306 CVE-2015-0307 CVE-2015-0308 CVE-2015-0309 Package : flashplugin Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package flashplugin before version 11.2.202.440-1 is vulnerable to multiple issues including remote code execution, denial of service, keylogging and memory leaks. Resolution ========= Upgrade to 11.2.202.440-1. # pacman -Syu "flashplugin> =11.2.202.440-1" The problems have been fixed upstream in version 11.2.202.440. Workaround ========= None. Description ========== - CVE-2015-0311 (remote code execution) Unspecified vulnerability allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015. - CVE-2015-0309 (remote code execution) Heap-based buffer overflow allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0304. - CVE-2015-0308 (remote code execution) Use-after-free vulnerability allows attackers to execute arbitrary code via unspecified vectors. - CVE-2015-0307 (memory leaks, denial of service) A vulnerability allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors. - CVE-2015-0306 (remote code execution, denial of service) A vulnerability allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0303. - CVE-2015-0305 (remote code execution) Avulnerability allows attackers to execute arbitrary code by leveraging an unspecified "type confusion". - CVE-2015-0304 (remote code execution) Heap-based buffer overflow allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-0309. - CVE-2015-0303 (remote code execution, denial of service) A vulnerability allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-0306. - CVE-2015-0302 (keylogging) A vulnerability allows attackers to obtain sensitive keystroke information via unspecified vectors. - CVE-2015-0301 (file validation) The flashplugin does not properly validate files, which has unspecified impact and attack vectors. Impact ===== A remote attacker is able to perform remote code execution, keylogging, denial of service and resource consumption through memory leaks. References ========= https://malware.dontneedcoffee.com/2015/01/unpatched-vulnerability-0day-in-flash.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0311 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0309 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0308 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0307 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0306 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0305 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0304 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0303 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0302 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-0301 . Urgent security vulnerabilities in Flash Plugin on Arch Linux necessitate swift remediation to avert potential remote code execution and keystroke capture.. Arch Linux Flashplugin Issues, Remote Code Execution Risks, Security Advisory for Flashplugin. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 26, 2015 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here