Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 31: 2020-0fbd043bcf Moderate: Kronolith Notification Security Fix

**kronolith 4.2.29** * [mjr] Fix regresssion in event modification notifications (Bug #15022). ---- **kronolith 4.2.28** * [mjr] **SECURITY**: Don't leak private details when sending notifications for private events (Bug #15011). * [mjr] Fix regression in display of clickable event URL property (Bug #14941).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0fbd043bcf 2020-07-22 01:19:44.413079 --------------------------------------------------------------------------------Name : php-horde-kronolith Product : Fedora 31 Version : 4.2.29 Release : 1.fc31 URL : https://www.horde.org/apps/kronolith Summary : A web based calendar Description : Kronolith is the Horde calendar application. It provides web-based calendars backed by a SQL database or a Kolab server. Supported features include Ajax and mobile interfaces, shared calendars, remote calendars, invitation management (iCalendar/iTip), free/busy management, resource management, alarms, recurring events, and a sophisticated day/week view which handles arbitrary numbers of overlapping events. --------------------------------------------------------------------------------Update Information: **kronolith 4.2.29** * [mjr] Fix regresssion in event modification notifications (Bug #15022). ---- **kronolith 4.2.28** * [mjr] **SECURITY**: Don't leak private details when sending notifications for private events (Bug #15011). * [mjr] Fix regression in display of clickable event URL property (Bug #14941). --------------------------------------------------------------------------------ChangeLog: * Mon Jul 13 2020 Remi Collet - 4.2.29-1 - update to 4.2.29 * Mon Jul 6 2020 Remi Collet - 4.2.28-1 - update to 4.2.28 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-0fbd043bcf' at the command line.For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Kronolith enhancement focuses on security features in alerts for private gatherings, alongside various upgrades.. php-horde-kronolith, Fedora 31, notification security, event management. . LinuxSecurity.com Team

Calendar%202 Jul 21, 2020 Fedora
89

Fedora 25: 2017-692c05119d Moderate: Open Redirect Issues in kronolith

**kronolith 4.2.22** * [jan] SECURITY: Fix open redirects. * [mjr] Prevent broken iCalendar files from causing fatal errors (Bug #14672). * [jan] Work around calendar servers advertising as CalDAV-capable, but ignoring CalDAV requests (Bug #14662). * [jan] Fix displaying yesterday's event in Prior Events portal block (This email address is being protected from spambots. You need JavaScript enabled to view it., Bug #14638).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-692c05119d 2017-08-10 15:18:03.832503 --------------------------------------------------------------------------------Name : php-horde-kronolith Product : Fedora 25 Version : 4.2.22 Release : 1.fc25 URL : https://www.horde.org/apps/kronolith Summary : A web based calendar Description : Kronolith is the Horde calendar application. It provides web-based calendars backed by a SQL database or a Kolab server. Supported features include Ajax and mobile interfaces, shared calendars, remote calendars, invitation management (iCalendar/iTip), free/busy management, resource management, alarms, recurring events, and a sophisticated day/week view which handles arbitrary numbers of overlapping events. --------------------------------------------------------------------------------Update Information: **kronolith 4.2.22** * [jan] SECURITY: Fix open redirects. * [mjr] Prevent broken iCalendar files from causing fatal errors (Bug #14672). * [jan] Work around calendar servers advertising as CalDAV-capable, but ignoring CalDAV requests (Bug #14662). * [jan] Fix displaying yesterday's event in Prior Events portal block (This email address is being protected from spambots. You need JavaScript enabled to view it., Bug #14638). --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade php-horde-kronolith' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Updates addressing open redirect vulnerabilities, iCalendar discrepancies, and calendar rendering problems in php-horde-kronolith for Fedora 25.. php-horde-kronolith,Fedora security update,open redirect issue. . LinuxSecurity.com Team

Calendar%202 Aug 10, 2017 Fedora
87

Debian: DSA-1560-1 Critical: Cross-Site Scripting in Kronolith2

"The-0utl4w" discovered that the Kronolith, calendar component for the Horde Framework, didn't properly sanitise URL input, leading to a cross-site scripting vulnerability in the add event screen.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1560-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst April 28, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : kronolith2 Vulnerability : insufficient input sanitising Problem type : remote Debian-specific: no Debian Bug : 478121 "The-0utl4w" discovered that the Kronolith, calendar component for the Horde Framework, didn't properly sanitise URL input, leading to a cross-site scripting vulnerability in the add event screen. For the stable distribution (etch), this problem has been fixed in version 2.1.4-1etch1. The unstable distribution (sid) will be fixed soon. We recommend that you upgrade your kronolith2 package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 988 bed4712a2341c3a5043c6e69ad6e8309 Size/MD5 checksum: 5388 580890a3d47459f77dd89aa664ca4a44 Size/MD5 checksum: 1691114 df6d6fc99012865b18b089212c7544ad Architecture independent packages: Size/MD5 checksum: 1694916 d93492c52a99397b76f862705b7fd24e These files will probably be movedinto the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover a solution for a vulnerable cross-site scripting issue within Debian's kronolith2, bolstering security measures and preserving user confidence.. Kronolith Security Fix, Debian Advisory, Cross Site Scripting, Package Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 28, 2008 Critical Debian
87

Debian DSA 970-1 Moderate: Kronolith Cross-Site Scripting Issue

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 970-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze February 14th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : kronolith Vulnerability : missing input sanitising Problem type : remote Debian-specific: no CVE ID : CVE-2005-4189 Debian Bugs : 342943 349261 Johannes Greil of SEC Consult discovered several cross-site scripting vulnerabilities in kronolith, the Horde calendar application. The old stable distribution (woody) does not contain kronolith packages. For the stable distribution (sarge) these problems have been fixed in version 1.1.4-2sarge1. For the unstable distribution (sid) these problems have been fixed in version 2.0.6-1 of kronolith2. We recommend that you upgrade your kronolith and kronolith2 packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 581 246f510d44a3a79fe88d9b6f0efc0cda Size/MD5 checksum: 12005 c10a7d82b97300d62e6ef45f6e5e3cfe Size/MD5 checksum: 530945 8f5e5bca2a8b383e8a00fe19dacd138f Architecture independent components: Size/MD5 checksum: 528516 4d4ed7e51485ca96008175597612d72a These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 972-1 addresses vulnerabilities in the sogo package, enhancing protection measures for all users.. Debian Kronolith Update, Cross-Site Scripting Fix, Package Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 14, 2006 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200