Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
219

Rocky Linux 8 RLBA-2021:3577 Unknown: Python-LDAP Bug Fix Available

python-ldap bug fix and enhancement update. \{'type': 'BugFix', 'shortCode': 'RL', 'name': 'RLBA-2021:3577', 'synopsis': 'python-ldap bug fix and enhancement update', 'severity': 'UnknownSeverity', 'topic': 'An update for python-ldap is now available for Rocky Linux 8.', 'description': 'The python-ldap packages provide an object-oriented API for working with\nLDAP within Python programs. It allows access to LDAP directory servers by\nusing the OpenLDAP 2.x libraries, and contains modules for other\nLDAP-related tasks (including processing LDIF, LDAPURLs, LDAPv3 schema,\netc.).\nworthy mechs found (Unknown authentication method) (BZ#1987313)', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': [], 'cves': ['Red Hat:::https://access.redhat.com/errata/RHBA-2021:3577:::RHBA-2021:3577'], 'references': ['https://github.com/python-ldap/python-ldap/pull/416'], 'publishedAt': '2021-10-01T20:14:19.651179Z', 'rpms': ['python3-ldap-3.3.1-1.1.el8_4.aarch64.rpm', 'python3-ldap-3.3.1-1.1.el8_4.x86_64.rpm', 'python3-ldap-debuginfo-3.3.1-1.1.el8_4.aarch64.rpm', 'python3-ldap-debuginfo-3.3.1-1.1.el8_4.x86_64.rpm', 'python-ldap-3.3.1-1.1.el8_4.src.rpm']}\. Newly released Python-ldap improvement update for Rocky Linux 8, tackling previous bugs and enhancing functionality.. python-ldap, bug fix, rocky linux, enhancement, ldap authentication. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2022 Rocky Linux
203

Mageia 8: MGASA-2022-0299 Moderate: Samba Security Issues Fixed

Fixed AD restrictions bypass associated with changing passwords (bsc#1201495). (CVE-2022-2031) Fixed a memory leak in SMB1 (bsc#1201496). (CVE-2022-32742) Fixed an arbitrary password change request for any AD user (bsc#1201493). (CVE-2022-32744) . MGASA-2022-0299 - Updated ldb/samba/sssd packages fix security vulnerability Publication date: 25 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0299.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-2031, CVE-2022-32742, CVE-2022-32744, CVE-2022-32745, CVE-2022-32746 Fixed AD restrictions bypass associated with changing passwords (bsc#1201495). (CVE-2022-2031) Fixed a memory leak in SMB1 (bsc#1201496). (CVE-2022-32742) Fixed an arbitrary password change request for any AD user (bsc#1201493). (CVE-2022-32744) Fixed a remote server crash with an LDAP add or modify request (bsc#1201492) (CVE-2022-32745) Fixed a use-after-free occurring in database audit logging (bsc#1201490). (CVE-2022-32746) References: - https://bugs.mageia.org/show_bug.cgi?id=30675 - - - - - - - https://ubuntu.com/security/notices/USN-5542-1 - https://lists.debian.org/debian-security-announce/2022/msg00174.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/2RORIRLFLRNQOCVXQU4V3RLZ5C2G75L2/ - https://www.cve.org/CVERecord?id=CVE-2022-2031 - https://www.cve.org/CVERecord?id=CVE-2022-32742 - https://www.cve.org/CVERecord?id=CVE-2022-32744 - https://www.cve.org/CVERecord?id=CVE-2022-32745 - https://www.cve.org/CVERecord?id=CVE-2022-32746 SRPMS: - 8/core/ldb-2.3.4-1.mga8 - 8/core/samba-4.14.14-1.mga8 - 8/core/sssd-2.4.0-1.4.mga8 . Investigate Mageia 2022-0299, which tackles significant Active Directory modifications and security vulnerabilities in ldb, samba, and sssd software packages.. Mageia Security Update,Samba Memory Leak,AD Restrictions Fix,Password Change Vulnerability. . LinuxSecurity.com Team

Calendar 2 Aug 25, 2022 Mageia
172

Ubuntu 7.04 & 7.10 USN-567-1 Critical: Dovecot LDAP Issue

It was discovered that in very rare configurations using LDAP, Dovecot may reuse cached connections for users with the same password. As a result, a user may be able to login as another if the connection is reused. The default Ubuntu configuration of Dovecot was not vulnerable. . =========================================================== Ubuntu Security Notice USN-567-1 January 10, 2008 dovecot vulnerability CVE-2007-6598 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 7.04 Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 7.04: dovecot-imapd 1.0.rc17-1ubuntu2.2 dovecot-pop3d 1.0.rc17-1ubuntu2.2 Ubuntu 7.10: dovecot-imapd 1:1.0.5-1ubuntu2.1 dovecot-pop3d 1:1.0.5-1ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that in very rare configurations using LDAP, Dovecot may reuse cached connections for users with the same password. As a result, a user may be able to login as another if the connection is reused. The default Ubuntu configuration of Dovecot was not vulnerable. Updated packages for Ubuntu 7.04: Source archives: Size/MD5: 101513 3a05fe3f2bdcd39c32e0a650b61c9b18 Size/MD5: 1100 89b4ea9a138396356ce51947d4a958b8 Size/MD5: 1512386 881bcc7d2c8fba6d337f3e616a602bf7 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1274744 7c4aea65aa4b2c8360ca296e4c7dd11b Size/MD5: 586662 3a4c663dd70057ff8a559512880f88b5 Size/MD5: 552404 d3c2ce0c2eb3aa58f8b17dad3fc4ee8f i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1164784 517cb8721acce093e3435565a2163a0e Size/MD5: 554298 eb6fbeeeee1889303647318298ad5150 Size/MD5: 521626 a82bae1bb6e26289a91166bc77f1a23b powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1291322 a4df46fd2fac7456d425bf66b5862188 Size/MD5: 591040 a27429b620664c82ada26d6cbfafcbc5 Size/MD5: 556188 16c2bdae0d14a402644c8c58439fa75c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1158252 875a51f7b4ee7c81ada93481e2fc7487 Size/MD5: 549596 75f43e94538ed72b7342b3ed00ba6005 Size/MD5: 517136 7a6bc0cd8bbf73514d54624431e8c1b3 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 107642 9e04e08b57194364c8248332817049e3 Size/MD5: 1115 0e95044d51301ec964cf96bda69f1a0a Size/MD5: 1775898 94b7d29cf44f63f89d538361afa05c40 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1814690 3c1b2d9247c7f246eb8c59b9d04a4362 Size/MD5: 654514 7140315d855e7fab6d796be4166514a4 Size/MD5: 617618 8c73c94bd43e89da32a0549c0c4218b6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1672926 1b323221b09fca189b471079f1ee5612 Size/MD5: 621486 fa8977d8a945022fcdcf460d25d57141 Size/MD5: 588164 df780cc94e95fabf7793139ed8ca4c1e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1831950 d79e9f2cd81daab0eb7ae642d0444a0e Size/MD5: 656610 941223abf4f45c00434ff50a1323efad Size/MD5: 621772 c4557afdeac4488718e3e4cd7d66aed6 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1666806 8dc28e714f31d687a1283f888f8b6301 Size/MD5: 618418 f7f5afcaf0de5164b0f1189dabb7761d Size/MD5: 585178 fdb2b1bfc470ed595671596656d1e12c . The latest Ubuntu security announcement tackles a connection reuse vulnerability in Dovecot, impacting certain versions; essential patches are included.. Dovecot Security Issue, Ubuntu Dovecot Update, LDAPConnection Problem, Cached Connections Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 10, 2008 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here