Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

SciLinux: SLSA-2018-1380-1 Critical: 389-DS-Base Crash Fix via LDAPsearch

389-ds-base: ns-slapd crash via large filter value in ldapsearch (CVE-2018-1089) Bug Fix(es): * Indexing tasks in Directory Server contain the nsTaskStatus attribute to monitor whether the task is completed and the database is ready to receive updates. Before this update, the server set the value that indexing had completed before the database was ready to receive updates. Applications which [More...]. Synopsis: Important: 389-ds-base security and bug fix update Advisory ID: SLSA-2018:1380-1 Issue Date: 2018-05-15 CVE Numbers: CVE-2018-1089 -- Security Fix(es): * 389-ds-base: ns-slapd crash via large filter value in ldapsearch (CVE-2018-1089) Bug Fix(es): * Indexing tasks in Directory Server contain the nsTaskStatus attribute to monitor whether the task is completed and the database is ready to receive updates. Before this update, the server set the value that indexing had completed before the database was ready to receive updates. Applications which monitor nsTaskStatus could start sending updates as soon as indexing completed, but before the database was ready. As a consequence, the server rejected updates with an UNWILLING_TO_PERFORM error. The problem has been fixed. As a result, the nsTaskStatus attribute now shows that indexing is completed after the database is ready to receive updates. * Previously, Directory Server did not remember when the first operation, bind, or a connection was started. As a consequence, the server applied in certain situations anonymous resource limits to an authenticated client. With this update, Directory Server properly marks authenticated client connections. As a result, it applies the correct resource limits, and authenticated clients no longer get randomly restricted by anonymous resource limits. * When debug replication logging is enabled, Directory Server incorrectly logged an error that updating the replica update vector (RUV) failed when in fact the update succeeded. The problem has been fixed, and the server no longer logs an error ifupdating the RUV succeeds. * This update adds the -W option to the ds-replcheck utility. With this option, ds-replcheck asks for the password, similar to OpenLDAP utilities. As a result, the password is not stored in the shell's history file when the -W option is used. * If an administrator moves a group in Directory Server from one subtree to another, the memberOf plug-in deletes the memberOf attribute with the old value and adds a new memberOf attribute with the new group's distinguished name (DN) in affected user entries. Previously, if the old subtree was not within the scope of the memberOf plug-in, deleting the old memberOf attribute failed because the values did not exist. As a consequence, the plug-in did not add the new memberOf value, and the user entry contained an incorrect memberOf value. With this update, the plug-in now checks the return code when deleting the old value. If the return code is "no such value", the plug-in only adds the new memberOf value. As a result, the memberOf attribute information is correct. * In a Directory Server replication topology, updates are managed by using Change Sequence Numbers (CSN) based on time stamps. New CSNs must be higher than the highest CSN present in the relative update vector (RUV). In case the server generates a new CSN in the same second as the most recent CSN, the sequence number is increased to ensure that it is higher. However, if the most recent CSN and the new CSN were identical, the sequence number was not increased. In this situation, the new CSN was, except the replica ID, identical to the most recent one. As a consequence, a new update in the directory appeared in certain situations older than the most recent update. With this update, Directory Server increases the CSN if the sequence number is lower or equal to the most recent one. As a result, new updates are no longer considered older than the most recent data. -- SL7 x86_64 389-ds-base-1.3.7.5-21.el7_5.x86_64.rpm 389-ds-base-debuginfo-1.3.7.5-21.el7_5.x86_64.rpm 389-ds-base-devel-1.3.7.5-21.el7_5.x86_64.rpm 389-ds-base-libs-1.3.7.5-21.el7_5.x86_64.rpm 389-ds-base-snmp-1.3.7.5-21.el7_5.x86_64.rpm - Scientific Linux Development Team . Critical enhancement for 389-ds-base addressing ldapsearch failure problems and boosting reliability in directory administration.. 389ds, slapd, bugfix, directoryservice, SCILinux. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2018 Critical Scientific Linux
200

Scientific Linux SL6: SLSA-2018-1364-1 Important ns-slapd Crash Fix

389-ds-base: ns-slapd crash via large filter value in ldapsearch (CVE-2018-1089) SL6 x86_64 389-ds-base-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-debuginfo-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-debuginfo-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-devel-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-devel-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-libs-1.2.11.15-95.el6_9.i68 [More...]. Synopsis: Important: 389-ds-base security update Advisory ID: SLSA-2018:1364-1 Issue Date: 2018-05-09 CVE Numbers: CVE-2018-1089 -- Security Fix(es): * 389-ds-base: ns-slapd crash via large filter value in ldapsearch (CVE-2018-1089) -- SL6 x86_64 389-ds-base-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-debuginfo-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-debuginfo-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-devel-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-devel-1.2.11.15-95.el6_9.x86_64.rpm 389-ds-base-libs-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-libs-1.2.11.15-95.el6_9.x86_64.rpm i386 389-ds-base-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-debuginfo-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-devel-1.2.11.15-95.el6_9.i686.rpm 389-ds-base-libs-1.2.11.15-95.el6_9.i686.rpm - Scientific Linux Development Team . Crucial 389-ds-base patch released for Scientific Linux SL6 addressing critical ldapsearch crash problems, including detailed package identifiers as indicated.. 389-ds-base, ns-slapd, ldapsearch, security fix, SL6. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 09, 2018 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here