Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 69 articles for you...
91

Gentoo: GLSA-202210-13 Normal: libgcrypt Denial Of Service Threat

Multiple vulnerabilities have been found in libgcrypt, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libgcrypt: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #766213, #795480, #811900 ID: 202210-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libgcrypt, the worst of which could result in denial of service. Background ========= libgcrypt is a general purpose cryptographic library derived out of GnuPG. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libgcrypt < 1.9.4 > = 1.9.4 Description ========== Multiple vulnerabilities have been discovered in libgcrypt. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All libgcrypt users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libgcrypt-1.9.4" References ========= [ 1 ] CVE-2021-33560 https://nvd.nist.gov/vuln/detail/CVE-2021-33560 [ 2 ] CVE-2021-40528 https://nvd.nist.gov/vuln/detail/CVE-2021-40528 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Security Advisory GLSA 202210-13 highlights critical flaws in libgcrypt affecting systems.. libgcrypt, Gentoo Linux, denial of service, cryptographic library. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 Gentoo
100

SUSE: 2022:2425-1 Important: Expat And Libgcrypt Security Update

The container suse/sles12sp4 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sles12sp4 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2425-1 Container Tags : suse/sles12sp4:26.510 , suse/sles12sp4:latest Container Release : 26.510 Severity : important Type : security References : 1200095 1203438 CVE-2022-40674 ----------------------------------------------------------------- The container suse/sles12sp4 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:3389-1 Released: Mon Sep 26 12:52:13 2022 Summary: Recommended update for libgcrypt Type: recommended Severity: moderate References: 1200095 This update for libgcrypt fixes the following issues: - FIPS: Auto-initialize drbg if needed. (bsc#1200095) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3466-1 Released: Thu Sep 29 11:43:25 2022 Summary: Security update for expat Type: security Severity: important References: 1203438,CVE-2022-40674 This update for expat fixes the following issues: - CVE-2022-40674: Fixed use-after-free in the doContent function in xmlparse.c (bsc#1203438). The following package changes have been done: - base-container-licenses-3.0-1.317 updated - container-suseconnect-2.0.0-1.203 updated - libexpat1-2.1.0-21.25.1 updated - libgcrypt20-1.6.1-16.83.1 updated . SUSE Container Notification SUSE-CU-2022:3426-1 presents vital enhancements for suse/sles15sp1 tackling vulnerabilities.. SUSE Container Update,SUSE-CU-2022:2425-1,Expat,Libgcrypt,Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 01, 2022 Important SuSE
219

Rocky Linux 8 RLSA-2021:4409 Moderate: Libgcrypt Update

Moderate: libgcrypt security and bug fix update. \{'type': 'Security', 'shortCode': 'RL', 'name': 'RLSA-2021:4409', 'synopsis': 'Moderate: libgcrypt security and bug fix update', 'severity': 'Moderate', 'topic': 'An update for libgcrypt is now available for Rocky Linux 8.\nRocky Linux Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.', 'description': 'The libgcrypt library provides general-purpose implementations of various cryptographic algorithms.\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\nAdditional Changes:\nFor detailed information on changes in this release, see the Rocky Linux 8.5 Release Notes linked from the References section.', 'solution': None, 'affectedProducts': ['Rocky Linux 8'], 'fixes': ['1970096', '1976137'], 'cves': ['Red Hat:::https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2021-33560.json:::CVE-2021-33560'], 'references': [], 'publishedAt': '2021-11-15T07:26:52.310353Z', 'rpms': ['libgcrypt-1.8.5-6.el8.aarch64.rpm', 'libgcrypt-1.8.5-6.el8.i686.rpm', 'libgcrypt-1.8.5-6.el8.src.rpm', 'libgcrypt-1.8.5-6.el8.x86_64.rpm', 'libgcrypt-debuginfo-1.8.5-6.el8.aarch64.rpm', 'libgcrypt-debuginfo-1.8.5-6.el8.i686.rpm', 'libgcrypt-debuginfo-1.8.5-6.el8.x86_64.rpm', 'libgcrypt-debugsource-1.8.5-6.el8.aarch64.rpm', 'libgcrypt-debugsource-1.8.5-6.el8.i686.rpm', 'libgcrypt-debugsource-1.8.5-6.el8.x86_64.rpm', 'libgcrypt-devel-1.8.5-6.el8.aarch64.rpm', 'libgcrypt-devel-1.8.5-6.el8.i686.rpm', 'libgcrypt-devel-1.8.5-6.el8.x86_64.rpm', 'libgcrypt-devel-debuginfo-1.8.5-6.el8.aarch64.rpm', 'libgcrypt-devel-debuginfo-1.8.5-6.el8.i686.rpm', 'libgcrypt-devel-debuginfo-1.8.5-6.el8.x86_64.rpm']}\. Dive into the recent security enhancement for libgcrypt inRocky Linux, which boosts cryptographic capabilities and addresses existing vulnerabilities.. libgcrypt update, Rocky Linux security, moderate severity, bug fix, open source security. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2022 Rocky Linux
217

Oracle Linux 8 ELSA-2022-5311 Moderate: Libgcrypt Update

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2022-5311 https://linux.oracle.com/errata/ELSA-2022-5311.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libgcrypt-1.8.5-7.el8_6.i686.rpm libgcrypt-1.8.5-7.el8_6.x86_64.rpm libgcrypt-devel-1.8.5-7.el8_6.i686.rpm libgcrypt-devel-1.8.5-7.el8_6.x86_64.rpm aarch64: libgcrypt-1.8.5-7.el8_6.aarch64.rpm libgcrypt-devel-1.8.5-7.el8_6.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates/libgcrypt-1.8.5-7.el8_6.src.rpm Related CVEs: CVE-2021-40528 Description of changes: [1.8.5-7] - Fix CVE-2021-33560 (#2018525) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2022-5311 outlines modifications and enhancements to libgcrypt aimed at reinforcing overall system security measures.. Oracle Linux Security Advisory, libgcrypt Update, ELSA-2022-5311. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2022 Important Oracle
98

Red Hat Enterprise Linux 8: RHSA-2022-5311 Moderate: libgcrypt ElGamal Risk

An update for libgcrypt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libgcrypt security update Advisory ID: RHSA-2022:5311-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:5311 Issue date: 2022-06-28 CVE Names: CVE-2021-40528 ==================================================================== 1. Summary: An update for libgcrypt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): * libgcrypt: ElGamal implementation allows plaintext recovery (CVE-2021-40528) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2002816 - CVE-2021-40528 libgcrypt: ElGamal implementation allows plaintext recovery 6. Package List: Red Hat Enterprise Linux BaseOS (v.8): Source: libgcrypt-1.8.5-7.el8_6.src.rpm aarch64: libgcrypt-1.8.5-7.el8_6.aarch64.rpm libgcrypt-debuginfo-1.8.5-7.el8_6.aarch64.rpm libgcrypt-debugsource-1.8.5-7.el8_6.aarch64.rpm libgcrypt-devel-1.8.5-7.el8_6.aarch64.rpm libgcrypt-devel-debuginfo-1.8.5-7.el8_6.aarch64.rpm ppc64le: libgcrypt-1.8.5-7.el8_6.ppc64le.rpm libgcrypt-debuginfo-1.8.5-7.el8_6.ppc64le.rpm libgcrypt-debugsource-1.8.5-7.el8_6.ppc64le.rpm libgcrypt-devel-1.8.5-7.el8_6.ppc64le.rpm libgcrypt-devel-debuginfo-1.8.5-7.el8_6.ppc64le.rpm s390x: libgcrypt-1.8.5-7.el8_6.s390x.rpm libgcrypt-debuginfo-1.8.5-7.el8_6.s390x.rpm libgcrypt-debugsource-1.8.5-7.el8_6.s390x.rpm libgcrypt-devel-1.8.5-7.el8_6.s390x.rpm libgcrypt-devel-debuginfo-1.8.5-7.el8_6.s390x.rpm x86_64: libgcrypt-1.8.5-7.el8_6.i686.rpm libgcrypt-1.8.5-7.el8_6.x86_64.rpm libgcrypt-debuginfo-1.8.5-7.el8_6.i686.rpm libgcrypt-debuginfo-1.8.5-7.el8_6.x86_64.rpm libgcrypt-debugsource-1.8.5-7.el8_6.i686.rpm libgcrypt-debugsource-1.8.5-7.el8_6.x86_64.rpm libgcrypt-devel-1.8.5-7.el8_6.i686.rpm libgcrypt-devel-1.8.5-7.el8_6.x86_64.rpm libgcrypt-devel-debuginfo-1.8.5-7.el8_6.i686.rpm libgcrypt-devel-debuginfo-1.8.5-7.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-40528 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYr5BQtzjgjWX9erEAQjA5g/9Hd2HgnMhl/37QqAX0oiGwygJRmcpt0lc YwCbjZmqvyO5wBOW4kJlO4YuMXB9Dw6sxOjyUSsA0qOZaFXK88KxwlsP8kZP9aJY 8YaphVoAbg3JgeZ8b4W3qL12JtjXAjYEXCUjuDj67UslZ7xnba719z8wsD/pmcRk tHUme1BPaMZDmgL0o65KyRwfvZ7m7wBvVuWL6eXE2AiV1hZc6ADYVXaUmVRIPair 0v7DgKjiN+x0fOBNjmpSI733OBUyOIff0TEgzAgoYslGPSixYb2ulGMl4PBLv8+u dcodPaq9CGIVnGbXgByMVf0adqx2z+87Nm/sIpHchWHVlMcD8ZRtftiXEEh8ksep Szq/hxBRY2p4Pb9Sv0FLt+dxRTAd+CUafYtd/IXzPLzAQV2sXH3Rq9BtDSniMCMD HqYRWa1O1lB9UfCRdhvS0xDwdaRJscLojZPbhkKCxtkV36CtfYj0BHQFOkV9qh75 22za2xZ9+IBurBZXM+yRymkrh4mFTbXjqmtZewP9/tpGcQB28pTB5fSKoR6+0goH GozR7ijcDzBrgfZ1hJ5yLRZ10uiLLryMveD8CWAkaS6RwPppn3cwGwlxPZfvRshY 7uuSptSb0Qpu1tD4kAtHjD/AbxBsghA8PG6CGw1Zg9D6QPr0ot/9AkFvDncI7PeF b43FJio26lo=EfsV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A new version of libgcrypt is released for Red Hat Enterprise Linux 8, classified as Moderate. Update promptly to bolster your security measures.. Red Hat Enterprise, libgcrypt update, cryptography security, software patch. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2022 Red Hat
98

RHEL 8: RHSA-2021-4409-03 Moderate libgcrypt Side-Channel Fix

An update for libgcrypt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libgcrypt security and bug fix update Advisory ID: RHSA-2021:4409-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:4409 Issue date: 2021-11-09 CVE Names: CVE-2021-33560 ==================================================================== 1. Summary: An update for libgcrypt is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The libgcrypt library provides general-purpose implementations of various cryptographic algorithms. Security Fix(es): * libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm (CVE-2021-33560) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.5 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1970096 - CVE-2021-33560 libgcrypt: mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm 1976137 - Enable hardware optimizations in FIPS mode 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: libgcrypt-1.8.5-6.el8.src.rpm aarch64: libgcrypt-1.8.5-6.el8.aarch64.rpm libgcrypt-debuginfo-1.8.5-6.el8.aarch64.rpm libgcrypt-debugsource-1.8.5-6.el8.aarch64.rpm libgcrypt-devel-1.8.5-6.el8.aarch64.rpm libgcrypt-devel-debuginfo-1.8.5-6.el8.aarch64.rpm ppc64le: libgcrypt-1.8.5-6.el8.ppc64le.rpm libgcrypt-debuginfo-1.8.5-6.el8.ppc64le.rpm libgcrypt-debugsource-1.8.5-6.el8.ppc64le.rpm libgcrypt-devel-1.8.5-6.el8.ppc64le.rpm libgcrypt-devel-debuginfo-1.8.5-6.el8.ppc64le.rpm s390x: libgcrypt-1.8.5-6.el8.s390x.rpm libgcrypt-debuginfo-1.8.5-6.el8.s390x.rpm libgcrypt-debugsource-1.8.5-6.el8.s390x.rpm libgcrypt-devel-1.8.5-6.el8.s390x.rpm libgcrypt-devel-debuginfo-1.8.5-6.el8.s390x.rpm x86_64: libgcrypt-1.8.5-6.el8.i686.rpm libgcrypt-1.8.5-6.el8.x86_64.rpm libgcrypt-debuginfo-1.8.5-6.el8.i686.rpm libgcrypt-debuginfo-1.8.5-6.el8.x86_64.rpm libgcrypt-debugsource-1.8.5-6.el8.i686.rpm libgcrypt-debugsource-1.8.5-6.el8.x86_64.rpm libgcrypt-devel-1.8.5-6.el8.i686.rpm libgcrypt-devel-1.8.5-6.el8.x86_64.rpm libgcrypt-devel-debuginfo-1.8.5-6.el8.i686.rpm libgcrypt-devel-debuginfo-1.8.5-6.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2021-33560 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.5_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGPSIGNATURE----- Version: GnuPG v1 iQIVAwUBYYrc7dzjgjWX9erEAQjhNw//RiJ7fkdY/H3C+UpkC4DWmYu18qSY/x9B topoqO8ID7x7Nnj8K+pXqBGA9TyHjhtGC+vxjHtXBWgbM1yIR1bIVcSWvalsiiMZ gEGsv/MNWbjvC0qDMxpYTBy1+Sa5qv3yV+D1XHU1rEDF9huPu/maQikyy7O/y5vl MWAyIee6LLZf+mebVN6VwGAH8puAvc7GA1Aobrwh5bjNKoVVesT46Wj2+oLV/tKW PNuINOjFL7ujNhpmzlYEitcsuDOdFJnr+XsEmPZcnNB80D/jlEJd6KNe7fZnrEVP YFQIFMz1VsEbPLGhRDJAnUQlCimq7viO9p6XTMLOZQ0TeeIrvu6owRMskI6qXHgb +3JUAU8kePQXrdf3ROhShd3o6jLEA7qjlIWTCdb6Id1TrPurbcd+hOofvFb+MGNi oreK3cH87/0Gja5C4t9eKUcuiM2mu6XCklJ0FeWN1xeOpp5+rHY2zKPQZ2RQ2EQE ZScqE1JHiVZ7sHzDWmmtqBnk3B8LbjMfWg3dHBcTNy2fn5DHy7uHP/2jlVACRbe+ EONHSy1V1r3BV2JzrEu69EPp0lPZRbjm4CgLZ6/qwwmrpVNV0A3UBEVeVsmxkpM4 pqmVkwdqxTkEq8VUA3GQRjP8n/Fjm6D0MK+BwEVOmbPPY3V00BsPnL/4ZCdhWcVt bIa6gK7va4U=Ldxd -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A revision for libgcrypt tackles a moderate vulnerability in CentOS Stream 8, bolstering cryptographic integrity.. libgcrypt update, Red Hat security, product security fix, encryption issues, enterprise Linux advisory. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2021 Red Hat
172

Ubuntu 16.04 ESM USN-5080-2 Critical: Libgcrypt Info Exposure

Libgcrypt could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-5080-2 September 16, 2021 libgcrypt20 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Libgcrypt could be made to expose sensitive information. Software Description: - libgcrypt20: LGPL Crypto library Details: USN-5080-1 fixed several vulnerabilities in Libgcrypt. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An attacker could possibly use this issue to recover sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libgcrypt20 1.6.5-2ubuntu0.6+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5080-2 https://ubuntu.com/security/notices/USN-5080-1 CVE-2021-33560, CVE-2021-40528 . Debian reveals critical vulnerability in OpenSSL, necessitating immediate patches to protect encryption keys.. libgcrypt vulnerabilities, Ubuntu security notice, information exposure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 16, 2021 Critical Ubuntu
172

Ubuntu 21.04, 20.04 LTS, 18.04 LTS Security Advisory - Libgcrypt Exposure

Libgcrypt could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-5080-1 September 16, 2021 libgcrypt20 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Libgcrypt could be made to expose sensitive information. Software Description: - libgcrypt20: LGPL Crypto library Details: It was discovered that Libgcrypt incorrectly handled ElGamal encryption. An attacker could possibly use this issue to recover sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: libgcrypt20 1.8.7-2ubuntu2.1 Ubuntu 20.04 LTS: libgcrypt20 1.8.5-5ubuntu1.1 Ubuntu 18.04 LTS: libgcrypt20 1.8.1-4ubuntu1.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5080-1 CVE-2021-33560, CVE-2021-40528 Package Information: https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.7-2ubuntu2.1 https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.5-5ubuntu1.1 https://launchpad.net/ubuntu/+source/libgcrypt20/1.8.1-4ubuntu1.3 . Security flaws discovered in Libgcrypt for Ubuntu versions 21.04, 20.04 LTS, and 18.04 LTS. Ensure you install latest updates to mitigate potential threats.. Libgcrypt Issues, Ubuntu Security Notices, Information Exposure Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 16, 2021 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200