Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
172

Ubuntu 16.04 LTS USN-6584-2 Critical: Libspf2 Denial Of Service

Several security issues were fixed in Libspf2.. ========================================================================== Ubuntu Security Notice USN-6584-2 February 21, 2024 libspf2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Libspf2. Software Description: - libspf2: Sender Policy Framework for SMTP authorization Details: USN-6584-1 fixed several vulnerabilities in Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. This update provides the corresponding updates for CVE-2021-33912 and CVE-2021-33913 in Ubuntu 16.04 LTS. We apologize for the inconvenience. Original advisory details: Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-20314) It was discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-6ubuntu0.1~esm2 libspf2-2 1.2.10-6ubuntu0.1~esm2 libspf2-dev 1.2.10-6ubuntu0.1~esm2 spfquery 1.2.10-6ubuntu0.1~esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6584-2 https://ubuntu.com/security/notices/USN-6584-1 CVE-2021-33912, CVE-2021-33913 . New guidelines released for addressing libspf2 security flaws in Ubuntu. Take action to safeguard your system from possible threats.. Ubuntu Pro Updates, Security Issues, Libspf2 Fix, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 21, 2024 Critical Ubuntu
172

Ubuntu 20.04 LTS USN-6584-1 Critical: Libspf2 RCE & DoS Threat

Several security issues were fixed in Libspf2.. ========================================================================== Ubuntu Security Notice USN-6584-1 January 15, 2024 libspf2 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Libspf2. Software Description: - libspf2: Sender Policy Framework for SMTP authorization Details: Philipp Jeitner and Haya Shulman discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-20314) It was discovered that Libspf2 incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-33912, CVE-2021-33913) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libmail-spf-xs-perl 1.2.10-7+deb9u2build0.20.04.1 libspf2-2 1.2.10-7+deb9u2build0.20.04.1 libspf2-dev 1.2.10-7+deb9u2build0.20.04.1 spfquery 1.2.10-7+deb9u2build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-7ubuntu0.18.04.1~esm1 libspf2-2 1.2.10-7ubuntu0.18.04.1~esm1 libspf2-dev 1.2.10-7ubuntu0.18.04.1~esm1 spfquery 1.2.10-7ubuntu0.18.04.1~esm1 Ubuntu 16.04 LTS(Available with Ubuntu Pro): libmail-spf-xs-perl 1.2.10-6ubuntu0.1~esm1 libspf2-2 1.2.10-6ubuntu0.1~esm1 libspf2-dev 1.2.10-6ubuntu0.1~esm1 spfquery 1.2.10-6ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6584-1 CVE-2021-20314, CVE-2021-33912, CVE-2021-33913 Package Information: https://launchpad.net/ubuntu/+source/libspf2/1.2.10-7+deb9u2build0.20.04.1 . To fortify Ubuntu 20.04 against libspf2 vulnerabilities, keep your system updated, configure security protocols, audit packages, utilize IDS, replace libspf2, and backup data regularly. Libspf2 Security, Remote Code Execution Fix, Ubuntu Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 15, 2024 Critical Ubuntu
91

Gentoo GLSA 202401-22: libspf2 Normal Severity Multiple Issues

Multiple vulnerabilities have been discovered in libspf2, the worst of which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202401-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libspf2: Multiple vulnerabilities Date: January 15, 2024 Bugs: #807739 ID: 202401-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in libspf2, the worst of which can lead to remote code execution. Background ========== libspf2 is a library that implements the Sender Policy Framework, allowing mail transfer agents to make sure that an email is authorized by the domain name that it is coming from. Affected packages ================= Package Vulnerable Unaffected ------------------- ------------ ------------ mail-filter/libspf2 < 1.2.11 > = 1.2.11 Description =========== Multiple vulnerabilities have been discovered in libspf2. Please review the CVE identifiers referenced below for details. Impact ====== Various buffer overflows have been identified that can lead to denial of service and possibly arbitrary code execution. Workaround ========== There is no known workaround at this time. Resolution ========== All libspf2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/libspf2-1.2.11" References ========== [ 1 ] CVE-2021-20314 https://nvd.nist.gov/vuln/detail/CVE-2021-20314 [ 2 ] CVE-2021-33912 https://nvd.nist.gov/vuln/detail/CVE-2021-33912 [ 3 ] CVE-2021-33913 https://nvd.nist.gov/vuln/detail/CVE-2021-33913 Availability ============ This GLSA and any updates to it are available for viewingat the Gentoo Security Website: https://security.gentoo.org/glsa/202401-22 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Explore multiple libspf2 weaknesses that can potentially enable remote code execution, all while staying updated on Gentoo's security notifications.. libspf2 vulnerabilities,Gentoo GLSA,buffer overflow,code execution,severity report. . LinuxSecurity.com Team

Calendar 2 Jan 15, 2024 Gentoo
89

Fedora 39 FEDORA-2023-b317dd9220 Critical Remote Code Execution for libspf2

Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-b317dd9220 2023-11-03 18:20:20.951386 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 39 Version : 1.2.11 Release : 11.20210922git4915c308.fc39 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf"update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-b317dd9220' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Update for Fedora 39 tackling CVE-2023-42118 along with supplementary corrections for the libspf2 library.. libspf2, email system, SPF specification, Fedora security, exploitation risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 03, 2023 Critical Fedora
89

Fedora 39: FEDORA-2023-8e12f879ad High: libxml2 Memory Leak

Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-7f01e967ad 2023-10-09 01:54:42.687350 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 38 Version : 1.2.11 Release : 11.20210922git4915c308.fc38 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 * Thu Jul 20 2023 Fedora Release Engineering - 1.2.11-8.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 11 2023 Jitka Plesnikova - 1.2.11-7.20210922git4915c308 - Perl 5.38 rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow RemoteCode Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7f01e967ad' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Urgent security notice for Fedora 38 pertaining to libspf2 updates addressing CVE-2023-42118 and ensuring essential corrections.. Fedora 38 Security, libspf2 Update, Email Security Patch. . LinuxSecurity.com Team

Calendar 2 Oct 09, 2023 Fedora
89

Fedora 37: FEDORA-2023-ae340c92ea Critical: Remote Code Exec via libspf2

Patch CVE-2023-42118, plus some other fixes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-ae340c92ea 2023-10-09 01:26:34.405082 -------------------------------------------------------------------------------- Name : libspf2 Product : Fedora 37 Version : 1.2.11 Release : 11.20210922git4915c308.fc37 URL : Summary : An implementation of the SPF specification Description : libspf2 is an implementation of the SPF (Sender Policy Framework) specification as found at: https://www.ietf.org/archive/id/draft-mengwong-spf-00.txt SPF allows email systems to check SPF DNS records and make sure that an email is authorized by the administrator of the domain name that it is coming from. This prevents email forgery, commonly used by spammers, scammers, and email viruses/worms. A lot of effort has been put into making it secure by design, and a great deal of effort has been put into the regression tests. -------------------------------------------------------------------------------- Update Information: Patch CVE-2023-42118, plus some other fixes. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 3 2023 Bojan Smojver - 1.2.11-11.20210922git4915c308 - Add fixes from pull request 47 * Mon Oct 2 2023 Bojan Smojver - 1.2.11-10.20210922git4915c308 - CVE-2023-42118 * Thu Jul 20 2023 Fedora Release Engineering - 1.2.11-8.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Tue Jul 11 2023 Jitka Plesnikova - 1.2.11-7.20210922git4915c308 - Perl 5.38 rebuild * Thu Jan 19 2023 Fedora Release Engineering - 1.2.11-6.20210922git4915c308 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Fri Jan 6 2023 Peter Fordham - 1.2.11-5.20210922git4915c308 - Add missing include of string.h for memset in spf_utils.c https://github.com/shevek/libspf2/issues/41 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2241536 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241536 [ 2 ] Bug #2241537 - CVE-2023-42118 libspf2: Integer Underflow Remote Code Execution Vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2241537 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-ae340c92ea' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Apply essential updates for libspf2 in Fedora 37 to mitigate serious vulnerabilities associated with CVE-2023-42118, ensuring system security through patching. Fedora Updates, libspf2, Email Security, Critical Update, Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 09, 2023 Critical Fedora
197

Debian 9 DLA-2890-1 Critical: Libspf2 Heap Overflow Issues

Two issues have been found in libspf2, a library for validating mail senders with SPF. Both issues are related to heap-based buffer overflows. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2890-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz January 21, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libspf2 Version : 1.2.10-7+deb9u2 CVE ID : CVE-2021-33912 CVE-2021-33913 Two issues have been found in libspf2, a library for validating mail senders with SPF. Both issues are related to heap-based buffer overflows. For Debian 9 stretch, these problems have been fixed in version 1.2.10-7+deb9u2. We recommend that you upgrade your libspf2 packages. For the detailed security status of libspf2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libspf2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2901-1 addresses critical updates for libxml2, resolving buffer overflow vulnerabilities in XML parsing.. debian lts, libspf2 update, heap overflow fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 20, 2022 Critical Debian LTS
203

Mageia 8 MGASA-2021-0454 Critical: Libspf2 Buffer Overflow

Updated libspf2 packages fix buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=29396 - https://www.openwall.com/lists/oss-security/2021/08/11/6 . MGASA-2021-0454 - Updated libspf2 packages fix security vulnerability Publication date: 02 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0454.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-20314 Updated libspf2 packages fix buffer overflow. References: - https://bugs.mageia.org/show_bug.cgi?id=29396 - https://www.openwall.com/lists/oss-security/2021/08/11/6 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/CMSFT2NJDZ7PATRZSQPAOGSE7JD6ELOB/ - https://www.cve.org/CVERecord?id=CVE-2021-20314 SRPMS: - 8/core/libspf2-1.2.11-0.git20210609.1.mga8 . Latest libspf2 updates resolve a critical buffer overflow vulnerability in Mageia, vital for ensuring system security.. Mageia Security Advisory, libspf2 Update, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 02, 2021 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here