Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 10 Buster DLA-3481-1 Critical: Libusrsctp Out-Of-Bounds Fix

An out-of-bounds read was found in sctp_load_addresses_from_init. For Debian 10 buster, this problem has been fixed in version 0.9.3.0+20190127-2+deb10u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3481-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès July 06, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libusrsctp Version : 0.9.3.0+20190127-2+deb10u1 CVE ID : CVE-2019-20503 Debian Bug : 953270 An out-of-bounds read was found in sctp_load_addresses_from_init. For Debian 10 buster, this problem has been fixed in version 0.9.3.0+20190127-2+deb10u1. We recommend that you upgrade your libusrsctp packages. For the detailed security status of libusrsctp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libusrsctp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Bulletin DLA-3482-1: Security vulnerability resolved for libusrsctp in Debian 10.. Libusrsctp Update, Debian Security, Out-Of-Bounds Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 06, 2023 Critical Debian LTS
203

Mageia 8: 2023-0018 Moderate: Firefox NSS Crash and Library Risks

A vulnerability was found in NSS. The NSS client auth crashes without a user certificate in the database, leading to a segmentation fault or crash (CVE-2022-3479). An out of date library (libusrsctp) contained vulnerabilities that could . MGASA-2023-0018 - Updated firefox packages fix security vulnerability Publication date: 24 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0018.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-3479, CVE-2022-46871, CVE-2022-46877, CVE-2023-23598, CVE-2023-23601, CVE-2023-23602, CVE-2023-23603, CVE-2023-23605 A vulnerability was found in NSS. The NSS client auth crashes without a user certificate in the database, leading to a segmentation fault or crash (CVE-2022-3479). An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited (CVE-2022-46871). By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks (CVE-2022-46877). Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to DataTransfer.setData (CVE-2023-23598). Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks (CVE-2023-23601). A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers (CVE-2023-23602). Regular expressions used to filter out forbidden properties and values from style directives in calls to console.log weren't accounting for external URLs, allowing bypassing Content Security Policy via format directives. Data could then be potentially exfiltrated from the browser (CVE-2023-23603). Mozilla developers and the Mozilla Fuzzing Teamreported memory safety bugs present in Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2023-23605). References: - https://bugs.mageia.org/show_bug.cgi?id=31415 - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/7D6OeqrEDcE - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_87.html - https://www.mozilla.org/en-US/security/advisories/mfsa2023-02/ - - https://access.redhat.com/errata/RHSA-2023:0288 - https://www.cve.org/CVERecord?id=CVE-2022-3479 - https://www.cve.org/CVERecord?id=CVE-2022-46871 - https://www.cve.org/CVERecord?id=CVE-2022-46877 - https://www.cve.org/CVERecord?id=CVE-2023-23598 - https://www.cve.org/CVERecord?id=CVE-2023-23601 - https://www.cve.org/CVERecord?id=CVE-2023-23602 - https://www.cve.org/CVERecord?id=CVE-2023-23603 - https://www.cve.org/CVERecord?id=CVE-2023-23605 SRPMS: - 8/core/firefox-102.7.0-1.mga8 - 8/core/firefox-l10n-102.7.0-1.mga8 - 8/core/nss-3.87.0-1.mga8 . An array of Chrome upgrades targeting various vulnerabilities identified by Google, affecting BoringSSL and libc functions stability.. Mageia Security Advisory, Firefox Risks, Browser Security Updates, NSS Issues. . LinuxSecurity.com Team

Calendar 2 Jan 24, 2023 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here