Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
217

Oracle Linux 9 ELSA-2025-7431 moderate: PHP HTTP Wrapper Fixes

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7431 http://linux.oracle.com/errata/ELSA-2025-7431.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable LinuxNetwork: x86_64: php-8.0.30-3.el9_6.x86_64.rpm php-bcmath-8.0.30-3.el9_6.x86_64.rpm php-cli-8.0.30-3.el9_6.x86_64.rpm php-common-8.0.30-3.el9_6.x86_64.rpm php-dba-8.0.30-3.el9_6.x86_64.rpm php-dbg-8.0.30-3.el9_6.x86_64.rpm php-devel-8.0.30-3.el9_6.x86_64.rpm php-embedded-8.0.30-3.el9_6.x86_64.rpm php-enchant-8.0.30-3.el9_6.x86_64.rpm php-ffi-8.0.30-3.el9_6.x86_64.rpm php-fpm-8.0.30-3.el9_6.x86_64.rpm php-gd-8.0.30-3.el9_6.x86_64.rpm php-gmp-8.0.30-3.el9_6.x86_64.rpm php-intl-8.0.30-3.el9_6.x86_64.rpm php-ldap-8.0.30-3.el9_6.x86_64.rpm php-mbstring-8.0.30-3.el9_6.x86_64.rpm php-mysqlnd-8.0.30-3.el9_6.x86_64.rpm php-odbc-8.0.30-3.el9_6.x86_64.rpm php-opcache-8.0.30-3.el9_6.x86_64.rpm php-pdo-8.0.30-3.el9_6.x86_64.rpm php-pgsql-8.0.30-3.el9_6.x86_64.rpm php-process-8.0.30-3.el9_6.x86_64.rpm php-snmp-8.0.30-3.el9_6.x86_64.rpm php-soap-8.0.30-3.el9_6.x86_64.rpm php-xml-8.0.30-3.el9_6.x86_64.rpm aarch64: php-8.0.30-3.el9_6.aarch64.rpm php-bcmath-8.0.30-3.el9_6.aarch64.rpm php-cli-8.0.30-3.el9_6.aarch64.rpm php-common-8.0.30-3.el9_6.aarch64.rpm php-dba-8.0.30-3.el9_6.aarch64.rpm php-dbg-8.0.30-3.el9_6.aarch64.rpm php-devel-8.0.30-3.el9_6.aarch64.rpm php-embedded-8.0.30-3.el9_6.aarch64.rpm php-enchant-8.0.30-3.el9_6.aarch64.rpm php-ffi-8.0.30-3.el9_6.aarch64.rpm php-fpm-8.0.30-3.el9_6.aarch64.rpm php-gd-8.0.30-3.el9_6.aarch64.rpm php-gmp-8.0.30-3.el9_6.aarch64.rpm php-intl-8.0.30-3.el9_6.aarch64.rpm php-ldap-8.0.30-3.el9_6.aarch64.rpm php-mbstring-8.0.30-3.el9_6.aarch64.rpm php-mysqlnd-8.0.30-3.el9_6.aarch64.rpm php-odbc-8.0.30-3.el9_6.aarch64.rpm php-opcache-8.0.30-3.el9_6.aarch64.rpm php-pdo-8.0.30-3.el9_6.aarch64.rpm php-pgsql-8.0.30-3.el9_6.aarch64.rpm php-process-8.0.30-3.el9_6.aarch64.rpm php-snmp-8.0.30-3.el9_6.aarch64.rpm php-soap-8.0.30-3.el9_6.aarch64.rpm php-xml-8.0.30-3.el9_6.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//php-8.0.30-3.el9_6.src.rpm Related CVEs: CVE-2025-1217 CVE-2025-1219 CVE-2025-1734 CVE-2025-1736 CVE-2025-1861 Description of changes: [8.0.30-3] - Fix libxmlstreams use wrong content-type header when requesting a redirected resource CVE-2025-1219 - Fix Stream HTTP wrapper header check might omit basic auth header CVE-2025-1736 - Fix Stream HTTP wrapper truncate redirect location to 1024 bytes CVE-2025-1861 - Fix Streams HTTP wrapper does not fail for headers without colon CVE-2025-1734 - Fix Header parser of http stream wrapper does not handle folded headers CVE-2025-1217 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux enhancements for PHP addressing urgent vulnerabilities in HTTP handling and cybersecurity risks. Discover further details today!. Oracle Linux Updates, PHP Security, HTTP Wrapper Fix, Linux Security Advisory, Moderate Severity. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 27, 2025 Important Oracle
89

Fedora 40: qt6-qtwebengine 2025-af22a87e43 Security Advisory Updates

Unbundle libxml.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-af22a87e43 2025-03-13 01:47:29.556536+00:00 -------------------------------------------------------------------------------- Name : qt6-qtwebengine Product : Fedora 40 Version : 6.8.2 Release : 4.fc40 URL : http://www.qt.io Summary : Qt6 - QtWebEngine components Description : Qt6 - QtWebEngine components. -------------------------------------------------------------------------------- Update Information: Unbundle libxml. -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 4 2025 Jan Grulich - 6.8.2-4 - Unbundle libxml and libxslt * Mon Mar 3 2025 Jan Grulich - 6.8.2-3 - Rework OpenH264 support following Chromium package - Backport upstream change for ffmpeg codec selection issues. * Mon Feb 17 2025 Jan Grulich - 6.8.2-2 - Bump build for ppc64le enablement -------------------------------------------------------------------------------- References: [ 1 ] Bug #2280538 - CVE-2024-34459 qt6-qtwebengine: libxml2: buffer over-read in xmlHTMLPrintFileContext in xmllint.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2280538 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-af22a87e43' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Qt6 - QtWebEngine update in Fedora 40 addresses libxml buffer over-read security issue; essential advisory details included.. unbundle, libxml, --------------------------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 13, 2025 Critical Fedora
203

Mageia 8: 2023-0248 Critical: PHP Buffer Overflow And Entity Loading

Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phar_dir_read()) (CVE-2023-3824) . MGASA-2023-0248 - Updated php packages fix security vulnerability Publication date: 23 Aug 2023 URL: https://advisories.mageia.org/MGASA-2023-0248.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-3823, CVE-2023-3824 Libxml - GHSA-3qrf-m4j2-pcrr (Security issue with external entity loading in XML without enabling it). (CVE-2023-3823) Phar - GHSA-jqcx-ccgc-xwhv (Buffer mismanagement in phar_dir_read()) (CVE-2023-3824) References: - https://bugs.mageia.org/show_bug.cgi?id=32158 - https://www.php.net/ChangeLog-8.php#8.0.30 - https://www.cve.org/CVERecord?id=CVE-2023-3823 - https://www.cve.org/CVERecord?id=CVE-2023-3824 SRPMS: - 8/core/php-8.0.30-1.mga8 . Ubuntu 2023-0385 resolves serious python vulnerabilities affecting earlier editions by rectifying memory handling flaws and injection threats.. Mageia Security, PHP Update, Buffer Management, Entity Loading Issue, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 23, 2023 Critical Mageia
172

Ubuntu 15.04 USN-2592-1 Critical: Libxml-libxml-perl Information Exposure

XML::LibXML could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-2592-1 May 04, 2015 libxml-libxml-perl vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: XML::LibXML could be made to expose sensitive information. Software Description: - libxml-libxml-perl: Perl interface to the libxml2 library Details: Tilmann Haak discovered that XML::LibXML incorrectly handled the expand_entities parameter in certain situations. A remote attacker could possibly use this issue to access sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.15.04.1 Ubuntu 14.10: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.14.10.1 Ubuntu 14.04 LTS: libxml-libxml-perl 2.0108+dfsg-1ubuntu0.1 Ubuntu 12.04 LTS: libxml-libxml-perl 1.89+dfsg-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2592-1 CVE-2015-3451 Package Information: https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0108+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/1.89+dfsg-1ubuntu0.1 . A vulnerability found in the libxml-libxml-perl package of Ubuntu could potentially leak confidential information. Follow the provided steps for updates.. libxml, update instructions, exposure risk, ubuntu security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 04, 2015 Critical Ubuntu
87

Debian: DSA-3243-1 Critical: Libxml-Libxml-Perl Access Issue Fix

Tilmann Haak from xing.com discovered that XML::LibXML, a Perl interface to the libxml2 library, did not respect the expand_entities parameter to disable processing of external entities in some circumstances. This may allow attackers to gain read access to otherwise protected ressources, . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3243-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso May 01, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxml-libxml-perl CVE ID : CVE-2015-3451 Debian Bug : 783443 Tilmann Haak from xing.com discovered that XML::LibXML, a Perl interface to the libxml2 library, did not respect the expand_entities parameter to disable processing of external entities in some circumstances. This may allow attackers to gain read access to otherwise protected ressources, depending on how the library is used. For the oldstable distribution (wheezy), this problem has been fixed in version 2.0001+dfsg-1+deb7u1. For the stable distribution (jessie), this problem has been fixed in version 2.0116+dfsg-1+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 2.0116+dfsg-2. We recommend that you upgrade your libxml-libxml-perl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Debian Security Advisory DSA-3243-1 announces an important patch for libxml-libxml-perl focusing on a significant vulnerability in access control.. Libxml Security, Access Control Update, Debian Advisory, XML Processing Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 01, 2015 Critical Debian
87

Debian: DSA-2580-1 Urgent: Buffer Overflow in libxml Security Patch

Jueri Aedla discovered a buffer overflow in the libxml XML library, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2580-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff December 02, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libxml2 Vulnerability : buffer overflow Problem type : local(remote) Debian-specific: no CVE ID : CVE-2012-5134 Jueri Aedla discovered a buffer overflow in the libxml XML library, which could result in the execution of arbitrary code. For the stable distribution (squeeze), this problem has been fixed in version 2.7.8.dfsg-2+squeeze6. For the unstable distribution (sid), this problem has been fixed in version 2.8.0+dfsg1-7. We recommend that you upgrade your libxml2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch for memory corruption vulnerability in libxml2 library mitigates serious security threats. Users advised to update.. Debian, libxml2, buffer overflow, security advisory, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 02, 2012 Critical Debian
89

Fedora 10: 2009-8594 Critical: Libxml DoS And Code Execution Risks

This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8594 2009-08-15 07:20:42 -------------------------------------------------------------------------------- Name : libxml Product : Fedora 10 Version : 1.8.17 Release : 24.fc10 URL : http://veillard.com/XML/ Summary : Old XML library for Gnome-1 application compatibility Description : This library allows old Gnome-1 applications to manipulate XML files. -------------------------------------------------------------------------------- Update Information: This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities) -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 12 2009 Paul Howarth 1:1.8.17-24 - renumber existing patches to free up low-numbered patches for EL-3 patches - add patch for CAN-2004-0110 and CAN-2004-0989 (#139090) - add patch for CVE-2009-2414 and CVE-2009-2416 (#515195, #515205) * Sat Jul 25 2009 Fedora Release Engineering 1:1.8.17-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Apr 20 2009 Paul Howarth 1:1.8.17-22 - rebuild for %{_isa} provides/requires * Wed Feb 25 2009 Fedora Release Engineering 1:1.8.17-21 - rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #430644- CVE-2004-0110 libxml2 long URL causes SEGV https://bugzilla.redhat.com/show_bug.cgi?id=430644 [ 2 ] Bug #430645 - CVE-2004-0989 libxml2 various overflows https://bugzilla.redhat.com/show_bug.cgi?id=430645 [ 3 ] Bug #515195 - CVE-2009-2414 libxml, libxml2: Stack overflow by parsing root XML element DTD definition https://bugzilla.redhat.com/show_bug.cgi?id=515195 [ 4 ] Bug #515205 - CVE-2009-2416 libxml, libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types https://bugzilla.redhat.com/show_bug.cgi?id=515205 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libxml' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent libxml update for Fedora tackles severe security vulnerabilities, covering multiple execution risks and Denial of Service (DoS) threats. Take immediate action!. libxml security, Fedora update, software patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 15, 2009 Critical Fedora
89

CentOS 6: CENTOS-2011-5678 Urgent OpenSSL Vulnerability Fix

This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8582 2009-08-15 07:17:49 -------------------------------------------------------------------------------- Name : libxml Product : Fedora 11 Version : 1.8.17 Release : 24.fc11 URL : http://veillard.com/XML/ Summary : Old XML library for Gnome-1 application compatibility Description : This library allows old Gnome-1 applications to manipulate XML files. -------------------------------------------------------------------------------- Update Information: This update includes patches from RHEL-3 addressing a number of security vulnerabilities: - CVE-2004-0110 (arbitrary code execution via a long URL) - CVE-2004-0989 (arbitrary code execution via a long URL) - CVE-2009-2414 (stack consumption DoS vulnerabilities) - CVE-2009-2416 (use-after-free DoS vulnerabilities) -------------------------------------------------------------------------------- ChangeLog: * Wed Aug 12 2009 Paul Howarth 1:1.8.17-24 - renumber existing patches to free up low-numbered patches for EL-3 patches - add patch for CAN-2004-0110 and CAN-2004-0989 (#139090) - add patch for CVE-2009-2414 and CVE-2009-2416 (#515195, #515205) * Sat Jul 25 2009 Fedora Release Engineering 1:1.8.17-23 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Mon Apr 20 2009 Paul Howarth 1:1.8.17-22 - rebuild for %{_isa} provides/requires -------------------------------------------------------------------------------- References: [ 1 ] Bug #430644 - CVE-2004-0110 libxml2 long URL causes SEGV https://bugzilla.redhat.com/show_bug.cgi?id=430644 [ 2 ] Bug #430645 -CVE-2004-0989 libxml2 various overflows https://bugzilla.redhat.com/show_bug.cgi?id=430645 [ 3 ] Bug #515195 - CVE-2009-2414 libxml, libxml2: Stack overflow by parsing root XML element DTD definition https://bugzilla.redhat.com/show_bug.cgi?id=515195 [ 4 ] Bug #515205 - CVE-2009-2416 libxml, libxml2: Pointer use-after-free flaws by parsing Notation and Enumeration attribute types https://bugzilla.redhat.com/show_bug.cgi?id=515205 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libxml' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 11 has rolled out an update addressing security vulnerabilities in libxml. The patch includes vital fixes to counter serious threats and improves overall system integrity. Fedora Update, libxml Security, DoS Attacks, Security Patches, Linux Library. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 15, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200