Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
98

Red Hat Enterprise Linux 8: RHSA-2019-3673-01 Low: lldpad Security Fix

An update for lldpad is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: lldpad security and bug fix update Advisory ID: RHSA-2019:3673-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3673 Issue date: 2019-11-05 CVE Names: CVE-2018-10932 ==================================================================== 1. Summary: An update for lldpad is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64 3. Description: The lldpad packages provide the Linux user space daemon and configuration tool for Intel's Link Layer Discovery Protocol (LLDP) Agent with Enhanced Ethernet support. Security Fix(es): * lldptool: improper sanitization of shell-escape codes (CVE-2018-10932) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.1 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory,refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1614896 - CVE-2018-10932 lldptool: improper sanitization of shell-escape codes 1727326 - lldpad memory usage increases over time 6. Package List: Red Hat Enterprise Linux BaseOS (v. 8): Source: lldpad-1.0.1-13.git036e314.el8.src.rpm aarch64: lldpad-1.0.1-13.git036e314.el8.aarch64.rpm lldpad-debuginfo-1.0.1-13.git036e314.el8.aarch64.rpm lldpad-debugsource-1.0.1-13.git036e314.el8.aarch64.rpm ppc64le: lldpad-1.0.1-13.git036e314.el8.ppc64le.rpm lldpad-debuginfo-1.0.1-13.git036e314.el8.ppc64le.rpm lldpad-debugsource-1.0.1-13.git036e314.el8.ppc64le.rpm s390x: lldpad-1.0.1-13.git036e314.el8.s390x.rpm lldpad-debuginfo-1.0.1-13.git036e314.el8.s390x.rpm lldpad-debugsource-1.0.1-13.git036e314.el8.s390x.rpm x86_64: lldpad-1.0.1-13.git036e314.el8.i686.rpm lldpad-1.0.1-13.git036e314.el8.x86_64.rpm lldpad-debuginfo-1.0.1-13.git036e314.el8.i686.rpm lldpad-debuginfo-1.0.1-13.git036e314.el8.x86_64.rpm lldpad-debugsource-1.0.1-13.git036e314.el8.i686.rpm lldpad-debugsource-1.0.1-13.git036e314.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-10932 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.1_release_notes/ 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPGv1 iQIVAwUBXcHqL9zjgjWX9erEAQg8uxAAp1sXX7k616voF4T1ESaLw/2xgwVpXcFA rssf0zsmwNH4Ckt/ehyTMTyeE2b0pEZajfQDLfP5u6Baz6YHJr3/gnDG8/ffHJZ5 alvJGBoWPTtgVvcmC/T8++eUyMQ9KmpG1SX6sUiIvTbxNVGAe8eYEWmEv3cOVNo9 fClotoOCiOc+T18xqHfBiUybFuqYYnApzb/UH5R0LEY5hND76PKaijrnNhw+vLe8 KOnfFu3h79IAfAFbSfj62LTKLNnScHtzNB5N0dlmt/UzyTX0yRZLD4ISqq4j6a7H svOTOb7w2PefY+pIN/nwooR2rcD9w98N7KmH2q+8euzE2x9BeuoEgBLe7hH40dSo P8siGfzIGhnw1xNdF/8VgUlow0HFRfNXycxVYtTJCwcPczrUFJr0NeaQ9ATwdToI N14/JjJ/dpLGoTboUAub2Nhgx3Y4PJEKqnNHfA0hC/0YJ6VHHtbXAmKFiHmZGiNz LwAUMQYQ4BcOU0eIy1y55rDy4drAmf1QI+QXq7A0Ax8e8uCxAVcjkoeYbS1ecl1V fbC9wtM5Ev/OMWt1nEJfsScDeqIUZKpOYk2nYPVB2EoDzyzlPKJKiv8T1Eu9brY3 WcffJxHFd2JhPvrxEj9YfCZK4Zk7UEN0swQMEURknKgbSEyaU79mnU6Qlk8DNSJ4 KxLsAQumMR8=tsSa -----END PGP SIGNATURE-------RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A new version of lldpad has been released for Red Hat Enterprise Linux 8, addressing a low severity security vulnerability alongside several critical updates.. Red Hat Enterprise Linux,lldpad update,security advisory,bug fix. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Nov 05, 2019 Low Red Hat
89

Fedora 27 lldpad Security Patch: CVE-2018-10932 Critical Sanitization Flaw

- Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-e9d1ec6dbc 2018-11-16 03:41:37.813095 --------------------------------------------------------------------------------Name : lldpad Product : Fedora 27 Version : 1.0.1 Release : 9.git036e314.fc27 URL : https://www.resiliencecounselling.uk.com/ Summary : Intel LLDP Agent Description : This package contains the Linux user space daemon and configuration tool for Intel LLDP Agent with Enhanced Ethernet support for the Data Center. --------------------------------------------------------------------------------Update Information: - Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices. --------------------------------------------------------------------------------ChangeLog: * Thu Aug 16 2018 Petr Machata - 1.0.1-9.git036e314 - Add open-lldp-v1.0.1-29-basman_clif-print-the-OID-properly.patch (BZ 1614932, 1614896 (CVE-2018-10932) - Add open-lldp-v1.0.1-28-support-DSCP-selectors.patch (BZ 1618377) --------------------------------------------------------------------------------References: [ 1 ] Bug #1614896 - CVE-2018-10932 lldptool: improper sanitization of shell-escape codes https://bugzilla.redhat.com/show_bug.cgi?id=1614896 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-e9d1ec6dbc' at the command line. Formore information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora has released a patch addressing vulnerabilities related to insufficient sanitization in lldpad, alongside enhancements to its packet prioritization features.. Fedora Update,lldpad Security Fix,Improper Sanitization,DSCP Selectors,Network Device Configuration. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 16, 2018 Critical Fedora
89

Fedora 29: FEDORA-2018-06d56c8c9d Critical: Lldpad Sanitization Flaw

- Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-06d56c8c9d 2018-11-03 00:00:04.467603 --------------------------------------------------------------------------------Name : lldpad Product : Fedora 29 Version : 1.0.1 Release : 12.git036e314.fc29 URL : / Summary : Intel LLDP Agent Description : This package contains the Linux user space daemon and configuration tool for Intel LLDP Agent with Enhanced Ethernet support for the Data Center. --------------------------------------------------------------------------------Update Information: - Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 23 2018 Petr Machata - 1.0.1-12.git036e314 - Add open-lldp-v1.0.1-29-basman_clif-print-the-OID-properly.patch (BZ 1614932, 1614896 (CVE-2018-10932) - Add open-lldp-v1.0.1-28-support-DSCP-selectors.patch (BZ 1618377) --------------------------------------------------------------------------------References: [ 1 ] Bug #1614896 - CVE-2018-10932 lldptool: improper sanitization of shell-escape codes https://bugzilla.redhat.com/show_bug.cgi?id=1614896 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-06d56c8c9d' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Arch Linux 2021 lldpad patch addresses a vulnerability related to input validation, improving network functions.. Fedora Lldpad Update, Security Patch, Network Enhancement. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 03, 2018 Critical Fedora
89

Fedora 28: Security Advisory for lldpad - Improper Shell Code Sanitization

- Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-cec7093baa 2018-10-26 17:06:17.983421 --------------------------------------------------------------------------------Name : lldpad Product : Fedora 28 Version : 1.0.1 Release : 10.git036e314.fc28 URL : / Summary : Intel LLDP Agent Description : This package contains the Linux user space daemon and configuration tool for Intel LLDP Agent with Enhanced Ethernet support for the Data Center. --------------------------------------------------------------------------------Update Information: - Add upstream fix for improper sanitization of shell-escape codes when lldptool parses a mngAddr TLV (CVE-2018-10932). - Add upstream patch to support DSCP selectors in APP TLVs. This allows configuration of DSCP-based packet prioritization on capable network devices. --------------------------------------------------------------------------------ChangeLog: * Tue Oct 23 2018 Petr Machata - 1.0.1-10.git036e314 - Add open-lldp-v1.0.1-29-basman_clif-print-the-OID-properly.patch (BZ 1614932, 1614896 (CVE-2018-10932) - Add open-lldp-v1.0.1-28-support-DSCP-selectors.patch (BZ 1618377) --------------------------------------------------------------------------------References: [ 1 ] Bug #1614896 - CVE-2018-10932 lldptool: improper sanitization of shell-escape codes https://bugzilla.redhat.com/show_bug.cgi?id=1614896 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-cec7093baa' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This patch resolves a vulnerability in lldptool that impacts Fedora 28, thereby improving the overall security of the network.. lldpad security,Fedora update,network configuration,shell-escape sanitization,packet prioritization. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 26, 2018 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here