Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 38: FEDORA-2024-5dc487ee89 Moderate: llhttp Security Fix

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5dc487ee89 2024-04-20 02:13:26.365190 -------------------------------------------------------------------------------- Name : uxplay Product : Fedora 38 Version : 1.68.2 Release : 3.fc38 URL : https://github.com/FDH2/UxPlay Summary : AirPlay Unix mirroring server Description : An AirPlay2 Mirror and AirPlay2 Audio (but not Video) server that provides screen-mirroring (with audio) of iOS/MacOS clients in a display window on the server host (which can be shared using a screen-sharing application); Apple Lossless Audio (ALAC) (e.g.,iTunes) can be streamed from client to server in non-mirror mode. -------------------------------------------------------------------------------- Update Information: Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 16 2024 Benjamin A. Beasley - 1.68.2-3 - Rebuild for llhttp-9.2.0 * Sat Jan 27 2024 Fedora Release Engineering - 1.68.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273352 - llhttp-9.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273352 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5dc487ee89' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Discover the new Fedora 38 uxplay update that tackles llhttp vulnerabilities alongside various bug corrections for enhanced efficiency.. uxplay Update, llhttp Security, Fedora Advisory, AirPlay Server Fix. . LinuxSecurity.com Team

Calendar 2 Apr 20, 2024 Fedora
89

Fedora 38 Update: llhttp 9.2.1 Critical Fix Released for 2024-5dc487ee89

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5dc487ee89 2024-04-20 02:13:26.365190 -------------------------------------------------------------------------------- Name : python-aiohttp Product : Fedora 38 Version : 3.9.3 Release : 3.fc38 URL : https://github.com/aio-libs/aiohttp Summary : Python HTTP client/server for asyncio Description : Python HTTP client/server for asyncio which supports both the client and the server side of the HTTP protocol, client and server websocket, and webservers with middlewares and pluggable routing. -------------------------------------------------------------------------------- Update Information: Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Benjamin A. Beasley - 3.9.3-3 - Backport support for llhttp 9.2.1 - Started rejecting obsolete line folding in Python parser to match * Fri Feb 16 2024 Benjamin A. Beasley - 3.9.3-2 - Rebuilt for llhttp-9.2.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273352 - llhttp-9.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273352 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5dc487ee89' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Upgrade llhttp version 9.2.1 in Fedora 38 for python-aiohttp to address significant vulnerabilities and improve security measures efficiently.. Python Aiohttp Fixes, Fedora Security, HTTP Client Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 20, 2024 Critical Fedora
89

Fedora 39 uxplay Update: llhttp 9.2.1 Critical Security Fix

Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-f83b123d63 2024-04-20 01:02:39.396055 -------------------------------------------------------------------------------- Name : uxplay Product : Fedora 39 Version : 1.68.2 Release : 3.fc39 URL : https://github.com/FDH2/UxPlay Summary : AirPlay Unix mirroring server Description : An AirPlay2 Mirror and AirPlay2 Audio (but not Video) server that provides screen-mirroring (with audio) of iOS/MacOS clients in a display window on the server host (which can be shared using a screen-sharing application); Apple Lossless Audio (ALAC) (e.g.,iTunes) can be streamed from client to server in non-mirror mode. -------------------------------------------------------------------------------- Update Information: Update llhttp to 9.2.1, fixing CVE-2024-27982. Additionally, llhttp 9.2.0 contained a number of bug fixes. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3. -------------------------------------------------------------------------------- ChangeLog: * Fri Feb 16 2024 Benjamin A. Beasley - 1.68.2-3 - Rebuild for llhttp-9.2.0 * Sat Jan 27 2024 Fedora Release Engineering - 1.68.2-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273352 - llhttp-9.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273352 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-f83b123d63' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The upgrade to llhttp version 9.2.1 addresses the critical vulnerability CVE-2024-27982 for Fedora 39's uxplay, improving both reliability and efficiency.. llhttp,Fedora upgrades,uxplay security,AirPlay server updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 20, 2024 Critical Fedora
89

Fedora 40: FEDORA-2024-2f15e6e876 Critical: Python-Aiohttp CVE Fix

Update llhttp to 9.2.1, fixing CVE-2024-27982. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2f15e6e876 2024-04-19 21:20:20.799430 -------------------------------------------------------------------------------- Name : python-aiohttp Product : Fedora 40 Version : 3.9.3 Release : 3.fc40 URL : https://github.com/aio-libs/aiohttp Summary : Python HTTP client/server for asyncio Description : Python HTTP client/server for asyncio which supports both the client and the server side of the HTTP protocol, client and server websocket, and webservers with middlewares and pluggable routing. -------------------------------------------------------------------------------- Update Information: Update llhttp to 9.2.1, fixing CVE-2024-27982. Backport llhttp 9.2.1 support to python-aiohttp 3.9.3. -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 11 2024 Benjamin A. Beasley - 3.9.3-3 - Backport support for llhttp 9.2.1 - Started rejecting obsolete line folding in Python parser to match -------------------------------------------------------------------------------- References: [ 1 ] Bug #2273352 - llhttp-9.2.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2273352 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2f15e6e876' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Upgrade llhttp to 9.2.1 within Fedora 40's python-aiohttp to address the severe CVE-2024-27982 vulnerability.. Fedora 40, Python Aiohttp Update, Security Advisory, Critical CVE Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 19, 2024 Critical Fedora
89

Fedora 37 Release: Critical llhttp Update for CVE-2023-30589 Fix

Update `llhttp` to 8.1.1 (including a SONAME version bump and ABI break, and `python-aiohttp` to 3.8.5. Fixes CVE-2023-30589.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-105880e618 2023-08-17 00:33:38.714924 -------------------------------------------------------------------------------- Name : llhttp Product : Fedora 37 Version : 8.1.1 Release : 1.fc37 URL : https://github.com/nodejs/llhttp Summary : Port of http_parser to llparse Description : This project is a port of http_parser to TypeScript. llparse is used to generate the output C source file, which could be compiled and linked with the embedder's program (like Node.js). This copy of the library is compiled with LLHTTP_STRICT_MODE set to 0 (disabled), which is the default. -------------------------------------------------------------------------------- Update Information: Update `llhttp` to 8.1.1 (including a SONAME version bump and ABI break, and `python-aiohttp` to 3.8.5. Fixes CVE-2023-30589. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 29 2023 Benjamin A. Beasley - 8.1.1-1 - Update to 8.1.1 (close RHBZ#2216591) * Thu Jul 20 2023 Fedora Release Engineering - 8.1.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Sat Jun 3 2023 Benjamin A. Beasley - 8.1.0-5 - Remove explicit %set_build_flags, not needed since F36 * Wed Feb 15 2023 Benjamin A. Beasley - 8.1.0-4 - Fix test compiling/execution * Thu Jan 19 2023 Fedora Release Engineering - 8.1.0-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Tue Dec 20 2022 Benjamin A. Beasley - 8.1.0-2 - Indicate dirs. in files list with trailing slashes * Sat Oct 15 2022 Benjamin A. Beasley - 8.1.0-1 - Update to 8.1.0 (close RHBZ#2131175) * Sat Oct 15 2022 Benjamin A. Beasley - 8.0.0-1 - Update to 8.0.0 (close RHBZ#2131175) * Sat Oct 15 2022Benjamin A. Beasley - 6.0.10-2 - Drop workarounds for Python 3.10 and older -------------------------------------------------------------------------------- References: [ 1 ] Bug #2216591 - llhttp-8.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2216591 [ 2 ] Bug #2227458 - python-aiohttp-3.8.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2227458 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-105880e618' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Major revision to llhttp and python-aiohttp for Fedora 37, responding to CVE-2023-30589 with crucial patches.. llhttp Update,Fedora 37 Security,python-aiohttp Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 17, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-f75af676f2 Critical: llhttp Remote Code Execution

Update `llhttp` to 8.1.1 and `python-aiohttp` to 3.8.5. Fixes CVE-2023-30589.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f75af676f2 2023-08-07 01:25:45.125887 -------------------------------------------------------------------------------- Name : llhttp Product : Fedora 38 Version : 8.1.1 Release : 1.fc38 URL : https://github.com/nodejs/llhttp Summary : Port of http_parser to llparse Description : This project is a port of http_parser to TypeScript. llparse is used to generate the output C source file, which could be compiled and linked with the embedder's program (like Node.js). This copy of the library is compiled with LLHTTP_STRICT_MODE set to 0 (disabled), which is the default. -------------------------------------------------------------------------------- Update Information: Update `llhttp` to 8.1.1 and `python-aiohttp` to 3.8.5. Fixes CVE-2023-30589. -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 29 2023 Benjamin A. Beasley - 8.1.1-1 - Update to 8.1.1 (close RHBZ#2216591) * Thu Jul 20 2023 Fedora Release Engineering - 8.1.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Sat Jun 3 2023 Benjamin A. Beasley - 8.1.0-5 - Remove explicit %set_build_flags, not needed since F36 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2216591 - llhttp-8.1.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2216591 [ 2 ] Bug #2227458 - python-aiohttp-3.8.5 is available https://bugzilla.redhat.com/show_bug.cgi?id=2227458 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f75af676f2' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . To secure your Fedora 38 environment against CVE-2023-30589, follow these steps: update packages, install llhttp and python-aiohttp, check versions, reboot if needed, and audit for security.. llhttp Update, Fedora 38 Security, Critical Fix, Remote Code Execution, python-aiohttp Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 07, 2023 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here