Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 438
Alerts This Week
Warning Icon 1 438

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
217

Oracle Linux 7 ImageMagick Moderate CVE-2026-32636 Local File Disclosure

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-17618 http://linux.oracle.com/errata/ELSA-2026-17618.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.11.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.11.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.11.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.11.el7_9.src.rpm Related CVEs: CVE-2026-32636 Description of changes: [6.9.10.68-7.0.11] - Fix CVE-2026-32636 [Orabug: 39375225] [6.9.10.68-7.0.9] - Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244] [6.9.10.68-7.0.7] - Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995] - Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985) [6.9.10.68-7.0.5] - Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140] [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 7 ImageMagick update addresses several security issues. Critical flaws fixed to enhance system stability and safety.. Oracle Linux ImageMagick Update Moderate Local File Disclosure. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2026 Important Oracle
217

Oracle Linux 7 ImageMagick Important CVE-2026-28691 ELSA-2026-6713

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-6713 http://linux.oracle.com/errata/ELSA-2026-6713.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: ImageMagick-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.0.9.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.0.9.el7_9.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/ImageMagick-6.9.10.68-7.0.9.el7_9.src.rpm Related CVEs: CVE-2026-28691 CVE-2026-28693 Description of changes: [6.9.10.68-7.0.9] - Fix CVE-2026-28691 and CVE-2026-28693 [Orabug: 39174244] [6.9.10.68-7.0.7] - Fixes Local File Disclosure via Path Traversal (CVE-2026-25965) [Orabug: 39118995] - Fixes Memory allocation with excessive without limits in the internal SVG decoder (CVE-2026-25985) [6.9.10.68-7.0.5] - Fix CVE-2025-62171 and CVE-2026-23876 [Orabug: 38997140] [6.9.10.68-7.0.3] - Security update CVE-2025-57803 [Orabug: 38455460] [6.9.10.68-7.0.1] - Fix for CVE-2025-55154 [Orabug: 38417011] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 7 updates for ImageMagick address important security issues. Check the advisory for details on patched vulnerabilities.. Oracle Linux 7, ImageMagick, security updates, CVE fixes, advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 22, 2026 Important Oracle
202

openSUSE: 2019:1619-1 Moderate GraphicsMagick Local File Disclosure

An update that contains security fixes can now be installed.. openSUSE Security Update: Security update for GraphicsMagick ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1619-1 Rating: moderate References: #1138425 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for GraphicsMagick fixes the following issues: - disable indirect reads that disclosed file contents from the local system (boo#1138425) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2019-1619=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1619=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1619=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): GraphicsMagick-1.3.25-144.1 GraphicsMagick-debuginfo-1.3.25-144.1 GraphicsMagick-debugsource-1.3.25-144.1 GraphicsMagick-devel-1.3.25-144.1 libGraphicsMagick++-Q16-12-1.3.25-144.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.25-144.1 libGraphicsMagick++-devel-1.3.25-144.1 libGraphicsMagick-Q16-3-1.3.25-144.1 libGraphicsMagick-Q16-3-debuginfo-1.3.25-144.1 libGraphicsMagick3-config-1.3.25-144.1 libGraphicsMagickWand-Q16-2-1.3.25-144.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.25-144.1 perl-GraphicsMagick-1.3.25-144.1 perl-GraphicsMagick-debuginfo-1.3.25-144.1 - openSUSE Leap 15.1 (x86_64): GraphicsMagick-1.3.29-lp151.4.6.1 GraphicsMagick-debuginfo-1.3.29-lp151.4.6.1 GraphicsMagick-debugsource-1.3.29-lp151.4.6.1 GraphicsMagick-devel-1.3.29-lp151.4.6.1 libGraphicsMagick++-Q16-12-1.3.29-lp151.4.6.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp151.4.6.1 libGraphicsMagick++-devel-1.3.29-lp151.4.6.1 libGraphicsMagick-Q16-3-1.3.29-lp151.4.6.1 libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp151.4.6.1 libGraphicsMagick3-config-1.3.29-lp151.4.6.1 libGraphicsMagickWand-Q16-2-1.3.29-lp151.4.6.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp151.4.6.1 perl-GraphicsMagick-1.3.29-lp151.4.6.1 perl-GraphicsMagick-debuginfo-1.3.29-lp151.4.6.1 - openSUSE Leap 15.0 (x86_64): GraphicsMagick-1.3.29-lp150.3.34.1 GraphicsMagick-debuginfo-1.3.29-lp150.3.34.1 GraphicsMagick-debugsource-1.3.29-lp150.3.34.1 GraphicsMagick-devel-1.3.29-lp150.3.34.1 libGraphicsMagick++-Q16-12-1.3.29-lp150.3.34.1 libGraphicsMagick++-Q16-12-debuginfo-1.3.29-lp150.3.34.1 libGraphicsMagick++-devel-1.3.29-lp150.3.34.1 libGraphicsMagick-Q16-3-1.3.29-lp150.3.34.1 libGraphicsMagick-Q16-3-debuginfo-1.3.29-lp150.3.34.1 libGraphicsMagick3-config-1.3.29-lp150.3.34.1 libGraphicsMagickWand-Q16-2-1.3.29-lp150.3.34.1 libGraphicsMagickWand-Q16-2-debuginfo-1.3.29-lp150.3.34.1 perl-GraphicsMagick-1.3.29-lp150.3.34.1 perl-GraphicsMagick-debuginfo-1.3.29-lp150.3.34.1 References: https://bugzilla.suse.com/1138425 -- . GraphicsMagick security patch deployed for openSUSE users tackling local file exposure vulnerabilities.. openSUSE security update, GraphicsMagick patch, local file exposure fix. . LinuxSecurity.com Team

Calendar%202 Jun 24, 2019 OpenSUSE
197

Debian 8: DLA-1591-1 Moderate: Local File Disclosure in libphp-phpmailer

It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path . Package : libphp-phpmailer Version : 5.2.9+dfsg-2+deb8u4 CVE IDs : CVE-2017-5223 CVE-2018-19296 It was discovered that there were two vulnerabilities libphp-phpmailer, an email library for the PHP programming language: * CVE-2017-5223: Local file disclosure vulnerability via relative path HTML transformations. * CVE-2018-19296: Object injection attack. For Debian 8 "Jessie", this issue has been fixed in libphp-phpmailer version 5.2.9+dfsg-2+deb8u4. We recommend that you upgrade your libphp-phpmailer packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Critical security flaws in libphp-phpmailer addressed for Debian 8. Immediate upgrade advised.. libphp-phpmailer vulnerabilities, Local File Disclosure, Email Library Security. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2018 Debian LTS
200

Scientific Linux 3.x/4.x: SeaMonkey Critical Security Flaw CVE-2008-2798

Critical: seamonkey security update. Date: Fri, 4 Jul 2008 10:06:15 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for seamonkey on SL3.x, SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: seamonkey security update Issue date: 2008-07-02 CVE Names: CVE-2008-2798 CVE-2008-2799 CVE-2008-2800 CVE-2008-2801 CVE-2008-2802 CVE-2008-2803 CVE-2008-2805 CVE-2008-2807 CVE-2008-2808 CVE-2008-2809 CVE-2008-2810 CVE-2008-2811 Multiple flaws were found in the processing of malformed JavaScript content. A web page containing such malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code as the user running SeaMonkey. (CVE-2008-2801, CVE-2008-2802, CVE-2008-2803) Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause SeaMonkey to crash or, potentially, execute arbitrary code as the user running SeaMonkey. (CVE-2008-2798, CVE-2008-2799, CVE-2008-2811) Several flaws were found in the way malformed web content was displayed. A web page containing specially-crafted content could potentially trick a SeaMonkey user into surrendering sensitive information. (CVE-2008-2800) Two local file disclosure flaws were found in SeaMonkey. A web page containing malicious content could cause SeaMonkey to reveal the contents of a local file to a remote attacker. (CVE-2008-2805, CVE-2008-2810) A flaw was found in the way a malformed.properties file was processed by SeaMonkey. A malicious extension could read uninitialized memory, possibly leaking sensitive data to the extension. (CVE-2008-2807) A flaw was found in the way SeaMonkey escaped a listing of local file names. If a user could be tricked into listing a local directory containing malicious file names, arbitrary JavaScript could be run with the permissions of the user running SeaMonkey. (CVE-2008-2808) A flaw was found in the way SeaMonkey displayed informationabout self-signed certificates. It was possible for a self-signed certificate to contain multiple alternate name entries, which were not all displayed to the user, allowing them to mistakenly extend trust to an unknown site. (CVE-2008-2809) SL 3.0.x SRPMS: seamonkey-1.0.9-0.20.el3.src.rpm i386: seamonkey-1.0.9-0.20.el3.i386.rpm seamonkey-chat-1.0.9-0.20.el3.i386.rpm seamonkey-devel-1.0.9-0.20.el3.i386.rpm seamonkey-dom-inspector-1.0.9-0.20.el3.i386.rpm seamonkey-js-debugger-1.0.9-0.20.el3.i386.rpm seamonkey-mail-1.0.9-0.20.el3.i386.rpm seamonkey-nspr-1.0.9-0.20.el3.i386.rpm seamonkey-nspr-devel-1.0.9-0.20.el3.i386.rpm seamonkey-nss-1.0.9-0.20.el3.i386.rpm seamonkey-nss-devel-1.0.9-0.20.el3.i386.rpm x86_64: seamonkey-1.0.9-0.20.el3.i386.rpm seamonkey-1.0.9-0.20.el3.x86_64.rpm seamonkey-chat-1.0.9-0.20.el3.i386.rpm seamonkey-chat-1.0.9-0.20.el3.x86_64.rpm seamonkey-devel-1.0.9-0.20.el3.x86_64.rpm seamonkey-dom-inspector-1.0.9-0.20.el3.i386.rpm seamonkey-dom-inspector-1.0.9-0.20.el3.x86_64.rpm seamonkey-js-debugger-1.0.9-0.20.el3.i386.rpm seamonkey-js-debugger-1.0.9-0.20.el3.x86_64.rpm seamonkey-mail-1.0.9-0.20.el3.i386.rpm seamonkey-mail-1.0.9-0.20.el3.x86_64.rpm seamonkey-nspr-1.0.9-0.20.el3.i386.rpm seamonkey-nspr-1.0.9-0.20.el3.x86_64.rpm seamonkey-nspr-devel-1.0.9-0.20.el3.x86_64.rpm seamonkey-nss-1.0.9-0.20.el3.i386.rpm seamonkey-nss-1.0.9-0.20.el3.x86_64.rpm seamonkey-nss-devel-1.0.9-0.20.el3.x86_64.rpm SL 4.x SRPMS: seamonkey-1.0.9-16.3.el4_6.src.rpm i386: seamonkey-1.0.9-16.3.el4_6.i386.rpm seamonkey-chat-1.0.9-16.3.el4_6.i386.rpm seamonkey-devel-1.0.9-16.3.el4_6.i386.rpm seamonkey-dom-inspector-1.0.9-16.3.el4_6.i386.rpm seamonkey-js-debugger-1.0.9-16.3.el4_6.i386.rpm seamonkey-mail-1.0.9-16.3.el4_6.i386.rpm seamonkey-nspr-1.0.9-16.3.el4_6.i386.rpm seamonkey-nspr-devel-1.0.9-16.3.el4_6.i386.rpm seamonkey-nss-1.0.9-16.3.el4_6.i386.rpm seamonkey-nss-devel-1.0.9-16.3.el4_6.i386.rpm x86_64: seamonkey-1.0.9-16.3.el4_6.i386.rpm seamonkey-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-chat-1.0.9-16.3.el4_6.i386.rpm seamonkey-chat-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-devel-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-dom-inspector-1.0.9-16.3.el4_6.i386.rpm seamonkey-dom-inspector-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-js-debugger-1.0.9-16.3.el4_6.i386.rpm seamonkey-js-debugger-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-mail-1.0.9-16.3.el4_6.i386.rpm seamonkey-mail-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-nspr-1.0.9-16.3.el4_6.i386.rpm seamonkey-nspr-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-nspr-devel-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-nss-1.0.9-16.3.el4_6.i386.rpm seamonkey-nss-1.0.9-16.3.el4_6.x86_64.rpm seamonkey-nss-devel-1.0.9-16.3.el4_6.x86_64.rpm -Connie Sieh -Troy Dawson . Urgent patch deployed for SeaMonkey resolves numerous vulnerabilities affecting Scientific Linux versions SL3.x and SL4.x.. seamonkey security, scientific linux, critical flaws, update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 04, 2008 Critical Scientific Linux
200

Scientific Linux: CVE-2006-2842 Moderate Severity for Squirrelmail LFD

An updated squirrelmail package that fixes a local file . Date: Wed, 5 Jul 2006 12:12:57 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "squirrelmail" on SL 40,41,42,43 i386,x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. The ERRATA for SL 40,41,42,43 i386 x86_64 are now available from: Synopsis: An updated squirrelmail package that fixes a local file disclosure flaw, is now available Severity: moderate Issued on: 2006-07-03 CVEs: CVE-2006-2842 SRPMS squirrelmail-1.4.6-7.el4.src.rpm i386 squirrelmail-1.4.6-7.el4.noarch.rpm x86_64 squirrelmail-1.4.6-7.el4.noarch.rpm --Troy Dawson --Connie Sieh . A new squirrelmail update has been released for Scientific Linux addressing a local file exposure vulnerability.. squirrelmail update, Scientific Linux security, file disclosure, software patch, security advisory. . LinuxSecurity.com Team

Calendar%202 Jul 05, 2006 Scientific Linux
200

Scientific Linux: Updated Squirrelmail Fixes Local File Disclosure

An updated squirrelmail package that fixes a local file . Date: Wed, 5 Jul 2006 12:06:22 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: ERRATA for "squirrelmail" on SL 301,302,303,304,305,307 i386,x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. The following ERRATA for SL 301,302,303,304,305,307 i386,x86_64 are now available from: Synopsis: An updated squirrelmail package that fixes a local file disclosure flaw, is now available Severity: moderate Issued on: 2006-07-03 CVEs: CVE-2006-2842 SRPMS squirrelmail-1.4.6-7.el3.src.rpm i386 squirrelmail-1.4.6-7.el3.noarch.rpm x86_64 squirrelmail-1.4.6-7.el3.noarch.rpm --Troy Dawson --Connie Sieh . An upgraded squirrelmail package addresses a local file exposure vulnerability in Scientific Linux versions 301 through 307.. Squirrelmail Update, Scientific Linux Advisory, Security Update for Squirrelmail. . LinuxSecurity.com Team

Calendar%202 Jul 05, 2006 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200