Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
172

Ubuntu 20.04 LTS USN-5866-1 Critical: Nova Denial Of Service

Several security issues were fixed in Nova.. =========================================================================Ubuntu Security Notice USN-5866-1 February 13, 2023 nova vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: Several security issues were fixed in Nova. Software Description: - nova: OpenStack Compute cloud infrastructure Details: It was discovered that Nova did not properly manage data logged into the log file. An attacker with read access to the service's logs could exploit this issue and may obtain sensitive information. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2015-9543) It was discovered that Nova did not properly handle attaching and reattaching the encrypted volume. An attacker could possibly use this issue to perform a denial of service attack. This issue only affected Ubuntu 16.04 ESM. (CVE-2017-18191) It was discovered that Nova did not properly handle the updation of domain XML after live migration. An attacker could possibly use this issue to corrupt the volume or perform a denial of service attack. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-17376) It was discovered that Nova was not properly validating the URL passed to noVNC. An attacker could possibly use this issue by providing malicious URL to the noVNC proxy to redirect to any desired URL. This issue only affected Ubuntu 16.04 ESM and Ubuntu 18.04 LTS. (CVE-2021-3654) It was discovered that Nova did not properly handle changes in the neutron port of vnic_type type. An authenticated user could possibly use this issue to perform a denial of service attack. This issue only affected Ubuntu 20.04 LTS. (CVE-2022-37394) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: nova-common 2:21.2.4-0ubuntu2.2 python3-nova 2:21.2.4-0ubuntu2.2 Ubuntu 18.04 LTS: nova-common 2:17.0.13-0ubuntu5.3 python-nova 2:17.0.13-0ubuntu5.3 Ubuntu 16.04 ESM: nova-common 2:13.1.4-0ubuntu4.5+esm1 python-nova 2:13.1.4-0ubuntu4.5+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5866-1 CVE-2015-9543, CVE-2017-18191, CVE-2020-17376, CVE-2021-3654, CVE-2022-37394 Package Information: https://launchpad.net/ubuntu/+source/nova/2:21.2.4-0ubuntu2.2 https://launchpad.net/ubuntu/+source/nova/2:17.0.13-0ubuntu5.3 . Several vulnerabilities resolved in Ubuntu for Nova with critical patches for impacted versions.. OpenStack Nova Updates, Ubuntu Security Announcements, Critical Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 13, 2023 Critical Ubuntu
89

Fedora 36: Critical Golang Update 2022-37aef44d1e Released Today

Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-oklog Product : Fedora 36 Version : 0.3.2 Release : 12.20190701gitca7cdf5.fc36 URL : https://github.com/oklog/oklog Summary : Distributed and coordination-free log management system Description : OK Log is a distributed and coordination-free log management system for big ol' clusters. It's an on-prem solution that's designed to be a sort of building block: easy to understand, easy to operate, and easy to extend. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G - 0.3.2-12 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 36 implements vital mitigation strategies for CVE-2022 vulnerabilities in the golang-github-oklog package, urging users to upgrade for improved security and best practices compliance. Fedora Security, Golang Advisory, CVE Mitigation, Open Source Updates, Log Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2022 Critical Fedora
89

Fedora 36 Advisory: Update for golang-github-oklog CVE-2022-27191

Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08ae2dd481 2022-05-07 04:08:14.315797 --------------------------------------------------------------------------------Name : golang-github-oklog Product : Fedora 36 Version : 0.3.2 Release : 9.20190701gitca7cdf5.fc36 URL : https://github.com/oklog/oklog Summary : Distributed and coordination-free log management system Description : OK Log is a distributed and coordination-free log management system for big ol' clusters. It's an on-prem solution that's designed to be a sort of building block: easy to understand, easy to operate, and easy to extend. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 ---- Fix FTBFS Close: rhbz#2045471 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati - 0.3.2-9 - Rebuilt for CVE-2022-27191 --------------------------------------------------------------------------------References: [ 1 ] Bug #2045471 - golang-github-appc-goaci: FTBFS in Fedora rawhide/f36 https://bugzilla.redhat.com/show_bug.cgi?id=2045471 [ 2 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08ae2dd481' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . CentOS Refresh involving golang-github-oklog tackles CVE-2022-27191 and fixes FTBFS complications through essential enhancements.. Fedora Update,golang-github-oklog,CVE-2022-27191,Log System,FTBFS Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2022 Critical Fedora
89

Fedora 35: 2022-3a63897745 Critical: Golang Crash Risk Mitigation

Rebuild for CVE-2022-27191. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3a63897745 2022-04-28 05:50:06.248389 --------------------------------------------------------------------------------Name : golang-github-oklog Product : Fedora 35 Version : 0.3.2 Release : 9.20190701gitca7cdf5.fc35 URL : https://github.com/oklog/oklog Summary : Distributed and coordination-free log management system Description : OK Log is a distributed and coordination-free log management system for big ol' clusters. It's an on-prem solution that's designed to be a sort of building block: easy to understand, easy to operate, and easy to extend. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-27191 --------------------------------------------------------------------------------ChangeLog: * Sat Apr 16 2022 Fabio Alessandro Locati - 0.3.2-9 - Rebuilt for CVE-2022-27191 * Thu Jan 20 2022 Fedora Release Engineering - 0.3.2-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2074262 - CVE-2022-27191 golang-x-crypto: golang: crash in a golang.org/x/crypto/ssh server [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2074262 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3a63897745' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . An essential security update for golang-github in Fedora 35 addresses CVE-2022-27191. Users must update to protect their systems from exploitation. Fedora Updates,Golang Security,Log Management,Cybersecurity Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2022 Critical Fedora
203

Mageia 7 And 8 MGASA-2021-0342 Critical: Freeradius Password Exposure

Moved logrotate options into specific parts for each log as "global" options will persist past and clobber global options in the main logrotate config (bsc#1180525). Fixed plaintext password entries in logfiles (bsc#1184016). . MGASA-2021-0342 - Updated freeradius packages fix security vulnerabilities Publication date: 12 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0342.html Type: security Affected Mageia releases: 7, 8 Moved logrotate options into specific parts for each log as "global" options will persist past and clobber global options in the main logrotate config (bsc#1180525). Fixed plaintext password entries in logfiles (bsc#1184016). The freeradius package has been updated to version 3.0.22, fixing these issues and other bugs. See the upstream release announcements for details. References: - https://bugs.mageia.org/show_bug.cgi?id=29059 - https://github.com/FreeRADIUS/freeradius-server/releases/tag/release_3_0_21 - https://github.com/FreeRADIUS/freeradius-server/releases/tag/release_3_0_22 - - SRPMS: - 8/core/freeradius-3.0.22-1.mga8 - 7/core/freeradius-3.0.22-1.mga7 . The latest freeradius update for Mageia resolves critical vulnerabilities, notably mitigating risks associated with direct password visibility and enhancing log handling practices.. Freeradius Security Update,Mageia Security Advisory,Log Management Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 12, 2021 Critical Mageia
202

openSUSE Leap 15.2: 2021:0544-1 Moderate: Ceph Issues Resolved

An update that solves two vulnerabilities and has 12 fixes is now available. . openSUSE Security Update: Security update for ceph ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0544-1 Rating: moderate References: #1172926 #1176390 #1176489 #1176679 #1176828 #1177360 #1177857 #1178837 #1178860 #1178905 #1178932 #1179569 #1179997 #1182766 Cross-References: CVE-2020-25678 CVE-2020-27839 CVSS scores: CVE-2020-25678 (NVD) : 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N CVE-2020-27839 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves two vulnerabilities and has 12 fixes is now available. Description: This update for ceph fixes the following issues: - ceph was updated to to 15.2.9 - cephadm: fix 'inspect' and 'pull' (bsc#1182766) - CVE-2020-27839: mgr/dashboard: Use secure cookies to store JWT Token (bsc#1179997) - CVE-2020-25678: Do not add sensitive information in Ceph log files (bsc#1178905) - mgr/orchestrator: Sort 'ceph orch device ls' by host (bsc#1172926) - mgr/dashboard: enable different URL for users of browser to Grafana (bsc#1176390, bsc#1176679) - mgr/cephadm: lock multithreaded access to OSDRemovalQueue (bsc#1176489) - cephadm: command_unit: call systemctl with verbose=True (bsc#1176828) - cephadm: silence "Failed to evict container" log msg (bsc#1177360) - mgr/cephadm: upgrade: fail gracefully, if daemon redeploy fails (bsc#1177857) - rgw: cls/user: set from_index for reset stats calls (bsc#1178837) - mgr/dashboard: Disable TLS 1.0 and 1.1 (bsc#1178860) - cephadm: reference the last local image by digest (bsc#1178932, bsc#1179569) This update was imported from theSUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-544=1 Package List: - openSUSE Leap 15.2 (x86_64): ceph-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-base-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-base-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-common-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-common-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-debugsource-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-fuse-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-fuse-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-immutable-object-cache-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-immutable-object-cache-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mds-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mds-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mon-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mon-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-osd-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-osd-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-radosgw-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-radosgw-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-test-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-test-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-test-debugsource-15.2.9.83+g4275378de0-lp152.2.12.1 cephfs-shell-15.2.9.83+g4275378de0-lp152.2.12.1 libcephfs-devel-15.2.9.83+g4275378de0-lp152.2.12.1 libcephfs2-15.2.9.83+g4275378de0-lp152.2.12.1 libcephfs2-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 librados-devel-15.2.9.83+g4275378de0-lp152.2.12.1 librados-devel-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 librados2-15.2.9.83+g4275378de0-lp152.2.12.1 librados2-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 libradospp-devel-15.2.9.83+g4275378de0-lp152.2.12.1 librbd-devel-15.2.9.83+g4275378de0-lp152.2.12.1 librbd1-15.2.9.83+g4275378de0-lp152.2.12.1 librbd1-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 librgw-devel-15.2.9.83+g4275378de0-lp152.2.12.1 librgw2-15.2.9.83+g4275378de0-lp152.2.12.1 librgw2-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 python3-ceph-argparse-15.2.9.83+g4275378de0-lp152.2.12.1 python3-ceph-common-15.2.9.83+g4275378de0-lp152.2.12.1 python3-cephfs-15.2.9.83+g4275378de0-lp152.2.12.1 python3-cephfs-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rados-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rados-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rbd-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rbd-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rgw-15.2.9.83+g4275378de0-lp152.2.12.1 python3-rgw-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 rados-objclass-devel-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-fuse-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-fuse-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-mirror-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-mirror-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-nbd-15.2.9.83+g4275378de0-lp152.2.12.1 rbd-nbd-debuginfo-15.2.9.83+g4275378de0-lp152.2.12.1 - openSUSE Leap 15.2 (noarch): ceph-grafana-dashboards-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-cephadm-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-dashboard-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-diskprediction-cloud-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-diskprediction-local-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-k8sevents-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-modules-core-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-mgr-rook-15.2.9.83+g4275378de0-lp152.2.12.1 ceph-prometheus-alerts-15.2.9.83+g4275378de0-lp152.2.12.1 cephadm-15.2.9.83+g4275378de0-lp152.2.12.1 References: https://www.suse.com/security/cve/CVE-2020-25678.html https://www.suse.com/security/cve/CVE-2020-27839.html https://bugzilla.suse.com/1172926 https://bugzilla.suse.com/1176390 https://bugzilla.suse.com/1176489 https://bugzilla.suse.com/1176679 https://bugzilla.suse.com/1176828 https://bugzilla.suse.com/1177360 https://bugzilla.suse.com/1177857 https://bugzilla.suse.com/1178837 https://bugzilla.suse.com/1178860 https://bugzilla.suse.com/1178905 https://bugzilla.suse.com/1178932 https://bugzilla.suse.com/1179569 https://bugzilla.suse.com/1179997 https://bugzilla.suse.com/1182766 . The recent openSUSE update significantly boosts Ceph functionalities with enhanced cookie security and improved log management for better user trust and efficiency. openSUSE Security Update, Ceph Fixes, System Update. . LinuxSecurity.com Team

Calendar 2 Apr 12, 2021 OpenSUSE
202

openSUSE Leap 15.2: 2021:0428-1 Low: Freeradius-Server Security Fix

An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for freeradius-server ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0428-1 Rating: low References: #1180525 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for freeradius-server fixes the following issues: - move logrotate options into specific parts for each log as "global" options will persist past and clobber global options in the main logrotate config (bsc#1180525) This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-428=1 Package List: - openSUSE Leap 15.2 (x86_64): freeradius-server-3.0.21-lp152.2.6.1 freeradius-server-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-debugsource-3.0.21-lp152.2.6.1 freeradius-server-devel-3.0.21-lp152.2.6.1 freeradius-server-doc-3.0.21-lp152.2.6.1 freeradius-server-krb5-3.0.21-lp152.2.6.1 freeradius-server-krb5-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-ldap-3.0.21-lp152.2.6.1 freeradius-server-ldap-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-libs-3.0.21-lp152.2.6.1 freeradius-server-libs-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-mysql-3.0.21-lp152.2.6.1 freeradius-server-mysql-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-perl-3.0.21-lp152.2.6.1 freeradius-server-perl-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-postgresql-3.0.21-lp152.2.6.1 freeradius-server-postgresql-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-python3-3.0.21-lp152.2.6.1 freeradius-server-python3-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-sqlite-3.0.21-lp152.2.6.1 freeradius-server-sqlite-debuginfo-3.0.21-lp152.2.6.1 freeradius-server-utils-3.0.21-lp152.2.6.1 freeradius-server-utils-debuginfo-3.0.21-lp152.2.6.1 References: https://bugzilla.suse.com/1180525 . OpenSUSE Security Patch for freeradius-server addresses critical logging vulnerabilities and improves protective protocols.. openSUSE Updates, Freeradius Server, Security Fixes, Linux Security. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Mar 16, 2021 Low OpenSUSE
89

Fedora Core 4: 2005-748 Moderate: Audit System Update with Fixes

This update fixes several problems where the audit system is used on systems with SE Linux disabled, it provides a sample CAPP configuration, adds new auditd config option to keep all logs instead of rotating them, and does some sanity checks on some rules before sending them to the kernel.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-748 2005-08-11 ---------------------------------------------------------------------Product : Fedora Core 4 Name : audit Version : 1.0.2 Release : 3.FC4 Summary : User space tools for 2.6 kernel auditing. Description : The audit package contains the user space utilities for storing and processing the audit records generate by the audit subsystem in the Linux 2.6 kernel. ---------------------------------------------------------------------Update Information: This update fixes several problems where the audit system is used on systems with SE Linux disabled, it provides a sample CAPP configuration, adds new auditd config option to keep all logs instead of rotating them, and does some sanity checks on some rules before sending them to the kernel. ---------------------------------------------------------------------* Wed Aug 10 2005 Steve Grubb 1.0.2-3.FC4 - Set audit_pid to 0 in kernel on auditd shutdown * Mon Aug 8 2005 Steve Grubb 1.0.2-1.FC4 - Make sure error packets get eaten. - Fix a few error messages in auditctl - Fix handling of unsupported watches when reading rules from file in auditctl * Wed Aug 3 2005 Steve Grubb 1.0.1-1.FC4 - Add check for fields that cannot be used with syscall entry in auditctl - Make auditctl not tolerate duplicate rule and watches - Remove uid check in ausearch * Tue Aug 2 2005 Steve Grubb 1.0-1.FC4 - Update sample CAPP config - Remove warning for trimming file path in auditctl - Make auditctl tolerate duplicate rule and watches - auditd has new option so it doesn'toverwrite log files - Fixed bug in autrace that was reporting bad descriptor * Fri Jul 29 2005 Steve Grubb 0.9.20-1.FC4 - Fix ausearch to handle missing audit log better - Fix auditctl blank line handling - Trim trailing '/' from file system watches in auditctl - Catch cases where parameter was passed without option being given to auditctl - Add CAPP sample configuration ---------------------------------------------------------------------This update can be downloaded from: c9bba4ca1f3dac09663d2181cda6e040 SRPMS/audit-1.0.2-3.FC4.src.rpm f1b6e1c8169508f3858e545e07562d67 ppc/audit-1.0.2-3.FC4.ppc.rpm be4990c76ed12d8a49761f588d775577 ppc/audit-libs-1.0.2-3.FC4.ppc.rpm d30397cc5147adfd00da87295afca9c0 ppc/audit-libs-devel-1.0.2-3.FC4.ppc.rpm cf630242cb25801c91ce38affe919958 ppc/debug/audit-debuginfo-1.0.2-3.FC4.ppc.rpm 75c4d69246b19f48a3e44a61fdbd121d ppc/audit-libs-1.0.2-3.FC4.ppc64.rpm f20217790f81e1b211d80dcc682396e3 x86_64/audit-1.0.2-3.FC4.x86_64.rpm bff3c1cfe7613f5611be996aad447e13 x86_64/audit-libs-1.0.2-3.FC4.x86_64.rpm 68eb5d3a89aac95b943ff165d6ce27dc x86_64/audit-libs-devel-1.0.2-3.FC4.x86_64.rpm 2d5bbb4e52b12f5c840e56b3df877e23 x86_64/debug/audit-debuginfo-1.0.2-3.FC4.x86_64.rpm 86688cc5b18ff61af7dc413a98c0ae11 x86_64/audit-libs-1.0.2-3.FC4.i386.rpm 117f055c03b4a3733ec60f9dc11d6195 i386/audit-1.0.2-3.FC4.i386.rpm 86688cc5b18ff61af7dc413a98c0ae11 i386/audit-libs-1.0.2-3.FC4.i386.rpm bc181772c4d323308fe6e1c75a57f960 i386/audit-libs-devel-1.0.2-3.FC4.i386.rpm cb4d094c5509ab086cba740c33747589 i386/debug/audit-debuginfo-1.0.2-3.FC4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolves auditing challenges within SE Linux, improves log oversight, and introduces new configuration settings.. Audit Update,Fedora Security,SystemAudit Tools,Log Retention,Configurations. . LinuxSecurity.com Team

Calendar 2 Aug 15, 2005 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here