Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 36 Critical Update: libXpm Loop Issue Fix (FEDORA-2023-49dbeb6b03)

libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-49dbeb6b03 2023-01-26 01:43:10.764896 --------------------------------------------------------------------------------Name : libXpm Product : Fedora 36 Version : 3.5.15 Release : 2.fc36 URL : https://www.x.org/wiki/ Summary : X.Org X11 libXpm runtime library Description : X.Org X11 libXpm runtime library --------------------------------------------------------------------------------Update Information: libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883 --------------------------------------------------------------------------------ChangeLog: * Wed Jan 18 2023 Peter Hutterer - 3.5.15-2 - Add missing BuildRequires * Wed Jan 18 2023 Peter Hutterer - 3.5.15-1 - libXpm 3.5.15, fixes CVE-2022-46285, CVE-2022-44617, CVE-2022-4883 * Wed Jan 11 2023 Peter Hutterer - 3.5.14-1 - libXpm 3.5.14 * Thu Jul 21 2022 Fedora Release Engineering - 3.5.13-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2160092 - CVE-2022-46285 libXpm: Infinite loop on unclosed comments https://bugzilla.redhat.com/show_bug.cgi?id=2160092 [ 2 ] Bug #2160193 - CVE-2022-44617 libXpm: Runaway loop on width of 0 and enormous height https://bugzilla.redhat.com/show_bug.cgi?id=2160193 [ 3 ] Bug #2160213 - CVE-2022-4883 libXpm: compression commands depend on $PATH https://bugzilla.redhat.com/show_bug.cgi?id=2160213 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-49dbeb6b03' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . libXpm 3.5.15 for Fedora 36 addresses security concerns, fixing infinite loop scenarios and vulnerabilities related to compression commands.. libXpm, critical fix, Fedora 36, loop issue, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 26, 2023 Critical Fedora
98

Red Hat Enterprise Linux 8.4 RHSA-2023:0382-01 Important: LibXpm Fixes

An update for libXpm is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libXpm security update Advisory ID: RHSA-2023:0382-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0382 Issue date: 2023-01-23 CVE Names: CVE-2022-4883 CVE-2022-44617 CVE-2022-46285 ==================================================================== 1. Summary: An update for libXpm is now available for Red Hat Enterprise Linux 8.4 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.4) - aarch64, ppc64le, s390x, x86_64 3. Description: X.Org X11 libXpm runtime library. Security Fix(es): * libXpm: compression commands depend on $PATH (CVE-2022-4883) * libXpm: Runaway loop on width of 0 and enormous height (CVE-2022-44617) * libXpm: Infinite loop on unclosed comments (CVE-2022-46285) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2160092 - CVE-2022-46285 libXpm: Infinite loop on unclosed comments 2160193 - CVE-2022-44617 libXpm:Runaway loop on width of 0 and enormous height 2160213 - CVE-2022-4883 libXpm: compression commands depend on $PATH 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.4): Source: libXpm-3.5.12-9.el8_4.src.rpm aarch64: libXpm-3.5.12-9.el8_4.aarch64.rpm libXpm-debuginfo-3.5.12-9.el8_4.aarch64.rpm libXpm-debugsource-3.5.12-9.el8_4.aarch64.rpm libXpm-devel-3.5.12-9.el8_4.aarch64.rpm libXpm-devel-debuginfo-3.5.12-9.el8_4.aarch64.rpm ppc64le: libXpm-3.5.12-9.el8_4.ppc64le.rpm libXpm-debuginfo-3.5.12-9.el8_4.ppc64le.rpm libXpm-debugsource-3.5.12-9.el8_4.ppc64le.rpm libXpm-devel-3.5.12-9.el8_4.ppc64le.rpm libXpm-devel-debuginfo-3.5.12-9.el8_4.ppc64le.rpm s390x: libXpm-3.5.12-9.el8_4.s390x.rpm libXpm-debuginfo-3.5.12-9.el8_4.s390x.rpm libXpm-debugsource-3.5.12-9.el8_4.s390x.rpm libXpm-devel-3.5.12-9.el8_4.s390x.rpm libXpm-devel-debuginfo-3.5.12-9.el8_4.s390x.rpm x86_64: libXpm-3.5.12-9.el8_4.i686.rpm libXpm-3.5.12-9.el8_4.x86_64.rpm libXpm-debuginfo-3.5.12-9.el8_4.i686.rpm libXpm-debuginfo-3.5.12-9.el8_4.x86_64.rpm libXpm-debugsource-3.5.12-9.el8_4.i686.rpm libXpm-debugsource-3.5.12-9.el8_4.x86_64.rpm libXpm-devel-3.5.12-9.el8_4.i686.rpm libXpm-devel-3.5.12-9.el8_4.x86_64.rpm libXpm-devel-debuginfo-3.5.12-9.el8_4.i686.rpm libXpm-devel-debuginfo-3.5.12-9.el8_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2022-4883 https://access.redhat.com/security/cve/CVE-2022-44617 https://access.redhat.com/security/cve/CVE-2022-46285 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY88LfdzjgjWX9erEAQjdpA/+P7c+ANR7nat0OAnp7te+/b3BhXTObkmi yEOyuzeio9s0mqQag9ViA6ZWoloW7LxCJHkbKTNFxo2XyRPR6m3Xqx0HkFJxxIuj WXa1G56p3YDkYDqmCr+O6ahdsUDSuuafe/yGHO3uhZfp68p16GhKnr5ww2HL/be0 scBtPDbBaXkP9o6olpJuR80Iq+MIq8M008cpRJzQG/oX2xiUeTZoPatTlLCJP5UQ DDHzHiL6YrVO4QDDIC8nEN/zRERwEK56Gy7ZSZtVTyV9miSN+erfTMmix9Rbwfxt OGtsuco3w7eswfc8lnCAC5weHcyP/D08tfpvDH1Y+4STdsyvTPGFbf6jr2OwuJjJ Z9ZArvMer/MPtRfZ7PSuZjGA38CenxPtf/Dh7fIzviZXudGK+rCS+DZrgFDB2Y2K WofCLx/R43wYIo6R4AvQgDLckxkdEE1rVTz46FD2IIee3BSJOAGYzoKeV6OZw4TB VuuwHLkpxt3BGNNut91cn7DFOB/5i59rbraSUQMA9gJOhMP8jB0U8Ui6uyqdqwrS PTNNPFnsPenWx9cPC4N4BrMeC0CVl//2yfhJaNiBZZ/6bS88gyohLnGsi3lU1Lao xpl+hhP9yJiPWyL/nt+OtMB9s3rnowhePBSKsCYra9dM3qehl8dfGFedlcBBBMZt AUapJAmCNiw=6x3G -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical has announced a significant security patch for libXrender, fixing numerous high-priority vulnerabilities. Discover the details today.. libXpm, security update, red hat, enterprise linux, vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 23, 2023 Important Red Hat
98

Red Hat: RHSA-2020-2419-01 Important: Unbound DNS Security Threats

An update for unbound is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: unbound security update Advisory ID: RHSA-2020:2419-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:2419 Issue date: 2020-06-08 CVE Names: CVE-2020-12662 CVE-2020-12663 ==================================================================== 1. Summary: An update for unbound is now available for Red Hat Enterprise Linux 8.1 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v. 8.1) - aarch64, ppc64le, s390x, x86_64 3. Description: The unbound packages provide a validating, recursive, and caching DNS or DNSSEC resolver. Security Fix(es): * unbound: amplification of an incoming query into a large number of queries directed to a target (CVE-2020-12662) * unbound: infinite loop via malformed DNS answers received from upstream servers (CVE-2020-12663) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1837597 - CVE-2020-12662 unbound:amplification of an incoming query into a large number of queries directed to a target 1837604 - CVE-2020-12663 unbound: infinite loop via malformed DNS answers received from upstream servers 6. Package List: Red Hat Enterprise Linux AppStream EUS (v. 8.1): Source: unbound-1.7.3-9.el8_1.src.rpm aarch64: python3-unbound-1.7.3-9.el8_1.aarch64.rpm python3-unbound-debuginfo-1.7.3-9.el8_1.aarch64.rpm unbound-1.7.3-9.el8_1.aarch64.rpm unbound-debuginfo-1.7.3-9.el8_1.aarch64.rpm unbound-debugsource-1.7.3-9.el8_1.aarch64.rpm unbound-devel-1.7.3-9.el8_1.aarch64.rpm unbound-libs-1.7.3-9.el8_1.aarch64.rpm unbound-libs-debuginfo-1.7.3-9.el8_1.aarch64.rpm ppc64le: python3-unbound-1.7.3-9.el8_1.ppc64le.rpm python3-unbound-debuginfo-1.7.3-9.el8_1.ppc64le.rpm unbound-1.7.3-9.el8_1.ppc64le.rpm unbound-debuginfo-1.7.3-9.el8_1.ppc64le.rpm unbound-debugsource-1.7.3-9.el8_1.ppc64le.rpm unbound-devel-1.7.3-9.el8_1.ppc64le.rpm unbound-libs-1.7.3-9.el8_1.ppc64le.rpm unbound-libs-debuginfo-1.7.3-9.el8_1.ppc64le.rpm s390x: python3-unbound-1.7.3-9.el8_1.s390x.rpm python3-unbound-debuginfo-1.7.3-9.el8_1.s390x.rpm unbound-1.7.3-9.el8_1.s390x.rpm unbound-debuginfo-1.7.3-9.el8_1.s390x.rpm unbound-debugsource-1.7.3-9.el8_1.s390x.rpm unbound-devel-1.7.3-9.el8_1.s390x.rpm unbound-libs-1.7.3-9.el8_1.s390x.rpm unbound-libs-debuginfo-1.7.3-9.el8_1.s390x.rpm x86_64: python3-unbound-1.7.3-9.el8_1.x86_64.rpm python3-unbound-debuginfo-1.7.3-9.el8_1.i686.rpm python3-unbound-debuginfo-1.7.3-9.el8_1.x86_64.rpm unbound-1.7.3-9.el8_1.x86_64.rpm unbound-debuginfo-1.7.3-9.el8_1.i686.rpm unbound-debuginfo-1.7.3-9.el8_1.x86_64.rpm unbound-debugsource-1.7.3-9.el8_1.i686.rpm unbound-debugsource-1.7.3-9.el8_1.x86_64.rpm unbound-devel-1.7.3-9.el8_1.i686.rpm unbound-devel-1.7.3-9.el8_1.x86_64.rpm unbound-libs-1.7.3-9.el8_1.i686.rpm unbound-libs-1.7.3-9.el8_1.x86_64.rpm unbound-libs-debuginfo-1.7.3-9.el8_1.i686.rpm unbound-libs-debuginfo-1.7.3-9.el8_1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify thesignature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-12662 https://access.redhat.com/security/cve/CVE-2020-12663 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXt4R/9zjgjWX9erEAQjHFg/+KV+8wOKlADE05U8lSffqpK2gjj7LqM7X 0XO3ABTvS1ISwrsOZrqyVRzpStJdpwAcDCuzVxWthCM7G2FGMo/6YMzYEdOK1DL3 yeLOhzih3WJcnEPzAYRjfN1NFvY52zD30T2llnO3Oym07h5JYoiS7VBe13asbIPN ypcf9lF+QDP1FheOfLmORJCSWHTT2skwpRnLFVrw5Dvi8IGyDl17dUkNX72M6/4g ImXBgKmin6cFVfQDSX0AwxFctB25tutRfSeYXaKoROTFMb4d4DqzuEuwQttoCaqg HCJ4821CI9pQcQe8ECAcrs2mjtwOqh1T/XYtyuoZXiPxksmTa1FzWBhHYtlRqdhG M+NvZ9szKqOc82ZzeOVA8edccpOTw6bG7XjjIplz/nwP2TRfKpCYyQSt/Us9f5/K gMJTX773Em6YHKqaSZPRbLUNEvSDOflpYd5tyKzjZUaAeNuZQm+e2bhxwQ3E2K5/ yU4z6ti8qBSlXSFg2FWeQQEw3rgRR/9pBcqgfOQLLkumaUq9ErFn+ZtfzxBux3UI p1gDz0vY6geUUzCX5UPUrjeKh9gHIP2S7QmuMZ2iputjYHuOKz9A+3wklketPbj6 k9UsHrz613DXJBvTqymqGtPpNt/dy/OUuzG6DnGT3eZQ5EA5kejyfQHUbArphw3z TZV7LeSzBbo=g9lH -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial alert from Red Hat highlights significant unbound security patch tackling critical vulnerabilities. Discover more about what this means for users.. unbound security update, Red Hat advisory, important security fix, DNS resolution issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 08, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here