Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 8: 2022-0367 Moderate: Python Mailcap And Urlparse Security Threats

The mailcap module does not add escape characters into commands discovered in the system mailcap file. (CVE-2015-20107) Allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. (CVE-2021-4189) . MGASA-2022-0367 - Updated python packages fix security vulnerability Publication date: 13 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0367.html Type: security Affected Mageia releases: 8 CVE: CVE-2015-20107, CVE-2021-4189, CVE-2022-0391 The mailcap module does not add escape characters into commands discovered in the system mailcap file. (CVE-2015-20107) Allows an attacker to set up a malicious FTP server that can trick FTP clients into connecting back to a given IP address and port. (CVE-2021-4189) The urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection attacks. (CVE-2022-0391) References: - https://bugs.mageia.org/show_bug.cgi?id=30572 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/UIOJUZ5JMEMGSKNISTOVI4PDP36FDL5Y/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/Y4E2WBEJ42CGLGDHD6ZXOLZ2W6G3YOVD/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/W5664BGZVTA46LQDNTYX5THG6CN4FYJX/ - https://ubuntu.com/security/notices/USN-5519-1 - https://lists.suse.com/pipermail/sle-security-updates/2022-October/012483.html - - https://www.cve.org/CVERecord?id=CVE-2015-20107 - https://www.cve.org/CVERecord?id=CVE-2021-4189 - https://www.cve.org/CVERecord?id=CVE-2022-0391 SRPMS: - 8/core/python-2.7.18-7.5.mga8 . Recent updates to Python libraries in Mageia address several vulnerabilities concerning mailcap and urlparse components.. Mageia Python Update, Mailcap Threat, URL Injection, FTP Security Fix. . LinuxSecurity.com Team

Calendar 2 Oct 13, 2022 Mageia
89

Fedora 36: FEDORA-2022-dbe9a8f9ac Moderate: PyPy 3.9 Mailcap Mitigation

Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-dbe9a8f9ac 2022-07-08 01:15:45.190364 --------------------------------------------------------------------------------Name : pypy3.9 Product : Fedora 36 Version : 7.3.9 Release : 2.3.9.fc36 URL : https://pypy.org/ Summary : Python 3.9 implementation with a Just-In-Time compiler Description : PyPy's implementation of Python 3.9, featuring a Just-In-Time compiler on some CPU architectures, and various optimized implementations of the standard types (strings, dictionaries, etc.). This build of PyPy has JIT-compilation enabled. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Tue Jun 28 2022 Charalampos Stratakis - 7.3.9-2.3.9 - Security fix for CVE-2015-20107 - Fixes: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076532 - CVE-2015-20107 pypy3.9: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076532 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-dbe9a8f9ac' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . An enhancement for Fedora 36 resolves a vulnerability in PyPy 3.9, bolstering system security.. Fedora Python Security Update, PyPy 3.9 Security Fix, Mailcap Issue. . LinuxSecurity.com Team

Calendar 2 Jul 07, 2022 Fedora
89

Fedora 35: FEDORA-2022-ec74ac4079 Critical: Python2 Mailcap Flaw

Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-ec74ac4079 2022-06-26 01:18:35.111743 --------------------------------------------------------------------------------Name : python2.7 Product : Fedora 35 Version : 2.7.18 Release : 22.fc35 URL : https://www.python.org/ Summary : Version 2.7 of the Python interpreter Description : Python 2 is an old version of the language that is incompatible with the 3.x line of releases. The language is mostly the same, but many details, especially how built-in objects like dictionaries and strings work, have changed considerably, and a lot of deprecated features have finally been removed in the 3.x line. Note that Python 2 is not supported upstream after 2020-01-01, please use the python3 package instead if you can. This package also provides the "python2" executable. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 9 2022 Charalampos Stratakis - 2.7.18-22 - Security fix for CVE-2015-20107 Resolves: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076509 - CVE-2015-20107 python2.7: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076509 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-ec74ac4079' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important patch for Python 2.7 on Fedora 35 resolves issue linked to CVE-2015-20107 involving vulnerabilities within the mailcap functionality.. Fedora Security, Python 2.7 Advisory, CVE-2015-20107 Fix, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 25, 2022 Critical Fedora
89

Fedora 36 FEDORA-2022-4b0dfda810 moderate: Python mailcap Threat

Security fix for CVE-2015-20107. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-4b0dfda810 2022-06-19 00:37:42.144179 --------------------------------------------------------------------------------Name : python3.6 Product : Fedora 36 Version : 3.6.15 Release : 9.fc36 URL : https://www.python.org/ Summary : Version 3.6 of the Python interpreter Description : Python 3.6 package for developers. This package exists to allow developers to test their code against an older version of Python. This is not a full Python stack and if you wish to run your applications with Python 3.6, see other distributions that support it, such as CentOS or RHEL with Software Collections or older Fedora releases. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2015-20107 --------------------------------------------------------------------------------ChangeLog: * Fri Jun 10 2022 Charalampos Stratakis - 3.6.15-9 - Security fix for CVE-2015-20107 Resolves: rhbz#2075390 --------------------------------------------------------------------------------References: [ 1 ] Bug #2076513 - CVE-2015-20107 python3.6: python(mailcap): findmatch() function does not sanitise the second argument [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2076513 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-4b0dfda810' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Update for Fedora 36 python3.6 to mitigate CVE-2015-20107 vulnerability. Act promptly to secure your systems!. Fedora Python Security, Software Updates, Python Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 18, 2022 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here