Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 40: FEDORA-2024-14c006b8bb critical: sympa denial of service

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40 users should promptly update sympa software for crucial security updates pertaining to CVE-2024-55919. Use the command: dnf update sympa to secure your system. Fedora Updates, sympa Security, Mailing List Management, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 25, 2024 Critical Fedora
197

Debian 9: DLA-2401-1 Critical: Sympa Privilege Escalation Fix

Sympa, a modern mailing list manager, allows privilege escalation through setuid wrappers. A local attacker can obtain root access. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2401-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ October 07, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sympa Version : 6.2.16~dfsg-3+deb9u3 CVE ID : CVE-2020-10936 Debian Bug : 961491 Sympa, a modern mailing list manager, allows privilege escalation through setuid wrappers. A local attacker can obtain root access. For Debian 9 stretch, this problem has been fixed in version 6.2.16~dfsg-3+deb9u3. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sympa Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update Sympa on Debian 9 stretch to address security vulnerability regarding privilege escalation. Refer to critical advisory DLA-2401-1 for comprehensive information.. Debian Sympa Security Update, Privilege Escalation Fix, Debian LTS Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 07, 2020 Critical Debian LTS
89

Fedora 31: FEDORA-2020-62f2df3ca4 Critical: Mailman Security Fix

notes=Security fix for CVE-2020-12108. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-62f2df3ca4 2020-07-22 01:19:44.413051 --------------------------------------------------------------------------------Name : mailman Product : Fedora 31 Version : 2.1.34 Release : 1.fc31 URL : https://www.list.org/ Summary : Mailing list manager with built in Web access Description : Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. Documentation can be found in: /usr/share/doc/mailman When the package has finished installing, you will need to perform some additional installation steps, these are described in: /usr/share/doc/mailman/INSTALL.REDHAT --------------------------------------------------------------------------------Update Information: notes=Security fix for CVE-2020-12108 --------------------------------------------------------------------------------ChangeLog: * Fri Jul 3 2020 Pavel Zhukov - 3:2.1.34-1 - new version v2.1.34 * Mon May 11 2020 Pavel Zhukov - 3:2.1.33-1 - new version v2.1.33 * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-2 - Change mode of /etc/mailman to 2755 (#1656765) * Wed May 6 2020 Pavel Zhukov - 3:2.1.32-1 - New version v2.1.32 --------------------------------------------------------------------------------References: [ 1 ] Bug #1848856 - CVE-2020-12108 mailman: /options/mailman allows Arbitrary Content Injection https://bugzilla.redhat.com/show_bug.cgi?id=1848856 --------------------------------------------------------------------------------This updatecan be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-62f2df3ca4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Mitigating CVE-2020-12108 through an update in RPM Mailman system to bolster email list administration security protocols.. Fedora Mailman Security, Update Notification, Mailing List Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 21, 2020 Critical Fedora
89

Fedora 31: FEDORA-2020-79516cb689 Critical DoS Fix for Sympa

Update to sympa 6.2.54 : - Fixes CVE-2020-9369 - See https://www.sympa.community/security/2020-001.html for details. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-79516cb689 2020-03-12 21:55:08.821728 --------------------------------------------------------------------------------Name : sympa Product : Fedora 31 Version : 6.2.54 Release : 1.fc31 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.54 : - Fixes CVE-2020-9369 - See https://www.sympa.community/security/2020-001.html for details --------------------------------------------------------------------------------ChangeLog: * Mon Mar 2 2020 Xavier Bachelot 6.2.54-1 - Update to 6.2.54. * Fri Jan 31 2020 Fedora Release Engineering - 6.2.52-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Sun Jan 19 2020 Xavier Bachelot 6.2.52-2 - Add upstream patches to fix 2 scenario failures. * Fri Dec 27 2019 Xavier Bachelot 6.2.52-1 - Update to 6.2.52. * Sun Dec 22 2019 Xavier Bachelot 6.2.50-1 - Update to 6.2.50. - Re-enable Crypt::OpenSSL::X509 for EL8. * Fri Nov 29 2019 Xavier Bachelot 6.2.48-3 - Add patch to fix compile executables test on F32. - Add dependency on Socket6 and IO::Socket::IP (or alternatively Socket6 and IO::Socket::INET6 on EL6). - Add patch to fixldap 2 level query. - Re-enable Crypt::SMIME for EL8. - Re-enable all web subpackages for EL8. * Wed Oct 16 2019 Xavier Bachelot 6.2.48-2 - Don't require optional perl modules unavailable on EL8. - Disable httpd and lighttpd support for EL8 until missing bits are available. - Change sympa localstatedir owner/group to sympa:sympa. Fixes RHBZ#1761455. * Mon Sep 30 2019 Xavier Bachelot 6.2.48-1 - Update to 6.2.48. * Mon Sep 23 2019 Xavier Bachelot 6.2.46-1 - Update to 6.2.46. - Unbundle foundation-icons font. - Add dependency on LWP::Protocol::https (RHBZ#1753111). - Don't unbundle js-respond on EL8 (yet). --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-79516cb689' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Upgrade to sympa version 6.2.54 addresses the serious vulnerability CVE-2020-9369 in Fedora 31, ensuring secure management of mailing lists.. Sympa Update Fedora Security Critical Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 12, 2020 Critical Fedora
89

Fedora 23: 2016-4780 High: WordPress Plugin SQL Injection

Update to version 2.1.20.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5333 2015-04-02 00:27:50 -------------------------------------------------------------------------------- Name : mailman Product : Fedora 22 Version : 2.1.20 Release : 1.fc22 URL : https://www.list.org/ Summary : Mailing list manager with built in Web access Description : Mailman is software to help manage email discussion lists, much like Majordomo and Smartmail. Unlike most similar products, Mailman gives each mailing list a webpage, and allows users to subscribe, unsubscribe, etc. over the Web. Even the list manager can administer his or her list entirely from the Web. Mailman also integrates most things people want to do with mailing lists, including archiving, mail news gateways, and so on. Documentation can be found in: /usr/share/doc/mailman When the package has finished installing, you will need to perform some additional installation steps, these are described in: /usr/share/doc/mailman/INSTALL.REDHAT -------------------------------------------------------------------------------- Update Information: Update to version 2.1.20. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1208059 - CVE-2015-2775 mailman: directory traversal in MTA transports that deliver programmatically https://bugzilla.redhat.com/show_bug.cgi?id=1208059 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mailman' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 22’s Mailman has been patched to resolve a critical directory traversal vulnerability. Safeguard your mailing list functionalities!. Fedora Security Update, Mailman Update, Directory Traversal Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 21, 2015 Important Fedora
87

Debian: DSA-2477-1 Moderate: Remote Access Risk Found in Sympa

Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2477-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer May 20, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sympa Vulnerability : authorization bypass Problem type : remote Debian-specific: no CVE ID : CVE-2012-2352 Debian Bug : Several vulnerabilities have been discovered in Sympa, a mailing list manager, that allow to skip the scenario-based authorization mechanisms. This vulnerability allows to display the archives management page, and download and delete the list archives by unauthorized users. For the stable distribution (squeeze), this problem has been fixed in version 6.0.1+dfsg-4+squeeze1. For the testing distribution (wheezy), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 6.1.11~dfsg-2. We recommend that you upgrade your sympa packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical patch addresses vulnerabilities in Sympa, permitting unauthorized entry to stored archives. It is advised to perform an upgrade.. Sympa Security Update, Debian Advisory, Remote Access Risk, Authorization Bypass, Mailing List Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 20, 2012 Important Debian
87

Debian 2.2 DSA-123-1 Urgent: Enumerate Network Exploit Buffer Overflow

Janusz Niewiadomski and Wojciech Purczynski reported a buffer overflowin the address_match of listar (a listserv style mailing-list manager).. ------------------------------------------------------------------------ Debian Security Advisory DSA-123-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Wichert Akkerman March 19, 2002 ------------------------------------------------------------------------ Package : listar Problem type : remote exploit Debian-specific: no Janusz Niewiadomski and Wojciech Purczynski reported a buffer overflow in the address_match of listar (a listserv style mailing-list manager). This has been fixed in version 0.129a-2.potato1. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: a6e40875491815afc37d351b880da632 MD5 checksum: c878e05868e010738c7af76126bf6f57 MD5 checksum: 0302a199d9e5ee180c9e6e55ee7a0780 Alpha architecture: MD5 checksum: 513df9fe1518dccf2017fe153956ced6 MD5 checksum: fe8c81f9b9cda57b07aa48a6b946cbb5 ARM architecture: MD5 checksum: 7c24002166961b3e038b48088665841d MD5 checksum: c6a88928d9ef5ec6297dda0f1db6eaf8 Intel IA-32 architecture: MD5 checksum: 51d454473b8f1ff57dc5ed5f38395dea MD5 checksum: 5d0f77b0846f256fc12e69146fb9b8b6 Motorola 680x0 architecture: MD5 checksum: 593bfe2d9e25d2cb7154dcd11f5a36db MD5 checksum: abf4288fc12d7d925cbb106aba436da2 PowerPC architecture: MD5 checksum: 6410a8e2aa507cfe4e55ee4324b06ec3 MD5 checksum: e28fd90f9ba8fd2bf1aa6605fea622cb Sun Sparc architecture: MD5 checksum: 3a14fd7b53a0e8b25dff34ec55c4d52c MD5 checksum:2a45b969ef367fcbaf8bd2851df711f7 These packages will be moved into the stable distribution on its next revision. -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical buffer overflow vulnerability in the listar package could allow attackers to run arbitrary code on your system, prompting an upgrade to listar 2.4.5-1 for security.. Debian Listar Exploit Alert, Buffer Overflow Issue, Critical Advisories. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 19, 2002 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here