Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

RHEL 6.5: RHSA-2018-2096 Important: Patch Malicious Command Issue

An update for patch is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: patch security update Advisory ID: RHSA-2018:2096-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:2096 Issue date: 2018-06-27 CVE Names: CVE-2018-1000156 ==================================================================== 1. Summary: An update for patch is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 6.5) - x86_64 3. Description: The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Security Fix(es): * patch: Malicious patch files cause ed to execute arbitrary commands (CVE-2018-1000156) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1564326 -CVE-2018-1000156 patch: Malicious patch files cause ed to execute arbitrary commands 6. Package List: Red Hat Enterprise Linux Server AUS (v. 6.5): Source: patch-2.6-8.el6_5.src.rpm x86_64: patch-2.6-8.el6_5.x86_64.rpm patch-debuginfo-2.6-8.el6_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-1000156 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBWzPe89zjgjWX9erEAQgKORAApY8f5EOkTM3kYYEKoVShQQsAHQeKd4rk cGNClGJou5oi/zDTHHyckgbFDZ4KhJt8rigXH6BeB1Fq6kZNNJeekp6duxvvo82S fTgA2xVbXQpnFxFbZoSWBg1TJeRfJipHsDgy1iNp0yjSJZGx7VMzSDGoiyJ/WlZY ZGrFjb1Vf13RJCUh/Na5RSTmr4BNWZWz3wiUU5wfKU/mgZBZiId2ZsHa7vvc0hEa rmUwmT2UH0Rvkin2W5T1whfvqbPa3CItfKnhOL2Ja6YQ0Y6UDq5MWkbEnEOJQMAu E0PJs+CtaDBmmPzMwDLd4P43zgs7hsE9jXPgEZD4hj0+yyB9tPrv1AgP7QNPX3uv Q47psYU8avGBheJW5sap0comaVEpmq4cv40BTkAf9+XxvgZVL1auDjr+T8qmuBKK lMUz6PPDFhw3SIMWwGJX/BGEkEuzlJ+bHwImj/jgHM9Ny7XRFYiWSjqXKqTBjusY qTBqG5FmviL3krYg83QhNbhc8XF7s/cWEqJbyukQJ/B61vmH3/XbfGZU+n1i9i0n iOxkZLnTKU5Z6xhXQRu+2BDpK05h3LwcXumY+xSQsRw5cIf/VrV6gSg/Ul/9fDya msTMw8wofdkl1yp6DYNTNMaEUw9r2dh1l2D6rSvQD9Hp0eKfN5Nc9vRDJEBEf7LI vV5gxjG9OlM=DNxv -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent security correction released for Red Hat Enterprise Linux 6.5 addressing significant vulnerabilities.. Red Hat, Patch Update, Security Advisory, Linux Enterprise. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 27, 2018 Important Red Hat
100

SUSE: 2018:1162-1 Important: Multiple Security Issues Addressed

An update that solves four vulnerabilities and has one errata is now available.. SUSE Security Update: Security update for patch ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1162-1 Rating: important References: #1059698 #1080918 #1088420 #662957 #914891 Cross-References: CVE-2010-4651 CVE-2014-9637 CVE-2016-10713 CVE-2018-1000156 Affected Products: SUSE Linux Enterprise Server 11-SP4 SUSE Linux Enterprise Server 11-SP3-LTSS SUSE Linux Enterprise Point of Sale 11-SP3 SUSE Linux Enterprise Debuginfo 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP3 ______________________________________________________________________________ An update that solves four vulnerabilities and has one errata is now available. Description: This update for patch fixes several issues. These security issues were fixed: - CVE-2018-1000156: patch: Malicious patch files cause ed to execute arbitrary commands (bsc#1088420). - CVE-2014-9637: Prevent DoS by remote attackers (memory consumption and segmentation fault) via a crafted diff file (bsc#914891). - CVE-2016-10713: Prevent out-of-bounds access within pch_write_line() that could have lead to DoS via a crafted input file (bsc#1080918). - CVE-2010-4651: Fixed a directory traversal bug (bsc#662957): Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4: zypper in -t patch slessp4-patch-13589=1 - SUSE Linux Enterprise Server 11-SP3-LTSS: zypper in -t patch slessp3-patch-13589=1 - SUSE Linux Enterprise Point of Sale 11-SP3: zypper in -t patch sleposp3-patch-13589=1 - SUSE LinuxEnterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-patch-13589=1 - SUSE Linux Enterprise Debuginfo 11-SP3: zypper in -t patch dbgsp3-patch-13589=1 Package List: - SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64): patch-2.5.9-252.22.7.1 - SUSE Linux Enterprise Server 11-SP3-LTSS (i586 s390x x86_64): patch-2.5.9-252.22.7.1 - SUSE Linux Enterprise Point of Sale 11-SP3 (i586): patch-2.5.9-252.22.7.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): patch-debuginfo-2.5.9-252.22.7.1 patch-debugsource-2.5.9-252.22.7.1 - SUSE Linux Enterprise Debuginfo 11-SP3 (i586 s390x x86_64): patch-debuginfo-2.5.9-252.22.7.1 patch-debugsource-2.5.9-252.22.7.1 References: https://www.suse.com/security/cve/CVE-2010-4651.html https://www.suse.com/security/cve/CVE-2014-9637.html https://www.suse.com/security/cve/CVE-2016-10713.html https://www.suse.com/security/cve/CVE-2018-1000156.html https://bugzilla.suse.com/1059698 https://bugzilla.suse.com/1080918 https://bugzilla.suse.com/1088420 https://bugzilla.suse.com/662957 https://bugzilla.suse.com/914891 -- . SUSE announces critical patch to resolve numerous vulnerabilities affecting a range of applications and offerings.. SUSE Patch, Security Update, Linux Support, Enterprise Server, Critical Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 07, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here