Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 8: 2022-0475 Critical: Firefox Exploits and Memory Safety Issues

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages (CVE-2022-46872). A drag-and-dropped file with a long filename could have had its filename . MGASA-2022-0475 - Updated firefox packages fix security vulnerability Publication date: 17 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0475.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-46872, CVE-2022-46874, CVE-2022-46878, CVE-2022-46880, CVE-2022-46881, CVE-2022-46882 An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages (CVE-2022-46872). A drag-and-dropped file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code (CVE-2022-46874). Mozilla developers Randell Jesup, Valentin Gosu, Olli Pettay, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox ESR 102.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2022-46878). A missing check related to tex units could have led to a use-after-free in WebGL and potentially exploitable crash (CVE-2022-46880). An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash (CVE-2022-46881). A use-after-free in WebGL extensions could have led to a potentially exploitable crash (CVE-2022-46882). References: - https://bugs.mageia.org/show_bug.cgi?id=31272 - https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/NqCkaX216zY - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_86.html - https://www.mozilla.org/en-US/security/advisories/mfsa2022-52/ - https://www.cve.org/CVERecord?id=CVE-2022-46872 -https://www.cve.org/CVERecord?id=CVE-2022-46874 - https://www.cve.org/CVERecord?id=CVE-2022-46878 - https://www.cve.org/CVERecord?id=CVE-2022-46880 - https://www.cve.org/CVERecord?id=CVE-2022-46881 - https://www.cve.org/CVERecord?id=CVE-2022-46882 SRPMS: - 8/core/firefox-102.6.0-1.mga8 - 8/core/firefox-l10n-102.6.0-1.mga8 - 8/core/nss-3.86.0-1.mga8 . Mageia 8 Security Notice for Firefox addresses various vulnerabilities and resolutions that affect user safety and system reliability.. Firefox Security,Mageia Advisory,Memory Safety Issues,Sandbox Escape,Malicious Exploits. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 17, 2022 Critical Mageia
198

ArchLinux Flash Plugin: Unpatched 0day Risk From Angler EK Malware

. The malware researcher 'kafeine' found an 0day in Flash used by Angler EK malware. CVE-2014-8440 CVE-2015-0310 CVE-2015-0311 Description: Actual Version flash version in archlinux: flashplugin 11.2.202.429-1 Is our version vulnerable too? Have somebody some information about this? According to the information provided by Adobe in [1], I think so. Unfortunately there is not much information available on the issue and no fix available as far as I know, therefore I would recommend completely disabling the flash plugin, which might be a good idea if you care about security anyway. Oh and please don't hijack existing unrelated thread for starting a new topic :) [1]: . Cybersecurity specialist reveals unaddressed vulnerability in Flash impacting ArchLinux users. Users advised to turn off the plugin to enhance security.. 0day Attack, Adobe Flash Issue, ArchLinux Security, Angler EK Malware, Flash Plugin Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 23, 2015 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200