Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 22.04 LTS USN-5694-1 Critical: LibreOffice Improper Link Handling

Several security issues were fixed in LibreOffice.. =========================================================================Ubuntu Security Notice USN-5694-1 October 20, 2022 libreoffice vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in LibreOffice. Software Description: - libreoffice: Office productivity suite Details: It was discovered that LibreOffice incorrectly handled links using the Office URI Schemes. If a user were tricked into opening a specially crafted document, a remote attacker could use this issue to execute arbitrary scripts. (CVE-2022-3140) Thomas Florian discovered that LibreOffice incorrectly handled crashes when an encrypted document is open. If the document is recovered upon restarting LibreOffice, subsequent saves of the document were unencrypted. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-12801) Jens Müller discovered that LibreOffice incorrectly handled certain documents containing forms. If a user were tricked into opening a specially crafted document, a remote attacker could overwrite arbitrary files when the form was submitted. This issue only affected Ubuntu 18.04 LTS. (CVE-2020-12803) It was discovered that LibreOffice incorrectly validated macro signatures. If a user were tricked into opening a specially crafted document, a remote attacker could possibly use this issue to execute arbitrary macros. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-26305) It was discovered that Libreoffice incorrectly handled encrypting the master key provided by the user for storing passwords for web connections. A local attacker could possibly use this issue to obtain access to passwords stored in the user’s configuration data. This issue only affected Ubuntu 18.04 LTS. (CVE-2022-26306, CVE-2022-26307) Updateinstructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: libreoffice 1:7.3.6-0ubuntu0.22.04.2 Ubuntu 20.04 LTS: libreoffice 1:6.4.7-0ubuntu0.20.04.6 Ubuntu 18.04 LTS: libreoffice 1:6.0.7-0ubuntu0.18.04.12 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5694-1 CVE-2020-12801, CVE-2020-12803, CVE-2022-26305, CVE-2022-26306, CVE-2022-26307, CVE-2022-3140 Package Information: https://launchpad.net/ubuntu/+source/libreoffice/1:7.3.6-0ubuntu0.22.04.2 https://launchpad.net/ubuntu/+source/libreoffice/1:6.4.7-0ubuntu0.20.04.6 . Critical vulnerabilities in LibreOffice can lead to document-related exploits, requiring immediate updates for Ubuntu.. LibreOffice Security, Document Exploits, Ubuntu Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 20, 2022 Critical Ubuntu
200

Scientific Linux: Critical Firefox Security Update 3.6.4

Critical: firefox security, bug fix, and enhancement update. Date: Wed, 23 Jun 2010 10:54:44 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: firefox security, bug fix, and enhancement update Issue date: 2010-06-22 CVE Names: CVE-2008-5913 CVE-2010-0182 CVE-2010-1121 CVE-2010-1125 CVE-2010-1196 CVE-2010-1197 CVE-2010-1198 CVE-2010-1199 CVE-2010-1200 CVE-2010-1202 CVE-2010-1203 Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-1121, CVE-2010-1200, CVE-2010-1202, CVE-2010-1203) A flaw was found in the way browser plug-ins interact. It was possible for a plug-in to reference the freed memory from a different plug-in, resulting in the execution of arbitrary code with the privileges of the user running Firefox. (CVE-2010-1198) Several integer overflow flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-1196, CVE-2010-1199) A focus stealing flaw was found in the way Firefox handled focus changes. A malicious website could use this flaw to steal sensitive data from a user, such as usernames and passwords. (CVE-2010-1125) A flaw was found in the way Firefox handled the "Content-Disposition: attachment" HTTP header when the "Content-Type: multipart" HTTP header was also present. A website that allows arbitrary uploads and relies on the "Content-Disposition: attachment" HTTP header to prevent content from being displayed inline, could be used by an attacker to serve malicious content to users. (CVE-2010-1197) A flaw was found in the Firefox Math.random() function. Thisfunction could be used to identify a browsing session and track a user across different websites. (CVE-2008-5913) A flaw was found in the Firefox XML document loading security checks. Certain security checks were not being called when an XML document was loaded. This could possibly be leveraged later by an attacker to load certain resources that violate the security policies of the browser or its add-ons. Note that this issue cannot be exploited by only loading an XML document. (CVE-2010-0182) This erratum upgrades Firefox from version 3.0.19 to version 3.6.4. Due to the requirements of Firefox 3.6.4, this erratum also provides a number of other updated packages, including esc, totem, and yelp. This erratum also contains multiple bug fixes and numerous enhancements. Space precludes documenting these changes in this advisory. Important: Firefox 3.6.4 is not completely backwards-compatible with all Mozilla Add-ons and Firefox plug-ins that worked with Firefox 3.0.19. Firefox 3.6 checks compatibility on first-launch, and, depending on the individual configuration and the installed Add-ons and plug-ins, may disable said Add-ons and plug-ins, or attempt to check for updates and upgrade them. Add-ons and plug-ins may have to be manually updated. After installing the update, Firefox must be restarted for the changes to take effect. SL 5.x SRPMS: devhelp-0.12-21.el5.src.rpm esc-1.1.0-12.el5.src.rpm firefox-3.6.4-8.el5.src.rpm gnome-python2-extras-2.14.2-7.el5.src.rpm totem-2.16.7-7.el5.src.rpm xulrunner-1.9.2.4-9.el5.src.rpm yelp-2.16.0-26.el5.src.rpm i386: devhelp-0.12-21.el5.i386.rpm devhelp-devel-0.12-21.el5.i386.rpm esc-1.1.0-12.el5.i386.rpm firefox-3.6.4-8.el5.i386.rpm gnome-python2-extras-2.14.2-7.el5.i386.rpm gnome-python2-gtkhtml2-2.14.2-7.el5.i386.rpm gnome-python2-gtkmozembed-2.14.2-7.el5.i386.rpm gnome-python2-gtkspell-2.14.2-7.el5.i386.rpm gnome-python2-libegg-2.14.2-7.el5.i386.rpm totem-2.16.7-7.el5.i386.rpm totem-devel-2.16.7-7.el5.i386.rpm totem-mozplugin-2.16.7-7.el5.i386.rpm xulrunner-1.9.2.4-9.el5.i386.rpm xulrunner-devel-1.9.2.4-9.el5.i386.rpm yelp-2.16.0-26.el5.i386.rpm x86_64: devhelp-0.12-21.el5.i386.rpm devhelp-0.12-21.el5.x86_64.rpm devhelp-devel-0.12-21.el5.i386.rpm devhelp-devel-0.12-21.el5.x86_64.rpm esc-1.1.0-12.el5.x86_64.rpm firefox-3.6.4-8.el5.i386.rpm firefox-3.6.4-8.el5.x86_64.rpm gnome-python2-extras-2.14.2-7.el5.x86_64.rpm gnome-python2-gtkhtml2-2.14.2-7.el5.x86_64.rpm gnome-python2-gtkmozembed-2.14.2-7.el5.x86_64.rpm gnome-python2-gtkspell-2.14.2-7.el5.x86_64.rpm gnome-python2-libegg-2.14.2-7.el5.x86_64.rpm totem-2.16.7-7.el5.i386.rpm totem-2.16.7-7.el5.x86_64.rpm totem-devel-2.16.7-7.el5.i386.rpm totem-devel-2.16.7-7.el5.x86_64.rpm totem-mozplugin-2.16.7-7.el5.x86_64.rpm xulrunner-1.9.2.4-9.el5.i386.rpm xulrunner-1.9.2.4-9.el5.x86_64.rpm xulrunner-devel-1.9.2.4-9.el5.i386.rpm xulrunner-devel-1.9.2.4-9.el5.x86_64.rpm yelp-2.16.0-26.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Uncover essential adjustments in Firefox that tackle numerous vulnerabilities on Scientific Linux, fortifying your system's defenses.. firefox security fix, scientific linux update, firefox vulnerabilities, web browser enhancements. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 23, 2010 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here