Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
172

Ubuntu 16.04 LTS: USN-4506-1 Critical: MCabber Message Interception

MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets.. =========================================================================Ubuntu Security Notice USN-4506-1 September 16, 2020 mcabber vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: MCabber could be made to modify the roster and intercept messages if it received specially crafted XMPP packets. Software Description: - mcabber: small Jabber (XMPP) console client Details: It was discovered that MCabber does not properly manage roster pushes. An attacker could possibly use this issue to remotely perform man-in-the-middle attacks. (CVE-2016-9928). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: mcabber 0.10.2-1+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4506-1 CVE-2016-9928 Package Information: https://launchpad.net/ubuntu/+source/mcabber/0.10.2-1+deb8u1build0.16.04.1 . A security flaw in MCabber permits unauthorized alterations and interception of messages on Ubuntu 16.04. Guidance for updates is included.. mcabber vulnerability, Ubuntu security notice, XMPP packet issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 16, 2020 Critical Ubuntu
197

Debian 8 Jessie: DLA-2260-1 Critical: Mcabber Roster Push Attack

It was discovered that there was a "roster push attack" in mcabber, a console-based Jabber (XMPP) client. This is identical to CVE-2015-8688 for gajim. . Package : mcabber Version : 0.10.2-1+deb8u1 CVE ID : CVE-2016-9928 It was discovered that there was a "roster push attack" in mcabber, a console-based Jabber (XMPP) client. This is identical to CVE-2015-8688 for gajim. For Debian 8 "Jessie", this problem has been fixed in version 0.10.2-1+deb8u1. We recommend that you upgrade your mcabber packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . New release of Mcabber, the text-only Jabber client for Debian, addresses critical roster push vulnerability. It is advisable to update promptly to ensure user security.. Mcabber Update, Debian LTS Security, Roster Attack Fix, XMPP Client Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 28, 2020 Critical Debian LTS
99

Urgent Mcabber MITM Fix for Slackware 14.x Released on 2016-347-02

New mcabber packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mcabber (SSA:2016-347-02) New mcabber packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/loudmouth-1.5.3-i586-1_slack14.2.txz: Upgraded. This update is needed for the mcabber security update. patches/packages/mcabber-1.0.4-i586-1_slack14.2.txz: Upgraded. This update fixes a security issue which can lead to a malicious actor MITMing a conversation, or adding themselves as an entity on a third parties roster (thereby granting themselves the associated priviledges such as observing when the user is online). For more information, see: https://gultsch.de/posts/gajim-roster-push_and-message-interception/ https://www.cve.org/CVERecord?id=CVE-2016-9928 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: fd38253e79e4b766ad194d4fceaa5d8d mcabber-1.0.4-i486-1_slack14.0.txz Slackware x86_64 14.0 package: c859617864745e03fd527fca1030d518 mcabber-1.0.4-x86_64-1_slack14.0.txz Slackware 14.1 package: d5adbde2cba42fcfa915c07814fb33b5 mcabber-1.0.4-i486-1_slack14.1.txz Slackware x86_64 14.1package: 2af12adcb6691b94edd3f668eb424805 mcabber-1.0.4-x86_64-1_slack14.1.txz Slackware 14.2 package: d2a06d1fd910aecaaa384f115bb58bc3 mcabber-1.0.4-i586-1_slack14.2.txz Slackware x86_64 14.2 package: cda2b990fe27fb3a33039ffd53aad42e mcabber-1.0.4-x86_64-1_slack14.2.txz Slackware -current package: a2b3fc780a5013e96aee9924bac333c9 n/mcabber-1.0.4-i586-1.txz Slackware x86_64 -current package: e212a2abac6dd59728869361651ecdc7 n/mcabber-1.0.4-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mcabber-1.0.4-i586-1_slack14.2.txz A new loudmouth package is also provided. Be sure to update this as well. +-----+ . Stay informed about mcabber updates on Slackware to address critical communication concerns stemming from security vulnerabilities. Upgrade immediately!. mcabber update, Slackware security, communication fix, MITM vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 12, 2016 Critical Slackware
89

Fedora 23: Latest Security Update Released For Mcabber Chat Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-7da97a3914 2016-12-11 16:19:11.675039 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 23 Version : 1.0.4 Release : 1.fc23 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora's mcabber console messaging client receives a security patch improving chat functionalities and strengthening SSL integration.. Fedora Update, mcabber Client, Console Messaging, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Important Fedora
89

Fedora 24: Security Update on Mcabber Instant Messaging Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-30f68ec06b 2016-12-11 16:19:33.990660 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 24 Version : 1.0.4 Release : 1.fc24 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Delve into the Fedora 24 security patch for mcabber, enhancing your messaging application with essential improvements and repairs.. Fedora 24, mcabber, security updates, instant messaging client. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Important Fedora
89

Fedora 25 Mcabber Security Advisory: Updates for Instant Messaging Client

update. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-e865601498 2016-12-11 16:19:57.246617 -------------------------------------------------------------------------------- Name : mcabber Product : Fedora 25 Version : 1.0.4 Release : 1.fc25 URL : https://mcabber.com Summary : Console Jabber instant messaging client Description : mcabber is a console Jabber instant messaging/chat client with SSL support, MUC (Multi-User Chat) support, history logging, commands completion, and external action triggers. -------------------------------------------------------------------------------- Update Information: update -------------------------------------------------------------------------------- References: [ 1 ] Bug #1397220 - mcabber-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1397220 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mcabber' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Mcabber release for Fedora 25 enhances security mechanisms and fixes associated vulnerabilities. Update now for optimal functionality.. Fedora Updates, Mcabber Client, Security Enhancements, Instant Messaging App. . LinuxSecurity.com Team

Calendar 2 Dec 11, 2016 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here