Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE: 2024:0287-1 Critical: Slurm Message Attack Issues Resolved

* bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 . # Security update for slurm Announcement ID: SUSE-SU-2024:0287-1 Rating: important References: * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 Cross-References: * CVE-2023-49933 * CVE-2023-49936 * CVE-2023-49937 * CVE-2023-49938 CVSS scores: * CVE-2023-49933 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49936 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49936 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-49937 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49937 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49938 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for slurm fixes the following issues: Security fixes: * CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) * CVE-2023-49936: Prevent NULL pointer dereference on `size_valp` overflow. (bsc#1218050) * CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) * CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: * Fix slurm upgrading to incompatible versions (bsc#1216869). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for yourproduct: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-287=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * perl-slurm-debuginfo-20.02.7-150200.3.20.1 * slurm-sview-debuginfo-20.02.7-150200.3.20.1 * slurm-doc-20.02.7-150200.3.20.1 * slurm-node-20.02.7-150200.3.20.1 * slurm-pam_slurm-debuginfo-20.02.7-150200.3.20.1 * slurm-auth-none-20.02.7-150200.3.20.1 * slurm-devel-20.02.7-150200.3.20.1 * slurm-webdoc-20.02.7-150200.3.20.1 * libnss_slurm2-20.02.7-150200.3.20.1 * libslurm35-debuginfo-20.02.7-150200.3.20.1 * slurm-munge-20.02.7-150200.3.20.1 * slurm-torque-debuginfo-20.02.7-150200.3.20.1 * slurm-20.02.7-150200.3.20.1 * slurm-plugins-20.02.7-150200.3.20.1 * slurm-plugins-debuginfo-20.02.7-150200.3.20.1 * libnss_slurm2-debuginfo-20.02.7-150200.3.20.1 * slurm-sql-debuginfo-20.02.7-150200.3.20.1 * libslurm35-20.02.7-150200.3.20.1 * perl-slurm-20.02.7-150200.3.20.1 * slurm-torque-20.02.7-150200.3.20.1 * slurm-auth-none-debuginfo-20.02.7-150200.3.20.1 * libpmi0-debuginfo-20.02.7-150200.3.20.1 * libpmi0-20.02.7-150200.3.20.1 * slurm-debugsource-20.02.7-150200.3.20.1 * slurm-slurmdbd-20.02.7-150200.3.20.1 * slurm-config-man-20.02.7-150200.3.20.1 * slurm-lua-20.02.7-150200.3.20.1 * slurm-config-20.02.7-150200.3.20.1 * slurm-debuginfo-20.02.7-150200.3.20.1 * slurm-munge-debuginfo-20.02.7-150200.3.20.1 * slurm-slurmdbd-debuginfo-20.02.7-150200.3.20.1 * slurm-lua-debuginfo-20.02.7-150200.3.20.1 * slurm-pam_slurm-20.02.7-150200.3.20.1 * slurm-sql-20.02.7-150200.3.20.1 * slurm-sview-20.02.7-150200.3.20.1 * slurm-node-debuginfo-20.02.7-150200.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2023-49933.html * https://www.suse.com/security/cve/CVE-2023-49936.html *https://www.suse.com/security/cve/CVE-2023-49937.html * https://www.suse.com/security/cve/CVE-2023-49938.html * https://bugzilla.suse.com/show_bug.cgi?id=1216869 * https://bugzilla.suse.com/show_bug.cgi?id=1218046 * https://bugzilla.suse.com/show_bug.cgi?id=1218050 * https://bugzilla.suse.com/show_bug.cgi?id=1218051 * https://bugzilla.suse.com/show_bug.cgi?id=1218053 . A critical patch for slurm resolves several security flaws within the SUSE High Performance Computing environment.. SUSE Security, Slurm Update, Important Patch, Security Fixes, HPC Software. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 31, 2024 Important SuSE
203

Mageia 8 MGASA-2022-0343 Moderate: libexample Out-Of-Bounds Access

An attacker can send a message with evil sdp to FreeSWITCH, which may a cause a crash due to an out-of-bounds access. (CVE-2022-31001) An attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. (CVE-2022-31002) An out-of-bounds write. (CVE-2022-31003) . MGASA-2022-0343 - Updated sofia-sip packages fix security vulnerability Publication date: 21 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0343.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-31001, CVE-2022-31002, CVE-2022-31003 An attacker can send a message with evil sdp to FreeSWITCH, which may a cause a crash due to an out-of-bounds access. (CVE-2022-31001) An attacker can send a message with evil sdp to FreeSWITCH, which may cause a crash. (CVE-2022-31002) An out-of-bounds write. (CVE-2022-31003) References: - https://bugs.mageia.org/show_bug.cgi?id=30806 - https://lists.debian.org/debian-lts-announce/2022/09/msg00001.html - https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-79jq-hh82-cv9g - https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-g3x6-p824-x6hm - https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8w5j-6g2j-pxcp - https://www.cve.org/CVERecord?id=CVE-2022-31001 - https://www.cve.org/CVERecord?id=CVE-2022-31002 - https://www.cve.org/CVERecord?id=CVE-2022-31003 SRPMS: - 8/core/sofia-sip-1.12.11-10.1.mga8 . Mageia 2022-0343 resolves issues in sofia-sip concerning out-of-bounds access that could result in service interruptions.. SofiaSIP Update,Mageia Security,Exploit Prevention,OutOfBounds,Message Attack. . LinuxSecurity.com Team

Calendar 2 Sep 21, 2022 Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here