Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
100

SUSE: 2024:0313-1 Critical: Slurm File Access and Message Issues

* bsc#1216207 * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 . # Security update for slurm_18_08 Announcement ID: SUSE-SU-2024:0313-1 Rating: important References: * bsc#1216207 * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 Cross-References: * CVE-2023-41914 * CVE-2023-49933 * CVE-2023-49936 * CVE-2023-49937 * CVE-2023-49938 CVSS scores: * CVE-2023-41914 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-41914 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49933 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49936 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49936 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-49937 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49937 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49938 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for slurm_18_08 fixes thefollowing issues: Security fixes: * CVE-2023-41914: Prevent filesystem race conditions that could let an attacker take control of an arbitrary file, or remove entire directories' contents. (bsc#1216207) * CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) * CVE-2023-49936: Prevent NULL pointer dereference on `size_valp` overflow. (bsc#1218050) * CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) * CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: * Fix slurm upgrading to incompatible versions (bsc#1216869). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2024-313=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * slurm_18_08-lua-debuginfo-18.08.9-3.23.1 * slurm_18_08-torque-18.08.9-3.23.1 * slurm_18_08-lua-18.08.9-3.23.1 * slurm_18_08-plugins-18.08.9-3.23.1 * slurm_18_08-auth-none-debuginfo-18.08.9-3.23.1 * slurm_18_08-node-debuginfo-18.08.9-3.23.1 * slurm_18_08-sql-18.08.9-3.23.1 * slurm_18_08-pam_slurm-18.08.9-3.23.1 * slurm_18_08-slurmdbd-debuginfo-18.08.9-3.23.1 * slurm_18_08-sql-debuginfo-18.08.9-3.23.1 * slurm_18_08-doc-18.08.9-3.23.1 * slurm_18_08-config-18.08.9-3.23.1 * libpmi0_18_08-18.08.9-3.23.1 * libslurm33-18.08.9-3.23.1 * slurm_18_08-munge-debuginfo-18.08.9-3.23.1 * slurm_18_08-debugsource-18.08.9-3.23.1 * slurm_18_08-devel-18.08.9-3.23.1 * perl-slurm_18_08-debuginfo-18.08.9-3.23.1 * slurm_18_08-torque-debuginfo-18.08.9-3.23.1 * perl-slurm_18_08-18.08.9-3.23.1 * slurm_18_08-auth-none-18.08.9-3.23.1 * slurm_18_08-node-18.08.9-3.23.1 * slurm_18_08-slurmdbd-18.08.9-3.23.1 *slurm_18_08-18.08.9-3.23.1 * slurm_18_08-plugins-debuginfo-18.08.9-3.23.1 * slurm_18_08-munge-18.08.9-3.23.1 * libslurm33-debuginfo-18.08.9-3.23.1 * slurm_18_08-debuginfo-18.08.9-3.23.1 * slurm_18_08-pam_slurm-debuginfo-18.08.9-3.23.1 * libpmi0_18_08-debuginfo-18.08.9-3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2023-41914.html * https://www.suse.com/security/cve/CVE-2023-49933.html * https://www.suse.com/security/cve/CVE-2023-49936.html * https://www.suse.com/security/cve/CVE-2023-49937.html * https://www.suse.com/security/cve/CVE-2023-49938.html * https://bugzilla.suse.com/show_bug.cgi?id=1216207 * https://bugzilla.suse.com/show_bug.cgi?id=1216869 * https://bugzilla.suse.com/show_bug.cgi?id=1218046 * https://bugzilla.suse.com/show_bug.cgi?id=1218050 * https://bugzilla.suse.com/show_bug.cgi?id=1218051 * https://bugzilla.suse.com/show_bug.cgi?id=1218053 . Crucial Ubuntu security patch for apache_20_04 tackling urgent vulnerabilities and fortifying defenses against potential threats.. SUSE Security Update, Slurm 18.08 Patch, SUSE Advisory, Critical Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 02, 2024 Critical SuSE
203

Mageia 8 MGASA-2023-0098 Critical: Heimdal Message Integrity Issue

The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted. (CVE-2022-45142) . MGASA-2023-0098 - Updated heimdal packages fix security vulnerability Publication date: 18 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0098.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-45142 The fix for CVE-2022-3437 included changing memcmp to be constant time and a workaround for a compiler bug by adding "!= 0" comparisons to the result of memcmp. When these patches were backported a logic inversion sneaked in causing the validation of message integrity codes in gssapi/arcfour to be inverted. (CVE-2022-45142) References: - https://bugs.mageia.org/show_bug.cgi?id=31530 - https://www.openwall.com/lists/oss-security/2023/02/08/1 - https://lists.debian.org/debian-security-announce/2023/msg00033.html - https://ubuntu.com/security/notices/USN-5849-1 - https://www.cve.org/CVERecord?id=CVE-2022-45142 SRPMS: - 8/core/heimdal-7.7.1-1.3.mga8 . Revised heimdal software addresses a critical security flaw in Mageia, improving the robustness of cryptographic communications.. Heimdal Security, Mageia Updates, Message Integrity, Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2023 Critical Mageia
200

Scientific Linux SL7 SLSA-2021-2658-1 Important Linuxptp Update

linuxptp: missing length check of forwarded messages (CVE-2021-3570) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 - linuxptp-2.0-2.el7_9.1.x86_64.rpm - linuxptp-debuginfo-2.0-2.el7_9.1.x86_64.rpm - Scientific Linux Development Team. Synopsis: Important: linuxptp security update Advisory ID: SLSA-2021:2658-1 Issue Date: 2021-07-07 CVE Numbers: CVE-2021-3570 -- Security Fix(es): * linuxptp: missing length check of forwarded messages (CVE-2021-3570) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE --- SL7 x86_64 - linuxptp-2.0-2.el7_9.1.x86_64.rpm - linuxptp-debuginfo-2.0-2.el7_9.1.x86_64.rpm -- - Scientific Linux Development Team . A noteworthy patch for linuxptp resolves a significant boundary validation problem, thereby enhancing message reliability on CentOS Scientific.. linuxptp update, security patch, message integrity. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 07, 2021 Important Scientific Linux
100

SUSE 15-SP1: SUSE-SU-2020:2267-1 Important Dovecot23 Issues

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for dovecot23 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2267-1 Rating: important References: #1174922 #1174923 Cross-References: CVE-2020-12673 CVE-2020-12674 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for dovecot23 fixes the following issues: - CVE-2020-12673: improper implementation of NTLM does not check message buffer size (bsc#1174922). - CVE-2020-12674: improper implementation of RPA mechanism (bsc#1174923). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-2267=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (aarch64 ppc64le s390x x86_64): dovecot23-2.3.10-16.1 dovecot23-backend-mysql-2.3.10-16.1 dovecot23-backend-mysql-debuginfo-2.3.10-16.1 dovecot23-backend-pgsql-2.3.10-16.1 dovecot23-backend-pgsql-debuginfo-2.3.10-16.1 dovecot23-backend-sqlite-2.3.10-16.1 dovecot23-backend-sqlite-debuginfo-2.3.10-16.1 dovecot23-debuginfo-2.3.10-16.1 dovecot23-debugsource-2.3.10-16.1 dovecot23-devel-2.3.10-16.1 dovecot23-fts-2.3.10-16.1 dovecot23-fts-debuginfo-2.3.10-16.1 dovecot23-fts-lucene-2.3.10-16.1 dovecot23-fts-lucene-debuginfo-2.3.10-16.1 dovecot23-fts-solr-2.3.10-16.1 dovecot23-fts-solr-debuginfo-2.3.10-16.1 dovecot23-fts-squat-2.3.10-16.1 dovecot23-fts-squat-debuginfo-2.3.10-16.1 References: https://www.suse.com/security/cve/CVE-2020-12673.html https://www.suse.com/security/cve/CVE-2020-12674.html https://bugzilla.suse.com/1174922 https://bugzilla.suse.com/1174923 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Important SUSE Security Patch for dovecot23 addresses significant flaws. Safeguard your system's strength today.. SUSE security update, dovecot threats, server application fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 18, 2020 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here