Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
203

Mageia: 2021-0208 Moderate: KMail Attachment Decryption Risk

Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g. an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. This is not easily noticeable by the user because KMail does not display the decrypted content. . MGASA-2021-0208 - Updated messagelib packages fix security vulnerability Publication date: 07 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0208.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-31855 Deleting an attachment of a decrypted encrypted message stored on a remote server (e.g. an IMAP server) causes KMail to upload the decrypted content of the message to the remote server. This is not easily noticeable by the user because KMail does not display the decrypted content. With a specially crafted message a user could be tricked into decrypting an encrypted message and then deleting an attachment attached to this message. If the attacker has access to the messages stored on the email server, then the attacker could read the decrypted content of the encrypted message (CVE-2021-31855). References: - https://bugs.mageia.org/show_bug.cgi?id=28861 - https://kde.org/info/security/advisory-20210429-1.txt - https://www.cve.org/CVERecord?id=CVE-2021-31855 SRPMS: - 8/core/messagelib-20.12.0-1.1.mga8 - 7/core/messagelib-19.04.0-1.2.mga7 . Revised messagelib modules resolve a vulnerability, permitting exposed data to be retrieved from afar.. Messagelib Security Update, Mageia 7, KMail Attachment Issue, Encrypted Message Risk. . LinuxSecurity.com Team

Calendar 2 May 07, 2021 Mageia
203

Mageia 7 MGASA-2021-0067 Critical: KMail Attack Vector and Fix

In KDE KMail, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the . MGASA-2021-0067 - Updated messagelib packages fix a security vulnerability Publication date: 04 Feb 2021 URL: https://advisories.mageia.org/MGASA-2021-0067.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-10732 In KDE KMail, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker (CVE-2019-10732). References: - https://bugs.mageia.org/show_bug.cgi?id=28260 - - https://www.cve.org/CVERecord?id=CVE-2019-10732 SRPMS: - 7/core/messagelib-19.04.0-1.1.mga7 . Recent updates to the messagelib packages aim to fix a security vulnerability linked to encoded emails in the Mageia environment. Learn more about this exploit's nature. Mageia Email Threat, KDE KMail Security Fix, Email Encryption Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 04, 2021 Critical Mageia
202

openSUSE: 2021:0227-1 Moderate Messagelib Content Disclosure Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for messagelib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0227-1 Rating: moderate References: #1131885 Cross-References: CVE-2019-10732 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for messagelib fixes the following issues: - CVE-2019-10732: Prevented accidental disclosure of encrypted content when replying (boo#1131885). This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2021-227=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 x86_64): messagelib-18.12.3-bp151.3.3.1 messagelib-devel-18.12.3-bp151.3.3.1 - openSUSE Backports SLE-15-SP1 (noarch): messagelib-lang-18.12.3-bp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-10732.html https://bugzilla.suse.com/1131885 . OpenSUSE Security Patch for messagelib addresses CVE-2019-10732 to mitigate the unintended exposure of encrypted data.. openSUSE Security Update,messagelib patch,content protection. . LinuxSecurity.com Team

Calendar 2 Feb 02, 2021 OpenSUSE
202

openSUSE Leap 15.1: 2021:0188-1 Moderate: Messagelib Info Leak

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for messagelib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0188-1 Rating: moderate References: #1131885 Cross-References: CVE-2019-10732 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for messagelib fixes the following issues: - CVE-2019-10732: Prevented accidental disclosure of encrypted content when replying (boo#1131885). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2021-188=1 Package List: - openSUSE Leap 15.1 (noarch): messagelib-lang-18.12.3-lp151.2.4.1 - openSUSE Leap 15.1 (x86_64): messagelib-18.12.3-lp151.2.4.1 messagelib-debuginfo-18.12.3-lp151.2.4.1 messagelib-debugsource-18.12.3-lp151.2.4.1 messagelib-devel-18.12.3-lp151.2.4.1 References: https://www.suse.com/security/cve/CVE-2019-10732.html https://bugzilla.suse.com/1131885 . An urgent patch for messagelib addresses a severe data exposure vulnerability in openSUSE. More information follows.. openSUSE updates,message library,messagelib security,software patch,moderate fixes. . LinuxSecurity.com Team

Calendar 2 Jan 29, 2021 OpenSUSE
202

openSUSE Leap 15.0 Advisory 2018:4029-1 Low Severity Messagelib HTML Issue

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for messagelib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:4029-1 Rating: low References: #1117958 Cross-References: CVE-2018-19516 Affected Products: openSUSE Leap 15.0 openSUSE Backports SLE-15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for messagelib fixes the following issues: The following security vulnerability was addressed: - CVE-2018-19516: Fix a potential issue with opening messages in a new browser window when displaying mails as HTML (boo#1117958). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1508=1 - openSUSE Backports SLE-15: zypper in -t patch openSUSE-2018-1508=1 Package List: - openSUSE Leap 15.0 (x86_64): messagelib-17.12.3-lp150.2.6.1 messagelib-debuginfo-17.12.3-lp150.2.6.1 messagelib-debugsource-17.12.3-lp150.2.6.1 messagelib-devel-17.12.3-lp150.2.6.1 - openSUSE Leap 15.0 (noarch): messagelib-lang-17.12.3-lp150.2.6.1 - openSUSE Backports SLE-15 (x86_64): messagelib-17.12.3-bp150.3.6.1 messagelib-devel-17.12.3-bp150.3.6.1 - openSUSE Backports SLE-15 (noarch): messagelib-lang-17.12.3-bp150.3.6.1 References: https://www.suse.com/security/cve/CVE-2018-19516.html https://bugzilla.suse.com/1117958 -- . This patch addresses a minor concern in the communication library for Fedora. Review the update guidelines immediately.. openSUSE security update,messagelib fix,low severity patch. .Severity: Low. LinuxSecurity.com Team

Calendar 2 Dec 08, 2018 Low OpenSUSE
203

Mageia: MGASA-2018-0476 Critical: Messagelib HTML Email Threat

Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their access logs your IP address (CVE-2018-19516). . MGASA-2018-0476 - Updated messagelib packages fix security vulnerability Publication date: 03 Dec 2018 URL: https://advisories.mageia.org/MGASA-2018-0476.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-19516 Some HTML emails can trick messagelib into opening a new browser window when displaying said email as HTML. This happens even if the option to allow the HTML emails to access remote servers is disabled in KMail settings. This means that the owners of the servers referred in the email can see in their access logs your IP address (CVE-2018-19516). References: - https://bugs.mageia.org/show_bug.cgi?id=23923 - https://kde.org/info/security/advisory-20181128-1.txt - https://www.cve.org/CVERecord?id=CVE-2018-19516 SRPMS: - 6/core/messagelib-17.12.2-1.1.mga6 . The latest messagelib updates fix vulnerabilities related to HTML email processing and enhance the protection of user IP information.. messagelib security, Mageia update, HTML email threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 03, 2018 Critical Mageia
198

Arch Linux Advisory ASA-201706-17 Medium: Messagelib Info Disclosure

The package messagelib before version 17.04.2-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-201706-17 ========================================= Severity: Medium Date : 2017-06-14 CVE-ID : CVE-2017-9604 Package : messagelib Type : information disclosure Remote : Yes Link : https://security.archlinux.org/AVG-300 Summary ====== The package messagelib before version 17.04.2-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 17.04.2-1. # pacman -Syu "messagelib> =17.04.2-1" The problem has been fixed upstream in version 17.04.2. Workaround ========= None. Description ========== KDE kmail before 5.5.2 and messagelib before 5.5.2, as distributed in KDE Applications before 17.04.2, do not ensure that a plugin's sign/encrypt action occurs during use of the Send Later feature, which allows remote attackers to obtain sensitive information by sniffing the network. Impact ===== A remote attacker who is sniffing the network may be able to obtain sensitive information when an email that should be encrypted is sent via the "Send Later with Delay" function. References ========= https://kde.org/info/security/advisory-20170615-1.txt https://security.archlinux.org/CVE-2017-9604 . The Fedora Security Team released FSA-202312-09, addressing vulnerabilities in the libmessaging component that could potentially expose sensitive user information.. messagelib update, Arch Linux security, information breach, software vulnerabilities. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jun 15, 2017 Medium ArchLinux
198

Arch Linux: ASA-201610-5 Moderate: Messagelib Remote Access Risk

The package messagelib before version 16.08.1-2 is vulnerable to multiple issues including cross-site scripting and insufficient validation. . Arch Linux Security Advisory ASA-201610-5 ======================================== Severity: Medium Date : 2016-10-07 CVE-ID : CVE-2016-7967 CVE-2016-7968 Package : messagelib Type : multiple issues Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package messagelib before version 16.08.1-2 is vulnerable to multiple issues including cross-site scripting and insufficient validation. Resolution ========= Upgrade to 16.08.1-2. # pacman -Syu "messagelib> =16.08.1-2" The problems have been fixed upstream but no release is available yet. Workaround ========= None. Description ========== - CVE-2016-7967 (cross-site scripting) KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled. - CVE-2016-7968 (insufficient validation) KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed. Impact ===== An attacker is able to access local or remote urls via injected javascript. References ========= https://kde.org/info/security/advisory-20161006-1.txt https://kde.org/info/security/advisory-20161006-3.txt https://seclists.org/oss-sec/2016/q4/23 https://kde.org/info/security/advisory-20161006-2.txt https://seclists.org/oss-sec/2016/q4/21 https://access.redhat.com/security/cve/CVE-2016-7967 https://access.redhat.com/security/cve/CVE-2016-7968s . The Arch Linux Security Notice ASA-201610-5 regarding messagelib denotes moderate severity vulnerabilities. Please ensure that you perform the necessary updates.. Arch Linux, Messagelib, Cybersecurity Update, XSS Risk, Package Advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Oct 07, 2016 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here