Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 37: FEDORA-2023-1a7e2b3dda Critical Threat in glib2 Update

Update to glib2-2.74.7.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-1a7e2b3dda 2023-06-16 02:13:40.625179 --------------------------------------------------------------------------------Name : mingw-glib2 Product : Fedora 37 Version : 2.74.7 Release : 1.fc37 URL : https://www.gtk.org/ Summary : MinGW Windows GLib2 library Description : MinGW Windows Glib2 library. --------------------------------------------------------------------------------Update Information: Update to glib2-2.74.7. --------------------------------------------------------------------------------ChangeLog: * Tue Jun 6 2023 Sandro Mani - 2.74.7-1 - Update to 2.74.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2212693 - CVE-2023-32665 mingw-glib2: glib: GVariant deserialisation does not match spec for non-normal data [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212693 [ 2 ] Bug #2212697 - CVE-2023-32665 mingw-glib2: glib: GVariant deserialisation does not match spec for non-normal data [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212697 [ 3 ] Bug #2212701 - CVE-2023-29499 mingw-glib2: glib: GVariant offset table entry size is not checked in is_normal() [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212701 [ 4 ] Bug #2212707 - CVE-2023-29499 mingw-glib2: glib: GVariant offset table entry size is not checked in is_normal() [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212707 [ 5 ] Bug #2212710 - CVE-2023-32611 mingw-glib2: glib: g_variant_byteswap() can take a long time with some non-normal inputs [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212710 [ 6 ] Bug #2212712 - CVE-2023-32611 mingw-glib2: glib: g_variant_byteswap() can take a long time with some non-normal inputs [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212712 [ 7 ] Bug #2212718 - CVE-2023-32643 mingw-glib2: glib: fuzz_variant_binary_byteswap: Heap-buffer-overflow in g_variant_serialised_get_child [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2212718 [ 8 ] Bug #2212723 - CVE-2023-32636 mingw-glib2: glib: fuzz_variant_text: Timeout in fuzz_variant_text [fedora-37] https://bugzilla.redhat.com/show_bug.cgi?id=2212723 [ 9 ] Bug #2212728 - CVE-2023-32636 mingw-glib2: glib: fuzz_variant_text: Timeout in fuzz_variant_text [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2212728 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1a7e2b3dda' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The Fedora 37 release has seen an update to the mingw-glib2 library, now at version 2.74.7, which rectifies significant vulnerabilities and enhances overall application robustness.. Fedora Updates, glib2 Patch, MinGW Library Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 16, 2023 Critical Fedora
89

Fedora 32: FEDORA-2020-e244f22a51 Moderate: OpenEXR Out-Of-Bounds Access

Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e244f22a51 2020-05-16 03:38:08.854649 --------------------------------------------------------------------------------Name : mingw-OpenEXR Product : Fedora 32 Version : 2.4.1 Release : 1.fc32 URL : https://openexr.com/en/latest/ Summary : MinGW Windows OpenEXR library Description : MinGW Windows OpenEXR library. --------------------------------------------------------------------------------Update Information: Update to OpenEXR-2.4.1, see https://github.com/AcademySoftwareFoundation/openexr/releases/tag/v2.4.1 for details. --------------------------------------------------------------------------------ChangeLog: * Wed Feb 12 2020 Sandro Mani - 2.4.1-1 - Update to 2.4.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1828987 - CVE-2020-11765 mingw-OpenEXR: OpenEXR: off-by-one error in ImfXdr.h read function by DwaCompressor::Classifier::Classifier leading to an out-of-bounds read [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1828987 [ 2 ] Bug #1828992 - CVE-2020-11764 mingw-OpenEXR: OpenEXR: out-of-bounds write in copyIntoFrameBuffer function in ImfMisc.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1828992 [ 3 ] Bug #1828997 - CVE-2020-11763 mingw-OpenEXR: OpenEXR: std::vector out-of-bounds read and write as demonstrated by ImfTileOffsets.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1828997 [ 4 ] Bug #1829001 - CVE-2020-11762 mingw-OpenEXR: OpenEXR: out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829001 [ 5 ] Bug #1829003 - CVE-2020-11761 mingw-OpenEXR: OpenEXR: out-of-bounds read duringHuffman uncompression [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829003 [ 6 ] Bug #1829007 - CVE-2020-11760 mingw-OpenEXR: OpenEXR: out-of-bounds read during RLE uncompression in rleUncompress function in ImfRle.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829007 [ 7 ] Bug #1829011 - CVE-2020-11759 mingw-OpenEXR: OpenEXR: out-of-bounds write due to integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829011 [ 8 ] Bug #1829015 - CVE-2020-11758 mingw-OpenEXR: OpenEXR: out-of-bounds read in ImfOptimizedPixelReading.h [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829015 [ 9 ] Bug #1829018 - CVE-2020-11759 mingw-OpenEXR: OpenEXR: out-of-bounds write due to integer overflows in CompositeDeepScanLine::Data::handleDeepFrameBuffer and readSampleCountForLineBlock [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829018 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e244f22a51' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This notification outlines the CentOS update CENTOS-2020-b37d2f19b8, which resolves memory corruption issues in mingw-OpenCV.. OpenEXR Update, Fedora Security, Out-Of-Bounds Access Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2020 Important Fedora
89

Fedora 23: 2015-13668fff74 Moderate: Mingw-Libpng Buffer Overflow Fix

libpng 1.6.19 release, fixing CVE-2015-8126. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-13668fff74 2015-11-27 16:47:54.519073 -------------------------------------------------------------------------------- Name : mingw-libpng Product : Fedora 23 Version : 1.6.19 Release : 1.fc23 URL : http://www.libpng.org/pub/png/ Summary : MinGW Windows Libpng library Description : MinGW Windows Libpng library. -------------------------------------------------------------------------------- Update Information: libpng 1.6.19 release, fixing CVE-2015-8126 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1281756 - CVE-2015-8126 libpng: Buffer overflow vulnerabilities in png_get_PLTE/png_set_PLTE functions https://bugzilla.redhat.com/show_bug.cgi?id=1281756 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mingw-libpng' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 23 has issued a critical security patch targeting a buffer overflow vulnerability in mingw-libpng linked to CVE-2015-8126. This is a significant update.. libpng security,Fedora updates,mingw library fix,buffer overflow patches,software vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 27, 2015 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200