Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 25 Security Advisory: Mojarra 2.2.13 Critical XSS Fix

update to 2.2.13. fix CVE-2013-5855 rhbz#1087182,1065139. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-d6c87eb4af 2016-10-09 02:40:57.468639 -------------------------------------------------------------------------------- Name : mojarra Product : Fedora 25 Version : 2.2.13 Release : 1.fc25 URL : https://javaee.github.io/javaserverfaces-spec/ Summary : JSF Reference Implementation Description : JvaServer(TM) Faces technology simplifies building user interfaces for JavaServer applications. Developers of various skill levels can quickly build web applications by: assembling reusable UI components in a page; connecting these components to an application data source; and wiring client-generated events to server-side event handlers. -------------------------------------------------------------------------------- Update Information: update to 2.2.13. fix CVE-2013-5855 rhbz#1087182,1065139 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1065139 - CVE-2013-5855 Mojarra JSF: XSS due to insufficient escaping of user-supplied content in outputText tags and EL expressions https://bugzilla.redhat.com/show_bug.cgi?id=1065139 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mojarra' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 25 haslaunched an important Mojarra update to fix a major XSS vulnerability. Users should check the update notes and adhere to the installation guidelines for security. Mojarra Update, Fedora Security, XSS Fix, Software Patch, JavaServer Faces. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 09, 2016 Critical Fedora
87

Debian: DSA-2360-1 Vital: Hibernate Remote Code Execution Vulnerability

It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParameters is set to true. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2359-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer December 06, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mojarra Vulnerability : EL injection Problem type : remote Debian-specific: no CVE ID : CVE-2011-4358 It was discovered that Mojarra, an implementation of JavaServer Faces, evaluates untrusted values as EL expressions if includeViewParametersis set to true. For the stable distribution (squeeze), this problem has been fixed in version 2.0.3-1+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 2.0.3-2. We recommend that you upgrade your mojarra packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Unapproved inputs in Mojarra interpreted as EL statements; update advised for security patch.. Mojarra, JavaServer Faces, EL Injection, Debian Security, Remote Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 06, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here