Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 33: 2021-888ccfd5b6 Critical: Python-Impacket Path Traversal

Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-888ccfd5b6 2021-05-16 02:06:09.511375 --------------------------------------------------------------------------------Name : python-impacket Product : Fedora 33 Version : 0.9.22 Release : 3.fc33 URL : https://github.com/fortra/impacket Summary : Collection of Python classes providing access to network packets Description : Impacket is a collection of Python classes focused on providing access to network packets. Impacket allows Python developers to craft and decode network packets in simple and consistent manner. It is highly effective when used in conjunction with a packet capture utility or package such as Pcapy. Packets can be constructed from scratch, as well as parsed from raw data. Furthermore, the object oriented API makes it simple to work with deep protocol hierarchies. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22 --------------------------------------------------------------------------------ChangeLog: * Fri May 7 2021 Michal Ambroz - 0.9.22-3 - fix CVE-2021-31800 - #1957428, #1957427 during 0.9.22 lifecycle * Sun May 2 2021 Michal Ambroz - 0.9.22-2 - fix dependencies for EPEL7 as of #1893859 * Wed Apr 14 2021 Michal Ambroz - 0.9.22-1 - Updated to new upstream release 0.9.22 - modernize specfile with bconds - upstream patch for python39 compatibility (needed for FC34+) * Wed Jan 27 2021 Fedora Release Engineering - 0.9.21-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1957426 - CVE-2021-31800 python-impacket: Multiple path traversal vulnerabilities in smbserver.py https://bugzilla.redhat.com/show_bug.cgi?id=1957426 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-888ccfd5b6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Tackling directory traversal vulnerabilities in python-impacket on Fedora 33, incorporating significant upgrades that bolster security measures and improve functionality.. python-impacket,Fedora 33,security fix,path traversal,network packets. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2021 Critical Fedora
89

Fedora 34: 2021-52dfb60726 Critical: Python-Impacket Path Traversal

Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-52dfb60726 2021-05-16 02:01:05.994424 --------------------------------------------------------------------------------Name : python-impacket Product : Fedora 34 Version : 0.9.22 Release : 3.fc34 URL : https://github.com/fortra/impacket Summary : Collection of Python classes providing access to network packets Description : Impacket is a collection of Python classes focused on providing access to network packets. Impacket allows Python developers to craft and decode network packets in simple and consistent manner. It is highly effective when used in conjunction with a packet capture utility or package such as Pcapy. Packets can be constructed from scratch, as well as parsed from raw data. Furthermore, the object oriented API makes it simple to work with deep protocol hierarchies. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-31800 - #1957428, #1957427 - fix path traversal in smbserver.py ---- Updated to new upstream release 0.9.22 --------------------------------------------------------------------------------ChangeLog: * Fri May 7 2021 Michal Ambroz - 0.9.22-3 - fix CVE-2021-31800 - #1957428, #1957427 during 0.9.22 lifecycle * Sun May 2 2021 Michal Ambroz - 0.9.22-2 - fix dependencies for EPEL7 as of #1893859 * Wed Apr 14 2021 Michal Ambroz - 0.9.22-1 - Updated to new upstream release 0.9.22 - modernize specfile with bconds - upstream patch for python39 compatibility (needed for FC34+) * Wed Jan 27 2021 Fedora Release Engineering - 0.9.21-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1957426 - CVE-2021-31800 python-impacket: Multiple path traversal vulnerabilities in smbserver.py https://bugzilla.redhat.com/show_bug.cgi?id=1957426 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-52dfb60726' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Critical patch for directory traversal vulnerability in python-impacket on Fedora, mitigating CVE-2021-31800. Apply the update immediately!. Python Impacket,Fedora Update,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2021 Critical Fedora
98

RedHat OpenShift 4.5.16 RHSA-2020:4320 Low: Network Packet Issue Fix

Red Hat OpenShift Container Platform release 4.5.16 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: OpenShift Container Platform 4.5.16 security update Advisory ID: RHSA-2020:4320-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2020:4320 Issue date: 2020-10-26 CVE Names: CVE-2020-14336 ==================================================================== 1. Summary: Red Hat OpenShift Container Platform release 4.5.16 is now available with updates to packages and images that fix several bugs and add enhancements. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Red Hat OpenShift Container Platform is Red Hat's cloud computing Kubernetes application platform solution designed for on-premise or private cloud deployments. Security Fix(es): * openshift: Restricted SCC allows pods to craft custom network packets (CVE-2020-14336) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For OpenShift Container Platform 4.5 see the following documentation, which will be updated shortly for this release, for important instructions on how to upgrade your cluster and fully apply this asynchronous errataupdate: https://docs.redhat.com/en/documentation/openshift_container_platform/4.5/html/release_notes/ocp-4-5-release-notes Details on how to access this content are available at - -cli.html. 4. Bugs fixed (https://bugzilla.redhat.com/): 1856529 - CVE-2020-14336 ose-machine-config-operator-container: openshift: restricted SCC allows pods to craft custom network packets [openshift-4] 1858981 - CVE-2020-14336 openshift: restricted SCC allows pods to craft custom network packets 5. References: https://access.redhat.com/security/cve/CVE-2020-14336 https://access.redhat.com/security/updates/classification/#low 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX5bghtzjgjWX9erEAQgpAQ/+PDKD81hbLiUf9C7EPfyPnFmCkxQF1e2/ ecpKivZjK2Ekgb6T0Ryj99o3H+pZ3rNcltSSZ3BiMqSQ2TEWAPBETKmWSvXokfBi Mdh/CJhbRg8xbjk3AkdhLsZO5tPjASx+ZIE+vf2GDrj5pQcPLhdTbNNl3O6C8bmQ v7VrQud+kVruREusBmVWg1HTa4bG7LAUv3kQg8aoGtnJseSd/IhbAXqshR5tL2r5 WGQ0C/GWByabVUPhQbJcNe9xP7M+H5yZWTUbAWOzSderQaFyS25uOdJo3TO3lKnR dg2c6LXj5+SVSQgSQlaUka+du2k4KYwQZfBPsnEf5c7c5XmY1LoDgFkoFhbetHRN rECJlAwBnubrpd68MVEP9uU9ujCmUhBBqfJ8YpOu6Qr78JMtHpIFXZ+gJ1WgR/AU FcTAvu9ou93es66gCfxI31RjnLaiL4DWtfMoZQ6H+7tR/O0wMHs5cgm0zWICvL3x jHOdeqy118Sn9ZbfPr975d3AbDBDdz+qQrTd99Rg8068xxPjtMED0Uptsn5GAGRJ mFlWBOpyRSL1QOjM4I80UhL1IrDBtkGf7x2XTb8dmAD0lg71qLOQcosQmGmNcwSA l7beFbrjvWV+KQScXD80MbB7PzUFdMbr55ycqwyNmHLqhZP82hSS1/CaTiQ/coxW ShBj5Z9Ua1E=Kg/D -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhancements in OpenShift Container Platform version 4.5.16 boost security measures with minimal disruption while addressing existing issues.. OpenShift Container Update, Red Hat Security, Container Platform Release, OpenShift Security Fix. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Oct 26, 2020 Low Red Hat
87

Ubuntu: USN-4763-1 Moderate: Teeworlds Service Disruption

It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4763-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 14, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : teeworlds CVE ID : CVE-2020-12066 It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. For the stable distribution (buster), this problem has been fixed in version 0.7.2-5+deb10u1. We recommend that you upgrade your teeworlds packages. For the detailed security status of teeworlds please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/teeworlds Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Inadequate validation of incoming network data in Teeworlds poses risks for denial-of-service attacks. It's crucial to update Teeworlds to enhance its security measures.. Teeworlds Security Update, Debian Advisory, Denial Of Service. . LinuxSecurity.com Team

Calendar 2 Sep 14, 2020 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here