Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 22.04 LTS: USN-7552-1 critical: Wireshark DoS fixes

Several security issues were fixed in Wireshark.. ========================================================================== Ubuntu Security Notice USN-7552-1 June 04, 2025 wireshark vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Wireshark. Software Description: - wireshark: network traffic analyzer Details: It was discovered that Wireshark did not correctly handle recursion. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-39929) Roman Donchenko discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4182) It was discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2021-4185, CVE-2022-0581) It was discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-4186) Sharon Brizinov discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issueto cause a denial of service. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2022-0582, CVE-2022-0583, CVE-2022-0586) Sharon Brizinov discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2022-0585) Jason Cohen discovered that Wireshark did not correctly handle parsing certain files. If a user or system were tricked into opening a specially crafted file, an attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-3190) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS libwireshark15 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro tshark 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro wireshark 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro wireshark-common 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro wireshark-gtk 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro wireshark-qt 3.6.2-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS libwireshark13 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro tshark 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro wireshark 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro wireshark-common 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro wireshark-gtk 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro wireshark-qt 3.2.3-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS libwireshark11 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro tshark 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro wireshark 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro wireshark-common 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro wireshark-gtk 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro wireshark-qt 2.6.10-1~ubuntu18.04.0+esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS libwireshark11 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro tshark 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro wireshark 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro wireshark-common 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro wireshark-gtk 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro wireshark-qt 2.6.10-1~ubuntu16.04.0+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS libwireshark11 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro tshark 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro wireshark 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro wireshark-common 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro wireshark-gtk 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro wireshark-qt 2.6.10-1~ubuntu14.04.0~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7552-1 CVE-2021-39929, CVE-2021-4182, CVE-2021-4185, CVE-2021-4186, CVE-2022-0581, CVE-2022-0582, CVE-2022-0583, CVE-2022-0585, CVE-2022-0586, CVE-2022-3190 . Multiple security vulnerabilities have been addressed in Wireshark impacting various versions of Ubuntu LTS. Ensure your system is current for enhanced protection.. Wireshark Security Issues, Ubuntu Updates, DoS Exploit, Network Analyzer Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 05, 2025 Critical Ubuntu
89

Fedora 40: Security Advisory FEDORA-2024-5aad2fda6a for chisel TCP tunnel

Update to new upstream version (closes rhbz#2303131). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5aad2fda6a 2024-09-26 02:43:43.727628 -------------------------------------------------------------------------------- Name : chisel Product : Fedora 40 Version : 1.10.0 Release : 1.fc40 URL : https://github.com/jpillora/chisel Summary : TCP tunnel over HTTP Description : A fast TCP tunnel over HTTP. -------------------------------------------------------------------------------- Update Information: Update to new upstream version (closes rhbz#2303131) -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 17 2024 Fabian Affolter - 1.10.0-1 - Update to new upstream version (closes rhbz#2303131) - Set version (closes rhbz#2265825) - Fix CVE-2024-43798 (closes rhbz#2308435, closes rhbz#2308436) * Wed Jul 17 2024 Fedora Release Engineering - 1.9.1-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2265825 - Version is 0.0.0-src https://bugzilla.redhat.com/show_bug.cgi?id=2265825 [ 2 ] Bug #2303131 - chisel-1.10.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2303131 [ 3 ] Bug #2308435 - CVE-2024-43798 chisel: From NVD collector [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2308435 [ 4 ] Bug #2308436 - CVE-2024-43798 chisel: From NVD collector [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2308436 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5aad2fda6a' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Chisel TCP tunnel enhancement for Fedora 40 to version 1.10.0 tackling major vulnerability and improving efficiency.. Fedora Updates, Chisel TCP Tunnel, Security Advisory, Software Upgrade, Networking Tool. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 26, 2024 Important Fedora
98

Red Hat 8.0 RHSA-2005:001-00 Moderate: Gnome-Lokkit Firewall Patch

Updated Gnome-lokkit packages fix missing FORWARD ruleset in Red Hat Linux 8.0.. `` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated Gnome-lokkit packages fix vulnerability Advisory ID: RHSA-2003:072-00 Issue date: 2003-03-17 Updated on: 2003-03-17 Product: Red Hat Linux Keywords: iptables forward lokkit Cross references: Obsoletes: CVE Names: CAN-2003-0080 --------------------------------------------------------------------- 1. Topic: Updated Gnome-lokkit packages fix missing FORWARD ruleset in Red Hat Linux 8.0 2. Relevant releases/architectures: Red Hat Linux 8.0 - i386 3. Problem description: Gnome-lokkit is a utility that provides firewalling for the average Linux end user based on responses to a small number of simple questions. Red Hat made modifications to Gnome-lokkit to support firewalls based on iptables instead of ipchains. In Red Hat Linux 8.0, the iptables ruleset created by Gnome-lokkit did not place any rules on the FORWARD chain. This is a security vulnerability if an administrator enables packet forwarding and uses an unmodified ruleset created by the Gnome-lokkit tool. Users are advised to upgrade to these erratum packages which contain a patch to Gnome-lokkit to also apply the INPUT chain ruleset to the FORWARD chain. Red Hat would like to thank Deneb Meketa for bringing this issue to our attention. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please notethat this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 84975 - does not include FORWARD chain 6. RPMs required: Red Hat Linux 8.0: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 5e5edd316950132ec84f9c727dac63f6 8.0/en/os/SRPMS/gnome-lokkit-0.50-21.8.0.src.rpm 01f42937db89e8afb3f30a704e52ca7f 8.0/en/os/i386/gnome-lokkit-0.50-21.8.0.i386.rpm 0f80d90d4766f04eef08928b33b6a25e 8.0/en/os/i386/lokkit-0.50-21.8.0.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at About You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. References: CVE -CVE-2003-0080 9. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: ``. Revised Gnome-lokkit packages fix missing FORWARD ruleset vulnerabilities in Red Hat Linux 8.0 for enhanced security.. Gnome-Lokkit Firewall, Red Hat Networking, Forward Ruleset Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 17, 2003 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here