Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat Enterprise Linux 7.7: RHSA-2021:1026-01 Moderate NSS Softokn Issue

An update for nss-softokn is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: nss-softokn security update Advisory ID: RHSA-2021:1026-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:1026 Issue date: 2021-03-30 CVE Names: CVE-2019-11756 CVE-2019-17006 CVE-2020-12403 ==================================================================== 1. Summary: An update for nss-softokn is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - ppc64, ppc64le, s390x, x86_64 3. Description: The nss-softokn package provides the Network Security Services Softoken Cryptographic Module. Security Fix(es): * nss: Use-after-free in sftk_FreeSession due to improper refcounting (CVE-2019-11756) * nss: Check length of inputs for cryptographic primitives (CVE-2019-17006) * nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read (CVE-2020-12403) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to applythis update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1774835 - CVE-2019-11756 nss: Use-after-free in sftk_FreeSession due to improper refcounting 1775916 - CVE-2019-17006 nss: Check length of inputs for cryptographic primitives 1868931 - CVE-2020-12403 nss: CHACHA20-POLY1305 decryption with undersized tag leads to out-of-bounds read 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.7): Source: nss-softokn-3.44.0-9.el7_7.src.rpm x86_64: nss-softokn-3.44.0-9.el7_7.i686.rpm nss-softokn-3.44.0-9.el7_7.x86_64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-3.44.0-9.el7_7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): x86_64: nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-devel-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.7): Source: nss-softokn-3.44.0-9.el7_7.src.rpm ppc64: nss-softokn-3.44.0-9.el7_7.ppc.rpm nss-softokn-3.44.0-9.el7_7.ppc64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc64.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc64.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc64.rpm ppc64le: nss-softokn-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-devel-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-freebl-3.44.0-9.el7_7.ppc64le.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.ppc64le.rpm s390x: nss-softokn-3.44.0-9.el7_7.s390.rpm nss-softokn-3.44.0-9.el7_7.s390x.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.s390.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.s390x.rpm nss-softokn-devel-3.44.0-9.el7_7.s390.rpm nss-softokn-devel-3.44.0-9.el7_7.s390x.rpm nss-softokn-freebl-3.44.0-9.el7_7.s390.rpm nss-softokn-freebl-3.44.0-9.el7_7.s390x.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.s390.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.s390x.rpm x86_64: nss-softokn-3.44.0-9.el7_7.i686.rpm nss-softokn-3.44.0-9.el7_7.x86_64.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.i686.rpm nss-softokn-debuginfo-3.44.0-9.el7_7.x86_64.rpm nss-softokn-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-devel-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-3.44.0-9.el7_7.x86_64.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.i686.rpm nss-softokn-freebl-devel-3.44.0-9.el7_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2019-11756 https://access.redhat.com/security/cve/CVE-2019-17006 https://access.redhat.com/security/cve/CVE-2020-12403 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYGLw6tzjgjWX9erEAQil5RAAk4SQyOwg4jjHXl8KvhhYyhjeC6KIYb5g ojisBr4cVKjGo1fMVZTfpg8DE2OTHetZfiQ0BVSkEMXPxr+nuT+p+qxQIyiq2Idb uDzO+ttBUdPiTYEFMNodbrit0x9nhpgH6eJ4hQ90hRRBah6DxftOKde36MuozKkg GZ4+JHf8UoJo6LX7lwz4sMTWOtIdOo3fsknxiLAVC7IUFURm5wXNhhgobSQSpiou WFlMeTfqBT7A9ZNzh2DEAv80ltUDp/z6qEqRCvk1VkVfR/JYzUGbWZWjmbL0Srs2 kscz1yRIJSeeT5IlUsvZDTQYZ2XBJotynMPlDc4y51FraFuBZu5gg5lLqhQXhpnz 10H9xVKrDbXkHPFEzinE6WzcowTdlTlicPaWLtWpvDQO0n0dWZyX64wP3Ym7/8kK mdTaX5HS5YdHBWSy9FF4pVzJdM8TOkNKTqaMQikSAav3/UNAeL5l3SVgLXjSPgh9 Fe4GiPJG2PU6aPmYHzSZAPvoxCA6NXm+N4eNnZL7mMFQc33Y9QcbFJpNr8/5ROMm LZvGerUbwlLnavZFkhrr2Rvj9pdgXLWGCNP8SH/AiErfy+3dFOWQlAqy5CNnepBW Y/swsuMBspTe4aMqsefOnbCFrHbGYKgZPsLsLnzByBuqemtn5SrAgh1TWOAqfmHx +Pi1slDSt2U=Y2VV -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . A new version of nss-softokn has been released for Red Hat Enterprise Linux 7.7, classified as Moderate. It is recommended to install this update to enhance system security.. NSS Softokn Update, Red Hat 7.7 Security, Linux Software Patch. . LinuxSecurity.com Team

Calendar 2 Mar 30, 2021 Red Hat
89

Fedora 27: FEDORA-2018-4a21a8ca59 Critical: nss-softokn Security Fix

Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-4a21a8ca59 2018-09-18 07:52:14.644261 --------------------------------------------------------------------------------Name : nss-softokn Product : Fedora 27 Version : 3.39.0 Release : 1.0.fc27 URL : https://firefox-source-docs.mozilla.org/security/nss/index.html Summary : Network Security Services Softoken Module Description : Network Security Services Softoken Cryptographic Module --------------------------------------------------------------------------------Update Information: Updates the nss family of packages to upstream NSPR 4.20 and NSS 3.39. For details about new functionality and a list of bugs fixed in this release please see the upstream release notes --------------------------------------------------------------------------------ChangeLog: * Mon Sep 3 2018 Daiki Ueno - 3.39.0-1.0 - Update to NSS 3.39 * Tue Jul 3 2018 Daiki Ueno - 3.38.0-1.0 - Update to NSS 3.38 * Tue Jun 5 2018 Daiki Ueno - 3.37.3-1.0 - Update to NSS 3.37.3 * Thu Apr 19 2018 Daiki Ueno - 3.36.1-1.0 - Update to NSS 3.36.1 * Fri Mar 9 2018 Daiki Ueno - 3.36.0-1.0 - Update to NSS 3.36.0 * Wed Feb 7 2018 Daiki Ueno - 3.35.0-1.0 - Update to NSS 3.35.0 - Set NSS_FORCE_FIPS in %build * Tue Nov 14 2017 Daiki Ueno - 3.34.0-1.0 - Update to NSS 3.34.0 * Wed Oct 18 2017 Daiki Ueno - 3.33.0-1.1 - Add explicit version dependency from -freebl, on nspr and nss-util --------------------------------------------------------------------------------References: [ 1 ] Bug #1624704 - CVE-2018-12384 nss: ServerHello.random is all zeros when handling a v2-compatible ClientHello [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1624704 [ 2 ]Bug #1620207 - Enable SSLKEYLOGFILE support https://bugzilla.redhat.com/show_bug.cgi?id=1620207 [ 3 ] Bug #1578106 - Package version is invalid, or no Source URL provided https://bugzilla.redhat.com/show_bug.cgi?id=1578106 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-4a21a8ca59' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 27 enhances the nss-softokn package with crucial security enhancements. Discover the latest features and resolved issues.. NSS Softoken Update,Fedora 27 Security,Network Security Services. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 18, 2018 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here