Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 40: FEDORA-2024-ee96e0c470 Critical: Libvirt Event Loop Update

Fix crash in event loop (CVE-2024-4418) Fix leak of GSource object Fix leak of udev object reference. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-ee96e0c470 2024-06-11 01:48:54.482850 -------------------------------------------------------------------------------- Name : libvirt Product : Fedora 40 Version : 10.1.0 Release : 2.fc40 URL : https://libvirt.org/ Summary : Library providing a simple virtualization API Description : Libvirt is a C toolkit to interact with the virtualization capabilities of recent versions of Linux (and other OSes). The main package includes the libvirtd server exporting the virtualization support. -------------------------------------------------------------------------------- Update Information: Fix crash in event loop (CVE-2024-4418) Fix leak of GSource object Fix leak of udev object reference -------------------------------------------------------------------------------- ChangeLog: -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278616 - CVE-2024-4418 libvirt: stack use-after-free in virNetClientIOEventLoop() https://bugzilla.redhat.com/show_bug.cgi?id=2278616 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-ee96e0c470' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The latest Fedora libvirt revision addresses critical crash problems and memory leaks, incorporating necessary security updates to ensure user protection.. Fedora Libvirt Security Update, Critical Fixes, Event Loop Crash Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 11, 2024 Critical Fedora
89

Debian 11: 2023-b1854ff321 Important: Python-Django Security Update

Security fix for CVE-2015-7581 Security fix for CVE-2016-0751 Security fix for CVE-2015-7576. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f486068393 2016-02-28 08:31:31.054902 -------------------------------------------------------------------------------- Name : rubygem-actionpack Product : Fedora 23 Version : 4.2.3 Release : 4.fc23 URL : https://rubyonrails.org/ Summary : Web-flow and rendering framework putting the VC in MVC Description : Eases web-request routing, handling, and response as a half-way front, half-way page controller. Implemented with specific emphasis on enabling easy unit/integration testing that doesn't require a browser. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7581 Security fix for CVE-2016-0751 Security fix for CVE-2015-7576 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1301933 - CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller https://bugzilla.redhat.com/show_bug.cgi?id=1301933 [ 2 ] Bug #1301946 - CVE-2016-0751 rubygem-actionpack: possible object leak and denial of service attack in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301946 [ 3 ] Bug #1301981 - CVE-2015-7581 rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301981 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionpack' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Essential security patches for rubygem-actionpack targeting various weaknesses in Fedora 23.. Fedora Security, Actionpack Update, Web Framework Security, CVE Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 28, 2016 Important Fedora
89

Fedora 22: Security Notice Regarding Rubygem-Activemodel CVE-2015-7581

Security fix for CVE-2015-7581 CVE-2015-7576 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-94e71ee673 2016-02-28 04:00:02.128575 -------------------------------------------------------------------------------- Name : rubygem-activemodel Product : Fedora 22 Version : 4.2.0 Release : 2.fc22 URL : https://rubyonrails.org/ Summary : A toolkit for building modeling frameworks Description : Rich support for attributes, callbacks, validations, observers, serialization, internationalization, and testing. It provides a known set of interfaces for usage in model classes. It also helps building custom ORMs for use outside of the Rails framework. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7581 CVE-2015-7576 CVE-2016-0751 CVE-2016-0752 CVE-2016-0753 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1301973 - CVE-2016-0753 rubygem-activemodel, rubygem-activerecord: possible input validation circumvention in Active Model https://bugzilla.redhat.com/show_bug.cgi?id=1301973 [ 2 ] Bug #1301933 - CVE-2015-7576 rubygem-actionpack: Timing attack vulnerability in basic authentication in Action Controller https://bugzilla.redhat.com/show_bug.cgi?id=1301933 [ 3 ] Bug #1301946 - CVE-2016-0751 rubygem-actionpack: possible object leak and denial of service attack in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301946 [ 4 ] Bug #1301981 - CVE-2015-7581 rubygem-actionpack: Object leak vulnerability for wildcard controller routes in Action Pack https://bugzilla.redhat.com/show_bug.cgi?id=1301981 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activemodel' at the command line. Formore information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 23 security patch for rubygem-activerecord tackles serious vulnerabilities that involve data sanitization and resource mismanagement.. rubygem-activemodel, Fedora 22, security update, input validation, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 28, 2016 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here