Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
217

Oracle Linux 9: ELSA-2025-1330 Important Security Advisory for OpenSSL

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-1330 http://linux.oracle.com/errata/ELSA-2025-1330.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: openssl-3.2.2-6.0.1.el9_5.1.x86_64.rpm openssl-devel-3.2.2-6.0.1.el9_5.1.i686.rpm openssl-devel-3.2.2-6.0.1.el9_5.1.x86_64.rpm openssl-libs-3.2.2-6.0.1.el9_5.1.i686.rpm openssl-libs-3.2.2-6.0.1.el9_5.1.x86_64.rpm openssl-perl-3.2.2-6.0.1.el9_5.1.x86_64.rpm aarch64: openssl-3.2.2-6.0.1.el9_5.1.aarch64.rpm openssl-devel-3.2.2-6.0.1.el9_5.1.aarch64.rpm openssl-libs-3.2.2-6.0.1.el9_5.1.aarch64.rpm openssl-perl-3.2.2-6.0.1.el9_5.1.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//openssl-3.2.2-6.0.1.el9_5.1.src.rpm Related CVEs: CVE-2024-12797 Description of changes: [3.2.2-6.0.1.1] - Enable openssl-fips-provider dependency [Orabug: 36504822] - Temporary disable openssl-fips-provider dependency [Orabug: 36504822] - Replace upstream references [Orabug: 34340177] [1:3.2.2-6.1] - RFC7250 handshakes with unauthenticated servers don't abort as expected (CVE-2024-12797) Resolves: RHEL-76755 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux updates OpenSSL in advisory ELSA-2025-1330. Address issues quickly through the Unbreakable Linux Network.. Oracle Linux, OpenSSL, Security Advisory, Software Update, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 13, 2025 Important Oracle
89

Fedora 38 Update: Keyring-Ima-Signer Fixes Tokio and OpenSSL Issues

Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) - `h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`:. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-cc21019773 2023-05-07 01:19:58.787245 --------------------------------------------------------------------------------Name : keyring-ima-signer Product : Fedora 38 Version : 0.1.0 Release : 9.fc38 URL : https://github.com/fedora-iot/keyring-ima-signer/ Summary : An IMA file signing tool using the kernel keyring Description : The IMA (Integrity Measurement Architecture) is a key component of the Linux integrity subsystem designed to ensure integrity, authenticity, and confidentiality of systems including hardware root of trusts (TPM). This tool allows signing of files in userspace, inclusding options of including the signature in xattr or a .sig file, using signing keys stored in the kernel keyring to ensure they're not recoverable. --------------------------------------------------------------------------------Update Information: Recent updates for the `tokio`, `h2`, and `openssl` crates addressed some (potential or confirmed) security or soundness issues: - `tokio`: [RUSTSEC-2023-0005](https://rustsec.org/advisories/RUSTSEC-2023-0005.html) -`h2`: [RUSTSEC-2023-0034](https://rustsec.org/advisories/RUSTSEC-2023-0034.html) / [CVE-2023-26964](https://nvd.nist.gov/vuln/detail/CVE-2023-26964) - `openssl`: [RUSTSEC-2023-0022](https://rustsec.org/advisories/RUSTSEC-2023-0022.html), [RUSTSEC-2023-0023](https://rustsec.org/advisories/RUSTSEC-2023-0023.html), [RUSTSEC-2023-0024](https://rustsec.org/advisories/RUSTSEC-2023-0024.html) This update contains rebuilds of allaffected applications against the latest versions of these crates, which have addressed all linked issues. --------------------------------------------------------------------------------ChangeLog: * Wed May 3 2023 Fabio Valentini - 0.1.0-9 - Rebuild for openssl crate > = v0.10.48 (RUSTSEC-2023-{0022,0023,0024}) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cc21019773' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Keyring-ima-signer in Fedora 38 has received patches to fix vulnerabilities in essential components such as tokio and openssl.. Fedora 38,keyring-ima-signer,application update,tokio security,openssl patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2023 Critical Fedora
100

SUSE: 2023:974-1 Moderate: bci/bci-init Security Update Details

The container bci/bci-init was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-init ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:974-1 Container Tags : bci/bci-init:15.4 , bci/bci-init:15.4.26.24 , bci/bci-init:latest Container Release : 26.24 Severity : moderate Type : security References : 1209624 CVE-2023-0464 ----------------------------------------------------------------- The container bci/bci-init was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:1745-1 Released: Tue Apr 4 09:05:23 2023 Summary: Security update for openssl-1_1 Type: security Severity: moderate References: 1209624,CVE-2023-0464 This update for openssl-1_1 fixes the following issues: - CVE-2023-0464: Fixed excessive Resource Usage Verifying X.509 Policy Constraints (bsc#1209624). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2023:1753-1 Released: Tue Apr 4 11:55:00 2023 Summary: Recommended update for systemd-presets-common-SUSE Type: recommended Severity: moderate References: This update for systemd-presets-common-SUSE fixes the following issue: - Enable systemd-pstore.service by default (jsc#PED-2663) The following package changes have been done: - libopenssl1_1-1.1.1l-150400.7.31.2 updated - libopenssl1_1-hmac-1.1.1l-150400.7.31.2 updated - systemd-presets-common-SUSE-15-150100.8.20.1 updated - container:sles15-image-15.0.0-27.14.48 updated . The latest security enhancement for bci/bci-init features fixes for several moderate risk vulnerabilities associated with the openssl library and the systemd management suite.. bci/bci-init,openssl update,container security,systemd update. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2023 SuSE
99

Slackware: SSA:2022-124-02 critical: OpenSSL Command Injection Risk

New openssl packages are available for Slackware 14.2, 15.0, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openssl (SSA:2022-124-02) New openssl packages are available for Slackware 14.2, 15.0, and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openssl-1.1.1o-i586-1_slack15.0.txz: Upgraded. Fixed a bug in the c_rehash script which was not properly sanitising shell metacharacters to prevent command injection. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-1292 (* Security fix *) patches/packages/openssl-solibs-1.1.1o-i586-1_slack15.0.txz: Upgraded. +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 14.2: Updated packages for Slackware x86_64 14.2: Updated packages for Slackware 15.0: Updated packages for Slackware x86_64 15.0: Updated packages for Slackware -current: Updated packages for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.2 packages: 9152e3d7dc57a263630b86f74b2dcb91 openssl-1.0.2u-i586-3_slack14.2.txz ff64c1be7a00a674e7b5e7daabdafb62 openssl-solibs-1.0.2u-i586-3_slack14.2.txz Slackware x86_64 14.2 packages: f00cdddf44ff89a9902d5ce698b96f9c openssl-1.0.2u-x86_64-3_slack14.2.txz c99427cc179aeadd4a7c1f2517870404 openssl-solibs-1.0.2u-x86_64-3_slack14.2.txz Slackware 15.0 packages: 251f23dfa198e5bfadd1d574fef23d69 openssl-1.1.1o-i586-1_slack15.0.txz a8ac31ef7af72e7a769e72716b61fab8 openssl-solibs-1.1.1o-i586-1_slack15.0.txz Slackware x86_64 15.0 packages: ac4876a340d1b2955577e0cf38f08373 openssl-1.1.1o-x86_64-1_slack15.0.txz 8c356653b569136b28a78dbd1030af06 openssl-solibs-1.1.1o-x86_64-1_slack15.0.txz Slackware -current packages: 5a1dfe896b159dea87cacc60a28ffd31 a/openssl-solibs-1.1.1o-i586-1.txz 26455879c333f25e50ff1367bf56ad11 n/openssl-1.1.1o-i586-1.txz Slackware x86_64 -current packages: 0dc2e79b2d7e471eef4a79ac93aae505 a/openssl-solibs-1.1.1o-x86_64-1.txz 724e66c1980f5dfbd664401740e0d2f8 n/openssl-1.1.1o-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg openssl-1.1.1o-i586-1_slack15.0.txz openssl-solibs-1.1.1o-i586-1_slack15.0.txz +-----+ . Updated OpenSSL versions for Slackware 14.2, 15.0, and -current effectively mitigate critical vulnerabilities.. OpenSSL Update, Slackware Packages, Command Injection Fix, Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 04, 2022 Critical Slackware
100

SUSE: 2022:283-1 Important: Chrony and OpenSSL Security Updates

The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:283-1 Container Tags : suse/sle15:15.0 , suse/sle15:15.0.4.22.529 Container Release : 4.22.529 Severity : important Type : security References : 1099272 1115529 1128846 1162964 1172113 1173277 1174075 1174911 1180689 1180995 1181826 1182959 1187906 1190926 1193805 1194229 1195149 1195792 1195856 1196877 1197004 CVE-2020-14367 CVE-2022-0778 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:845-1 Released: Tue Mar 15 11:40:52 2022 Summary: Security update for chrony Type: security Severity: moderate References: 1099272,1115529,1128846,1162964,1172113,1173277,1174075,1174911,1180689,1181826,1187906,1190926,1194229,CVE-2020-14367 This update for chrony fixes the following issues: Chrony was updated to 4.1, bringing features and bugfixes. Update to 4.1 * Add support for NTS servers specified by IP address (matching Subject Alternative Name in server certificate) * Add source-specific configuration of trusted certificates * Allow multiple files and directories with trusted certificates * Allow multiple pairs of server keys and certificates * Add copy option to server/pool directive * Increase PPS lock limit to 40% of pulse interval * Perform source selection immediately after loading dump files * Reload dump files for addresses negotiated by NTS-KE server * Update seccomp filter and add less restrictive level * Restart ongoing name resolution on online command * Fix dump files to not include uncorrected offset * Fix initstepslew toaccept time from own NTP clients * Reset NTP address and port when no longer negotiated by NTS-KE server - Ensure the correct pool packages are installed for openSUSE and SLE (bsc#1180689). - Fix pool package dependencies, so that SLE prefers chrony-pool-suse over chrony-pool-empty. (bsc#1194229) - Enable syscallfilter unconditionally [bsc#1181826]. Update to 4.0 - Enhancements - Add support for Network Time Security (NTS) authentication - Add support for AES-CMAC keys (AES128, AES256) with Nettle - Add authselectmode directive to control selection of unauthenticated sources - Add binddevice, bindacqdevice, bindcmddevice directives - Add confdir directive to better support fragmented configuration - Add sourcedir directive and 'reload sources' command to support dynamic NTP sources specified in files - Add clockprecision directive - Add dscp directive to set Differentiated Services Code Point (DSCP) - Add -L option to limit log messages by severity - Add -p option to print whole configuration with included files - Add -U option to allow start under non-root user - Allow maxsamples to be set to 1 for faster update with -q/-Q option - Avoid replacing NTP sources with sources that have unreachable address - Improve pools to repeat name resolution to get 'maxsources' sources - Improve source selection with trusted sources - Improve NTP loop test to prevent synchronisation to itself - Repeat iburst when NTP source is switched from offline state to online - Update clock synchronisation status and leap status more frequently - Update seccomp filter - Add 'add pool' command - Add 'reset sources' command to drop all measurements - Add authdata command to print details about NTP authentication - Add selectdata command to print details about source selection - Add -N option and sourcename command to print original names of sources - Add -a option to some commands to print also unresolved sources - Add -k, -p, -r options to clients command to select, limit, reset data - Bug fixes - Don’t set interface for NTP responses to allow asymmetric routing - Handle RTCs that don’t support interrupts - Respond to command requests with correct address on multihomed hosts - Removed features - Drop support for RIPEMD keys (RMD128, RMD160, RMD256, RMD320) - Drop support for long (non-standard) MACs in NTPv4 packets (chrony 2.x clients using non-MD5/SHA1 keys need to use option 'version 3') - Drop support for line editing with GNU Readline - By default we don't write log files but log to journald, so only recommend logrotate. - Adjust and rename the sysconfig file, so that it matches the expectations of chronyd.service (bsc#1173277). Update to 3.5.1: * Create new file when writing pidfile (CVE-2020-14367, bsc#1174911) - Fixes for %_libexecdir changing to /usr/libexec (bsc#1174075) - Use iburst in the default pool statements to speed up initial synchronisation (bsc#1172113). Update to 3.5: + Add support for more accurate reading of PHC on Linux 5.0 + Add support for hardware timestamping on interfaces with read-only timestamping configuration + Add support for memory locking and real-time priority on FreeBSD, NetBSD, Solaris + Update seccomp filter to work on more architectures + Validate refclock driver options + Fix bindaddress directive on FreeBSD + Fix transposition of hardware RX timestamp on Linux 4.13 and later + Fix building on non-glibc systems - Fix location of helper script in chrony-dnssrv@.service (bsc#1128846). - Read runtime servers from /var/run/netconfig/chrony.servers to fix bsc#1099272. - Move chrony-helper to /usr/lib/chrony/helper, because there should be no executables in /usr/share. Update to version 3.4 * Enhancements + Add filter option to server/pool/peer directive + Add minsamples and maxsamples options tohwtimestamp directive + Add support for faster frequency adjustments in Linux 4.19 + Change default pidfile to /var/run/chrony/chronyd.pid to allow chronyd without root privileges to remove it on exit + Disable sub-second polling intervals for distant NTP sources + Extend range of supported sub-second polling intervals + Get/set IPv4 destination/source address of NTP packets on FreeBSD + Make burst options and command useful with short polling intervals + Modify auto_offline option to activate when sending request failed + Respond from interface that received NTP request if possible + Add onoffline command to switch between online and offline state according to current system network configuration + Improve example NetworkManager dispatcher script * Bug fixes + Avoid waiting in Linux getrandom system call + Fix PPS support on FreeBSD and NetBSD Update to version 3.3 * Enhancements: + Add burst option to server/pool directive + Add stratum and tai options to refclock directive + Add support for Nettle crypto library + Add workaround for missing kernel receive timestamps on Linux + Wait for late hardware transmit timestamps + Improve source selection with unreachable sources + Improve protection against replay attacks on symmetric mode + Allow PHC refclock to use socket in /var/run/chrony + Add shutdown command to stop chronyd + Simplify format of response to manual list command + Improve handling of unknown responses in chronyc * Bug fixes: + Respond to NTPv1 client requests with zero mode + Fix -x option to not require CAP_SYS_TIME under non-root user + Fix acquisitionport directive to work with privilege separation + Fix handling of socket errors on Linux to avoid high CPU usage + Fix chronyc to not get stuck in infinite loop after clock step ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:851-1 Released: Tue Mar 15 19:25:522022 Summary: Security update for openssl-1_1 Type: security Severity: important References: 1180995,1196877,CVE-2022-0778 This update for openssl-1_1 fixes the following issues: - CVE-2022-0778: Infinite loop in BN_mod_sqrt() reachable when parsing certificates (bsc#1196877). - Add safe primes to DH parameter generation as recommended from RFC7919 and RFC3526 (bsc#1180995). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:861-1 Released: Tue Mar 15 23:30:48 2022 Summary: Recommended update for openssl-1_1 Type: recommended Severity: moderate References: 1182959,1195149,1195792,1195856 This update for openssl-1_1 fixes the following issues: openssl-1_1: - Fix PAC pointer authentication in ARM (bsc#1195856) - Pull libopenssl-1_1 when updating openssl-1_1 with the same version (bsc#1195792) - FIPS: Fix function and reason error codes (bsc#1182959) - Enable zlib compression support (bsc#1195149) glibc: - Resolve installation issue of `glibc-devel` in SUSE Linux Enterprise Micro 5.1 linux-glibc-devel: - Resolve installation issue of `linux-kernel-headers` in SUSE Linux Enterprise Micro 5.1 libxcrypt: - Resolve installation issue of `libxcrypt-devel` in SUSE Linux Enterprise Micro 5.1 zlib: - Resolve installation issue of `zlib-devel` in SUSE Linux Enterprise Micro 5.1 ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:867-1 Released: Wed Mar 16 07:14:44 2022 Summary: Recommended update for libtirpc Type: recommended Severity: moderate References: 1193805 This update for libtirpc fixes the following issues: - Fix memory leak in client protocol version 2 code (bsc#1193805) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2022:874-1 Released: Wed Mar 16 10:40:52 2022 Summary: Recommended update for openldap2 Type: recommended Severity: moderate References: 1197004 This update for openldap2 fixes thefollowing issue: - Revert jsc#PM-3288 - CLDAP ( -DLDAP_CONNECTIONLESS ) due to regression (bsc#1197004) The following package changes have been done: - libaugeas0-1.10.1-3.9.1 updated - libldap-2_4-2-2.4.46-9.64.1 updated - libldap-data-2.4.46-9.64.1 updated - libopenssl1_1-1.1.0i-4.66.1 updated - libtirpc-netconfig-1.0.2-3.11.1 updated - libtirpc3-1.0.2-3.11.1 updated - libz1-1.2.11-3.26.10 updated - openssl-1_1-1.1.0i-4.66.1 updated . SUSE Linux Enterprise 15 (SLE15) has released critical security updates addressing vulnerabilities in Chrony and OpenSSL, essential for system integrity and protection against exploits. SUSE Security Update, Container Advisory, Chrony Fixes, OpenSSL Patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 17, 2022 Important SuSE
203

Mageia: 2019-0106 Moderate: OpenSSL Padding Oracle Attack

If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently . MGASA-2019-0106 - Updated openssl packages fix security vulnerability Publication date: 07 Mar 2019 URL: https://advisories.mageia.org/MGASA-2019-0106.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-1559 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behaves differently based on that in a way that is detectable to the remote peer, then this amounts to a padding oracle that could be used to decrypt data (CVE-2019-1559). References: - https://bugs.mageia.org/show_bug.cgi?id=24434 - https://openssl-library.org/news/secadv/20190226.txt - https://www.cve.org/CVERecord?id=CVE-2019-1559 SRPMS: - 6/core/openssl-1.0.2r-1.mga6 . MGASA-2019-0106 - Updated openssl packages fix security vulnerability Publication date: 07 Mar 2019 . application, encounters, fatal, protocol, error, calls, ssl_shutdown(), twice, (once. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 07, 2019 Important Mageia
200

Scientific Linux SL5: SLSA-2016:1137-1 Critical: OpenSSL Denial of Service

Important: openssl security update. Date: Tue, 31 May 2016 16:26:36 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: openssl on SL5.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: openssl security update Advisory ID: SLSA-2016:1137-1 Issue Date: 2016-05-31 CVE Numbers: CVE-2016-2108 -- Security Fix(es): * A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which, when verified or re-encoded by OpenSSL, could cause it to crash, or execute arbitrary code using the permissions of the user running an application compiled against the OpenSSL library. (CVE-2016-2108) -- SL5 x86_64 openssl-0.9.8e-40.el5_11.i686.rpm openssl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.x86_64.rpm openssl-perl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.x86_64.rpm i386 openssl-0.9.8e-40.el5_11.i386.rpm openssl-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-perl-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm - Scientific Linux Development Team lastline . An essential security notice regarding OpenSSL upgrades on Scientific Linux SL5.x targeting major vulnerabilities and their resolutions.. openssl update, security advisory, scientific linux errata, critical security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 31, 2016 Critical Scientific Linux
87

Debian DSA-2896-2 Critical: OpenSSL Memory Exposure Risk

This revision to the recent OpenSSL update, DSA-2896-1, checks for some services that may use OpenSSL in a way that they expose the vulnerability. Such services are proposed to be restarted during the upgrade to help in the actual deployment of the fix. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2896-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso April 08, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl CVE ID : CVE-2014-0160 This revision to the recent OpenSSL update, DSA-2896-1, checks for some services that may use OpenSSL in a way that they expose the vulnerability. Such services are proposed to be restarted during the upgrade to help in the actual deployment of the fix. The list of services that are checked is not comprehensive. For a more detailed check, it is recommended to use the checkrestart tool from the debian-goodies package. Note that client applications also need to be restarted. In case of doubt a full system restart is recommended. For reference, the original advisory text follows. A vulnerability has been discovered in OpenSSL's support for the TLS/DTLS Hearbeat extension. Up to 64KB of memory from either client or server can be recovered by an attacker. This vulnerability might allow an attacker to compromise the private key and other sensitive data in memory. All users are urged to upgrade their openssl packages (especially libssl1.0.0) and restart applications as soon as possible. According to the currently available information, private keys should be considered as compromised and regenerated as soon as possible. More details will be communicated at a later time. The oldstable distribution (squeeze) is not affected by this vulnerability. For the stable distribution (wheezy), this problem has been fixed in version1.0.1e-2+deb7u6. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance security by updating OpenSSL on Debian to address memory handling vulnerabilities through version checks, package updates, and monitoring advisories. OpenSSL Update, Debian Security, Memory Exploit, Service Restart. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 08, 2014 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200