Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 430
Alerts This Week
Warning Icon 1 430

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux ASA-202107-46 Significant: Opera RCE Vulnerability Alert

The package opera before version 77.0.4054.277-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202107-46 ========================================= Severity: High Date : 2021-07-21 CVE-ID : CVE-2021-30541 CVE-2021-30559 CVE-2021-30560 CVE-2021-30561 CVE-2021-30562 CVE-2021-30563 CVE-2021-30564 Package : opera Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-2168 Summary ====== The package opera before version 77.0.4054.277-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 77.0.4054.277-1. # pacman -Syu "opera> =77.0.4054.277-1" The problems have been fixed upstream in version 77.0.4054.277. Workaround ========= None. Description ========== - CVE-2021-30541 (arbitrary code execution) A use after free security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30559 (arbitrary code execution) An out of bounds write security issue has been found in the ANGLE component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30560 (arbitrary code execution) A use after free security issue has been found in the Blink XSLT component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30561 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30562 (arbitrary code execution) A use after free security issue has been found in the WebSerial component of the Chromium browser engine before version 91.0.4472.164. - CVE-2021-30563 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 91.0.4472.164. Google is aware of reports that an exploit for CVE-2021-30563 exists in the wild. - CVE-2021-30564 (arbitrary code execution) A heap buffer overflow security issue has been found in the WebXR component ofthe Chromium browser engine before version 91.0.4472.164. Impact ===== A remote attacker could execute arbitrary code through a crafted web page. Google is aware that an exploit for one of the security issues exists in the wild. References ========= https://blogs.opera.com/desktop/changelog-for-77/ https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2021-30541 https://security.archlinux.org/CVE-2021-30559 https://security.archlinux.org/CVE-2021-30560 https://security.archlinux.org/CVE-2021-30561 https://security.archlinux.org/CVE-2021-30562 https://security.archlinux.org/CVE-2021-30563 https://security.archlinux.org/CVE-2021-30564 . Arch Linux Security Notice ASA-202107-47 brings attention to a critical remote code execution flaw within the opera software package.. Opera Arbitrary Execution, Arch Linux Security, High Severity Advisory. . LinuxSecurity.com Team

Calendar%202 Jul 22, 2021 ArchLinux
198

Arch Linux: ASA-202102-5 Critical: Multiple Opera Issues

The package opera before version 74.0.3911.75-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation, content spoofing and incorrect calculation. . Arch Linux Security Advisory ASA-202102-5 ======================================== Severity: Critical Date : 2021-02-06 CVE-ID : CVE-2020-16044 CVE-2021-21117 CVE-2021-21118 CVE-2021-21119 CVE-2021-21120 CVE-2021-21121 CVE-2021-21122 CVE-2021-21123 CVE-2021-21124 CVE-2021-21125 CVE-2021-21126 CVE-2021-21127 CVE-2021-21128 CVE-2021-21129 CVE-2021-21130 CVE-2021-21131 CVE-2021-21132 CVE-2021-21133 CVE-2021-21134 CVE-2021-21135 CVE-2021-21136 CVE-2021-21137 CVE-2021-21138 CVE-2021-21139 CVE-2021-21140 CVE-2021-21141 Package : opera Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1479 Summary ====== The package opera before version 74.0.3911.75-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation, content spoofing and incorrect calculation. Resolution ========= Upgrade to 74.0.3911.75-1. # pacman -Syu "opera> =74.0.3911.75-1" The problems have been fixed upstream in version 74.0.3911.75. Workaround ========= None. Description ========== - CVE-2020-16044 (arbitrary code execution) A security issue was found in Firefox before 84.0.2, Thunderbird before 78.6.1 and Chromium before 88.0.4324.96. A malicious peer could have modified a COOKIE-ECHO chunk in an SCTP packet in a way that potentially resulted in a use-after-free. Mozilla presumes that with enough effort it could have been exploited to run arbitrary code. - CVE-2021-21117 (insufficient validation) An insufficient policy enforcement security issue was found in the Cryptohome component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21118 (insufficient validation) An insufficient data validation security issue was found in the V8 component of theChromium browser before version 88.0.4324.96. - CVE-2021-21119 (arbitrary code execution) A use after free security issue was found in the Media component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21120 (arbitrary code execution) A use after free security issue was found in the WebSQL component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21121 (arbitrary code execution) A use after free security issue was found in the Omnibox component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21122 (arbitrary code execution) A use after free security issue was found in the Blink component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21123 (insufficient validation) An insufficient data validation security issue was found in the File System component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21124 (arbitrary code execution) A potential use after free security issue was found in the Speech Recognizer component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21125 (insufficient validation) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21126 (insufficient validation) An insufficient policy enforcement security issue was found in the extensions component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21127 (insufficient validation) An insufficient policy enforcement security issue was found in the extensions component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21128 (arbitrary code execution) A heap buffer overflow security issue was found in the Blink component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21129 (insufficient validation) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser beforeversion 88.0.4324.96. - CVE-2021-21130 (insufficient validation) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21131 (insufficient validation) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21132 (incorrect calculation) An inappropriate implementation security issue was found in the DevTools component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21133 (insufficient validation) An insufficient policy enforcement security issue was found in the Downloads component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21134 (content spoofing) An incorrect security UI security issue was found in the Page Info component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21135 (incorrect calculation) An inappropriate implementation security issue was found in the Performance API component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21136 (insufficient validation) An insufficient policy enforcement security issue was found in the WebView component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21137 (incorrect calculation) An inappropriate implementation security issue was found in the DevTools component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21138 (arbitrary code execution) A use after free security issue was found in the DevTools component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21139 (incorrect calculation) An inappropriate implementation security issue was found in the iframe sandbox component of the Chromium browser before version 88.0.4324.96. - CVE-2021-21140 (arbitrary code execution) An uninitialized use security issue was found in the USB component of the Chromium browser before version88.0.4324.96. - CVE-2021-21141 (insufficient validation) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser before version 88.0.4324.96. Impact ===== A remote attacker might be able to bypass security measures, trick the user into performing unwanted actions or execute arbitrarycode. References ========= https://blogs.opera.com/desktop/2021/02/opera-74-stable/ https://www.mozilla.org/en-US/security/advisories/mfsa2021-01/#CVE-2020-16044 https://bugzilla.mozilla.org/show_bug.cgi?id=1683964 https://hg-edge.mozilla.org/mozilla-central/rev/08ba03dc8d4420e04e7c77fee3013e68180e6ead https://hg-edge.mozilla.org/mozilla-central/rev/8c09f4813fc7e8f44605b6092262199bff15cdd7 https://hg-edge.mozilla.org/mozilla-central/rev/5991645a87d2abf289686d09d943229c9e3e54b5 https://chromereleases.googleblog.com/2021/01/stable-channel-update-for-desktop_19.html https://security.archlinux.org/CVE-2020-16044 https://security.archlinux.org/CVE-2021-21117 https://security.archlinux.org/CVE-2021-21118 https://security.archlinux.org/CVE-2021-21119 https://security.archlinux.org/CVE-2021-21120 https://security.archlinux.org/CVE-2021-21121 https://security.archlinux.org/CVE-2021-21122 https://security.archlinux.org/CVE-2021-21123 https://security.archlinux.org/CVE-2021-21124 https://security.archlinux.org/CVE-2021-21125 https://security.archlinux.org/CVE-2021-21126 https://security.archlinux.org/CVE-2021-21127 https://security.archlinux.org/CVE-2021-21128 https://security.archlinux.org/CVE-2021-21129 https://security.archlinux.org/CVE-2021-21130 https://security.archlinux.org/CVE-2021-21131 https://security.archlinux.org/CVE-2021-21132 https://security.archlinux.org/CVE-2021-21133 https://security.archlinux.org/CVE-2021-21134 https://security.archlinux.org/CVE-2021-21135 https://security.archlinux.org/CVE-2021-21136 https://security.archlinux.org/CVE-2021-21137 https://security.archlinux.org/CVE-2021-21138 https://security.archlinux.org/CVE-2021-21139 https://security.archlinux.org/CVE-2021-21140 https://security.archlinux.org/CVE-2021-21141 . Urgent notice regarding security issues in Arch Linux operatic compilation, highlighting risks of code execution and potential for misleading visual content.. Arch Linux Advisory, Opera Package Security, Critical Update. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 Feb 12, 2021 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200