Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
202

openSUSE Leap 15.6: SUSE-SU-2025:1492-1 moderate: escape injection

An update that solves one vulnerability can now be installed.. # Security update for rubygem-rack-1_6 Announcement ID: SUSE-SU-2025:1492-1 Release Date: 2025-05-06T14:36:05Z Rating: moderate References: * bsc#1238607 Cross-References: * CVE-2025-27111 CVSS scores: * CVE-2025-27111 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-27111 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-27111 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for rubygem-rack-1_6 fixes the following issues: * CVE-2025-27111: Fixed Escape Sequence Injection vulnerability (bsc#1238607) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1492=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-1_6-1.6.8-150000.3.6.1 * ruby2.5-rubygem-rack-testsuite-1_6-1.6.8-150000.3.6.1 * ruby2.5-rubygem-rack-doc-1_6-1.6.8-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27111.html * https://bugzilla.suse.com/show_bug.cgi?id=1238607 . Important patch for openSUSE Leap 15.6 tackling escape character injection vulnerability in rubygem-rack-1_6.. openSUSE security update, rubygem rack vulnerability, escape injection remedy. . LinuxSecurity.com Team

Calendar 2 May 07, 2025 OpenSUSE
100

SUSE 15 SP3: 2025:1260-1 important: Linux Kernel Fixes for Multiple Issues

* bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790 . # Security update for the Linux Kernel (Live Patch 44 for SLE 15 SP3) Announcement ID: SUSE-SU-2025:1260-1 Release Date: 2025-04-14T20:03:49Z Rating: important References: * bsc#1228714 * bsc#1232818 * bsc#1235218 * bsc#1238788 * bsc#1238790 Cross-References: * CVE-2022-49014 * CVE-2022-49563 * CVE-2022-49564 * CVE-2024-41090 * CVE-2024-56600 CVSS scores: * CVE-2022-49014 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49014 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49563 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-49563 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49563 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-49564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2022-49564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2022-49564 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-41090 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2024-56600 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2024-56600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-56600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Live Patching 15-SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 An update that solves five vulnerabilities can now be installed. ## Description: This update for the Linux Kernel 5.3.18-150300_59_161 fixes severalissues. The following security issues were fixed: * CVE-2022-49014: net: tun: Fix use-after-free in tun_detach() (bsc#1232818). * CVE-2022-49563: crypto: qat - add param check for RSA (bsc#1238788). * CVE-2022-49564: crypto: qat - add param check for DH (bsc#1238790). * CVE-2024-41090: tap: add missing verification for short frame (bsc#1228714). * CVE-2024-56600: net: inet6: do not leave a dangling sk pointer in inet6_create() (bsc#1235218). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1260=1 * SUSE Linux Enterprise Live Patching 15-SP3 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP3-2025-1260=1 ## Package List: * openSUSE Leap 15.3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_161-default-15-150300.2.1 * kernel-livepatch-5_3_18-150300_59_161-default-debuginfo-15-150300.2.1 * kernel-livepatch-SLE15-SP3_Update_44-debugsource-15-150300.2.1 * openSUSE Leap 15.3 (x86_64) * kernel-livepatch-5_3_18-150300_59_161-preempt-debuginfo-15-150300.2.1 * kernel-livepatch-5_3_18-150300_59_161-preempt-15-150300.2.1 * SUSE Linux Enterprise Live Patching 15-SP3 (ppc64le s390x x86_64) * kernel-livepatch-5_3_18-150300_59_161-default-15-150300.2.1 ## References: * https://www.suse.com/security/cve/CVE-2022-49014.html * https://www.suse.com/security/cve/CVE-2022-49563.html * https://www.suse.com/security/cve/CVE-2022-49564.html * https://www.suse.com/security/cve/CVE-2024-41090.html * https://www.suse.com/security/cve/CVE-2024-56600.html * https://bugzilla.suse.com/show_bug.cgi?id=1228714 * https://bugzilla.suse.com/show_bug.cgi?id=1232818 * https://bugzilla.suse.com/show_bug.cgi?id=1235218 * https://bugzilla.suse.com/show_bug.cgi?id=1238788 * https://bugzilla.suse.com/show_bug.cgi?id=1238790 . Address multipleimportant flaws in the Linux Kernel through this critical security update for SUSE 15 SP3.. Linux Kernel Update, SUSE Security Advisory, Package Patch Instructions, Linux Security Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 15, 2025 Important SuSE
202

openSUSE Leap 15.6: 2025:0116-1 important: git credential issues

An update that solves two vulnerabilities can now be installed.. # Security update for git Announcement ID: SUSE-SU-2025:0116-1 Release Date: 2025-01-15T08:32:46Z Rating: important References: * bsc#1235600 * bsc#1235601 Cross-References: * CVE-2024-50349 * CVE-2024-52006 CVSS scores: * CVE-2024-50349 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-52006 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP6 * Development Tools Module 15-SP6 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for git fixes the following issues: * CVE-2024-50349: Passwords for trusted sites could be sent to untrusted sites (bsc#1235600). * CVE-2024-52006: Carriage Returns via the credential protocol to credential helpers (bsc#1235601). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-116=1 openSUSE-SLE-15.6-2025-116=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2025-116=1 * Development Tools Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP6-2025-116=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * perl-Git-2.43.0-150600.3.9.1 * gitk-2.43.0-150600.3.9.1 *git-daemon-2.43.0-150600.3.9.1 * git-credential-libsecret-2.43.0-150600.3.9.1 * git-credential-libsecret-debuginfo-2.43.0-150600.3.9.1 * git-core-debuginfo-2.43.0-150600.3.9.1 * git-email-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-web-2.43.0-150600.3.9.1 * git-gui-2.43.0-150600.3.9.1 * git-2.43.0-150600.3.9.1 * git-arch-2.43.0-150600.3.9.1 * git-p4-2.43.0-150600.3.9.1 * git-cvs-2.43.0-150600.3.9.1 * git-core-2.43.0-150600.3.9.1 * git-daemon-debuginfo-2.43.0-150600.3.9.1 * git-svn-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * openSUSE Leap 15.6 (noarch) * git-doc-2.43.0-150600.3.9.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * git-core-debuginfo-2.43.0-150600.3.9.1 * git-core-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * Development Tools Module 15-SP6 (aarch64 ppc64le s390x x86_64) * perl-Git-2.43.0-150600.3.9.1 * gitk-2.43.0-150600.3.9.1 * git-daemon-2.43.0-150600.3.9.1 * git-email-2.43.0-150600.3.9.1 * git-debuginfo-2.43.0-150600.3.9.1 * git-web-2.43.0-150600.3.9.1 * git-gui-2.43.0-150600.3.9.1 * git-2.43.0-150600.3.9.1 * git-arch-2.43.0-150600.3.9.1 * git-cvs-2.43.0-150600.3.9.1 * git-daemon-debuginfo-2.43.0-150600.3.9.1 * git-svn-2.43.0-150600.3.9.1 * git-debugsource-2.43.0-150600.3.9.1 * Development Tools Module 15-SP6 (noarch) * git-doc-2.43.0-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2024-50349.html * https://www.suse.com/security/cve/CVE-2024-52006.html * https://bugzilla.suse.com/show_bug.cgi?id=1235600 * https://bugzilla.suse.com/show_bug.cgi?id=1235601 . Recent enhancements in git have addressed several vulnerabilities impacting various SUSE offerings, promoting more secure development methodologies.. openSUSE, git update, security patch, software vulnerabilities, advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 15, 2025 Important OpenSUSE
100

SUSE: 2025:0047-1 moderate: python39 Security Patch Announcement

* bsc#1232241 * bsc#1233307 Cross-References: * CVE-2024-11168 . # Security update for python39 Announcement ID: SUSE-SU-2025:0047-1 Release Date: 2025-01-09T15:36:42Z Rating: moderate References: * bsc#1232241 * bsc#1233307 Cross-References: * CVE-2024-11168 * CVE-2024-9287 CVSS scores: * CVE-2024-11168 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-11168 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:X/RE:X/U:X * CVE-2024-11168 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2024-9287 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green * CVE-2024-9287 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2024-9287 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 An update that solves two vulnerabilities can now be installed. ## Description: This update for python39 fixes the following issue: * Update to 3.9.21 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-47=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-47=1 ## Package List: * openSUSE Leap 15.3 (aarch64ppc64le s390x x86_64 i586) * python39-doc-devhelp-3.9.21-150300.4.61.1 * python39-testsuite-debuginfo-3.9.21-150300.4.61.1 * python39-core-debugsource-3.9.21-150300.4.61.1 * python39-curses-debuginfo-3.9.21-150300.4.61.1 * python39-testsuite-3.9.21-150300.4.61.1 * python39-tools-3.9.21-150300.4.61.1 * python39-base-debuginfo-3.9.21-150300.4.61.1 * python39-idle-3.9.21-150300.4.61.1 * python39-tk-3.9.21-150300.4.61.1 * python39-debugsource-3.9.21-150300.4.61.1 * python39-tk-debuginfo-3.9.21-150300.4.61.1 * python39-dbm-3.9.21-150300.4.61.1 * python39-3.9.21-150300.4.61.1 * python39-dbm-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-3.9.21-150300.4.61.1 * libpython3_9-1_0-debuginfo-3.9.21-150300.4.61.1 * python39-doc-3.9.21-150300.4.61.1 * python39-debuginfo-3.9.21-150300.4.61.1 * python39-base-3.9.21-150300.4.61.1 * python39-curses-3.9.21-150300.4.61.1 * python39-devel-3.9.21-150300.4.61.1 * openSUSE Leap 15.3 (x86_64) * python39-base-32bit-debuginfo-3.9.21-150300.4.61.1 * python39-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-3.9.21-150300.4.61.1 * python39-base-32bit-3.9.21-150300.4.61.1 * python39-32bit-3.9.21-150300.4.61.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.21-150300.4.61.1 * libpython3_9-1_0-64bit-3.9.21-150300.4.61.1 * python39-64bit-debuginfo-3.9.21-150300.4.61.1 * python39-base-64bit-3.9.21-150300.4.61.1 * libpython3_9-1_0-64bit-debuginfo-3.9.21-150300.4.61.1 * python39-base-64bit-debuginfo-3.9.21-150300.4.61.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * python39-doc-devhelp-3.9.21-150300.4.61.1 * python39-testsuite-debuginfo-3.9.21-150300.4.61.1 * python39-core-debugsource-3.9.21-150300.4.61.1 * python39-curses-debuginfo-3.9.21-150300.4.61.1 * python39-testsuite-3.9.21-150300.4.61.1 * python39-tools-3.9.21-150300.4.61.1 *python39-base-debuginfo-3.9.21-150300.4.61.1 * python39-idle-3.9.21-150300.4.61.1 * python39-tk-3.9.21-150300.4.61.1 * python39-debugsource-3.9.21-150300.4.61.1 * python39-tk-debuginfo-3.9.21-150300.4.61.1 * python39-dbm-3.9.21-150300.4.61.1 * python39-3.9.21-150300.4.61.1 * python39-dbm-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-3.9.21-150300.4.61.1 * libpython3_9-1_0-debuginfo-3.9.21-150300.4.61.1 * python39-doc-3.9.21-150300.4.61.1 * python39-debuginfo-3.9.21-150300.4.61.1 * python39-base-3.9.21-150300.4.61.1 * python39-curses-3.9.21-150300.4.61.1 * python39-devel-3.9.21-150300.4.61.1 * openSUSE Leap 15.6 (x86_64) * python39-base-32bit-debuginfo-3.9.21-150300.4.61.1 * python39-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-debuginfo-3.9.21-150300.4.61.1 * libpython3_9-1_0-32bit-3.9.21-150300.4.61.1 * python39-base-32bit-3.9.21-150300.4.61.1 * python39-32bit-3.9.21-150300.4.61.1 ## References: * https://www.suse.com/security/cve/CVE-2024-11168.html * https://www.suse.com/security/cve/CVE-2024-9287.html * https://bugzilla.suse.com/show_bug.cgi?id=1232241 * https://bugzilla.suse.com/show_bug.cgi?id=1233307 . Python39 security patch released for SUSE systems. Detailed release notes and installation guidelines for impacted products are available.. python39 update, SUSE patches, openSUSE security, package vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Jan 09, 2025 SuSE
87

Debian: DSA-5698-1 Critical: ruby-rack Denial of Service Issues

Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5698-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 24, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby-rack CVE ID : CVE-2024-25126 CVE-2024-26141 CVE-2024-26146 Multiple security issues were found in Rack, an interface for developing web applications in Ruby, which could result in denial of service. For the oldstable distribution (bullseye), these problems have been fixed in version 2.1.4-3+deb11u2. For the stable distribution (bookworm), these problems have been fixed in version 2.2.6.4-1+deb12u1. We recommend that you upgrade your ruby-rack packages. For the detailed security status of ruby-rack please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-rack Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A series of vulnerabilities in the ruby-rack library have been addressed. Ensure your packages are updated to safeguard against possible DoS risks in Debian systems.. ruby rack, debian security, application development, package updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 24, 2024 Critical Debian
100

openSUSE Leap 15.5: SUSE-SU-2023:4000-1 Moderate: yq Update

* #1215808 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 . # Security update for yq Announcement ID: SUSE-SU-2023:4000-1 Rating: moderate References: * #1215808 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that has one security fix can now be installed. ## Description: This update for yq fixes the following issues: yq was updated to 4.35.2 (bsc#1215808): * Fixed number parsing as float bug in JSON #1756 * Fixed string, null concatenation consistency #1712 * Fixed expression parsing issue #1711 Update to 4.35.1: * Added Lua output support * Added BSD checksum format Update to 4.34.1: * Added shell output format * Fixed nil pointer dereference Update to 4.33.3: * Fixed bug when splatting empty array #1613 * Added scalar output for TOML (#1617) * Fixed passing of read-only context in pipe (partial fix for #1631) Update to 4.33.2: * Add `--nul-output|-0` flag to separate element with NUL character (#1550) Thanks @vaab! * Add removable-media interface plug declaration to the snap packaging(#1618) Thanks @brlin-tw! * Scalar output now handled in csv, tsv and property files Update to 4.33.1: * Added read-only TOML support! #1364. Thanks @pelletier for making your API available in your toml lib :) * Added warning when auto detect by file type is outputs JSON Update to 4.32.2: * Fixes parsing terraform tfstate files results in "unknown" format * Added divide and modulo operators (#1593) * Add support for decoding base64 strings without padding * Add filter operation (#1588) - thanks @rbren! * Detect input format based on file name extension (#1582) * Auto output format when inputformat is automatically detected * Fixed npe in log #1596 * Improved binary file size! Update to 4.31.2: * Fixed merged anchor reference problem #1482 * Fixed xml encoding of ProcInst #1563, improved XML comment handling * Allow build without json and xml support (#1556) Thanks Update to 4.31.1: * Added shuffle command #1503 * Added ability to sort by multiple fields #1541 * Added @sh encoder #1526 * Added @uri/@urid encoder/decoder #1529 * Fixed date comparison with string date #1537 * Added from_unix/to_unix Operators ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4000=1 SUSE-2023-4000=1 * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2023-4000=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * yq-4.35.2-150500.3.3.1 * yq-debuginfo-4.35.2-150500.3.3.1 * openSUSE Leap 15.5 (noarch) * yq-bash-completion-4.35.2-150500.3.3.1 * yq-fish-completion-4.35.2-150500.3.3.1 * yq-zsh-completion-4.35.2-150500.3.3.1 * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * yq-4.35.2-150500.3.3.1 * yq-debuginfo-4.35.2-150500.3.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1215808 . This software upgrade introduces vital enhancements and corrections for multiple SUSE platforms. Upgrade today for improved performance and reliability.. SUSE Security Update,yq Fixes,SUSE Enterprise Desktop,openSUSE Leap. . LinuxSecurity.com Team

Calendar 2 Oct 06, 2023 SuSE
99

Slackware 15.0: 2023-213-01 Moderate OpenSSL Security Fix

New openssl packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] openssl (SSA:2023-213-01) New openssl packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/openssl-1.1.1v-i586-1_slack15.0.txz: Upgraded. This update fixes bugs and security issues: Fix excessive time spent checking DH q parameter value. Fix DH_check() excessive time with over sized modulus. For more information, see: https://openssl-library.org/news/secadv/20230731.txt https://openssl-library.org/news/secadv/20230719.txt https://www.cve.org/CVERecord?id=CVE-2023-3817 https://www.cve.org/CVERecord?id=CVE-2023-3446 (* Security fix *) patches/packages/openssl-solibs-1.1.1v-i586-1_slack15.0.txz: Upgraded. +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated packages for Slackware 15.0: Updated packages for Slackware x86_64 15.0: Updated packages for Slackware -current: Updated packages for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 packages: f8063e6a32e6d09b3589b95542978a53 openssl-1.1.1v-i586-1_slack15.0.txz 7cf83588ad6b1821015e2c886bd34f23 openssl-solibs-1.1.1v-i586-1_slack15.0.txz Slackware x86_64 15.0 packages: b7ecaea2473c40a8d2ccd9a8c7a4bc51 openssl-1.1.1v-x86_64-1_slack15.0.txz 36dd4b29f2dca9c776ec13c578c3d6e3 openssl-solibs-1.1.1v-x86_64-1_slack15.0.txz Slackware -current packages: fd660e4ef6911eacf08ab8cd085b7a3d a/openssl-solibs-3.1.2-i586-1.txz 1e91105d570621c561f218ede115c0fb n/openssl-3.1.2-i586-1.txz Slackware x86_64 -currentpackages: 23057ef0aa1b465af1945e15607678f6 a/openssl-solibs-3.1.2-x86_64-1.txz b9cc7784987a45c22337e5f0a52f8c55 n/openssl-3.1.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg openssl-1.1.1v-i586-1_slack15.0.txz openssl-solibs-1.1.1v-i586-1_slack15.0.txz +-----+ . Fresh OpenSSL updates have been released for Slackware 15.0 to tackle significant security vulnerabilities and enhance overall system security.. OpenSSL Update, Slackware Security, Package Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 02, 2023 Important Slackware
199

CentOS 7 CESA-2021-5195 Moderate: ipa Package Update Critical Fix

Upstream details at : https://access.redhat.com/errata/RHSA-2021:5195. CentOS Errata and Security Advisory 2021:5195 Moderate Upstream details at : https://access.redhat.com/errata/RHSA-2021:5195 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: ff13cc6851b7555532b91dc5f8a9c7b73fb8f47f0f39be06ad101f6250c679c5 ipa-client-4.6.8-5.el7.centos.10.x86_64.rpm 779491f4aff62cb66747a794b7b823e9645eed730e157ff87a8425bfd96871c9 ipa-client-common-4.6.8-5.el7.centos.10.noarch.rpm 9a646552f12a087de4493fe8a4dfec0a5fb87521f568758c6136443c9644c22f ipa-common-4.6.8-5.el7.centos.10.noarch.rpm 47f19899e75c7c9a5b74f30643d69d0ccff2cf5451546d7ad1a727bccaaf0ea4 ipa-python-compat-4.6.8-5.el7.centos.10.noarch.rpm ac419246df9921713ed1c65bf7621fa6b5266999545f33a73aab328bcd38d3f0 ipa-server-4.6.8-5.el7.centos.10.x86_64.rpm 505e596b1b77d05f545fd3684fbdd8591bf9ca308db67ff0a6b36dd0a1341c17 ipa-server-common-4.6.8-5.el7.centos.10.noarch.rpm 878d2dbcd884adb9e2de690242d04710df89bee67b51aa86e9468e01de78341b ipa-server-dns-4.6.8-5.el7.centos.10.noarch.rpm 58790e773666a310f1c4417f46de1fb127437bce225ed0d9cbf6b4a08054ae98 ipa-server-trust-ad-4.6.8-5.el7.centos.10.x86_64.rpm 341b7f6c5352eee2a98665ce78feaf6c4a52626e0322ce9b65c82f9e08190f7e python2-ipaclient-4.6.8-5.el7.centos.10.noarch.rpm 55921bf220651db8e53c670393336486760efc2eb102ac7de7bc83f6731698f6 python2-ipalib-4.6.8-5.el7.centos.10.noarch.rpm e568d73cd1ea3df0a67fb17bceeae36b33a91af90d651ab33c4ae492f208ff32 python2-ipaserver-4.6.8-5.el7.centos.10.noarch.rpm Source: cfdc4deb7112fb2ce42791bf940d930732c0ddccbe4d9ac8c29ae83a296dcfb8 ipa-4.6.8-5.el7.centos.10.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS 7's CESA-2021-5195 advisory warns of moderate vulnerabilities in IPA packages risking unauthorized access andintegrity. Quick updates are crucial for security. CentOS Security, IPA Updates, Security Patches, Linux Management. . LinuxSecurity.com Team

Calendar 2 Dec 21, 2021 CentOS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here