Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
100

SUSE: 2019:2829-1 Critical Update for Kernel Live Patch 35

An update that solves two vulnerabilities and has two fixes is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2829-1 Rating: important References: #1144903 #1153108 #1153158 #1153161 Cross-References: CVE-2019-10220 CVE-2019-17133 Affected Products: SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that solves two vulnerabilities and has two fixes is now available. Description: This update for the Linux Kernel 3.12.74-60_64_118 fixes several issues. The following security issues were fixed: - CVE-2019-10220: Fixed a relative path escape in the Samba client module (bsc#1144903, bsc#1153108). - CVE-2019-17133: Fixed a buffer overflow in cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c caused by long SSID IEs (bsc#1153158). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2019-2832=1 SUSE-SLE-SAP-12-SP3-2019-2833=1 SUSE-SLE-SAP-12-SP3-2019-2834=1 SUSE-SLE-SAP-12-SP3-2019-2835=1SUSE-SLE-SAP-12-SP3-2019-2836=1 SUSE-SLE-SAP-12-SP3-2019-2837=1 SUSE-SLE-SAP-12-SP3-2019-2838=1 SUSE-SLE-SAP-12-SP3-2019-2839=1 SUSE-SLE-SAP-12-SP3-2019-2840=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-2825=1 SUSE-SLE-SAP-12-SP2-2019-2826=1 SUSE-SLE-SAP-12-SP2-2019-2827=1 SUSE-SLE-SAP-12-SP2-2019-2828=1 SUSE-SLE-SAP-12-SP2-2019-2829=1 SUSE-SLE-SAP-12-SP2-2019-2830=1 SUSE-SLE-SAP-12-SP2-2019-2831=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-2822=1 SUSE-SLE-SAP-12-SP1-2019-2823=1 SUSE-SLE-SAP-12-SP1-2019-2824=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-2832=1 SUSE-SLE-SERVER-12-SP3-2019-2833=1 SUSE-SLE-SERVER-12-SP3-2019-2834=1 SUSE-SLE-SERVER-12-SP3-2019-2835=1 SUSE-SLE-SERVER-12-SP3-2019-2836=1 SUSE-SLE-SERVER-12-SP3-2019-2837=1 SUSE-SLE-SERVER-12-SP3-2019-2838=1 SUSE-SLE-SERVER-12-SP3-2019-2839=1 SUSE-SLE-SERVER-12-SP3-2019-2840=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-2825=1 SUSE-SLE-SERVER-12-SP2-2019-2826=1 SUSE-SLE-SERVER-12-SP2-2019-2827=1 SUSE-SLE-SERVER-12-SP2-2019-2828=1 SUSE-SLE-SERVER-12-SP2-2019-2829=1 SUSE-SLE-SERVER-12-SP2-2019-2830=1 SUSE-SLE-SERVER-12-SP2-2019-2831=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-2822=1 SUSE-SLE-SERVER-12-SP1-2019-2823=1 SUSE-SLE-SERVER-12-SP1-2019-2824=1 - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2019-2850=1 SUSE-SLE-Module-Live-Patching-15-SP1-2019-2851=1 SUSE-SLE-Module-Live-Patching-15-SP1-2019-2861=1 SUSE-SLE-Module-Live-Patching-15-SP1-2019-2862=1 SUSE-SLE-Module-Live-Patching-15-SP1-2019-2863=1 - SUSE Linux Enterprise Module for Live Patching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2019-2852=1 SUSE-SLE-Module-Live-Patching-15-2019-2853=1SUSE-SLE-Module-Live-Patching-15-2019-2854=1 SUSE-SLE-Module-Live-Patching-15-2019-2855=1 SUSE-SLE-Module-Live-Patching-15-2019-2856=1 SUSE-SLE-Module-Live-Patching-15-2019-2857=1 SUSE-SLE-Module-Live-Patching-15-2019-2858=1 SUSE-SLE-Module-Live-Patching-15-2019-2860=1 - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2019-2841=1 SUSE-SLE-Live-Patching-12-SP4-2019-2842=1 SUSE-SLE-Live-Patching-12-SP4-2019-2843=1 SUSE-SLE-Live-Patching-12-SP4-2019-2844=1 SUSE-SLE-Live-Patching-12-SP4-2019-2845=1 SUSE-SLE-Live-Patching-12-SP4-2019-2846=1 SUSE-SLE-Live-Patching-12-SP4-2019-2847=1 SUSE-SLE-Live-Patching-12-SP4-2019-2848=1 Package List: - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): kgraft-patch-4_4_156-94_64-default-8-2.1 kgraft-patch-4_4_156-94_64-default-debuginfo-8-2.1 kgraft-patch-4_4_162-94_69-default-7-2.1 kgraft-patch-4_4_162-94_69-default-debuginfo-7-2.1 kgraft-patch-4_4_162-94_72-default-7-2.1 kgraft-patch-4_4_162-94_72-default-debuginfo-7-2.1 kgraft-patch-4_4_175-94_79-default-6-2.1 kgraft-patch-4_4_175-94_79-default-debuginfo-6-2.1 kgraft-patch-4_4_176-94_88-default-5-2.1 kgraft-patch-4_4_176-94_88-default-debuginfo-5-2.1 kgraft-patch-4_4_178-94_91-default-5-2.1 kgraft-patch-4_4_178-94_91-default-debuginfo-5-2.1 kgraft-patch-4_4_180-94_100-default-3-2.1 kgraft-patch-4_4_180-94_100-default-debuginfo-3-2.1 kgraft-patch-4_4_180-94_103-default-3-2.1 kgraft-patch-4_4_180-94_103-default-debuginfo-3-2.1 kgraft-patch-4_4_180-94_97-default-5-2.1 kgraft-patch-4_4_180-94_97-default-debuginfo-5-2.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): kgraft-patch-4_4_121-92_101-default-6-2.1 kgraft-patch-4_4_121-92_104-default-6-2.1 kgraft-patch-4_4_121-92_109-default-6-2.1 kgraft-patch-4_4_121-92_114-default-5-2.1 kgraft-patch-4_4_121-92_117-default-4-2.1 kgraft-patch-4_4_121-92_120-default-3-2.1 kgraft-patch-4_4_121-92_98-default-8-2.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): kgraft-patch-3_12_74-60_64_115-default-5-2.1 kgraft-patch-3_12_74-60_64_115-xen-5-2.1 kgraft-patch-3_12_74-60_64_118-default-3-2.1 kgraft-patch-3_12_74-60_64_118-xen-3-2.1 kgraft-patch-3_12_74-60_64_121-default-3-2.1 kgraft-patch-3_12_74-60_64_121-xen-3-2.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le x86_64): kgraft-patch-4_4_156-94_64-default-8-2.1 kgraft-patch-4_4_156-94_64-default-debuginfo-8-2.1 kgraft-patch-4_4_162-94_69-default-7-2.1 kgraft-patch-4_4_162-94_69-default-debuginfo-7-2.1 kgraft-patch-4_4_162-94_72-default-7-2.1 kgraft-patch-4_4_162-94_72-default-debuginfo-7-2.1 kgraft-patch-4_4_175-94_79-default-6-2.1 kgraft-patch-4_4_175-94_79-default-debuginfo-6-2.1 kgraft-patch-4_4_176-94_88-default-5-2.1 kgraft-patch-4_4_176-94_88-default-debuginfo-5-2.1 kgraft-patch-4_4_178-94_91-default-5-2.1 kgraft-patch-4_4_178-94_91-default-debuginfo-5-2.1 kgraft-patch-4_4_180-94_100-default-3-2.1 kgraft-patch-4_4_180-94_100-default-debuginfo-3-2.1 kgraft-patch-4_4_180-94_103-default-3-2.1 kgraft-patch-4_4_180-94_103-default-debuginfo-3-2.1 kgraft-patch-4_4_180-94_97-default-5-2.1 kgraft-patch-4_4_180-94_97-default-debuginfo-5-2.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le x86_64): kgraft-patch-4_4_121-92_101-default-6-2.1 kgraft-patch-4_4_121-92_104-default-6-2.1 kgraft-patch-4_4_121-92_109-default-6-2.1 kgraft-patch-4_4_121-92_114-default-5-2.1 kgraft-patch-4_4_121-92_117-default-4-2.1 kgraft-patch-4_4_121-92_120-default-3-2.1 kgraft-patch-4_4_121-92_98-default-8-2.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (x86_64): kgraft-patch-3_12_74-60_64_115-default-5-2.1 kgraft-patch-3_12_74-60_64_115-xen-5-2.1 kgraft-patch-3_12_74-60_64_118-default-3-2.1 kgraft-patch-3_12_74-60_64_118-xen-3-2.1 kgraft-patch-3_12_74-60_64_121-default-3-2.1 kgraft-patch-3_12_74-60_64_121-xen-3-2.1 - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-195-default-7-19.1 kernel-livepatch-4_12_14-197_10-default-3-2.1 kernel-livepatch-4_12_14-197_21-default-2-2.1 kernel-livepatch-4_12_14-197_4-default-6-2.1 kernel-livepatch-4_12_14-197_7-default-5-2.1 - SUSE Linux Enterprise Module for Live Patching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150_14-default-5-2.1 kernel-livepatch-4_12_14-150_14-default-debuginfo-5-2.1 kernel-livepatch-4_12_14-150_17-default-5-2.1 kernel-livepatch-4_12_14-150_17-default-debuginfo-5-2.1 kernel-livepatch-4_12_14-150_22-default-4-2.1 kernel-livepatch-4_12_14-150_22-default-debuginfo-4-2.1 kernel-livepatch-4_12_14-150_27-default-3-2.1 kernel-livepatch-4_12_14-150_27-default-debuginfo-3-2.1 kernel-livepatch-4_12_14-150_32-default-3-2.1 kernel-livepatch-4_12_14-150_32-default-debuginfo-3-2.1 kernel-livepatch-4_12_14-150_38-default-2-2.1 kernel-livepatch-4_12_14-150_38-default-debuginfo-2-2.1 kernel-livepatch-4_12_14-25_25-default-7-2.1 kernel-livepatch-4_12_14-25_25-default-debuginfo-7-2.1 kernel-livepatch-4_12_14-25_28-default-6-2.1 kernel-livepatch-4_12_14-25_28-default-debuginfo-6-2.1 - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le x86_64): kgraft-patch-4_12_14-94_41-default-8-2.22.1 kgraft-patch-4_12_14-94_41-default-debuginfo-8-2.22.1 kgraft-patch-4_12_14-95_13-default-5-2.1 kgraft-patch-4_12_14-95_16-default-5-2.1 kgraft-patch-4_12_14-95_19-default-4-2.1 kgraft-patch-4_12_14-95_24-default-3-2.1 kgraft-patch-4_12_14-95_29-default-3-2.1 kgraft-patch-4_12_14-95_3-default-7-2.1 kgraft-patch-4_12_14-95_6-default-6-2.1 kgraft-patch-SLE12-SP4_Update_0-debugsource-8-2.22.1 References: https://www.suse.com/security/cve/CVE-2019-10220.html https://www.suse.com/security/cve/CVE-2019-17133.html https://bugzilla.suse.com/1144903 https://bugzilla.suse.com/1153108 https://bugzilla.suse.com/1153158 https://bugzilla.suse.com/1153161 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Key modifications to the Linux Kernel are now implemented to rectify essential flaws and security risks within SUSE distributions.. Linux Kernel Security, SUSE Updates, Kernel Patching. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 30, 2019 Important SuSE
100

SUSE: 2019:2859-1 Important: Kernel Security Update for SLE 15

An update that solves two vulnerabilities and has three fixes is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 14 for SLE 15) ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2859-1 Rating: important References: #1144903 #1149841 #1153108 #1153158 #1153161 Cross-References: CVE-2019-10220 CVE-2019-17133 Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 SUSE Linux Enterprise Module for Live Patching 15 SUSE Linux Enterprise Live Patching 12-SP4 ______________________________________________________________________________ An update that solves two vulnerabilities and has three fixes is now available. Description: This update for the Linux Kernel 4.12.14-150_35 fixes several issues. The following security issues were fixed: - CVE-2019-10220: Fixed a relative path escape in the Samba client module (bsc#1144903, bsc#1153108). - CVE-2019-17133: Fixed a buffer overflow in cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c caused by long SSID IEs (bsc#1153158). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2019-2865=1 - SUSE Linux Enterprise Module for Live Patching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2019-2859=1 - SUSE Linux Enterprise Live Patching 12-SP4: zypper in -t patch SUSE-SLE-Live-Patching-12-SP4-2019-2849=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_18-default-2-2.1 - SUSE Linux Enterprise Module for LivePatching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150_35-default-2-2.1 kernel-livepatch-4_12_14-150_35-default-debuginfo-2-2.1 - SUSE Linux Enterprise Live Patching 12-SP4 (ppc64le x86_64): kgraft-patch-4_12_14-95_32-default-2-2.1 References: https://www.suse.com/security/cve/CVE-2019-10220.html https://www.suse.com/security/cve/CVE-2019-17133.html https://bugzilla.suse.com/1144903 https://bugzilla.suse.com/1149841 https://bugzilla.suse.com/1153108 https://bugzilla.suse.com/1153158 https://bugzilla.suse.com/1153161 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Advisory: Major kernel update resolves significant vulnerabilities and improves performance for SLE 15 platforms.. SUSE Linux Kernel Patch, Live Patching Updates, SUSE Security Fixes, Kernel Update Optimization. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 30, 2019 Important SuSE
203

Mageia: 2019-0286 Moderate: Samba Path Escape and Remote Crash

Updated samba packages fix security vulnerabilities: A combination of parameters and permissions in smb.conf can allow user to escape from the share path definition (CVE-2019-10197). . MGASA-2019-0286 - Updated samba packages fix security vulnerabilities Publication date: 21 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0286.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-10197, CVE-2019-12435, CVE-2019-12436 Updated samba packages fix security vulnerabilities: A combination of parameters and permissions in smb.conf can allow user to escape from the share path definition (CVE-2019-10197). An authenticated user can crash the Samba AD DC''s RPC server process via a NULL pointer dereference (CVE-2019-12435) An user with read access to the directory can cause a NULL pointer dereference using the paged search control (CVE-2019-12436). For other fixes in this update, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=24980 - - - - - - - - https://www.cve.org/CVERecord?id=CVE-2019-10197 - https://www.cve.org/CVERecord?id=CVE-2019-12435 - https://www.cve.org/CVERecord?id=CVE-2019-12436 SRPMS: - 7/core/samba-4.10.8-3.mga7 . Mageia 2020-0458 enhances apache to resolve severe security flaws involving session and configuration problems.. samba security update, Mageia samba, vulnerability management, samba vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 21, 2019 Important Mageia
89

Fedora Core 1: 2004-116 Moderate Advisory for Rsync Path Escape Risk

A writing, non-chrooted rsync daemon could write outside of a module's path.. Fedora Update Notification FEDORA-2004-116 2004-07-01 --------------------------------------------------------------------- Product : Fedora Core 1 Name : rsync Version : 2.5.7 Release : 5.fc1 Summary : A program for synchronizing files over a network. Description : Rsync uses a reliable algorithm to bring remote and host files into sync very quickly. Rsync is fast because it just sends the differences in the files over the network instead of sending the complete files. Rsync is often used as a very powerful mirroring process or just as a more capable replacement for the rcp command. A technical report which describes the rsync algorithm is included in this package. --------------------------------------------------------------------- Update Information: Rsync before 2.6.1 does not properly sanitize paths when running a read/write daemon without using chroot. This could allow a remote attacker to write files outside of the module's "path", depending on the privileges assigned to the rsync daemon. Users not running an rsync daemon, running a read-only daemon, or running a chrooted daemon are not affected by this issue. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0426 to this issue. Updated packages were made available in June 2004 however the original update notification email did not make it to fedora-announce-list at that time. --------------------------------------------------------------------- * Wed May 05 2004 Jay Fenlason 2.5.7-5.fc1 - Include a patch from Wayne Davison which fixes CAN-2004-0426 --------------------------------------------------------------------- This update can be downloaded from: eea10f37a84d20da60b94ddd3a3c575c SRPMS/rsync-2.5.7-5.fc1.src.rpm f3ab287f51ad1048bf58cb2a3c85dd3d x86_64/rsync-2.5.7-5.fc1.x86_64.rpm f823931130df1d1d50276d52d9cc5e0c x86_64/debug/rsync-debuginfo-2.5.7-5.fc1.x86_64.rpm 236adecc9155a4728555650df95beb30 i386/rsync-2.5.7-5.fc1.i386.rpm d15048dea45f4e0db43e82f0a22940ea i386/debug/rsync-debuginfo-2.5.7-5.fc1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. . A path traversal vulnerability in rsync threatens Fedora Core 1, risking potential file breaches. Users must upgrade to the latest release to protect their systems. Rsync Path Escape,Fedora Security Advisory,rsync Update,Remote Exploit,Path Sanitization. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 02, 2004 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here