Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
202

openSUSE 15.5: SUSE-SU-2024:4396-1 moderate: aiohttp static path issue

An update that solves one vulnerability can now be installed.. # Security update for python-aiohttp Announcement ID: SUSE-SU-2024:4396-1 Release Date: 2024-12-20T12:02:05Z Rating: moderate References: * bsc#1223098 Cross-References: * CVE-2024-27306 CVSS scores: * CVE-2024-27306 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.5 * Public Cloud Module 15-SP2 * Public Cloud Module 15-SP3 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2024-27306: filenames and paths not escaped when generating index pages for static file handling. (bsc#1223098) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can runthe command listed for your product: * Public Cloud Module 15-SP3 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP3-2024-4396=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2024-4396=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2024-4396=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2024-4396=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4396=1 * Public Cloud Module 15-SP2 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2024-4396=1 ## Package List: * Public Cloud Module 15-SP3 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python-aiohttp-doc-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 * Public Cloud Module 15-SP2 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-debuginfo-3.6.0-150100.3.24.1 * python-aiohttp-debugsource-3.6.0-150100.3.24.1 * python-aiohttp-doc-3.6.0-150100.3.24.1 * python3-aiohttp-3.6.0-150100.3.24.1 ## References: *https://www.suse.com/security/cve/CVE-2024-27306.html * https://bugzilla.suse.com/show_bug.cgi?id=1223098 . The Fedora advisory refreshes python-aiohttp to address a directory flaw categorized as low impact. Important for developers.. openSUSE advisory, python-aiohttp security, package update, static file handling issue. . LinuxSecurity.com Team

Calendar%202 Dec 20, 2024 OpenSUSE
203

Mageia 9 MGASA-2024-0013 critical: HPLIP /tmp Path Security Fix

There were security issues in hplip's `hpps` program due to fixed /tmp path usage in prnt/hpps/hppsfilter.c This update fixes these issues. References: . MGASA-2024-0013 - Updated hplip packages fix security vulnerabilities Publication date: 16 Jan 2024 URL: https://advisories.mageia.org/MGASA-2024-0013.html Type: security Affected Mageia releases: 9 There were security issues in hplip's `hpps` program due to fixed /tmp path usage in prnt/hpps/hppsfilter.c This update fixes these issues. References: - https://bugs.mageia.org/show_bug.cgi?id=32701 - https://www.openwall.com/lists/oss-security/2023/11/17/1 - https://www.openwall.com/lists/oss-security/2024/01/04/1 SRPMS: - 9/core/hplip-3.22.10-4.1.mga9 . Essential HPLIP fix tackles critical flaws associated with /tmp processes, rectified in Mageia 9 as indicated in MGASA-2024-0013.. Mageia Updates,HPLIP Security,Open Source Fixes,Software Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 16, 2024 Critical Mageia
100

SUSE Linux Enterprise: Update 2023:4645-1 moderate: haproxy path issue

* bsc#1217653 Cross-References: * CVE-2023-45539 . # Security update for haproxy Announcement ID: SUSE-SU-2023:4645-1 Rating: moderate References: * bsc#1217653 Cross-References: * CVE-2023-45539 CVSS scores: * CVE-2023-45539 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2023-45539 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP2 * SUSE Linux Enterprise High Availability Extension 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 Business Critical Linux 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 Business Critical Linux 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Proxy 4.1 * SUSE Manager Proxy 4.2 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Server 4.1 * SUSE Manager Server 4.2 An update that solves one vulnerability can now be installed. ## Description: This update for haproxy fixes the following issues: * CVE-2023-45539: Fixed misinterpretation of a path_end rule with # as part of the URI component (bsc#1217653). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP2 zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2023-4645=1 * SUSE Linux Enterprise High Availability Extension 15 SP3 zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2023-4645=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP2 (aarch64 ppc64le s390x x86_64) *haproxy-debuginfo-2.0.31-150200.11.26.1 * haproxy-debugsource-2.0.31-150200.11.26.1 * haproxy-2.0.31-150200.11.26.1 * SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le s390x x86_64) * haproxy-debuginfo-2.0.31-150200.11.26.1 * haproxy-debugsource-2.0.31-150200.11.26.1 * haproxy-2.0.31-150200.11.26.1 ## References: * https://www.suse.com/security/cve/CVE-2023-45539.html * https://bugzilla.suse.com/show_bug.cgi?id=1217653 . SUSE-SU-2023:4645-1 security update for Haproxy addresses multiple security flaws and provides detailed installation instructions.. SUSE Haproxy Fix, Linux Enterprise Patching, Haproxy Update. . LinuxSecurity.com Team

Calendar%202 Dec 06, 2023 SuSE
202

openSUSE Leap 15.4, 15.5: SUSE-SU-2023:4469-1 moderate: go1.21-openssl fix

This update for go1.21-openssl fixes the following issues: Update to version 1.21.4.1 cut from the go1.21-openssl-fips branch at the revision tagged go1.21.4-1-openssl-fips.. # Security update for go1.21-openssl Announcement ID: SUSE-SU-2023:4469-1 Rating: moderate References: * bsc#1212475 * bsc#1212667 * bsc#1212669 * bsc#1215084 * bsc#1215085 * bsc#1215086 * bsc#1215087 * bsc#1215090 * bsc#1215985 * bsc#1216109 * bsc#1216943 * bsc#1216944 * jsc#SLE-18320 Cross-References: * CVE-2023-39318 * CVE-2023-39319 * CVE-2023-39320 * CVE-2023-39321 * CVE-2023-39322 * CVE-2023-39323 * CVE-2023-39325 * CVE-2023-44487 * CVE-2023-45283 * CVE-2023-45284 CVSS scores: * CVE-2023-39318 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2023-39318 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2023-39319 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2023-39319 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2023-39320 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2023-39320 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-39321 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39322 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39322 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39323 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-39323 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-39325 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-39325 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45283 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2023-45284 ( SUSE ): 6.8CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N Affected Products: * Development Tools Module 15-SP4 * Development Tools Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 10 vulnerabilities, contains one feature and has two security fixes can now be installed. ## Description: This update for go1.21-openssl fixes the following issues: Update to version 1.21.4.1 cut from the go1.21-openssl-fips branch at the revision tagged go1.21.4-1-openssl-fips. * Update to go1.21.4 go1.21.4 (released 2023-11-07) includes security fixes to the path/filepath package, as well as bug fixes to the linker, the runtime, the compiler, and the go/types, net/http, and runtime/cgo packages. * security: fix CVE-2023-45283 CVE-2023-45284 path/filepath: insecure parsing of Windows paths (bsc#1216943, bsc#1216944) * spec: update unification rules * cmd/compile: internal compiler error: expected struct value to have type struct * cmd/link: split text sections for arm 32-bit * runtime: MADV_COLLAPSE causes production performance issues on Linux * go/types, x/tools/go/ssa: panic: type param without replacement encountered * cmd/compile: -buildmode=c-archive produces code not suitable for use in a shared object on arm64 * net/http: http2 page fails on firefox/safari if pushing resources Initial package go1.21-openssl version 1.21.3.1 cut from the go1.21-openssl-fips branch at the revision tagged go1.21.3-1-openssl-fips.(jsc#SLE-18320) * Go upstream merged branch dev.boringcrypto in go1.19+. * In go1.x enable BoringCrypto via GOEXPERIMENT=boringcrypto. * In go1.x-openssl enable FIPS mode (or boring mode as the package is named) either via an environment variable GOLANG_FIPS=1 or by virtue of booting the host in FIPS mode. * When the operating system is operating in FIPS mode, Go applications which import crypto/tls/fipsonly limit operations to the FIPS ciphersuite. * go1.x-openssl is delivered as two large patches to go1.x applying necessary modifications from the golang-fips/go GitHub project for the Go crypto library to use OpenSSL as the external cryptographic library in a FIPS compliant way. * go1.x-openssl modifies the crypto/* packages to use OpenSSL for cryptographic operations. * go1.x-openssl uses dlopen() to call into OpenSSL. * SUSE RPM packaging introduces a fourth version digit go1.x.y.z corresponding to the golang-fips/go patchset tagged revision. * Patchset improvements can be updated independently of upstream Go maintenance releases. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4469=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4469=1 * Development Tools Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP4-2023-4469=1 * Development Tools Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP5-2023-4469=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * go1.21-openssl-doc-1.21.4.1-150000.1.5.1 * go1.21-openssl-race-1.21.4.1-150000.1.5.1 * go1.21-openssl-1.21.4.1-150000.1.5.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * go1.21-openssl-doc-1.21.4.1-150000.1.5.1 * go1.21-openssl-race-1.21.4.1-150000.1.5.1 * go1.21-openssl-1.21.4.1-150000.1.5.1 * Development ToolsModule 15-SP4 (aarch64 ppc64le s390x x86_64) * go1.21-openssl-doc-1.21.4.1-150000.1.5.1 * go1.21-openssl-race-1.21.4.1-150000.1.5.1 * go1.21-openssl-1.21.4.1-150000.1.5.1 * Development Tools Module 15-SP5 (aarch64 ppc64le s390x x86_64) * go1.21-openssl-doc-1.21.4.1-150000.1.5.1 * go1.21-openssl-race-1.21.4.1-150000.1.5.1 * go1.21-openssl-1.21.4.1-150000.1.5.1 ## References: * https://www.suse.com/security/cve/CVE-2023-39318.html * https://www.suse.com/security/cve/CVE-2023-39319.html * https://www.suse.com/security/cve/CVE-2023-39320.html * https://www.suse.com/security/cve/CVE-2023-39321.html * https://www.suse.com/security/cve/CVE-2023-39322.html * https://www.suse.com/security/cve/CVE-2023-39323.html * https://www.suse.com/security/cve/CVE-2023-39325.html * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2023-45283.html * https://www.suse.com/security/cve/CVE-2023-45284.html * https://bugzilla.suse.com/show_bug.cgi?id=1212475 * https://bugzilla.suse.com/show_bug.cgi?id=1212667 * https://bugzilla.suse.com/show_bug.cgi?id=1212669 * https://bugzilla.suse.com/show_bug.cgi?id=1215084 * https://bugzilla.suse.com/show_bug.cgi?id=1215085 * https://bugzilla.suse.com/show_bug.cgi?id=1215086 * https://bugzilla.suse.com/show_bug.cgi?id=1215087 * https://bugzilla.suse.com/show_bug.cgi?id=1215090 * https://bugzilla.suse.com/show_bug.cgi?id=1215985 * https://bugzilla.suse.com/show_bug.cgi?id=1216109 * https://bugzilla.suse.com/show_bug.cgi?id=1216943 * https://bugzilla.suse.com/show_bug.cgi?id=1216944 * . The recent release of go1.21-openssl resolves various concerns and introduces upgrades for development utilities on openSUSE.. openSUSE Update, Go1.21 Patch, OpenSSL Fix, Development Tools Upgrades. . LinuxSecurity.com Team

Calendar%202 Nov 16, 2023 OpenSUSE
203

Mageia 8: 2022-0140 Moderate: Subversion Memory Corruption Issue

SVN authz protected copyfrom paths regression. (CVE-2021-28544) Subversion's mod_dav_svn is vulnerable to memory corruption. (CVE-2022-24070) References: . MGASA-2022-0140 - Updated subversion packages fix security vulnerability Publication date: 13 Apr 2022 URL: https://advisories.mageia.org/MGASA-2022-0140.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-28544, CVE-2022-24070 SVN authz protected copyfrom paths regression. (CVE-2021-28544) Subversion's mod_dav_svn is vulnerable to memory corruption. (CVE-2022-24070) References: - https://bugs.mageia.org/show_bug.cgi?id=30274 - https://subversion.apache.org/security/CVE-2021-28544-advisory.txt - https://subversion.apache.org/security/CVE-2022-24070-advisory.txt - https://www.openwall.com/lists/oss-security/2022/04/12/2 - https://www.cve.org/CVERecord?id=CVE-2021-28544 - https://www.cve.org/CVERecord?id=CVE-2022-24070 SRPMS: - 8/core/subversion-1.14.2-1.mga8 . Updates for Subversion packages issued to resolve memory corruption vulnerabilities and path-related concerns. Urgent advisory for Mageia 8 users.. Mageia Security Update, Subversion Vulnerability, Memory Corruption Fix. . LinuxSecurity.com Team

Calendar%202 Apr 13, 2022 Mageia
89

Fedora 34: 2021-b9187c535c Moderate: php-league-flysystem Path Issue

**Version 1.1.4** * Reject paths with funky whitespace.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-b9187c535c 2021-07-04 01:06:05.754498 --------------------------------------------------------------------------------Name : php-league-flysystem Product : Fedora 34 Version : 1.1.4 Release : 1.fc34 URL : https://github.com/thephpleague/flysystem Summary : Filesystem abstraction: Many filesystems, one API Description : Flysystem is a filesystem abstraction which allows you to easily swap out a local filesystem for a remote one. Autoloader: /usr/share/php/League/Flysystem/autoload.php --------------------------------------------------------------------------------Update Information: **Version 1.1.4** * Reject paths with funky whitespace. --------------------------------------------------------------------------------ChangeLog: * Fri Jun 25 2021 Remi Collet - 1.1.4-1 - update to 1.1.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #1975956 - CVE-2021-32708 php-league-flysystem: Time-of-check Time-of-use Race Condition https://bugzilla.redhat.com/show_bug.cgi?id=1975956 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-b9187c535c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Debian Security Alert for php-league-flysystem 1.1.4 resolves path irregularities and various concerns.. php-league-flysystem,Fedora security,software update,filesystem issues. . LinuxSecurity.com Team

Calendar%202 Jul 03, 2021 Fedora
89

Fedora 34: 2021-403a7624fa Major: Critical Update For GNOME Online Accounts

GNOME 40.rc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-303f6623fa 2021-03-20 00:16:30.596999 --------------------------------------------------------------------------------Name : gnome-online-accounts Product : Fedora 34 Version : 3.39.92 Release : 1.fc34 URL : https://wiki.gnome.org/Projects/GnomeOnlineAccounts Summary : Single sign-on framework for GNOME Description : GNOME Online Accounts provides interfaces so that applications and libraries in GNOME can access the user's online accounts. It has providers for Google, Nextcloud, Facebook, Flickr, Foursquare, Microsoft Account, Microsoft Exchange, IMAP/SMTP and Kerberos. --------------------------------------------------------------------------------Update Information: GNOME 40.rc --------------------------------------------------------------------------------ChangeLog: * Tue Mar 16 2021 Debarshi Ray - 3.39.92-1 - Update to 3.39.92 --------------------------------------------------------------------------------References: [ 1 ] Bug #1925640 - CVE-2020-36241 gnome-autoar: directory traversal via a malicious archive that contains a file whose parent is a symbolic link which points outside of the destination directory https://bugzilla.redhat.com/show_bug.cgi?id=1925640 [ 2 ] Bug #1940026 - CVE-2021-28650 gnome-autoar: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations https://bugzilla.redhat.com/show_bug.cgi?id=1940026 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-303f6623fa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . An essential patch for GNOME Online Accounts in Fedora 34 resolves security concerns related to directory traversal vulnerabilities with a significant correction.. directory traversal, GNOME Online Accounts, Fedora Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 19, 2021 Critical Fedora
98

Red Hat Enterprise Linux: RHSA-2018:3800-01 Important: Git Path Issue

An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-git218-git security update Advisory ID: RHSA-2018:3800-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2018:3800 Issue date: 2018-12-10 CVE Names: CVE-2018-19486 ==================================================================== 1. Summary: An update for rh-git218-git is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Git is a distributed revision control system with a decentralized architecture. As opposed to centralized version control systems with a client-server model, Git ensures that each working copy of a Git repository is an exact copy with complete revision history. This not only allows the user to work on and contribute to projects without the need tohave permission to push the changes to their official repositories, but also makes it possible for the user to work with no network connection. Security Fix(es): * git: Improper handling of PATH allows for commands to be executed from the current directory (CVE-2018-19486) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1653143 - CVE-2018-19486 git: Improper handling of PATH allows for commands to be executed from the current directory 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-git218-git-2.18.1-3.el7.src.rpm aarch64: rh-git218-git-2.18.1-3.el7.aarch64.rpm rh-git218-git-core-2.18.1-3.el7.aarch64.rpm rh-git218-git-daemon-2.18.1-3.el7.aarch64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.aarch64.rpm rh-git218-git-instaweb-2.18.1-3.el7.aarch64.rpm rh-git218-git-subtree-2.18.1-3.el7.aarch64.rpm rh-git218-git-svn-2.18.1-3.el7.aarch64.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm ppc64le: rh-git218-git-2.18.1-3.el7.ppc64le.rpm rh-git218-git-core-2.18.1-3.el7.ppc64le.rpm rh-git218-git-daemon-2.18.1-3.el7.ppc64le.rpm rh-git218-git-debuginfo-2.18.1-3.el7.ppc64le.rpm rh-git218-git-instaweb-2.18.1-3.el7.ppc64le.rpm rh-git218-git-subtree-2.18.1-3.el7.ppc64le.rpm rh-git218-git-svn-2.18.1-3.el7.ppc64le.rpm s390x: rh-git218-git-2.18.1-3.el7.s390x.rpm rh-git218-git-core-2.18.1-3.el7.s390x.rpm rh-git218-git-daemon-2.18.1-3.el7.s390x.rpm rh-git218-git-debuginfo-2.18.1-3.el7.s390x.rpm rh-git218-git-instaweb-2.18.1-3.el7.s390x.rpm rh-git218-git-subtree-2.18.1-3.el7.s390x.rpm rh-git218-git-svn-2.18.1-3.el7.s390x.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-git218-git-2.18.1-3.el7.src.rpm aarch64: rh-git218-git-2.18.1-3.el7.aarch64.rpm rh-git218-git-core-2.18.1-3.el7.aarch64.rpm rh-git218-git-daemon-2.18.1-3.el7.aarch64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.aarch64.rpm rh-git218-git-instaweb-2.18.1-3.el7.aarch64.rpm rh-git218-git-subtree-2.18.1-3.el7.aarch64.rpm rh-git218-git-svn-2.18.1-3.el7.aarch64.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm ppc64le: rh-git218-git-2.18.1-3.el7.ppc64le.rpm rh-git218-git-core-2.18.1-3.el7.ppc64le.rpm rh-git218-git-daemon-2.18.1-3.el7.ppc64le.rpm rh-git218-git-debuginfo-2.18.1-3.el7.ppc64le.rpm rh-git218-git-instaweb-2.18.1-3.el7.ppc64le.rpm rh-git218-git-subtree-2.18.1-3.el7.ppc64le.rpm rh-git218-git-svn-2.18.1-3.el7.ppc64le.rpm s390x: rh-git218-git-2.18.1-3.el7.s390x.rpm rh-git218-git-core-2.18.1-3.el7.s390x.rpm rh-git218-git-daemon-2.18.1-3.el7.s390x.rpm rh-git218-git-debuginfo-2.18.1-3.el7.s390x.rpm rh-git218-git-instaweb-2.18.1-3.el7.s390x.rpm rh-git218-git-subtree-2.18.1-3.el7.s390x.rpm rh-git218-git-svn-2.18.1-3.el7.s390x.rpm x86_64: rh-git218-git-2.18.1-3.el7.x86_64.rpm rh-git218-git-core-2.18.1-3.el7.x86_64.rpm rh-git218-git-daemon-2.18.1-3.el7.x86_64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.x86_64.rpm rh-git218-git-instaweb-2.18.1-3.el7.x86_64.rpm rh-git218-git-subtree-2.18.1-3.el7.x86_64.rpm rh-git218-git-svn-2.18.1-3.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.4): Source: rh-git218-git-2.18.1-3.el7.src.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm ppc64le: rh-git218-git-2.18.1-3.el7.ppc64le.rpm rh-git218-git-core-2.18.1-3.el7.ppc64le.rpm rh-git218-git-daemon-2.18.1-3.el7.ppc64le.rpm rh-git218-git-debuginfo-2.18.1-3.el7.ppc64le.rpm rh-git218-git-instaweb-2.18.1-3.el7.ppc64le.rpm rh-git218-git-subtree-2.18.1-3.el7.ppc64le.rpm rh-git218-git-svn-2.18.1-3.el7.ppc64le.rpm s390x: rh-git218-git-2.18.1-3.el7.s390x.rpm rh-git218-git-core-2.18.1-3.el7.s390x.rpm rh-git218-git-daemon-2.18.1-3.el7.s390x.rpm rh-git218-git-debuginfo-2.18.1-3.el7.s390x.rpm rh-git218-git-instaweb-2.18.1-3.el7.s390x.rpm rh-git218-git-subtree-2.18.1-3.el7.s390x.rpm rh-git218-git-svn-2.18.1-3.el7.s390x.rpm x86_64: rh-git218-git-2.18.1-3.el7.x86_64.rpm rh-git218-git-core-2.18.1-3.el7.x86_64.rpm rh-git218-git-daemon-2.18.1-3.el7.x86_64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.x86_64.rpm rh-git218-git-instaweb-2.18.1-3.el7.x86_64.rpm rh-git218-git-subtree-2.18.1-3.el7.x86_64.rpm rh-git218-git-svn-2.18.1-3.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.5): Source: rh-git218-git-2.18.1-3.el7.src.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm ppc64le: rh-git218-git-2.18.1-3.el7.ppc64le.rpm rh-git218-git-core-2.18.1-3.el7.ppc64le.rpm rh-git218-git-daemon-2.18.1-3.el7.ppc64le.rpm rh-git218-git-debuginfo-2.18.1-3.el7.ppc64le.rpm rh-git218-git-instaweb-2.18.1-3.el7.ppc64le.rpm rh-git218-git-subtree-2.18.1-3.el7.ppc64le.rpm rh-git218-git-svn-2.18.1-3.el7.ppc64le.rpm s390x: rh-git218-git-2.18.1-3.el7.s390x.rpm rh-git218-git-core-2.18.1-3.el7.s390x.rpm rh-git218-git-daemon-2.18.1-3.el7.s390x.rpm rh-git218-git-debuginfo-2.18.1-3.el7.s390x.rpm rh-git218-git-instaweb-2.18.1-3.el7.s390x.rpm rh-git218-git-subtree-2.18.1-3.el7.s390x.rpm rh-git218-git-svn-2.18.1-3.el7.s390x.rpm x86_64: rh-git218-git-2.18.1-3.el7.x86_64.rpm rh-git218-git-core-2.18.1-3.el7.x86_64.rpm rh-git218-git-daemon-2.18.1-3.el7.x86_64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.x86_64.rpm rh-git218-git-instaweb-2.18.1-3.el7.x86_64.rpm rh-git218-git-subtree-2.18.1-3.el7.x86_64.rpm rh-git218-git-svn-2.18.1-3.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-git218-git-2.18.1-3.el7.src.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm ppc64le: rh-git218-git-2.18.1-3.el7.ppc64le.rpm rh-git218-git-core-2.18.1-3.el7.ppc64le.rpm rh-git218-git-daemon-2.18.1-3.el7.ppc64le.rpm rh-git218-git-debuginfo-2.18.1-3.el7.ppc64le.rpm rh-git218-git-instaweb-2.18.1-3.el7.ppc64le.rpm rh-git218-git-subtree-2.18.1-3.el7.ppc64le.rpm rh-git218-git-svn-2.18.1-3.el7.ppc64le.rpm s390x: rh-git218-git-2.18.1-3.el7.s390x.rpm rh-git218-git-core-2.18.1-3.el7.s390x.rpm rh-git218-git-daemon-2.18.1-3.el7.s390x.rpm rh-git218-git-debuginfo-2.18.1-3.el7.s390x.rpm rh-git218-git-instaweb-2.18.1-3.el7.s390x.rpm rh-git218-git-subtree-2.18.1-3.el7.s390x.rpm rh-git218-git-svn-2.18.1-3.el7.s390x.rpm x86_64: rh-git218-git-2.18.1-3.el7.x86_64.rpm rh-git218-git-core-2.18.1-3.el7.x86_64.rpm rh-git218-git-daemon-2.18.1-3.el7.x86_64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.x86_64.rpm rh-git218-git-instaweb-2.18.1-3.el7.x86_64.rpm rh-git218-git-subtree-2.18.1-3.el7.x86_64.rpm rh-git218-git-svn-2.18.1-3.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-git218-git-2.18.1-3.el7.src.rpm noarch: rh-git218-git-all-2.18.1-3.el7.noarch.rpm rh-git218-git-core-doc-2.18.1-3.el7.noarch.rpm rh-git218-git-cvs-2.18.1-3.el7.noarch.rpm rh-git218-git-email-2.18.1-3.el7.noarch.rpm rh-git218-git-gui-2.18.1-3.el7.noarch.rpm rh-git218-git-p4-2.18.1-3.el7.noarch.rpm rh-git218-gitk-2.18.1-3.el7.noarch.rpm rh-git218-gitweb-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-2.18.1-3.el7.noarch.rpm rh-git218-perl-Git-SVN-2.18.1-3.el7.noarch.rpm x86_64: rh-git218-git-2.18.1-3.el7.x86_64.rpm rh-git218-git-core-2.18.1-3.el7.x86_64.rpm rh-git218-git-daemon-2.18.1-3.el7.x86_64.rpm rh-git218-git-debuginfo-2.18.1-3.el7.x86_64.rpm rh-git218-git-instaweb-2.18.1-3.el7.x86_64.rpm rh-git218-git-subtree-2.18.1-3.el7.x86_64.rpm rh-git218-git-svn-2.18.1-3.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-19486 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXA4f2tzjgjWX9erEAQjtsw//Zt+3Qi2XRiWVO2Kh2/6QetzBqu1kmEeb gx39F4uRNZNyWOl0H+gIBRQ93DkMgenoIcst4aCd/BxZfv6VPmN8gKwfEbo2qdP6 +SCcva1nifDjPuao5L2ZCF88XM0RJl6WqECd76gToACcH1lNoGREsaR37oCYdAvD yQXfzDs9hlFBu/RYsrrpkY262SKsBR9cE3W3N1QXTH6C3/f0XH7oiT2DfSnIYJbn Fh9N2vifyAm55t1aGNw1fcscKIf9KWnDg8tqRHA5wql6pj6Mvbh+L2TazMvQhIZ9 e6ZwpJUV+5RkkWAoPX5hHMNtpQBSCad6TKu4xKLuyHSwCCCVSCEnPs/weorGyARH oCZbu+u8KsUNSS5K37sur5xPisVT2S7tWg+o8v4Ngmo460RyHb+zXBMUutoRlNnP bdIjQ6XjyRwDxGveP+KiGqJ55IHjupTv1Q5kgveC3Ilxx+DB53od4ddfYBxpmiBB GtF5j41QlpstS3RwHHtVaybkbQK3CK3zzXwR/TF8wwBjbxZOxjgrBf53N0mUedvy Ay2sxiGCKrh0PCIYrs0TTJ4Y+Tfpmz1KeJpj4kC+E+QCPu4D6QxUq7yCUiooSrbu faNGQJ+MPEFs3OjTx3D37mVECYXK6lnBfnw3AE0FgeW/gYJu6m8nLYoFELJ1Es1k u5+xetH4v3A=j/wr -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat has announced a crucial security patch for rh-git218-git to address potential vulnerabilities.. rh-git218-git security update, red hat advisory, important security fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 10, 2018 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200