Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
217

Oracle Linux 8 ELSA-2024-10219 moderate: perl-App-cpanminus HTTPS patch

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-10219 http://linux.oracle.com/errata/ELSA-2024-10219.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.noarch.rpm aarch64: perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.noarch.rpm perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.noarch.rpm perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.noarch.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90447+dcd0bd0b.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90448+352bb180.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90446+cd5c22a3.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-App-cpanminus-1.7044-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-DistnameInfo-0.12-13.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-CPAN-Meta-Check-0.014-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-File-pushd-1.014-6.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Module-CPANfile-1.1002-7.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-Parse-PMFile-0.41-7.module+el8.10.0+90444+3175cdc0.src.rpm http://oss.oracle.com/ol8/SRPMS-updates//perl-String-ShellQuote-1.04-24.module+el8.10.0+90444+3175cdc0.src.rpm Related CVEs: CVE-2024-45321 Description of changes: perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote perl-App-cpanminus [1.7044-6] - Patch the code to use https instead of http (CVE-2024-45321) perl-CPAN-DistnameInfo perl-CPAN-Meta-Check perl-File-pushd perl-Module-CPANfile perl-Parse-PMFile perl-String-ShellQuote _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Fedora 36 introduces improvements for Python libraries that resolve a critical vulnerability through enhanced encryption protocols for safety.. Oracle Linux, security advisory updates, perl modules, software patching. . LinuxSecurity.com Team

Calendar%202 Dec 13, 2024 Oracle
89

Fedora 39: Security Advisory on perl-App-cpanminus for HTTPS Patch

Patch the code to use https instead of http (CVE-2024-45321). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-78e43b4de6 2024-10-09 00:46:39.270360 -------------------------------------------------------------------------------- Name : perl-App-cpanminus Product : Fedora 39 Version : 1.7047 Release : 2.fc39 URL : https://metacpan.org/dist/App-cpanminus Summary : Get, unpack, build and install CPAN modules Description : Why? It's dependency free, requires zero configuration, and stands alone but it's maintainable and extensible with plug-ins and friendly to shell scripting. When running, it requires only 10 MB of RAM. -------------------------------------------------------------------------------- Update Information: Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Jitka Plesnikova - 1.7047-2 - Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2308438 - CVE-2024-45321 perl-App-cpanminus: From NVD collector [fedora-39] https://bugzilla.redhat.com/show_bug.cgi?id=2308438 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-78e43b4de6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . Patch issue fixed with updated HTTPS protocols in perl-App-cpanminus for Fedora 39, ensuring security compliance.. Fedora Updates, Security Advisory, HTTPS Protocols, perl-App-cpanminus. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 09, 2024 Important Fedora
89

Fedora 39: FEDORA-2023-921f6975c2 critical: perl-Spreadsheet exec risk

Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability).. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-921f6975c2 2024-01-08 01:23:05.713087 -------------------------------------------------------------------------------- Name : perl-Spreadsheet-ParseExcel Product : Fedora 39 Version : 0.6600 Release : 1.fc39 URL : https://metacpan.org/dist/Spreadsheet-ParseExcel Summary : Extract information from an Excel file Description : The Spreadsheet::ParseExcel module can be used to read information from an Excel 95-2003 file. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability). -------------------------------------------------------------------------------- ChangeLog: * Sat Dec 30 2023 Paul Howarth - 0.6600-1 - Update to 0.66 - Fix for CVE-2023-7101 (unvalidated input can lead to arbitrary code execution vulnerability) https://github.com/runrig/spreadsheet-parseexcel/issues/33 - Use author-independent source URL - Use SPDX-format license tag - No longer need to fix document file permissions - Fix permissions verbosely - Don't assume "pm" suffix on manpage files -------------------------------------------------------------------------------- References: [ 1 ] Bug #2255871 - CVE-2023-7101 perl-Spreadsheet-ParseExcel: unvalidated input can lead to arbitrary code execution vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2255871 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-921f6975c2' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 39 contains a flaw within the Spreadsheet-ParseExcel library that may permit arbitrary code execution.. perl Spreadsheet ParseExcel,Fedora update,arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 08, 2024 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200