Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 11: FEDORA-2009-7435 Moderate: perl-IO-Socket-SSL Hostname Fix

This update to version 1.26 fixes an issue where only the prefix of the hostname was checked if there was no wildcard present, so for example www.example.org would match a certificate starting with www.example.org . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-7435 2009-07-11 02:40:16 -------------------------------------------------------------------------------- Name : perl-IO-Socket-SSL Product : Fedora 11 Version : 1.26 Release : 1.fc11 URL : https://metacpan.org/dist/IO-Socket-SSL Summary : Perl library for transparent SSL Description : This module is a true drop-in replacement for IO::Socket::INET that uses SSL to encrypt data before it is transferred to a remote server or client. IO::Socket::SSL supports all the extra features that one needs to write a full-featured SSL client or server application: multiple SSL contexts, cipher selection, certificate verification, and SSL version selection. As an extra bonus, it works perfectly with mod_perl. -------------------------------------------------------------------------------- Update Information: This update to version 1.26 fixes an issue where only the prefix of the hostname was checked if there was no wildcard present, so for example ple.org would match a certificate starting with ple.org -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 4 2009 Paul Howarth - 1.26-1 - Update to 1.26 (verify_hostname_of_cert matched only the prefix for the hostname when no wildcard was given, e.g. ple.org matched against a certificate with name ple.com in it) * Fri Jul 3 2009 Paul Howarth - 1.25-1 - Update to 1.25 (fix t/nonblock.t for OS X 10.5 - CPAN RT#47240) -------------------------------------------------------------------------------- References: [ 1 ] Bug #509819 - perl-IO-Socket-SSL: incorrect checking of certificate hostnames https://bugzilla.redhat.com/show_bug.cgi?id=509819 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update perl-IO-Socket-SSL' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Enhances hostname prefix validation in SSL certificates for the Fedora 11 perl-IO-Socket-SSL package upgrade.. perl IO Socket SSL Fedora. . LinuxSecurity.com Team

Calendar 2 Oct 16, 2023 Fedora
172

Ubuntu 15.04 USN-2592-1 Critical: Libxml-libxml-perl Information Exposure

XML::LibXML could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-2592-1 May 04, 2015 libxml-libxml-perl vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: XML::LibXML could be made to expose sensitive information. Software Description: - libxml-libxml-perl: Perl interface to the libxml2 library Details: Tilmann Haak discovered that XML::LibXML incorrectly handled the expand_entities parameter in certain situations. A remote attacker could possibly use this issue to access sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.15.04.1 Ubuntu 14.10: libxml-libxml-perl 2.0116+dfsg-1ubuntu0.14.10.1 Ubuntu 14.04 LTS: libxml-libxml-perl 2.0108+dfsg-1ubuntu0.1 Ubuntu 12.04 LTS: libxml-libxml-perl 1.89+dfsg-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2592-1 CVE-2015-3451 Package Information: https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.15.04.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0116+dfsg-1ubuntu0.14.10.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/2.0108+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libxml-libxml-perl/1.89+dfsg-1ubuntu0.1 . A vulnerability found in the libxml-libxml-perl package of Ubuntu could potentially leak confidential information. Follow the provided steps for updates.. libxml, update instructions, exposure risk, ubuntu security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 04, 2015 Critical Ubuntu
87

Debian: DSA 960-2 Moderate: Libmail-Audit-Perl Local Threat Update

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 960-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 31st, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : libmail-audit-perl Vulnerability : insecure temporay file createion Problem type : local Debian-specific: no CVE ID : CVE-2005-4536 Debian Bug : 344029 This update only corrects the update for sarge, the version in woody is correct. Niko Tyni discovered that the Mail::Audit module, a Perl library for creating simple mail filters, logs to a temporary file with a predictable filename in an insecure fashion when logging is turned on, which is not the case by default. For the old stable distribution (woody) these problems have been fixed in version 2.0-4woody1. For the stable distribution (sarge) these problems have been fixed in version 2.1-5sarge2. For the unstable distribution (sid) these problems have been fixed in version 2.1-5.1. We recommend that you upgrade your libmail-audit-perl package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 786 00abe0533af4fb16e3f65a5dda9ded34 Size/MD5 checksum: 4266 4348a85b636a87503374874354eefdcd Size/MD5 checksum: 21669b52b1142fa9ed7d847c531186f913ea6 Architecture independent components: Size/MD5 checksum: 41874 136f752ab91f2ce393f1c943d151c0e3 Size/MD5 checksum: 12222 d3caeeef4e88540511c1fdb3ae3f8877 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Mail::Audit Perl library enhancement rectifies insecure temporary file flaw on Debian platforms.. Debian Security, Perl Library, Package Update. . LinuxSecurity.com Team

Calendar 2 Jan 31, 2006 Debian
87

Debian DSA 960-1 Moderate: Insecure Temporary File Risk in Mail::Audit

Niko Tyni discovered that the Mail::Audit module, a Perl library for creating simple mail filters, logs to a temporary file with a predictable filename in an insecure fashion when logging is turned on, which is not the case by default.. - --------------------------------------------------------------------------Debian Security Advisory DSA 960-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 31st, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : libmail-audit-perl Vulnerability : insecure temporay file createion Problem type : local Debian-specific: no CVE ID : CVE-2005-4536 Debian Bug : 344029 Niko Tyni discovered that the Mail::Audit module, a Perl library for creating simple mail filters, logs to a temporary file with a predictable filename in an insecure fashion when logging is turned on, which is not the case by default. For the old stable distribution (woody) these problems have been fixed in version 2.0-4woody1. For the stable distribution (sarge) these problems have been fixed in version 2.1-5sarge1. For the unstable distribution (sid) these problems have been fixed in version 2.1-5sarge1. We recommend that you upgrade your libmail-audit-perl package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 663f1cc82dae98e2a7ae42e29e757797b41 Size/MD5 checksum: 5548 64f85349649a968db3493fa8ba27aea1 Size/MD5 checksum: 12526 3bc6043611f0fabdd856498e25bd48f6 Architecture independent components: Size/MD5 checksum: 29446 d7e0e9264e08f04777eb05f543956498 Size/MD5 checksum: 8840 f97415f72fcf1806b18e9e059ae5c6e0 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 786 766a0a1d409fb6a55d0fd28cfeb9139d Size/MD5 checksum: 4227 48ed975c7c87db86bcafde084cde94a5 Size/MD5 checksum: 21669 b52b1142fa9ed7d847c531186f913ea6 Architecture independent components: Size/MD5 checksum: 41836 38128df51141ba4bd495f3d698629b52 Size/MD5 checksum: 12176 1d898a6a9f2a40cad0416d5b107df3bd These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 961-1 focuses on vulnerabilities in the handling of temporary files within the application Mail::Monitor.. Mail Filters, Debian DSA, Perl Library, File Security, Local Threat. . LinuxSecurity.com Team

Calendar 2 Jan 31, 2006 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here