Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3727-1
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5606-1
Phan Nguyên Long discovered an Open Redirect vulnerability in horizon, a web application to control an OpenStack cloud, which could lead to phishing. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3676-1
Open Redirect vulnerabilities were found in libapache2-mod-auth-openidc, OpenID Connect Relying Party implementation for Apache, which could lead to information disclosure via phishing attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3499-1
Remote unauthenticated attacker may redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. (CVE-2023-28370) References: . MGASA-2023-0211 - Updated python-tornado packages fix security vulnerability Publication date: 28 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0211.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-28370 Remote unauthenticated attacker may redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. (CVE-2023-28370) References: - https://bugs.mageia.org/show_bug.cgi?id=32033 - https://ubuntu.com/security/notices/USN-6159-1 - https://www.cve.org/CVERecord?id=CVE-2023-28370 SRPMS: - 8/core/python-tornado-6.1-1.1.mga8 . Revamped python-tornado versions in Mageia mend a significant security vulnerability that facilitates phishing through misleading URL redirects.. Mageia 8, Tornado Security, Phishing Risk, Remote Attack, Security Update. . Severity: Critical. LinuxSecurity.com Team
libapache2-mod-auth-mellon, a SAML 2.0 authentication module for Apache, were reported to have the following vulnerabilities. CVE-2019-13038 . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3359-1
Phishing website URL removed from package spec file and replaced with new official site link. References: - https://bugs.mageia.org/show_bug.cgi?id=30679 . MGASA-2022-0276 - Updated osmo packages fix security vulnerability Publication date: 05 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0276.html Type: security Affected Mageia releases: 8 Phishing website URL removed from package spec file and replaced with new official site link. References: - https://bugs.mageia.org/show_bug.cgi?id=30679 - https://lists.fedoraproject.org/archives/list/
removes phishing site as URL, and updates to new. explicitly BuildRequires gcc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e57547c384 2022-07-28 01:29:59.622188 --------------------------------------------------------------------------------Name : osmo Product : Fedora 35 Version : 0.4.4 Release : 2.fc35 URL : Summary : Personal organizer Description : Osmo is a handy personal organizer which includes calendar, tasks manager and address book modules. It was designed to be a small, easy to use and good looking PIM tool to help to manage personal information. In current state the organizer is quite convenient in use - for example, user can perform nearly all operations using keyboard. Also, a lot of parameters are configurable to meet user preferences. --------------------------------------------------------------------------------Update Information: removes phishing site as URL, and updates to new. explicitly BuildRequires gcc --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Ranjan Maitra - 0.4.4-2 - Changed URL to which is *only* official OSMO web page. - Addresses BZ #2108423 - Explicitly BuildRequires gcc * Thu Jan 20 2022 Fedora Release Engineering - 0.4.4-1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Mon Sep 27 2021 Ranjan Maitra - 0.4.4-0.1 - update to version 0.4.4 - Several compilation problems fixed - Replaced compiled-in graphics with resource images - Many bug fixes and cleanups --------------------------------------------------------------------------------References: [ 1 ] Bug #2108424 - osmo: point to a phishing site [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108424 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-e57547c384' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.