Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 14 articles for you...
197

Debian 10: DLA-3727-1 Moderate: Firefox-ESR Multiple Issues

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3727-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort January 31, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : firefox-esr Version : 115.7.0esr-1~deb10u1 CVE ID : CVE-2024-0741 CVE-2024-0742 CVE-2024-0746 CVE-2024-0747 CVE-2024-0749 CVE-2024-0750 CVE-2024-0751 CVE-2024-0753 CVE-2024-0755 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. For Debian 10 buster, these problems have been fixed in version 115.7.0esr-1~deb10u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/firefox-esr Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several vulnerabilities may lead to arbitrary code execution, cross-site scripting, and additional risks in Mozilla Firefox. It is advised to update your browser.. Debian, Firefox Security, Update Nightly, Bug Fixes. . LinuxSecurity.com Team

Calendar%202 Jan 31, 2024 Debian LTS
87

Debian Bullseye & Bookworm DSA-5606-1 Critical: Firefox-ESR Threats

Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5606-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 24, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2024-0741 CVE-2024-0742 CVE-2024-0746 CVE-2024-0747 CVE-2024-0749 CVE-2024-0750 CVE-2024-0751 CVE-2024-0753 CVE-2024-0755 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, phishing, clickjacking, privilege escalation, HSTS bypass or bypass of content security policies. For the oldstable distribution (bullseye), these problems have been fixed in version 115.7.0esr-1~deb11u1. For the stable distribution (bookworm), these problems have been fixed in version 115.7.0esr-1~deb12u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5606-1 warns of multiple critical issues in Firefox-ESR that could escalate risks.. Debian Security,Firefox ESR,Code Execution Risk,Web Browser Security,Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 24, 2024 Critical Debian
197

Debian 10 Horizon: DLA-3676-1 critical Open Redirect risk

Phan Nguyên Long discovered an Open Redirect vulnerability in horizon, a web application to control an OpenStack cloud, which could lead to phishing. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3676-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin November 30, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : horizon Version : 3:14.0.2-3+deb10u3 CVE ID : CVE-2022-45582 Phan Nguyên Long discovered an Open Redirect vulnerability in horizon, a web application to control an OpenStack cloud, which could lead to phishing. For Debian 10 buster, this problem has been fixed in version 3:14.0.2-3+deb10u3. We recommend that you upgrade your horizon packages. For the detailed security status of horizon please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/horizon Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update Horizon on Debian LTS to mitigate severe Open Redirect vulnerability that poses phishing dangers. Discover further information here.. Debian Security Update, Open Redirect Issue, Horizon Application Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 30, 2023 Critical Debian LTS
197

Debian 10 Buster: DLA-3499-1 Moderate: Open Redirect Threat Details

Open Redirect vulnerabilities were found in libapache2-mod-auth-openidc, OpenID Connect Relying Party implementation for Apache, which could lead to information disclosure via phishing attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3499-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin July 19, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libapache2-mod-auth-openidc Version : 2.3.10.2-1+deb10u3 CVE ID : CVE-2021-39191 CVE-2022-23527 Debian Bug : 993648 1026444 Open Redirect vulnerabilities were found in libapache2-mod-auth-openidc, OpenID Connect Relying Party implementation for Apache, which could lead to information disclosure via phishing attacks. CVE-2021-39191 The 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supplying a crafted URL in the target_link_uri parameter. CVE-2022-23527 When providing a logout parameter to the redirect URI, mod_auth_openidc failed to properly check for URLs starting with "/\t", leading to an open redirect. For Debian 10 buster, these problems have been fixed in version 2.3.10.2-1+deb10u3. We recommend that you upgrade your libapache2-mod-auth-openidc packages. For the detailed security status of libapache2-mod-auth-openidc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache2-mod-auth-openidc Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Mitigate Open Redirect vulnerabilities in libapache2-mod-auth-openidc to enhance cybersecurity and combat phishing threats.. Open Redirect, libapache2-mod-auth-openidc, Debian Advisory, PhishingProtection. . LinuxSecurity.com Team

Calendar%202 Jul 18, 2023 Debian LTS
203

Mageia 8: MGASA-2023-0211 Critical: Phishing Threat From Python-Tornado

Remote unauthenticated attacker may redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. (CVE-2023-28370) References: . MGASA-2023-0211 - Updated python-tornado packages fix security vulnerability Publication date: 28 Jun 2023 URL: https://advisories.mageia.org/MGASA-2023-0211.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-28370 Remote unauthenticated attacker may redirect a user to an arbitrary web site and conduct a phishing attack by having user access a specially crafted URL. (CVE-2023-28370) References: - https://bugs.mageia.org/show_bug.cgi?id=32033 - https://ubuntu.com/security/notices/USN-6159-1 - https://www.cve.org/CVERecord?id=CVE-2023-28370 SRPMS: - 8/core/python-tornado-6.1-1.1.mga8 . Revamped python-tornado versions in Mageia mend a significant security vulnerability that facilitates phishing through misleading URL redirects.. Mageia 8, Tornado Security, Phishing Risk, Remote Attack, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 28, 2023 Critical Mageia
197

Debian: DLA-3359-1 Moderate: libapache2-mod-auth-mellon Open Redirect Risk

libapache2-mod-auth-mellon, a SAML 2.0 authentication module for Apache, were reported to have the following vulnerabilities. CVE-2019-13038 . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-3359-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 13, 2023 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libapache2-mod-auth-mellon Version : 0.14.2-1+deb10u1 CVE ID : CVE-2019-13038 CVE-2021-3639 Debian Bug : 931265, 991730 libapache2-mod-auth-mellon, a SAML 2.0 authentication module for Apache, were reported to have the following vulnerabilities. CVE-2019-13038 mod_auth_mellon had an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL. CVE-2021-3639 mod_auth_mellon did not sanitize logout URLs properly. This issue could be used by an attacker to facilitate phishing attacks by tricking users into visiting a trusted web application URL that redirects to an external and potentially malicious server. For Debian 10 buster, these problems have been fixed in version 0.14.2-1+deb10u1. We recommend that you upgrade your libapache2-mod-auth-mellon packages. For the detailed security status of libapache2-mod-auth-mellon please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libapache2-mod-auth-mellon Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5000-1 resolves essential vulnerabilities in libapache2-mod-auth-mellon. Immediate upgrade advised.. libapache2-mod-auth-mellon, authentication module, debian security update. . LinuxSecurity.com Team

Calendar%202 Mar 12, 2023 Debian LTS
203

Mageia 8 MGASA-2022-0276 Moderate: Osmo Phishing Threat Fix

Phishing website URL removed from package spec file and replaced with new official site link. References: - https://bugs.mageia.org/show_bug.cgi?id=30679 . MGASA-2022-0276 - Updated osmo packages fix security vulnerability Publication date: 05 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0276.html Type: security Affected Mageia releases: 8 Phishing website URL removed from package spec file and replaced with new official site link. References: - https://bugs.mageia.org/show_bug.cgi?id=30679 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/LTWR4QVCBA3OCDWSLZBEHJLEDAGIUFRX/ SRPMS: - 8/core/osmo-0.4.4-1.1.mga8 . Recent updates to osmo packages in the Mageia distribution address a critical vulnerability concerning phishing URLs embedded in the package specification file.. Mageia Security, Osmo Update, Phishing Protection, Security Advisory, Package Change. . LinuxSecurity.com Team

Calendar%202 Aug 05, 2022 Mageia
89

Fedora 35: FEDORA-2022-e57547c384 Moderate: Osmo Fixes Phishing Threat

removes phishing site as URL, and updates to new. explicitly BuildRequires gcc. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e57547c384 2022-07-28 01:29:59.622188 --------------------------------------------------------------------------------Name : osmo Product : Fedora 35 Version : 0.4.4 Release : 2.fc35 URL : Summary : Personal organizer Description : Osmo is a handy personal organizer which includes calendar, tasks manager and address book modules. It was designed to be a small, easy to use and good looking PIM tool to help to manage personal information. In current state the organizer is quite convenient in use - for example, user can perform nearly all operations using keyboard. Also, a lot of parameters are configurable to meet user preferences. --------------------------------------------------------------------------------Update Information: removes phishing site as URL, and updates to new. explicitly BuildRequires gcc --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Ranjan Maitra - 0.4.4-2 - Changed URL to which is *only* official OSMO web page. - Addresses BZ #2108423 - Explicitly BuildRequires gcc * Thu Jan 20 2022 Fedora Release Engineering - 0.4.4-1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Mon Sep 27 2021 Ranjan Maitra - 0.4.4-0.1 - update to version 0.4.4 - Several compilation problems fixed - Replaced compiled-in graphics with resource images - Many bug fixes and cleanups --------------------------------------------------------------------------------References: [ 1 ] Bug #2108424 - osmo: point to a phishing site [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108424 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2022-e57547c384' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora Software Alert for osmo addresses phishing link vulnerability and specifies gcc as a necessary build dependency in the newest version.. Fedora Update, Osmo PIM, Phishing Fix, Build Requirements, Software Update. . LinuxSecurity.com Team

Calendar%202 Jul 27, 2022 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200