Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 14.04 LTS USN-2347-1 Critical: Django Phishing Threats and DoS

Several security issues were fixed in Django.. =========================================================================Ubuntu Security Notice USN-2347-1 September 16, 2014 python-django vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in Django. Software Description: - python-django: High-level Python web development framework Details: Florian Apolloner discovered that Django incorrectly validated URLs. A remote attacker could use this issue to conduct phishing attacks. (CVE-2014-0480) David Wilson discovered that Django incorrectly handled file name generation. A remote attacker could use this issue to cause Django to consume resources, resulting in a denial of service. (CVE-2014-0481) David Greisen discovered that Django incorrectly handled certain headers in contrib.auth.middleware.RemoteUserMiddleware. A remote authenticated user could use this issue to hijack web sessions. (CVE-2014-0482) Collin Anderson discovered that Django incorrectly checked if a field represented a relationship between models in the administrative interface. A remote authenticated user could use this issue to possibly obtain sensitive information. (CVE-2014-0483) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: python-django 1.6.1-2ubuntu0.4 Ubuntu 12.04 LTS: python-django 1.3.1-4ubuntu1.12 Ubuntu 10.04 LTS: python-django 1.1.1-2ubuntu1.13 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2347-1 CVE-2014-0480, CVE-2014-0481, CVE-2014-0482, CVE-2014-0483 Package Information: https://launchpad.net/ubuntu/+source/python-django/1.6.1-2ubuntu0.4 https://launchpad.net/ubuntu/+source/python-django/1.3.1-4ubuntu1.12 https://launchpad.net/ubuntu/+source/python-django/1.1.1-2ubuntu1.13 . Multiple vulnerabilities found in Django necessitate a system upgrade on Ubuntu to strengthen security measures.. Django Vulnerabilities, Ubuntu Security Updates, Web Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 16, 2014 Critical Ubuntu
200

Scientific Linux: 2013-02-19 Critical: Thunderbird Security Update

Critical: thunderbird security update. Date: Wed, 20 Feb 2013 13:16:37 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Critical: thunderbird on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: thunderbird security update Issue Date: 2013-02-19 CVE Numbers: CVE-2013-0783 CVE-2013-0775 CVE-2013-0776 CVE-2013-0780 CVE-2013-0782 -- Several flaws were found in the processing of malformed content. Malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2013-0775, CVE-2013-0780, CVE-2013-0782, CVE-2013-0783) It was found that, after canceling a proxy server's authentication prompt, the address bar continued to show the requested site's address. An attacker could use this flaw to conduct phishing attacks by tricking a user into believing they are viewing trusted content. (CVE-2013-0776) Note: All issues cannot be exploited by a specially-crafted HTML mail message as JavaScript is disabled by default for mail messages. They could be exploited another way in Thunderbird, for example, when viewing the full remote content of an RSS feed. Important: This erratum upgrades Thunderbird to version 17.0.3 ESR. Thunderbird 17 is not completely backwards-compatible with all Mozilla add-ons and Thunderbird plug-ins that worked with Thunderbird 10.0. Thunderbird 17 checks compatibility on first-launch, and, depending on the individual configuration and the installed add-ons and plug-ins, may disable said Add-ons and plug-ins, or attempt to check for updates and upgrade them. Add-ons and plug-ins may have to be manually updated. After installing the update, Thunderbird must be restarted for the changes to take effect. -- SL5 x86_64 thunderbird-17.0.3-1.el5_9.x86_64.rpm thunderbird-debuginfo-17.0.3-1.el5_9.x86_64.rpm i386 thunderbird-17.0.3-1.el5_9.i386.rpm thunderbird-debuginfo-17.0.3-1.el5_9.i386.rpm SL6 x86_64 thunderbird-17.0.3-1.el6_3.x86_64.rpm thunderbird-debuginfo-17.0.3-1.el6_3.x86_64.rpm i386 thunderbird-17.0.3-1.el6_3.i686.rpm thunderbird-debuginfo-17.0.3-1.el6_3.i686.rpm - Scientific Linux Development Team . Urgent security alert for Thunderbird on Scientific Linux SL5/SL6: Address serious vulnerabilities with immediate updates to protect your systems. thunderbird update, scientific linux security, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 20, 2013 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here