Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
203

Mageia 9: MGASA-2025-0086 moderate: x11-server & tigervnc security issues

Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598) . MGASA-2025-0086 - Updated x11-server, x11-server-xwayland & tigervnc packages fix security vulnerabilities Publication date: 03 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0086.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-26594, CVE-2025-26595, CVE-2025-26596, CVE-2025-26597, CVE-2025-26598, CVE-2025-26599, CVE-2025-26600, CVE-2025-26601 Use-after-free of the root cursor. (CVE-2025-26594) Buffer overflow in XkbVModMaskText(). (CVE-2025-26595) Heap overflow in XkbWriteKeySyms(). (CVE-2025-26596) Buffer overflow in XkbChangeTypesOfKey(). (CVE-2025-26597) Out-of-bounds write in CreatePointerBarrierClient(). (CVE-2025-26598) Use of uninitialized pointer in compRedirectWindow(). (CVE-2025-26599) Use-after-free in PlayReleasedEvents(). (CVE-2025-26600) Use-after-free in SyncInitTrigger(). (CVE-2025-26601) References: - https://bugs.mageia.org/show_bug.cgi?id=34052 - https://www.openwall.com/lists/oss-security/2025/02/25/1 - https://www.cve.org/CVERecord?id=CVE-2025-26594 - https://www.cve.org/CVERecord?id=CVE-2025-26595 - https://www.cve.org/CVERecord?id=CVE-2025-26596 - https://www.cve.org/CVERecord?id=CVE-2025-26597 - https://www.cve.org/CVERecord?id=CVE-2025-26598 - https://www.cve.org/CVERecord?id=CVE-2025-26599 - https://www.cve.org/CVERecord?id=CVE-2025-26600 - https://www.cve.org/CVERecord?id=CVE-2025-26601 SRPMS: - 9/core/x11-server-21.1.8-7.7.mga9 - 9/core/x11-server-xwayland-22.1.9-1.7.mga9 - 9/core/tigervnc-1.13.1-2.7.mga9 . Mageia 2025-0087: Updated kernel, glibc & openssl address critical vulnerabilities.. Mageia Security, x11-server updates, tigervnc vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Mar 03, 2025 Mageia
202

openSUSE Leap 15.5 SUSE-SU-2024:1174-1 Moderate: qt6-base Pointer Issue

This update for qt6-base fixes the following issues: CVE-2024-30161: Fixed QNetworkReply header data access via a dangling pointer (bsc#1221926).. # Security update for qt6-base Announcement ID: SUSE-SU-2024:1174-1 Rating: moderate References: * bsc#1221926 Cross-References: * CVE-2024-30161 CVSS scores: * CVE-2024-30161 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP5 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Package Hub 15 15-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for qt6-base fixes the following issues: * CVE-2024-30161: Fixed QNetworkReply header data access via a dangling pointer (bsc#1221926). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP5 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP5-2024-1174=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-1174=1 openSUSE-SLE-15.5-2024-1174=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-1174=1 ## Package List: * SUSE Package Hub 15 15-SP5 (aarch64 ppc64le s390x x86_64) * qt6-gui-private-devel-6.4.2-150500.3.17.1 * qt6-base-common-devel-debuginfo-6.4.2-150500.3.17.1 * qt6-concurrent-devel-6.4.2-150500.3.17.1 * qt6-kmssupport-devel-static-6.4.2-150500.3.17.1 * qt6-test-devel-6.4.2-150500.3.17.1 * libQt6Sql6-6.4.2-150500.3.17.1 * qt6-network-tls-6.4.2-150500.3.17.1 * qt6-sql-devel-6.4.2-150500.3.17.1 *libQt6Concurrent6-debuginfo-6.4.2-150500.3.17.1 * qt6-dbus-devel-6.4.2-150500.3.17.1 * libQt6Concurrent6-6.4.2-150500.3.17.1 * qt6-widgets-private-devel-6.4.2-150500.3.17.1 * libQt6Core6-6.4.2-150500.3.17.1 * qt6-core-private-devel-6.4.2-150500.3.17.1 * libQt6Network6-debuginfo-6.4.2-150500.3.17.1 * libQt6Sql6-debuginfo-6.4.2-150500.3.17.1 * qt6-platformsupport-devel-static-6.4.2-150500.3.17.1 * qt6-xml-devel-6.4.2-150500.3.17.1 * qt6-opengl-devel-6.4.2-150500.3.17.1 * qt6-core-devel-6.4.2-150500.3.17.1 * libQt6DBus6-6.4.2-150500.3.17.1 * libQt6Gui6-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGL6-debuginfo-6.4.2-150500.3.17.1 * libQt6PrintSupport6-6.4.2-150500.3.17.1 * qt6-sql-sqlite-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGL6-6.4.2-150500.3.17.1 * qt6-widgets-devel-6.4.2-150500.3.17.1 * libQt6DBus6-debuginfo-6.4.2-150500.3.17.1 * qt6-openglwidgets-devel-6.4.2-150500.3.17.1 * libQt6Xml6-debuginfo-6.4.2-150500.3.17.1 * qt6-gui-devel-6.4.2-150500.3.17.1 * libQt6Widgets6-6.4.2-150500.3.17.1 * qt6-network-tls-debuginfo-6.4.2-150500.3.17.1 * libQt6Core6-debuginfo-6.4.2-150500.3.17.1 * qt6-base-debuginfo-6.4.2-150500.3.17.1 * libQt6Xml6-6.4.2-150500.3.17.1 * libQt6Network6-6.4.2-150500.3.17.1 * libQt6OpenGLWidgets6-6.4.2-150500.3.17.1 * qt6-kmssupport-private-devel-6.4.2-150500.3.17.1 * qt6-base-debugsource-6.4.2-150500.3.17.1 * qt6-sql-sqlite-6.4.2-150500.3.17.1 * qt6-network-devel-6.4.2-150500.3.17.1 * libQt6Test6-debuginfo-6.4.2-150500.3.17.1 * qt6-opengl-private-devel-6.4.2-150500.3.17.1 * qt6-printsupport-devel-6.4.2-150500.3.17.1 * libQt6Test6-6.4.2-150500.3.17.1 * qt6-base-common-devel-6.4.2-150500.3.17.1 * libQt6PrintSupport6-debuginfo-6.4.2-150500.3.17.1 * libQt6Gui6-6.4.2-150500.3.17.1 * libQt6Widgets6-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGLWidgets6-debuginfo-6.4.2-150500.3.17.1 * SUSE Package Hub 15 15-SP5 (noarch) *qt6-base-devel-6.4.2-150500.3.17.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * qt6-gui-private-devel-6.4.2-150500.3.17.1 * qt6-base-common-devel-debuginfo-6.4.2-150500.3.17.1 * qt6-concurrent-devel-6.4.2-150500.3.17.1 * qt6-kmssupport-devel-static-6.4.2-150500.3.17.1 * qt6-test-devel-6.4.2-150500.3.17.1 * libQt6Sql6-6.4.2-150500.3.17.1 * qt6-printsupport-cups-debuginfo-6.4.2-150500.3.17.1 * qt6-test-private-devel-6.4.2-150500.3.17.1 * qt6-network-tls-6.4.2-150500.3.17.1 * qt6-sql-devel-6.4.2-150500.3.17.1 * libQt6Concurrent6-debuginfo-6.4.2-150500.3.17.1 * qt6-printsupport-cups-6.4.2-150500.3.17.1 * qt6-dbus-devel-6.4.2-150500.3.17.1 * qt6-sql-postgresql-6.4.2-150500.3.17.1 * qt6-base-docs-html-6.4.2-150500.3.17.1 * qt6-networkinformation-nm-6.4.2-150500.3.17.1 * libQt6Concurrent6-6.4.2-150500.3.17.1 * qt6-networkinformation-nm-debuginfo-6.4.2-150500.3.17.1 * qt6-platformtheme-gtk3-debuginfo-6.4.2-150500.3.17.1 * qt6-widgets-private-devel-6.4.2-150500.3.17.1 * qt6-platformsupport-private-devel-6.4.2-150500.3.17.1 * libQt6Core6-6.4.2-150500.3.17.1 * qt6-core-private-devel-6.4.2-150500.3.17.1 * libQt6Network6-debuginfo-6.4.2-150500.3.17.1 * libQt6Sql6-debuginfo-6.4.2-150500.3.17.1 * qt6-networkinformation-glib-6.4.2-150500.3.17.1 * qt6-platformsupport-devel-static-6.4.2-150500.3.17.1 * qt6-platformtheme-xdgdesktopportal-6.4.2-150500.3.17.1 * qt6-xml-devel-6.4.2-150500.3.17.1 * qt6-opengl-devel-6.4.2-150500.3.17.1 * qt6-core-devel-6.4.2-150500.3.17.1 * libQt6DBus6-6.4.2-150500.3.17.1 * qt6-sql-private-devel-6.4.2-150500.3.17.1 * qt6-sql-unixODBC-debuginfo-6.4.2-150500.3.17.1 * libQt6Gui6-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGL6-debuginfo-6.4.2-150500.3.17.1 * qt6-base-examples-6.4.2-150500.3.17.1 * libQt6PrintSupport6-6.4.2-150500.3.17.1 * qt6-sql-sqlite-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGL6-6.4.2-150500.3.17.1 *qt6-widgets-devel-6.4.2-150500.3.17.1 * qt6-printsupport-private-devel-6.4.2-150500.3.17.1 * qt6-base-docs-qch-6.4.2-150500.3.17.1 * qt6-sql-mysql-6.4.2-150500.3.17.1 * libQt6DBus6-debuginfo-6.4.2-150500.3.17.1 * qt6-platformtheme-gtk3-6.4.2-150500.3.17.1 * qt6-openglwidgets-devel-6.4.2-150500.3.17.1 * libQt6Xml6-debuginfo-6.4.2-150500.3.17.1 * qt6-network-private-devel-6.4.2-150500.3.17.1 * qt6-sql-postgresql-debuginfo-6.4.2-150500.3.17.1 * qt6-gui-devel-6.4.2-150500.3.17.1 * libQt6Widgets6-6.4.2-150500.3.17.1 * qt6-network-tls-debuginfo-6.4.2-150500.3.17.1 * libQt6Core6-debuginfo-6.4.2-150500.3.17.1 * qt6-networkinformation-glib-debuginfo-6.4.2-150500.3.17.1 * qt6-base-debuginfo-6.4.2-150500.3.17.1 * libQt6Xml6-6.4.2-150500.3.17.1 * qt6-platformtheme-xdgdesktopportal-debuginfo-6.4.2-150500.3.17.1 * libQt6Network6-6.4.2-150500.3.17.1 * qt6-sql-mysql-debuginfo-6.4.2-150500.3.17.1 * qt6-xml-private-devel-6.4.2-150500.3.17.1 * libQt6OpenGLWidgets6-6.4.2-150500.3.17.1 * qt6-kmssupport-private-devel-6.4.2-150500.3.17.1 * qt6-base-debugsource-6.4.2-150500.3.17.1 * qt6-sql-sqlite-6.4.2-150500.3.17.1 * qt6-sql-unixODBC-6.4.2-150500.3.17.1 * qt6-network-devel-6.4.2-150500.3.17.1 * libQt6Test6-debuginfo-6.4.2-150500.3.17.1 * qt6-base-examples-debuginfo-6.4.2-150500.3.17.1 * qt6-opengl-private-devel-6.4.2-150500.3.17.1 * qt6-printsupport-devel-6.4.2-150500.3.17.1 * libQt6Test6-6.4.2-150500.3.17.1 * qt6-base-common-devel-6.4.2-150500.3.17.1 * libQt6PrintSupport6-debuginfo-6.4.2-150500.3.17.1 * libQt6Gui6-6.4.2-150500.3.17.1 * libQt6Widgets6-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGLWidgets6-debuginfo-6.4.2-150500.3.17.1 * qt6-dbus-private-devel-6.4.2-150500.3.17.1 * openSUSE Leap 15.5 (noarch) * qt6-base-private-devel-6.4.2-150500.3.17.1 * qt6-base-devel-6.4.2-150500.3.17.1 * qt6-docs-common-6.4.2-150500.3.17.1 * Desktop Applications Module 15-SP5 (aarch64ppc64le s390x x86_64) * libQt6Network6-6.4.2-150500.3.17.1 * qt6-network-tls-debuginfo-6.4.2-150500.3.17.1 * libQt6Core6-6.4.2-150500.3.17.1 * libQt6OpenGL6-6.4.2-150500.3.17.1 * qt6-base-debuginfo-6.4.2-150500.3.17.1 * qt6-base-debugsource-6.4.2-150500.3.17.1 * libQt6Network6-debuginfo-6.4.2-150500.3.17.1 * libQt6DBus6-debuginfo-6.4.2-150500.3.17.1 * qt6-network-tls-6.4.2-150500.3.17.1 * libQt6Gui6-6.4.2-150500.3.17.1 * libQt6Widgets6-6.4.2-150500.3.17.1 * libQt6DBus6-6.4.2-150500.3.17.1 * libQt6Core6-debuginfo-6.4.2-150500.3.17.1 * libQt6Widgets6-debuginfo-6.4.2-150500.3.17.1 * libQt6Gui6-debuginfo-6.4.2-150500.3.17.1 * libQt6OpenGL6-debuginfo-6.4.2-150500.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30161.html * https://bugzilla.suse.com/show_bug.cgi?id=1221926 . qt6-core vulnerability fix addresses CVE-2024-30203 for Fedora. It's crucial to update your systems to ensure stability.. openSUSE Update, qt6-base Security Fix, Software Patch. . LinuxSecurity.com Team

Calendar 2 Apr 09, 2024 OpenSUSE
100

SUSE: 2023:4940-2 critical: LibXYZ buffer overflow and validation fixes

* bsc#1041783 * bsc#1120956 Cross-References: * CVE-2017-7511 . # Security update for poppler Announcement ID: SUSE-SU-2023:4941-1 Rating: moderate References: * bsc#1041783 * bsc#1120956 Cross-References: * CVE-2017-7511 * CVE-2018-20662 CVSS scores: * CVE-2017-7511 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2017-7511 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-20662 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-20662 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-20662 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2017-7511: Fixed a NULL pointer dereference in pdfunite (bsc#1041783) * CVE-2018-20662: PDFDoc setup in PDFDoc.cc allows attackers to cause DOS because of a wrong return value from PDFDoc:setup (bsc#1120956). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-4941=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libpoppler44-debuginfo-0.24.4-14.44.1 * libpoppler44-0.24.4-14.44.1 ## References: * https://www.suse.com/security/cve/CVE-2017-7511.html * https://www.suse.com/security/cve/CVE-2018-20662.html * https://bugzilla.suse.com/show_bug.cgi?id=1041783 * https://bugzilla.suse.com/show_bug.cgi?id=1120956 . Recentupdates for Poppler on SUSE have introduced critical security enhancements to improve PDF handling and mitigate vulnerabilities like buffer overflows and use-after-free issues. SUSE Linux, Poppler Security, Moderate Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 21, 2023 Important SuSE
203

Mageia 8: MGASA-2023-0192 Critical: Vim Pointer Offset Issue

Use of Out-of-range Pointer Offset in GitHub repository vim/vim. (CVE-2023-2426) References: - https://bugs.mageia.org/show_bug.cgi?id=31954 . MGASA-2023-0192 - Updated vim packages fix security vulnerability Publication date: 31 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0192.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-2426 Use of Out-of-range Pointer Offset in GitHub repository vim/vim. (CVE-2023-2426) References: - https://bugs.mageia.org/show_bug.cgi?id=31954 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/LOJP6M7ZTKZQYOGVOOAY6TIE6ACBJL55/ - https://www.cve.org/CVERecord?id=CVE-2023-2426 SRPMS: - 8/core/vim-9.0.1572-1.mga8 . Recent updates for Vim packages in Mageia resolve concerns related to out-of-bounds pointer challenges. Refer to advisory MGASA-2023-0192 for further information.. Mageia Security Update, Vim Package Fix, Pointer Offset Issue, Security Patch Details. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 31, 2023 Critical Mageia
89

Fedora 38: FEDORA-2023-d6baa1d93e Critical: VIM Pointer Offset Issue

The newest upstream commit Security fix for CVE-2023-2426. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-d6baa1d93e 2023-05-20 01:47:22.201589 --------------------------------------------------------------------------------Name : vim Product : Fedora 38 Version : 9.0.1562 Release : 1.fc38 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. --------------------------------------------------------------------------------Update Information: The newest upstream commit Security fix for CVE-2023-2426 --------------------------------------------------------------------------------ChangeLog: * Thu May 18 2023 Zdenek Dohnal - 2:9.0.1562-1 - patchlevel 1562 * Thu Apr 27 2023 Zdenek Dohnal - 2:9.0.1491-1 - patchlevel 1491 --------------------------------------------------------------------------------References: [ 1 ] Bug #2196584 - CVE-2023-2426 vim: out-of-range Pointer offset in mb_charlen() of mbyte.c [fedora-38] https://bugzilla.redhat.com/show_bug.cgi?id=2196584 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-d6baa1d93e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Ubuntu's recent patch for nano mitigates significant vulnerabilities, specifically CVE-2023-3814, to improve overall safety.. Vim Update Fedora, Security Patch, Out-of-Range Pointer. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 20, 2023 Critical Fedora
89

Fedora 35: E304FFFD34 Critical: Vim Buffer Overflow and Pointer Issue

The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e304fffd34 2022-04-23 19:27:30.913742 --------------------------------------------------------------------------------Name : vim Product : Fedora 35 Version : 8.2.4804 Release : 1.fc35 URL : https://www.vim.org/ Summary : The VIM editor Description : VIM (VIsual editor iMproved) is an updated and improved version of the vi editor. Vi was the first real screen-based editor for UNIX, and is still very popular. VIM improves on vi by adding new features: multiple windows, multi-level undo, block highlighting and more. --------------------------------------------------------------------------------Update Information: The newest upstream commit Security fixes for CVE-2022-1381, CVE-2022-1420 --------------------------------------------------------------------------------ChangeLog: * Fri Apr 22 2022 Zdenek Dohnal - 2:8.2.4804-1 - patchlevel 4804 * Fri Apr 8 2022 Zdenek Dohnal - 2:8.2.4701-2 - fix the upstream testsuite failure due downstream patch --------------------------------------------------------------------------------References: [ 1 ] Bug #2076170 - CVE-2022-1381 vim: global heap buffer overflow in skip_range https://bugzilla.redhat.com/show_bug.cgi?id=2076170 [ 2 ] Bug #2077734 - CVE-2022-1420 vim: Out-of-range Pointer Offset https://bugzilla.redhat.com/show_bug.cgi?id=2077734 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e304fffd34' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Debian 11 patch introduces vital security enhancement for nano, boosting the text editor's protection and efficiency.. Fedora 35 Vim Update, Software Security Fixes, Critical Buffer Overflow, Pointer Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 23, 2022 Critical Fedora
217

Oracle Linux 7 ELSA-2021-3798 Moderate: OpenSSL Pointer Issues Fix

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2021-3798 https://linux.oracle.com/errata/ELSA-2021-3798.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: openssl-1.0.2k-22.el7_9.aarch64.rpm openssl-devel-1.0.2k-22.el7_9.aarch64.rpm openssl-libs-1.0.2k-22.el7_9.aarch64.rpm openssl-perl-1.0.2k-22.el7_9.aarch64.rpm openssl-static-1.0.2k-22.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates/openssl-1.0.2k-22.el7_9.src.rpm Related CVEs: CVE-2021-23840 CVE-2021-23841 Description of changes: [1.0.2k-22] - fix CVE-2021-23841 openssl: NULL pointer dereference in X509_issuer_and_serial_hash() - fix CVE-2021-23840 openssl: integer overflow in CipherUpdate - Resolves: rhbz#1932132, rhbz#1932126 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Update ELSA-2021-3798 contains essential patches for critical vulnerabilities in the openssl library.. Oracle Linux, OpenSSL Update, Risk Management, Security Patching. . LinuxSecurity.com Team

Calendar 2 Oct 13, 2021 Oracle
197

Debian 8 LTS: DLA-1487-1 Critical Libtirpc Pointer Issue Fix

CVE-2018-14622 Fix for egmentation fault due to pointer becoming NULL. . Package : libtirpc Version : 0.2.5-1+deb8u2 CVE ID : CVE-2018-14622 CVE-2018-14622 Fix for egmentation fault due to pointer becoming NULL. For Debian 8 "Jessie", this problem has been fixed in version 0.2.5-1+deb8u2. We recommend that you upgrade your libtirpc packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Resolution for segmentation fault in libtirpc for Debian 8 users. Upgrade advised for security patch.. Debian 8 Security,Libtirpc Update,Segmentation Fault Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 31, 2018 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here