Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
203

Mageia: 2020-0417 Moderate: tpm2-tss PolicyPCR Security Fix

FAPI PolicyPCR not instatiating correctly (CVE-2020-24455). Note that all TPM object created with a PolicyPCR with the currentPcrs and currentPcrsAndBank options have been created with an incorrect policy that omits PCR checks. All such objects have to be recreated. . MGASA-2020-0417 - Updated tpm2-tss packages fix a security vulnerability Publication date: 13 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0417.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24455 FAPI PolicyPCR not instatiating correctly (CVE-2020-24455). Note that all TPM object created with a PolicyPCR with the currentPcrsand currentPcrsAndBank options have been created with an incorrect policy that omits PCR checks. All such objects have to be recreated. The tpm2-tss package has been updated to version 2.4.3, which includes a fix for this issue and several other changes. See the upstream release announcements for details. References: - https://bugs.mageia.org/show_bug.cgi?id=27412 - https://github.com/tpm2-software/tpm2-tss/releases/tag/2.4.3 - https://github.com/tpm2-software/tpm2-tss/releases - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/KBRTMYDRPQBDGNADVXGI745WGT2MGVOO/ - https://www.cve.org/CVERecord?id=CVE-2020-24455 SRPMS: - 7/core/tpm2-tss-2.4.3-1.mga7 . The latest tpm2-tss updates rectify a significant vulnerability in Mageia's handling of the Trusted Platform Module. Prompt measures are necessary.. Mageia Security Update, tpm2-tss Fix, PolicyPCR Issue. . LinuxSecurity.com Team

Calendar 2 Nov 13, 2020 Mageia
200

Scientific Linux: 10-20-17 Low SELinux Policy Updates for SL6.x

Low: selinux-policy enhancement update. Date: Tue, 14 Feb 2012 10:20:17 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: selinux-policy on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: selinux-policy enhancement update Issue date: 2012-02-13 The selinux-policy packages contain the rules that govern how confined processes run on the system. This update fixes the following bug: * An incorrect SELinux policy prevented the qpidd service from starting. These selinux-policy packages contain updated SELinux rules, which allow the qpidd service to be started correctly. * With SELinux in enforcing mode, the ssh-keygen utility was prevented from access to various applications and thus could not be used to generate SSH keys for these programs. With this update, the "ssh_keygen_t" SELinux domain type has been implemented as unconfined, which ensures the ssh-keygen utility to work correctly. All users of selinux-policy are advised to upgrade to these updated packages, which fix these bugs. SL6.x SRPMS: selinux-policy-3.7.19-126.el6_2.6.src.rpm i386: selinux-policy-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.6.noarch.rpm x86_64: selinux-policy-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.6.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.6.noarch.rpm . The recent SELinux policy modification addresses service initiation problems and enhances SSH key creation within Scientific Linux operating systems.. scientific linux selinux enhancement, selinux policy update, security patch. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Feb 14, 2012 Low Scientific Linux
87

Debian 4.0 Etch DSA-1617-1 Moderate: Fix For Named_t UDP Binding

In DSA-1603-1, Debian released an update to the BIND 9 domain name server, which introduced UDP source port randomization to mitigate the threat of DNS cache poisoning attacks (identified by the Common Vulnerabilities and Exposures project as CVE-2008-1447). - ------------------------------------------------------------------------Debian Security Advisory DSA-1617-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Devin Carraway July 25, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : refpolicy Vulnerability : incompatible policy Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-1447 Debian Bug : 490271 In DSA-1603-1, Debian released an update to the BIND 9 domain name server, which introduced UDP source port randomization to mitigate the threat of DNS cache poisoning attacks (identified by the Common Vulnerabilities and Exposures project as CVE-2008-1447). The fix, while correct, was incompatible with the version of SELinux Reference Policy shipped with Debian Etch, which did not permit a process running in the named_t domain to bind sockets to UDP ports other than the standard 'domain' port (53). The incompatibility affects both the 'targeted' and 'strict' policy packages supplied by this version of refpolicy. This update to the refpolicy packages grants the ability to bind to arbitrary UDP ports to named_t processes. When installed, the updated packages will attempt to update the bind policy module on systems where it had been previously loaded and where the previous version of refpolicy was 0.0.20061018-5 or below. Because the Debian refpolicy packages are not yet designed with policy module upgradeability in mind, and because SELinux-enabled Debian systems often have some degree of site-specific policy customization, it is difficult to assure that the new bind policy can be successfullyupgraded. To this end, the package upgrade will not abort if the bind policy update fails. The new policy module can be found at /usr/share/selinux/refpolicy-targeted/bind.pp after installation. Administrators wishing to use the bind service policy can reconcile any policy incompatibilities and install the upgrade manually thereafter. A more detailed discussion of the corrective procedure may be found here: https://wiki.debian.org/SELinux/Issues/BindPortRandomization For the stable distribution (etch), this problem has been fixed in version 0.0.20061018-5.1+etch1. The unstable distribution (sid) is not affected, as subsequent refpolicy releases have incorporated an analogous change. We recommend that you upgrade your refpolicy packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Debian (stable) - ---------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 571487 1bb326ee1b8aea1fa93c3bd86a3007ee Size/MD5 checksum: 53515 bd171f0cfa9adc59d451d176fb32c913 Size/MD5 checksum: 859 52bc8ea0cab864e990e9dacc4db3b678 Architecture independent packages: Size/MD5 checksum: 1541610 626c93fc13beaa01ff151d9103a7860b Size/MD5 checksum: 289230 b082a861eda93f9bc06dd2e2f03ba89d Size/MD5 checksum: 1288314 c00ed4f0ea4ddbb8dd945c24c710c788 Size/MD5 checksum: 595490 841f616c8f08b22ed7077c21c1065026 Size/MD5 checksum: 418666bee3f41fe8771b7b88693937814494a3 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-1618-2 outlines the corrective measures taken regarding sshd processes and their permissions to listen on specific TCP ports following the upgrade.. Debian Refpolicy Update, SELinux Policy Fix, DNS Cache Mitigation. . LinuxSecurity.com Team

Calendar 2 Jul 25, 2008 Debian
89

Fedora Core 5: 2006-271 Moderate Update For Libsepol Policy Fix

Update SELinux policy to current rawhide to fix many policy problems . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-271 2006-04-11 ---------------------------------------------------------------------Product : Fedora Core 5 Name : libsepol Version : 1.12.4 Release : 1.fc5 Summary : SELinux binary policy manipulation library Description : Security-enhanced Linux is a feature of the Linux® kernel and a number of utilities with enhanced security functionality designed to add mandatory access controls to Linux. The Security-enhanced Linux kernel contains new architectural components originally developed to improve the security of the Flask operating system. These architectural components provide general support for the enforcement of many kinds of mandatory access control policies, including those based on the concepts of Type Enforcement®, Role-based Access Control, and Multi-level Security. libsepol provides an API for the manipulation of SELinux binary policies. It is used by checkpolicy (the policy compiler) and similar tools, as well as by programs like load_policy that need to perform specific transformations on binary policies such as customizing policy boolean settings. ---------------------------------------------------------------------Update Information: Update SELinux policy to current rawhide to fix many policy problems ---------------------------------------------------------------------* Mon Apr 3 2006 Dan Walsh 1.12.4-1.fc5 - Bump for FC5 * Wed Mar 29 2006 Dan Walsh 1.12.4-1 - Upgrade to latest from NSA * Generalize test for bitmap overflow in ebitmap_set_bit. * Mon Mar 27 2006 Dan Walsh 1.12.3-1 - Upgrade to latest from NSA * Fixed attr_convert_callback and expand_convert_type_set typemap bug. * Fri Mar 24 2006 Dan Walsh 1.12.2-1 - Upgrade to latest from NSA * Fixed avrule_block_write num_decls endian bug. *Fri Mar 17 2006 Dan Walsh 1.12.1-1 - Upgrade to latest from NSA * Fixed sepol_module_package_write buffer overflow bug. ---------------------------------------------------------------------This update can be downloaded from: 898a86aaf531753c3d2df49cc685dc1c641f7a9b SRPMS/libsepol-1.12.4-1.fc5.src.rpm e0d976643374b7d6694f253f49697aa3cc669227 ppc/libsepol-1.12.4-1.fc5.ppc.rpm 0c0f1dfc42c5116b941937cda3e5ba0136292fd1 ppc/libsepol-devel-1.12.4-1.fc5.ppc.rpm 776bf940200ef1292c97d3f3d41025af96cd2b79 ppc/debug/libsepol-debuginfo-1.12.4-1.fc5.ppc.rpm 47cbad1912e07a8e949e6004d3d4023622f39fb6 x86_64/libsepol-1.12.4-1.fc5.x86_64.rpm 71fb2d5115076ec520e81752fdf430bcba345453 x86_64/libsepol-devel-1.12.4-1.fc5.x86_64.rpm b3d84eef5157ba7a92588b8a7aa7c5d18dc3b410 x86_64/debug/libsepol-debuginfo-1.12.4-1.fc5.x86_64.rpm eb81ee7b91bfb2540764e97bdd3571ffb874c69c i386/libsepol-1.12.4-1.fc5.i386.rpm 4f621a495943eb4ed5919d393d0a30962028bbb1 i386/libsepol-devel-1.12.4-1.fc5.i386.rpm 47e0e367adad01bbcbc51914fd0ca12f205432f2 i386/debug/libsepol-debuginfo-1.12.4-1.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolve SELinux policy issues related to address configurations found in the libsepol package for Fedora Core 5.. SELinux Management, Fedora Updates, libsepol Security Fix. . LinuxSecurity.com Team

Calendar 2 Apr 11, 2006 Fedora
89

Fedora Core 5: 2006-247 Moderate Update for SELinux Policy Issues

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-247 2006-04-03 ---------------------------------------------------------------------Product : Fedora Core 5 Name : selinux-policy Version : 2.2.25 Release : 3.fc5 Summary : SELinux policy configuration Description : SELinux Reference Policy - modular. --------------------------------------------------------------------- ---------------------------------------------------------------------This update can be downloaded from: dcbfaa8f1e69eacfe37da49004fd6898a62311d4 SRPMS/selinux-policy-2.2.25-3.fc5.src.rpm 911639245d8a3044976ec1c32989f394ace52593 ppc/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f ppc/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b ppc/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee ppc/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm 911639245d8a3044976ec1c32989f394ace52593 x86_64/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f x86_64/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b x86_64/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee x86_64/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm 911639245d8a3044976ec1c32989f394ace52593 i386/selinux-policy-2.2.25-3.fc5.noarch.rpm e0333457aa9785b5e678dd2293ca991d1ae3b34f i386/selinux-policy-targeted-2.2.25-3.fc5.noarch.rpm 186c6f5772a3fd00212a5518fbaac4218faca01b i386/selinux-policy-mls-2.2.25-3.fc5.noarch.rpm 96ad10776cde18547e3250619ccf793ed6e7d9ee i386/selinux-policy-strict-2.2.25-3.fc5.noarch.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at. ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . SELinux policy adjustments introduced in Fedora Core 5 focus on fortifying security settings and implementing enhanced safeguards.. Fedora Core 5, SELinux Policy Update, Security Fix. . LinuxSecurity.com Team

Calendar 2 Apr 03, 2006 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here