Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
91

Gentoo: GLSA 202107-08 Advisory: PostSRSd Denial of Service Alert

Multiple vulnerabilities in PostSRSd could lead to a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PostSRSd: Denial of service Date: July 06, 2021 Bugs: #760821, #793674 ID: 202107-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in PostSRSd could lead to a Denial of Service condition. Background ========= PostSRSd is a Postfix sender rewriting scheme daemon Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/postsrsd < 1.11 > = 1.11 Description ========== Multiple vulnerabilities have been discovered in PostSRSd. Please review the CVE identifiers referenced below for details. Impact ===== An attacker could cause a possible Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All postsrsd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/postsrsd-1.11" References ========= [ 1 ] CVE-2020-35573 https://nvd.nist.gov/vuln/detail/CVE-2020-35573 [ 2 ] CVE-2021-35525 https://nvd.nist.gov/vuln/detail/CVE-2021-35525 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Potential weaknesses found in PostSRSd may result in service interruptions. Ensure your Gentoo installation is updated for enhanced security.. PostSRSd Advisory,Gentoo Security Update,Service Attacks. . LinuxSecurity.com Team

Calendar 2 Jul 05, 2021 Gentoo
202

openSUSE: 2021:0669-1 Moderate: postsrsd Security Update CVE-2020-35573

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for postsrsd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0669-1 Rating: moderate References: #1180251 Cross-References: CVE-2020-35573 Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postsrsd fixes the following issues: Update to release 1.11 [boo#1180251] * Drop group privileges as well as user privileges * Fixed: The subprocess that talks to Postfix could be caused to hang with a very long email address. [CVE-2020-35573] Update to release 1.6 * Fix endianness issue with SHA-1 implementation * Add dual stack support * Make SRS separator configurable This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-669=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): postsrsd-1.11-bp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-35573.html https://bugzilla.suse.com/1180251 . This Fedora Security Patch targets a low impact vulnerability in postfix, improving overall performance.. postsrsd Update, openSUSE Security, Vulnerability Fix, Software Patch. . LinuxSecurity.com Team

Calendar 2 May 04, 2021 OpenSUSE
202

openSUSE Leap 15.2: SUSE-SU-2021:0646-1 Moderate Email Issue Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for postsrsd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0646-1 Rating: moderate References: #1180251 Cross-References: CVE-2020-35573 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postsrsd fixes the following issues: Update to release 1.11 [boo#1180251] * Drop group privileges as well as user privileges * Fixed: The subprocess that talks to Postfix could be caused to hang with a very long email address. [CVE-2020-35573] Update to release 1.6 * Fix endianness issue with SHA-1 implementation * Add dual stack support * Make SRS separator configurable Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-646=1 Package List: - openSUSE Leap 15.2 (x86_64): postsrsd-1.11-lp152.4.3.1 postsrsd-debuginfo-1.11-lp152.4.3.1 postsrsd-debugsource-1.11-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-35573.html https://bugzilla.suse.com/1180251 . A security update addressing one vulnerability in openSUSE's postsrsd has been issued. For further information, please consult the announcement ID.. openSUSE Security, postsrsd Update, Email Security Patch. . LinuxSecurity.com Team

Calendar 2 May 01, 2021 OpenSUSE
197

Debian 9 DLA-2502-1 Critical: Fix for Postsrsd Denial of Service Issue

A potential denial-of-service attack through malicious timestamp tags was fixed in PostSRSd, a Sender Rewriting Scheme (SRS) lookup table for Postfix. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2502-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk December 20, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : postsrsd Version : 1.4-1+deb9u1 CVE ID : CVE-2020-35573 Debian Bug : A potential denial-of-service attack through malicious timestamp tags was fixed in PostSRSd, a Sender Rewriting Scheme (SRS) lookup table for Postfix. For Debian 9 stretch, this problem has been fixed in version 1.4-1+deb9u1. We recommend that you upgrade your postsrsd packages. For the detailed security status of postsrsd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/postsrsd Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance postsrsd to mitigate a denial-of-service vulnerability highlighted in Debian LTS DLA-2502-1 notice.. Debian LTS, postsrsd update, denial of service fix, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 20, 2020 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here