Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE 12 SP5: 2024:4079-1 important: webkit2gtk3 process crash

* bsc#1231039 * bsc#1232747 Cross-References: * CVE-2024-44296 . # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2024:4079-1 Release Date: 2024-11-27T12:53:58Z Rating: important References: * bsc#1231039 * bsc#1232747 Cross-References: * CVE-2024-44296 * CVE-2024-46185 * CVE-2044-44244 CVSS scores: * CVE-2024-44296 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-44296 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-44296 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-44296 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: Update to version 2.46.3 (bsc#1232747): * CVE-2024-44244: Processing maliciously crafted web content may lead to an unexpected process crash. * CVE-2024-44296: Processing maliciously crafted web content may prevent Content Security Policy from being enforced. New references to version 2.46.0 (boo#1231039): * CVE-2024-44185: Processing maliciously crafted web content may lead to an unexpected process crash. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2024-4079=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libjavascriptcoregtk-4_0-18-debuginfo-2.46.3-4.18.2 * typelib-1_0-JavaScriptCore-4_0-2.46.3-4.18.2 * libwebkit2gtk-4_0-37-2.46.3-4.18.2 *libwebkit2gtk-4_0-37-debuginfo-2.46.3-4.18.2 * typelib-1_0-WebKit2-4_0-2.46.3-4.18.2 * libjavascriptcoregtk-4_0-18-2.46.3-4.18.2 * typelib-1_0-WebKit2WebExtension-4_0-2.46.3-4.18.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.46.3-4.18.2 * webkit2gtk3-debugsource-2.46.3-4.18.2 * webkit2gtk-4_0-injected-bundles-2.46.3-4.18.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libwebkit2gtk3-lang-2.46.3-4.18.2 ## References: * https://www.suse.com/security/cve/CVE-2024-44296.html * https://www.suse.com/security/cve/CVE-2024-46185.html * https://www.suse.com/security/cve/CVE-2044-44244.html * https://bugzilla.suse.com/show_bug.cgi?id=1231039 * https://bugzilla.suse.com/show_bug.cgi?id=1232747 . Critical enhancements for webkit2gtk3 tackling process failures and content safety vulnerabilities in openSUSE.. SUSE Linux Enterprise, webkit2gtk3 update, security patch, process crash. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 27, 2024 Important SuSE
87

Debian: DSA 144-1 Severe: Wwwoffle Input Handling Crash Issue

The web proxy didn'thandle input data with negative Content-Length settings properly whichcauses the processing child to crash.. -------------------------------------------------------------------------- Debian Security Advisory DSA 144-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 6th, 2002 -------------------------------------------------------------------------- Package : wwwoffle Vulnerability : improper input handling Problem-Type : local Debian-specific: no CVE Id : CAN-2002-0818 A problem with wwwoffle has been discovered. The web proxy didn't handle input data with negative Content-Length settings properly which causes the processing child to crash. It is at this time not obvious how this can lead to an exploitable vulnerability; however, it's better to be safe than sorry, so here's an update. Additionally, in the woody version empty passwords will be treated as wrong when trying to authenticate. In the woody version we also replaced CanonicaliseHost() with the latest routine from 2.7d, offered by upstream. This stops bad IPv6 format IP addresses in URLs from causing problems (memory overwriting, potential exploits). This problem has been fixed in version 2.5c-10.4 for the old stable distribution (potato), in version 2.7a-1.2 for the current stable distribution (woody) and in version 2.7d-1 for the unstable distribution (sid). We recommend that you upgrade your wwwoffle packages. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato --------------------------------- Source archives: Size/MD5 checksum: 576be6e528ce89bf62fa43f0df357cc079b Size/MD5 checksum: 42169 65906133e7bb10d41cd70f2c828b520a Size/MD5 checksum: 414642 4f0b9e36537dd39c02bd8a2477740cc5 Alpha architecture: Size/MD5 checksum: 641192 c4502218021ee68a971ffb66851724f4 ARM architecture: Size/MD5 checksum: 532172 954b2744514ececf82b131c967a3f800 Intel IA-32 architecture: Size/MD5 checksum: 514316 9130724c8fe2d8af0f55acc1876c06a0 Motorola 680x0 architecture: Size/MD5 checksum: 500890 b4d8f2336053d8926f024422e14f2b3e PowerPC architecture: Size/MD5 checksum: 559134 eaef2555bace43df204ed68ec2264ca6 Sun Sparc architecture: Size/MD5 checksum: 550050 d1206eec8d49e8407bbe1e8d740e4732 Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 570 20b6fb0e853730d5017cd379973edf13 Size/MD5 checksum: 71141 521096aefb0c0f5d99d2551ecf9c33ca Size/MD5 checksum: 846376 53831483996555f8ecd976a02ec5204b Alpha architecture: Size/MD5 checksum: 1263622 91fc8cceb39b2ed80c0d4545365e8fb6 ARM architecture: Size/MD5 checksum: 1118162 7e718e3593029df74138d910d1a69e34 Intel IA-32 architecture: Size/MD5 checksum: 1076766 05dbb5274e02807291ca9f5a1b6b0667 Intel IA-64 architecture: Size/MD5 checksum: 1376094 2f38fe26d02653eb7fa5de8b6aef59b7 HP Precision architecture: Size/MD5 checksum: 1157098 dc731105d40969a1a17dd50417be13ee Motorola 680x0 architecture: Size/MD5 checksum: 1066962 e505d6e42b63dade20a9418136be578b Big endian MIPS architecture: Size/MD5 checksum: 1170084 5b70d729600f7e21c41daf1adf550cfd Little endian MIPS architecture: Size/MD5 checksum: 1170934 b53381bebd138ba21d630c06021b58a0 PowerPC architecture: Size/MD5 checksum: 1150250 fe7fe230aa611ea6c3331bc692286c15 IBM S/390 architecture: Size/MD5 checksum: 1088814 21667f4861c34ab8c720d2a50a84ec27 Sun Sparc architecture: Size/MD5 checksum: 1146472 65eec1fc427a86a63d3c4ad7f38345d1 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Explore the Debian security announcement released on August 6, which discusses vulnerabilities associated with input handling within the wwwoffle proxy service.. web proxy issues, Debian update, wwwoffle security. . LinuxSecurity.com Team

Calendar 2 Aug 06, 2002 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here