Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 90 articles for you...
87

Debian DSA-3788-1 moderate: Apache Tomcat8 DoS Risk From Programming Error

It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3788-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 13, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tomcat8 CVE ID : not yet available Debian Bug : 851304 It was discovered that a programming error in the processing of HTTPS requests in the Apache Tomcat servlet and JSP engine may result in denial of service via an infinite loop. For the stable distribution (jessie), this problem has been fixed in version 8.0.14-1+deb8u7. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your tomcat8 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the latest Debian patch for tomcat8, targeting Denial of Service vulnerabilities linked to HTTPS handling issues.. apache tomcat, denial of service, debian security advisory. . LinuxSecurity.com Team

Calendar%202 Feb 13, 2017 Debian
87

Debian: DSA-2836-2 Critical OpenSSL Flaw Leading to TLS Denial of Service

Anton Johannson discovered that an invalid TLS handshake package could crash OpenSSL with a NULL pointer dereference. The oldstable distribution (squeeze) is not affected. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2837-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 07, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2013-4353 Anton Johannson discovered that an invalid TLS handshake package could crash OpenSSL with a NULL pointer dereference. The oldstable distribution (squeeze) is not affected. For the stable distribution (wheezy), this problem has been fixed in version 1.0.1e-2+deb7u3. For the unstable distribution (sid), this problem has been fixed in version 1.0.1f-1. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4215-1 outlines a significant OpenSSL patch that resolves a bug in the certificate verification process.. OpenSSL Update, Debian Security, Remote Crash Issue, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 07, 2014 Critical Debian
87

Debian: DSA-2764-1 Critical: Libvirt Denial Of Service Issue

Daniel P. Berrange discovered that incorrect memory handling in the remoteDispatchDomainMemoryStats() function could lead to denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2764-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 25, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libvirt Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2013-4296 Daniel P. Berrange discovered that incorrect memory handling in the remoteDispatchDomainMemoryStats() function could lead to denial of service. The oldstable distribution (squeeze) is not affected. For the stable distribution (wheezy), this problem has been fixed in version 0.9.12-11+deb7u4. This update also includes some non-security related bugfixes scheduled for the upcoming Wheezy 7.2 point release. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libvirt packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep your Debian libvirt version current to mitigate potential denial of service vulnerabilities caused by improper memory management.. libvirt security, Debian advisory, memory handling issue, denial of service fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2013 Critical Debian
87

Ubuntu KfreeBSD-10 DSA-2820-2 Urgent: Security Flaw Detected

Konstantin Belousov and Alan Cox discovered that insufficient permission checks in the memory management of the FreeBSD kernel could lead to privilege escalation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2714-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 25, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kfreebsd-9 Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2013-2171 Konstantin Belousov and Alan Cox discovered that insufficient permission checks in the memory management of the FreeBSD kernel could lead to privilege escalation. For the stable distribution (wheezy), this problem has been fixed in version 9.0-10+deb70.2. For the unstable distribution (sid), this problem has been fixed in version 9.0-12. We recommend that you upgrade your kfreebsd-9 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Inadequate authorization verifications within the FreeBSD core can result in potential elevation vulnerabilities. It is advisable to update kfreebsd-9 software packages.. kfreebsd Upgrade, Privilege Escalation, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2013 Critical Debian
87

Debian: DSA-2612-2 Moderate: ircd-ratbox Remote Programming Issue

This update to the previous ircd-ratbox DSA only raises the version number to ensure that a higher version is used than a previously binNMU on some architectures. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2612-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 10, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ircd-ratbox Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2012-6084 This update to the previous ircd-ratbox DSA only raises the version number to ensure that a higher version is used than a previously binNMU on some architectures. For the stable distribution (squeeze), this problem has been fixed in version 3.0.6.dfsg-2+squeeze1. We recommend that you upgrade your ircd-ratbox packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . This notification addresses a flaw in ircd-ratbox affecting Debian installations. Review specifics for patch application.. Debian Security, ircd-ratbox, Remote Error, Programming Fix. . LinuxSecurity.com Team

Calendar%202 Feb 10, 2013 Debian
87

Debian: DSA-2613-1 Important: openssl Vulnerability Warning

It was discovered that a bug in the server capability negotiation code of ircd-ratbox could result in denial of service. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2612-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 24, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ircd-ratbox Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2012-6084 It was discovered that a bug in the server capability negotiation code of ircd-ratbox could result in denial of service. For the stable distribution (squeeze), this problem has been fixed in version 3.0.6.dfsg-2squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 3.0.7.dfsg-3. For the unstable distribution (sid), this problem has been fixed in version 3.0.7.dfsg-3. We recommend that you upgrade your ircd-ratbox packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Denial of service vulnerability addressed in ircd-ratbox for Debian stable users following the identification of a server functionality flaw.. Denial of Service Issue, ircd-ratbox, Debian Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 24, 2013 Important Debian
87

Debian: DSA-2603-1 Moderate: Emacs23 Local Programming Issue

Paul Ling discovered that Emacs insufficiently restricted the evaluation of Lisp code if enable-local-variables is set to "safe". For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2603-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 09, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : emacs23 Vulnerability : programming error Problem type : local Debian-specific: no CVE ID : CVE-2012-3479 Paul Ling discovered that Emacs insufficiently restricted the evaluation of Lisp code if enable-local-variables is set to "safe". For the stable distribution (squeeze), this problem has been fixed in version 23.2+1-7+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 23.4+1-4. For the unstable distribution (sid), this problem has been fixed in version 23.4+1-4. We recommend that you upgrade your emacs23 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A flaw has been discovered in Emacs23 that permits unsafe execution of Lisp scripts. Debian users are strongly advised to upgrade to a patched version.. Debian Security Advisory, Emacs23 Update, Programming Error, Local Issue. . LinuxSecurity.com Team

Calendar%202 Jan 09, 2013 Debian
87

Ubuntu: USN-4079-1 Severe Vulnerability in QEMU Virtualization Software

"halfdog" discovered that incorrect interrupt handling in Virtualbox, a x86 virtualization solution - can lead to denial of service. For the stable distribution (squeeze), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2594-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff December 30, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : virtualbox-ose Vulnerability : programming error Problem type : remote Debian-specific: no CVE ID : CVE-2012-3221 "halfdog" discovered that incorrect interrupt handling in Virtualbox, a x86 virtualization solution - can lead to denial of service. For the stable distribution (squeeze), this problem has been fixed in version 3.2.10-dfsg-1+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 4.1.18-dfsg-1.1 of the virtualbox source package. We recommend that you upgrade your virtualbox-ose packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent security announcement for Debian: virtualbox-ose patch released to mitigate remote denial of service vulnerability.. Virtualbox Security Update, Debian DSA-2594-1, Remote Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 30, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200