Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 40 MOD_AUTH_OPENIDC: Critical Update for Data Leak Issue

REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-80600b51c5 2025-04-17 19:32:14.984529+00:00 -------------------------------------------------------------------------------- Name : mod_auth_openidc Product : Fedora 40 Version : 2.4.16.11 Release : 1.fc40 URL : https://github.com/OpenIDC/mod_auth_openidc Summary : OpenID Connect auth module for Apache HTTP Server Description : This module enables an Apache 2.x web server to operate as an OpenID Connect Relying Party and/or OAuth 2.0 Resource Server. -------------------------------------------------------------------------------- Update Information: REbase mod_auth_openidc-2.4.16.11 resolves CVE-2025-31492 - mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 8 2025 Tomas Halman - 2.4.16.11-1 Rebase to version 2.4.16.11 - Resolves: rhbz#2357672 - mod_auth_openidc-2.4.16.11 is available - Resolves: rhbz#2357848 - CVE-2025-31492 mod_auth_openidc allows OIDCProviderAuthRequestMethod POSTs to leak protected data -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-80600b51c5' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The Fedora 40 patch addresses a significant vulnerability in mod_auth_openidc, enhancing data security and preventing potential leaks.. mod_auth_openidc Update, Fedora Security, OIDC Data Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 17, 2025 Critical Fedora
98

Red Hat Enterprise Linux 8.6 RHSA-2023:4767-01 Moderate libxml2 XSS Issue

An update for libxml2 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: libxml2 security update Advisory ID: RHSA-2023:4767-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4767 Issue date: 2023-08-28 CVE Names: CVE-2016-3709 ===================================================================== 1. Summary: An update for libxml2 is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: The libxml2 library is a development toolbox providing the implementation of various XML standards. Security Fix(es): * libxml2: Incorrect server side include parsing can lead to XSS (CVE-2016-3709) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The desktop must be restarted (log out, then log back in) for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 2112766- CVE-2016-3709 libxml2: Incorrect server side include parsing can lead to XSS 6. Package List: Red Hat Enterprise Linux AppStream EUS (v.8.6): aarch64: libxml2-debuginfo-2.9.7-13.el8_6.2.aarch64.rpm libxml2-debugsource-2.9.7-13.el8_6.2.aarch64.rpm libxml2-devel-2.9.7-13.el8_6.2.aarch64.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.aarch64.rpm ppc64le: libxml2-debuginfo-2.9.7-13.el8_6.2.ppc64le.rpm libxml2-debugsource-2.9.7-13.el8_6.2.ppc64le.rpm libxml2-devel-2.9.7-13.el8_6.2.ppc64le.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.ppc64le.rpm s390x: libxml2-debuginfo-2.9.7-13.el8_6.2.s390x.rpm libxml2-debugsource-2.9.7-13.el8_6.2.s390x.rpm libxml2-devel-2.9.7-13.el8_6.2.s390x.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.s390x.rpm x86_64: libxml2-debuginfo-2.9.7-13.el8_6.2.i686.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.x86_64.rpm libxml2-debugsource-2.9.7-13.el8_6.2.i686.rpm libxml2-debugsource-2.9.7-13.el8_6.2.x86_64.rpm libxml2-devel-2.9.7-13.el8_6.2.i686.rpm libxml2-devel-2.9.7-13.el8_6.2.x86_64.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.i686.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.x86_64.rpm Red Hat Enterprise Linux BaseOS EUS(v.8.6): Source: libxml2-2.9.7-13.el8_6.2.src.rpm aarch64: libxml2-2.9.7-13.el8_6.2.aarch64.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.aarch64.rpm libxml2-debugsource-2.9.7-13.el8_6.2.aarch64.rpm python3-libxml2-2.9.7-13.el8_6.2.aarch64.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.aarch64.rpm ppc64le: libxml2-2.9.7-13.el8_6.2.ppc64le.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.ppc64le.rpm libxml2-debugsource-2.9.7-13.el8_6.2.ppc64le.rpm python3-libxml2-2.9.7-13.el8_6.2.ppc64le.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.ppc64le.rpm s390x: libxml2-2.9.7-13.el8_6.2.s390x.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.s390x.rpm libxml2-debugsource-2.9.7-13.el8_6.2.s390x.rpm python3-libxml2-2.9.7-13.el8_6.2.s390x.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.s390x.rpm x86_64: libxml2-2.9.7-13.el8_6.2.i686.rpm libxml2-2.9.7-13.el8_6.2.x86_64.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.i686.rpm libxml2-debuginfo-2.9.7-13.el8_6.2.x86_64.rpm libxml2-debugsource-2.9.7-13.el8_6.2.i686.rpm libxml2-debugsource-2.9.7-13.el8_6.2.x86_64.rpm python3-libxml2-2.9.7-13.el8_6.2.x86_64.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.i686.rpm python3-libxml2-debuginfo-2.9.7-13.el8_6.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIcBAEBCAAGBQJk7LPSAAoJENzjgjWX9erE2FEP/ji43JgJkMmrcIftmCy3Y9f1 mLivqqw2EHCseBCnWHUvumxKs9QUJEmdtPryDh81t2gZn62avyLqIXs9u1lIUxLY jlf/Ah2S2oVgLUfnkWyY41OgkpRTo46kaWviBUrglSY13bfArLNeEfJcTALMLImx A7N1G/ipxYJUifHtjRDDtemlTBFPAqemfFy+lk1cxWd9rcjQWCJB6zAm4X/Mf4S8 93Vm+tsD7cx2lOJbNlgG54p+Z20I8vI283Sa23/NjargMXYp+8RTnmGiMageLZ6E WNT3yriBmJCIeiliZg62XjkqPjar4H8Qo7FVVf3u36t0I1nZwE08iSUd+jBdUHSn EpWL0U7W3sPoDusOhgPxVbUZ+ykLzc2mUeLNVkkTQgR3YfW1MxYohDUlHN9y0xw7 FfFszQAzS3LhTBbkE3na1KrxjtLIcf3J9cMfM2NVDLBC4jGIf3gcCccNQoEFU3EV YI3p9295AjMZa3cp9kgJofNPohdknVhpN9fENcMrMAVKOE6+R3otvBVC4gST+RuH 1dzBiHtvlTiYu6qUyTFgEJ+RbUBkWrPrMTEHHb0cyCFD4txN8UYZVFW6RNKwyaw1 DsuJNREu23DpfFAG/rGuTOAMdXYgQThMmbgrEm9HyY00v1JnuHrlVD3He5/DJ4jW hlWpQeuNx6cqLM0cn+Cz =dM4K -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Cautious libxml2 security patch for CentOS enhances defenses against vulnerabilities in XML processing challenges.. Red Hat Enterprise Linux, libxml2 security, XSS Mitigation, security update, EUS Support. . LinuxSecurity.com Team

Calendar 2 Aug 28, 2023 Red Hat
89

Fedora 36 Advisory: golang-github-olekukonko-tablewriter Critical CVE Fix

Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --- See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-37aef44d1e 2022-07-30 01:52:05.591856 --------------------------------------------------------------------------------Name : golang-github-olekukonko-tablewriter Product : Fedora 36 Version : 0.0.5 Release : 4.fc36 URL : https://github.com/olekukonko/tablewriter Summary : ASCII table in Go Description : ASCII Table Writer. --------------------------------------------------------------------------------Update Information: Rebuild to mitigate CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang ---See https://groups.google.com/g/golang-dev/c/frczlF8OFQ0/m/4lrZh5BHDgAJ for more information about the specific vulnerabilities. ---- enable s390x build (rhbz#1971028) --------------------------------------------------------------------------------ChangeLog: * Tue Jul 19 2022 Maxwell G 0.0.5-4 - Rebuild for CVE-2022-{1705,32148,30631,30633,28131,30635,30632,30630,1962} in golang --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-37aef44d1e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Revamp the golang-github-olekukonko-tablewriter package to mitigate various CVEs for the Fedora 36 system.. Fedora 36, Golang Update, Security Issue, ASCII Table Writer Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here