Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
197

Debian 8: DLA-2187-1 Moderate: Radicale Timing Attack Issue

Radicale, a simple calendar and addressbook server - daemon, is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. . Package : radicale Version : 0.9-1+deb8u2 CVE ID : CVE-2017-8342 Radicale, a simple calendar and addressbook server - daemon, is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. For Debian 8 "Jessie", this problem has been fixed in version 0.9-1+deb8u2. We recommend that you upgrade your radicale packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security patch for Radicale addresses timing attack susceptibilities discovered in Debian 8, bolstering system safeguards.. Radicale Security Update, Timing Attack, Authentication Issue, Debian 8, Brute-Force. . LinuxSecurity.com Team

Calendar 2 Apr 25, 2020 Debian LTS
89

Fedora 25: FEDORA-2017-2ab5baea0a Critical: Radicale Server Timing Issue

Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2ab5baea0a 2017-05-14 20:16:02.224952 --------------------------------------------------------------------------------Name : radicale Product : Fedora 25 Version : 1.1.2 Release : 1.fc25 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch released for Fedora 25, addressing synchronization vulnerabilities in radicale server. Please update immediately to enhance the security of your system.. Fedora 25, radicale server, security fix, timing attack, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2017 Critical Fedora
89

Fedora 24: RADICALE-2017-cdc7caed36 Critical: Timing Attacks Fix

Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-cdc7caed36 2017-05-14 20:15:03.388678 --------------------------------------------------------------------------------Name : radicale Product : Fedora 24 Version : 1.1.2 Release : 1.fc24 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS patches Nextcloud to address security flaws, improving defense against injection attacks. Immediate upgrade advised. Fedora Security Update, Radicale Fix, Timing Attacks, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2017 Critical Fedora
89

Fedora 26: FEDORA-2017-863f86e7a9 Moderate: Radicale Timing Attack

Security fix for CVE-2017-8342. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-863f86e7a9 2017-05-12 14:09:49.178117 --------------------------------------------------------------------------------Name : radicale Product : Fedora 26 Version : 1.1.2 Release : 1.fc26 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-8342 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447247 - CVE-2017-8342 radicale: Insufficient protection against timing oracles and bruteforce attacks [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447247 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade radicale' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 27 has released a critical security patch for Radicale, mitigating CVE-2018-1234 and bolstering defenses against potential side-channel attacks.. Radicale Security Update,Fedora 26 Latest Fix,CVE-2017-8342 Patch. . LinuxSecurity.com Team

Calendar 2 May 12, 2017 Fedora
197

Debian 7 DLA-934-2 Important: Radicale Authentication Vulnerability Fix

Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. . Hash: SHA512 Package : radicale Version : 0.7-1.1+deb7u2 CVE ID : CVE-2017-8342 Radicale before 1.1.2 and 2.x before 2.0.0rc2 is prone to timing oracles and simple brute-force attacks when using the htpasswd authentication method. For Debian 7 "Wheezy", these problems have been fixed in version 0.7-1.1+deb7u2. We recommend that you upgrade your radicale packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Radicale 0.7-1.1+deb7u3 addresses vulnerabilities in timing and brute-force exploitation through the htpasswd authentication technique.. Radicale Security, Timing Attack Fix, Debian Security Update, Brute-Force Protection. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 09, 2017 Important Debian LTS
87

Debian: DSA-3462-1 Critical: Radicale File Access Problems

Two vulnerabilities were fixed in radicale, a CardDAV/CalDAV server. CVE-2015-8747 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3462-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Yves-Alexis Perez January 30, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : radicale CVE ID : CVE-2015-8747 CVE-2015-8748 Debian Bug : 809920 Two vulnerabilities were fixed in radicale, a CardDAV/CalDAV server. CVE-2015-8747 The (not configured by default and not available on Wheezy) multifilesystem storage backend allows read and write access to arbitrary files (still subject to the DAC permissions of the user the radicale server is running as). CVE-2015-8748 If an attacker is able to authenticate with a user name like `.*', he can bypass read/write limitations imposed by regex-based rules, including the built-in rules `owner_write' (read for everybody, write for the calendar owner) and `owner_only' (read and write for the the calendar owner). For the oldstable distribution (wheezy), these problems have been fixed in version 0.7-1.1+deb7u1. For the stable distribution (jessie), these problems have been fixed in version 0.9-1+deb8u1. For the testing distribution (stretch), these problems have been fixed in version 1.1.1-1. For the unstable distribution (sid), these problems have been fixed in version 1.1.1-1. We recommend that you upgrade your radicale packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --------------------------------------------------.vulnerabilities, radicale, carddav/caldav, server, cve-2015-8747, -----begin. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 30, 2016 Critical Debian
89

Fedora 23 Critical Update: Radicale 1.1.1 Security Issues Addressed

Version 1.1.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-f048c43393 2016-01-19 19:15:35.972948 -------------------------------------------------------------------------------- Name : radicale Product : Fedora 23 Version : 1.1.1 Release : 1.fc23 URL : https://radicale.org/ Summary : A simple CalDAV (calendar) and CardDAV (contact) server Description : The Radicale Project is a CalDAV (calendar) and CardDAV (contact) server. It aims to be a light solution, easy to use, easy to install, easy to configure. As a consequence, it requires few software dependencies and is pre-configured to work out-of-the-box. The Radicale Project runs on most of the UNIX-like platforms (Linux, BSD, MacOS X) and Windows. It is known to work with Evolution, Lightning, iPhone and Android clients. It is free and open-source software, released under GPL version 3. For further information, please visit the Radicale Website -------------------------------------------------------------------------------- Update Information: Version 1.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1295836 - CVE-2015-8747 CVE-2015-8748 radicale: Multiple security issues fixed in 1.1 https://bugzilla.redhat.com/show_bug.cgi?id=1295836 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update radicale' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Radicale security patch resolves various vulnerabilities in version 1.1.1 for Fedora 23, boosting overall functionality and dependability.. Fedora Security, Radicale Update, Critical Software Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 19, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here