Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
203

Mageia 9 MGASA-2024-0361: Critical tcpdf Vulnerability ReDoS Fix

TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. (CVE-2024-22641) References: . MGASA-2024-0361 - Updated php-tcpdf packages fix security vulnerability Publication date: 12 Nov 2024 URL: https://advisories.mageia.org/MGASA-2024-0361.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-22641 TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file. (CVE-2024-22641) References: - https://bugs.mageia.org/show_bug.cgi?id=33731 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/WGK7LQSJONZPU3VOQTQ36UN6OAD6ZM4H/ - https://www.cve.org/CVERecord?id=CVE-2024-22641 SRPMS: - 9/core/php-tcpdf-6.5.0-1.2.mga9 . TCPDF versions 6.6.5 and prior are susceptible to ReDoS vulnerabilities. Recent patches released to address these potential security issues.. tcpdf, redos, Mageia Security, php security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 12, 2024 Critical Mageia
100

SUSE: 2024:3411-1 important: python39 ReDoS and resource issues

* bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References: . # Security update for python39 Announcement ID: SUSE-SU-2024:3411-1 Rating: important References: * bsc#1229596 * bsc#1229704 * bsc#1230227 Cross-References: * CVE-2024-6232 * CVE-2024-7592 * CVE-2024-8088 CVSS scores: * CVE-2024-6232 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2024-6232 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-6232 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8088 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8088 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP5 * openSUSE Leap 15.3 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python39 fixes the following issues: * Update to 3.9.20: * CVE-2024-6232: excessive backtracking when parsing tarfile headers leads to ReDoS. (bsc#1230227) * CVE-2024-7592: quadratic algorithm used when parsing cookies leads to excessive resource consumption. (bsc#1229596) * CVE-2024-8088: lack of name validation when extracting a zip archive leads to infinite loops. (bsc#1229704) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methodslike YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-3411=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-3411=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-3411=1 * Legacy Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP5-2024-3411=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-3411=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-3411=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-3411=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-3411=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.3 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 *libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-64bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-64bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-64bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-64bit-3.9.20-150300.4.52.1 * python39-64bit-debuginfo-3.9.20-150300.4.52.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.5 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) *python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * python39-doc-devhelp-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-testsuite-debuginfo-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-testsuite-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * python39-doc-3.9.20-150300.4.52.1 * openSUSE Leap 15.6 (x86_64) * python39-32bit-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-32bit-3.9.20-150300.4.52.1 * python39-32bit-debuginfo-3.9.20-150300.4.52.1 * python39-base-32bit-3.9.20-150300.4.52.1 * Legacy Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python39-curses-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 *python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 *python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * python39-tk-debuginfo-3.9.20-150300.4.52.1 * python39-curses-3.9.20-150300.4.52.1 * python39-core-debugsource-3.9.20-150300.4.52.1 * python39-devel-3.9.20-150300.4.52.1 * python39-base-3.9.20-150300.4.52.1 * python39-debuginfo-3.9.20-150300.4.52.1 * python39-tools-3.9.20-150300.4.52.1 * python39-dbm-debuginfo-3.9.20-150300.4.52.1 * python39-curses-debuginfo-3.9.20-150300.4.52.1 * python39-debugsource-3.9.20-150300.4.52.1 * python39-tk-3.9.20-150300.4.52.1 * python39-dbm-3.9.20-150300.4.52.1 * python39-3.9.20-150300.4.52.1 * python39-base-debuginfo-3.9.20-150300.4.52.1 * libpython3_9-1_0-3.9.20-150300.4.52.1 * python39-idle-3.9.20-150300.4.52.1 * libpython3_9-1_0-debuginfo-3.9.20-150300.4.52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6232.html * https://www.suse.com/security/cve/CVE-2024-7592.html * https://www.suse.com/security/cve/CVE-2024-8088.html * https://bugzilla.suse.com/show_bug.cgi?id=1229596 * https://bugzilla.suse.com/show_bug.cgi?id=1229704 * https://bugzilla.suse.com/show_bug.cgi?id=1230227 . Bolster your platform's protection using SUSE's Python39 security patch that tackles urgent vulnerabilities throughout multiple components.. Python39 Security Update, SUSE Security Advisory, Linux Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 24, 2024 Important SuSE
100

SUSE: 2023:4799-2 Moderate: python3-setuptools ReDoS Threat

The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/manager/4.3/proxy-httpd ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3798-1 Container Tags : suse/manager/4.3/proxy-httpd:4.3.9 , suse/manager/4.3/proxy-httpd:4.3.9.9.40.9 , suse/manager/4.3/proxy-httpd:latest , suse/manager/4.3/proxy-httpd:susemanager-4.3.9 , suse/manager/4.3/proxy-httpd:susemanager-4.3.9.9.40.9 Container Release : 9.40.9 Severity : moderate Type : security References : 1206667 CVE-2022-40897 ----------------------------------------------------------------- The container suse/manager/4.3/proxy-httpd was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4517-1 Released: Tue Nov 21 17:30:27 2023 Summary: Security update for python3-setuptools Type: security Severity: moderate References: 1206667,CVE-2022-40897 This update for python3-setuptools fixes the following issues: - CVE-2022-40897: Fixed Regular Expression Denial of Service (ReDoS) in package_index.py (bsc#1206667). The following package changes have been done: - python3-setuptools-44.1.1-150400.9.6.1 updated . A security patch for the SUSE Container suse/manager/4.3/proxy-nginx has been released to mitigate a ReDoS vulnerability.. SUSE Manager, Container Update, Security Patches, ReDoS Threat. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2023 SuSE
203

Mageia 8: MGASA-2023-0302 Critical Update for Python-Nltk ReDoS Risk

python-nltk 3.6.6 update resolves ReDoS opportunity by fixing incorrectly specified regex References: - https://bugs.mageia.org/show_bug.cgi?id=30604 . MGASA-2023-0302 - Updated python-nltk package fixes a security vulnerability Publication date: 25 Oct 2023 URL: https://advisories.mageia.org/MGASA-2023-0302.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-3828 python-nltk 3.6.6 update resolves ReDoS opportunity by fixing incorrectly specified regex References: - https://bugs.mageia.org/show_bug.cgi?id=30604 - https://www.cve.org/CVERecord?id=CVE-2021-3828 SRPMS: - 8/core/python-nltk-3.6.6-1.mga8 - 8/core/python-regex-2022.9.13-1.mga8 . MGASA-2023-0303 patch addresses a vulnerability in python-requests, mitigating an information exposure risk linked to improper SSL verification settings.. python-nltk security, mageia update, regex threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 25, 2023 Critical Mageia
197

Debian 10 Buster DLA-3460-1 Critical: Python-Mechanize ReDoS DoS Threat

Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3460-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin June 20, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-mechanize Version : 1:0.2.5-3+deb10u1 CVE ID : CVE-2021-32837 Erik Krogh Kristensen and Rasmus Petersen from the GitHub Security Lab discovered a ReDoS (Regular Expression Denial of Service) vulnerability in python-mechanize, a library to automate interaction with websites modeled after the Perl module WWW::Mechanize, which could lead to Denial of Service when parsing a malformed authentication header. For Debian 10 buster, this problem has been fixed in version 1:0.2.5-3+deb10u1. We recommend that you upgrade your python-mechanize packages. For the detailed security status of python-mechanize please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-mechanize Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . To mitigate Denial of Service risks from the ReDoS vulnerability in python-mechanize, upgrade the package as per Debian LTS Advisory DLA-3460-1. Python Mechanize Security Update, Denial Of Service Fix, Debian Patch, LTS Advisory, ReDoS Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 20, 2023 Critical Debian LTS
89

Fedora 36: 2023-a7be7ea1aa Critical: ReDoS Fix in Ruby 3.1.4

Upgrade to Ruby 3.1.4. * Fix ReDoS vulnerability in URI (CVE-2023-28755) * Fix ReDoS vulnerability in Time (CVE-2023-28756) Fix bundler improperly resolving archful gems in Gemfile.lock. (rhbz#2178171). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-a7be7ea1aa 2023-04-21 01:23:34.069336 --------------------------------------------------------------------------------Name : ruby Product : Fedora 36 Version : 3.1.4 Release : 175.fc36 URL : https://www.ruby-lang.org/ Summary : An interpreter of object-oriented scripting language Description : Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible. --------------------------------------------------------------------------------Update Information: Upgrade to Ruby 3.1.4. * Fix ReDoS vulnerability in URI (CVE-2023-28755) * Fix ReDoS vulnerability in Time (CVE-2023-28756) Fix bundler improperly resolving archful gems in Gemfile.lock. (rhbz#2178171) --------------------------------------------------------------------------------ChangeLog: * Fri Mar 31 2023 Jarek Prokop This email address is being protected from spambots. You need JavaScript enabled to view it. - 3.1.4-175 - Upgrade to Ruby 3.1.4. - Fix ReDoS vulnerability in URI (CVE-2023-28755) - Fix ReDoS vulnerability in Time (CVE-2023-28756) - Fix bundler improperly resolving archful gems in Gemfile.lock. Resolves: rhbz#2178171 * Fri Jan 20 2023 Jun Aruga - 3.1.3-174 - Fix for tzdata-2022g. --------------------------------------------------------------------------------References: [ 1 ] Bug #2184059 - CVE-2023-28755 ruby: ReDoS vulnerability in URI https://bugzilla.redhat.com/show_bug.cgi?id=2184059 [ 2 ] Bug #2184061 - CVE-2023-28756 ruby: ReDoS vulnerability in Time https://bugzilla.redhat.com/show_bug.cgi?id=2184061 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-a7be7ea1aa' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . To mitigate ReDoS vulnerabilities in Ruby 3.1.4 on Fedora, apply patches and stay updated on critical security alerts to protect your system from risks. Ruby Upgrade, Fedora Security, ReDoS Threat Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 21, 2023 Critical Fedora
197

Debian 10 Advisory DLA-3392-1 Critical: ruby-rack ReDoS Issues

Two ruby-rack issues have been addressed: CVE-2023-27530 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3392-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Scarlett Moore April 17, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby-rack Version : 2.0.6-3+deb10u3 CVE ID : CVE-2023-27530 CVE-2023-27539 Debian Bug : Two ruby-rack issues have been addressed: CVE-2023-27530 Description: Limit all multipart parts, not just files. CVE-2023-27539 Description: Split headers on commas, then strip the strings in order to avoid ReDoS issues. For Debian 10 buster, these problems have been fixed in version 2.0.6-3+deb10u3. We recommend that you upgrade your ruby-rack packages. For the detailed security status of ruby-rack please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-rack Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the ruby-rack package to mitigate ReDoS vulnerabilities and improve multipart handling in accordance with Debian LTS DLA-3392-1.. Debian Security Update,Ruby Rack Issues,ReDoS Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2023 Critical Debian LTS
99

Slackware 15.0: 2023-090-01 Critical ReDoS Security Update for Ruby

New ruby packages are available for Slackware 15.0 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] ruby (SSA:2023-090-01) New ruby packages are available for Slackware 15.0 and -current to fix security issues. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/ruby-3.0.6-i586-1_slack15.0.txz: Upgraded. This update fixes security issues: ReDoS vulnerability in URI. ReDoS vulnerability in Time. For more information, see: https://www.ruby-lang.org/en/news/2023/03/28/redos-in-uri-cve-2023-28755/ https://www.ruby-lang.org/en/news/2023/03/30/redos-in-time-cve-2023-28756/ https://www.cve.org/CVERecord?id=CVE-2023-28755 https://www.cve.org/CVERecord?id=CVE-2023-28756 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 22ffa16679294ddce3265d913f2fac20 ruby-3.0.6-i586-1_slack15.0.txz Slackware x86_64 15.0 package: 0724127e313f586f6677e12e0316a070 ruby-3.0.6-x86_64-1_slack15.0.txz Slackware -current package: d39ba074e9714480e07880be54466086 d/ruby-3.2.2-i586-1.txz Slackware x86_64 -current package: 94a42ee743ed273628c09d9242ff125f d/ruby-3.2.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg ruby-3.0.6-i586-1_slack15.0.txz +-----+ . Recent updates to Ruby packages have been introduced in Slackware to mitigate significant security threats arising from ReDoS vulnerabilities.. ReDoSFix, Slackware 15.0, Ruby Update, Security Package. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 31, 2023 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200