Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
197

Debian 11: DLA-4052-2 moderate: PostgreSQL 13 buffer overflow fix

The fix for CVE-2025-1094 included an error that caused the PQescapeLiteral and PQescapeIdentifier methods to ignore their length parameter, reading until the null terminating byte instead. That could cause unintended characters to be included on the output, . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4052-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort February 21, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : postgresql-13 Version : 13.20-0+deb11u1 CVE ID : CVE-2025-1094 The fix for CVE-2025-1094 included an error that caused the PQescapeLiteral and PQescapeIdentifier methods to ignore their length parameter, reading until the null terminating byte instead. That could cause unintended characters to be included on the output, or worse, buffer overflows. For Debian 11 bullseye, this problem has been fixed in version 13.20-0+deb11u1. We recommend that you upgrade your postgresql-13 packages. For the detailed security status of postgresql-13 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/postgresql-13 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade PostgreSQL 13 on Debian 11 by performing essential steps like backing up databases, checking versions, and restarting the service for improved security. Debian LTS, PostgreSQL 13, security update. . LinuxSecurity.com Team

Calendar 2 Feb 21, 2025 Debian LTS
197

Debian 10 Buster DLA-3347-2: Moderate Spip Plugin Activation Issue

It was discovered that the fix for CVE-2023-27372 broke (de)activation of plugins with dependencies. For Debian 10 buster, this problem has been fixed in version . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3347-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin March 03, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : spip Version : 3.2.4-1+deb10u11 It was discovered that the fix for CVE-2023-27372 broke (de)activation of plugins with dependencies. For Debian 10 buster, this problem has been fixed in version 3.2.4-1+deb10u11. We recommend that you upgrade your spip packages. For the detailed security status of spip please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/spip Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3348-1 resolves an issue with Moodle related to course management that stemmed from previous updates.. Debian LTS, spip security, plugin compatibility, update advisory. . LinuxSecurity.com Team

Calendar 2 Mar 03, 2023 Debian LTS
197

Debian: DLA-2338-2 Moderate: ProFTPD Segmentation Fault Issue

The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2338-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany August 25, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : proftpd-dfsg Version : 1.3.5e+r1.3.5b-4+deb9u2 Debian Bug : 968967 The update of proftpd-dfsg released as DLA-2338-1 incorrectly destroyed the memory pool in function sftp_kex_handle in contrib/mod_sftp/kex.c which may cause a segmentation fault and thus prevent sftp connections. For Debian 9 stretch, this problem has been fixed in version 1.3.5e+r1.3.5b-4+deb9u2. We recommend that you upgrade your proftpd-dfsg packages. For the detailed security status of proftpd-dfsg please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2340-3 resolves a critical vulnerability in openssl impacting secure communications.. Debian LTS, ProFTPD, Memory Issues, SFTP Connections, Security Updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important Debian LTS
197

Debian 8: DLA-2228-2 Critical: json-c Integer Overflow Fix

The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. . Package : json-c Version : 0.11-4+deb8u2 CVE ID : CVE-2020-12762 Debian Bug : 960326 The json-c shared library had an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend. This follow-up version now uses an upstream sanctioned patch that was specifically published for json-c 0.11, rather than a self-backported patch. For Debian 8 "Jessie", this problem has been fixed in version 0.11-4+deb8u2. We recommend that you upgrade your json-c packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Debian LTS patches json-c library to address integer overflow and out-of-bounds write vulnerabilities, significantly improving security.. json-c Regression Update, Debian Security Advisory, Integer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 31, 2020 Critical Debian LTS
87

Debian: DSA-3795-2 Urgent: Munin Local File Manipulation Vulnerability

The update for munin issued as DSA-3794-2 caused a regression leading to Perl warnings being appended to the munin-cgi-graph log file. Updated packages are now available to correct this issue. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3794-3 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso March 03, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : munin Debian Bug : 856536 The update for munin issued as DSA-3794-2 caused a regression leading to Perl warnings being appended to the munin-cgi-graph log file. Updated packages are now available to correct this issue. For reference, the original advisory text follows. Stevie Trujillo discovered a local file write vulnerability in munin, a network-wide graphing framework, when CGI graphs are enabled. GET parameters are not properly handled, allowing to inject options into munin-cgi-graph and overwriting any file accessible by the user running the cgi-process. For the stable distribution (jessie), this problem has been fixed in version 2.0.25-1+deb8u3. We recommend that you upgrade your munin packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu issues notice regarding Munin patch update for DSA-3795-4. Addresses file permission vulnerabilities and resolves CGI interface rendering errors.. Debian Munin Exploit, Local File Overwrite, Network Graph Framework. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 03, 2017 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here