Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":550,"type":"x","order":1,"pct":78.57,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.29,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 9: 2025-0145 critical: tomcat DoS and rewrite bypass

DoS via malformed HTTP/2 PRIORITY_UPDATE frame. (CVE-2025-31650) Bypass of rules in Rewrite Valve. (CVE-2025-31651) References: - https://bugs.mageia.org/show_bug.cgi?id=34231 . MGASA-2025-0145 - Updated tomcat packages fix security vulnerabilities Publication date: 05 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0145.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-31650, CVE-2025-31651 DoS via malformed HTTP/2 PRIORITY_UPDATE frame. (CVE-2025-31650) Bypass of rules in Rewrite Valve. (CVE-2025-31651) References: - https://bugs.mageia.org/show_bug.cgi?id=34231 - https://www.openwall.com/lists/oss-security/2025/04/28/2 - https://www.openwall.com/lists/oss-security/2025/04/28/3 - https://www.cve.org/CVERecord?id=CVE-2025-31650 - https://www.cve.org/CVERecord?id=CVE-2025-31651 SRPMS: - 9/core/tomcat-9.0.104-1.mga9 . The latest Mageia 9 release effectively resolves the vulnerabilities related to Tomcat's denial of service and rewrite rule bypass issues.. Mageia security advisory, Tomcat DoS, Rewrite Valve Bypass, Software updates, Mageia vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 05, 2025 Critical Mageia
89

Fedora 9: 2008-11923 Moderate: Lighttpd Memory Leak and Rewrite Bypass

This update fixes some moderate security issues and includes a few enhancements.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-11923 2008-12-30 22:33:58 --------------------------------------------------------------------------------Name : lighttpd Product : Fedora 9 Version : 1.4.20 Release : 6.fc9 URL : http://www.lighttpd.net/ Summary : Lightning fast webserver with light system requirements Description : Secure, fast, compliant and very flexible web-server which has been optimized for high-performance environments. It has a very low memory footprint compared to other webservers and takes care of cpu-load. Its advanced feature-set (FastCGI, CGI, Auth, Output-Compression, URL-Rewriting and many more) make it the perfect webserver-software for every server that is suffering load problems. Available rpmbuild rebuild options : --with : gamin webdavprops webdavlocks memcache --without : ldap gdbm lua (cml) --------------------------------------------------------------------------------Update Information: This update fixes some moderate security issues and includes a few enhancements. --------------------------------------------------------------------------------ChangeLog: * Wed Dec 24 2008 Matthias Saou 1.4.20-6 - Partially revert last change by creating a "spawn-fastcgi" symlink, so that nothing breaks currently (especially for EL). - Install empty poweredby image on RHEL since the symlink's target is missing. - Split spawn-fcgi off in its own sub-package, have fastcgi package require it to provide backwards compatibility. * Mon Dec 22 2008 Matthias Saou 1.4.20-3 - Rename spawn-fastcgi to lighttpd-spawn-fastcgi to avoid clash with other packages providing it for their own needs (#472749). It's not used as-is by lighttpd, so it shouldn't be a problem... at worst, some custom scripts will need to be updated. * Mon Dec 22 2008 Matthias Saou 1.4.20-2 - Include conf.d/*.conf configuration snippets (#444953). - Mark the default index.html in order to not loose changes upon upgrade if it was edited or replaced with a different file (#438564). - Include patch to add the INIT INFO block to the init script (#246973). * Mon Oct 13 2008 Matthias Saou 1.4.20-1 - Update to 1.4.20 final. * Mon Sep 22 2008 Matthias Saou 1.4.20-0.1.r2303 - Update to 1.4.20 r2303 pre-release. * Mon Sep 22 2008 Matthias Saou 1.4.19-5 - Include memory leak patch (changeset #2305 from ticket #1774). * Thu Apr 24 2008 Matthias Saou 1.4.19-4 - Merge in second changest from upstream fix for upstream bug #285. * Thu Mar 27 2008 Matthias Saou 1.4.19-3 - Include sslshutdown patch, upstream fix to upstream bug #285 (#439066). --------------------------------------------------------------------------------References: [ 1 ] Bug #464637 - CVE-2008-4298 lighttpd: memory leak http_request_parse() in request.c https://bugzilla.redhat.com/show_bug.cgi?id=464637 [ 2 ] Bug #465751 - CVE-2008-4359 lighttpd: bypass of rewrite/redirect rules using encoded urls https://bugzilla.redhat.com/show_bug.cgi?id=465751 [ 3 ] Bug #465752 - CVE-2008-4360 lighttpd: mod_userdir information disclosure on case-insensitve filesystems https://bugzilla.redhat.com/show_bug.cgi?id=465752 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update lighttpd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent lighttpd update for Fedora 9 resolves several vulnerabilities and boosts overall performance with important security enhancements.. lighttpd update,Fedora 9 security,web server performance. . LinuxSecurity.com Team

Calendar 2 Feb 12, 2009 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":550,"type":"x","order":1,"pct":78.57,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.29,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here