Dino could be made to expose sensitive information over the network.. ========================================================================== Ubuntu Security Notice USN-7430-1 April 09, 2025 dino-im vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Dino could be made to expose sensitive information over the network. Software Description: - dino-im: modern XMPP client Details: Kim Alvefur discovered that Dino did not correctly sanitize certain messages. A remote attacker could possibly use this issue to leak sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS dino-im 0.3.0-3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS dino-im 0.1.0-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7430-1 CVE-2023-28686 . Discover the method to resolve the dino-im security vulnerability in Ubuntu which reveals confidential data through network channels.. Ubuntu Security, dino-im, Information Leak, Remote Threat. . Severity: Critical. LinuxSecurity.com Team
An update that solves two vulnerabilities and has 6 fixes An update that solves two vulnerabilities and has 6 fixes An update that solves two vulnerabilities and has 6 fixes is now available. is now available.. SUSE Security Update: Security update for Samba ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:0519-1 Rating: important References: #499233 #741623 #755663 #759731 #764577 #783384 #799641 #800982 Cross-References: CVE-2013-0213 CVE-2013-0214 Affected Products: SUSE Linux Enterprise Server 10 GPLv3 Extras ______________________________________________________________________________ An update that solves two vulnerabilities and has 6 fixes is now available. Description: The Samba Web Administration Tool (SWAT) in Samba versions 3.0.x to 4.0.1 was affected by a cross-site request forgery; CVE-2013-0214; (bnc#799641). The Samba Web Administration Tool (SWAT) in Samba versions 3.0.x to 4.0.1 could possibly be used in clickjacking attacks; CVE-2013-0213; (bnc#800982). Also the following bugs have been fixed: * Don't clutter the spec file diff view; (bnc#783384). * s3: Fix uninitialized memory read in talloc_free(); (bnc#764577). * Attempt to use samlogon validation level 6; (bso#7945); (bnc#741623). * Add PreReq /etc/init.d/nscd to the winbind package; (bnc#759731). * Recover from ncacn_ip_tcp ACCESS_DENIED/SEC_PKG_ERROR lsa errors; (bso#7944); (bnc#755663). * Fix lsa_LookupSids3 and lsa_LookupNames4 arguments. Security Issue references: * CVE-2013-0213 * CVE-2013-0214 Package List: - SUSE Linux Enterprise Server 10 GPLv3 Extras (i586 ia64 ppc s390x x86_64): libnetapi-devel-3.4.3-0.47.3 libnetapi0-3.4.3-0.47.3 libtalloc-devel-3.4.3-0.47.3 libtalloc1-3.4.3-0.47.3 libtdb-devel-3.4.3-0.47.3 libtdb1-3.4.3-0.47.3 libwbclient-devel-3.4.3-0.47.3 libwbclient0-3.4.3-0.47.3 samba-gplv3-3.4.3-0.47.3 samba-gplv3-client-3.4.3-0.47.3 samba-gplv3-krb-printing-3.4.3-0.47.3 samba-gplv3-winbind-3.4.3-0.47.3 - SUSE Linux Enterprise Server 10 GPLv3 Extras (noarch): samba-gplv3-doc-3.4.3-0.47.3 References: https://www.suse.com/security/cve/CVE-2013-0213.html https://www.suse.com/security/cve/CVE-2013-0214.html . Recent developments reveal critical Samba vulnerabilities in SUSE Linux, including remote code execution and data leakage documented in several CVEs.. Samba Security Update, SUSE Vulnerabilities, Fixes for Samba. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Mozilla Firefox, Thunderbird, SeaMonkey, NSS, GNU IceCat, and XULRunner, some of which may allow execution of arbitrary code or local privilege escalation. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201301-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Mozilla Products: Multiple vulnerabilities Date: January 08, 2013 Bugs: #180159, #181361, #207261, #238535, #246602, #251322, #255221, #255234, #255687, #257577, #260062, #261386, #262704, #267234, #273918, #277752, #280226, #280234, #280393, #282549, #284439, #286721, #290892, #292034, #297532, #305689, #307045, #311021, #312361, #312645, #312651, #312675, #312679, #312763, #313003, #324735, #326341, #329279, #336396, #341821, #342847, #348316, #357057, #360055, #360315, #365323, #373595, #379549, #381245, #388045, #390771, #395431, #401701, #403183, #404437, #408161, #413657, #419917, #427224, #433383, #437780, #439586, #439960, #444318 ID: 201301-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Mozilla Firefox, Thunderbird, SeaMonkey, NSS, GNU IceCat, and XULRunner, some of which may allow execution of arbitrary code or local privilege escalation. Background ========= Mozilla Firefox is an open-source web browser and Mozilla Thunderbird an open-source email client, both from the Mozilla Project. The SeaMonkey project is a community effort to deliver production-quality releases of code derived from the application formerly known as the 'Mozilla Application Suite'. XULRunner is a Mozilla runtime package thatcan be used to bootstrap XUL+XPCOM applications such as Firefox and Thunderbird. NSS is Mozilla's Network Security Services library that implements PKI support. IceCat is the GNU version of Firefox. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-client/firefox < 10.0.11 > = 10.0.11 2 www-client/firefox-bin < 10.0.11 > = 10.0.11 3 mail-client/thunderbird < 10.0.11 > = 10.0.11 4 mail-client/thunderbird-bin < 10.0.11 > = 10.0.11 5 www-client/seamonkey < 2.14-r1 > = 2.14-r1 6 www-client/seamonkey-bin < 2.14 > = 2.14 7 dev-libs/nss < 3.14 > = 3.14 8 www-client/mozilla-firefox
Several vulnerabilities have been discovered in OpenJDK, an implementation of the Java platform: CVE-2011-3389 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2356-1
Get the latest Linux and open source security news straight to your inbox.