Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
203

Mageia 9: MGASA-2025-0045 moderate: Fixes for firefox and nss issues

Use-after-free in XSLT. (CVE-2025-1009) Use-after-free in Custom Highlight. (CVE-2025-1010) A bug in WebAssembly code generation could result in a crash. (CVE-2025-1011) Use-after-free during concurrent delazification. (CVE-2025-1012) . MGASA-2025-0045 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 09 Feb 2025 URL: https://advisories.mageia.org/MGASA-2025-0045.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-1009, CVE-2025-1010, CVE-2025-1011, CVE-2025-1012, CVE-2024-11704, CVE-2025-1013, CVE-2025-1014, CVE-2025-1016, CVE-2025-1017 Use-after-free in XSLT. (CVE-2025-1009) Use-after-free in Custom Highlight. (CVE-2025-1010) A bug in WebAssembly code generation could result in a crash. (CVE-2025-1011) Use-after-free during concurrent delazification. (CVE-2025-1012) Potential double-free vulnerability in PKCS#7 decryption handling. (CVE-2024-11704) Potential opening of private browsing tabs in normal browsing windows. (CVE-2025-1013) Certificate length was not properly checked. (CVE-2025-1014) Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and Thunderbird 128.7. (CVE-2025-1016) Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7. (CVE-2025-1017) References: - https://bugs.mageia.org/show_bug.cgi?id=33983 - https://www.firefox.com/en-US/firefox/128.7.0/releasenotes/?redirect_source=mozilla-org - https://www.mozilla.org/en-US/security/advisories/mfsa2025-09/ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_108.html#mozilla-projects-nss-nss-3-108-release-notes - https://www.cve.org/CVERecord?id=CVE-2025-1009 - https://www.cve.org/CVERecord?id=CVE-2025-1010 - https://www.cve.org/CVERecord?id=CVE-2025-1011 - https://www.cve.org/CVERecord?id=CVE-2025-1012 - https://www.cve.org/CVERecord?id=CVE-2024-11704 - https://www.cve.org/CVERecord?id=CVE-2025-1013 -https://www.cve.org/CVERecord?id=CVE-2025-1014 - https://www.cve.org/CVERecord?id=CVE-2025-1016 - https://www.cve.org/CVERecord?id=CVE-2025-1017 SRPMS: - 9/core/rootcerts-20250130.00-1.mga9 - 9/core/nss-3.108.0-1.mga9 - 9/core/firefox-128.7.0-1.mga9 - 9/core/firefox-l10n-128.7.0-1.mga9 . Mageia 2025-0046 resolves various vulnerabilities in libssl, gnutls, and chromium software to improve overall performance.. firefox updates, mageia security, rootcerts vulnerabilities, nss patches. . LinuxSecurity.com Team

Calendar 2 Feb 09, 2025 Mageia
203

Mageia 9: MGASA-2024-0383 Critical Security Fixes for Firefox, NSS

Select list elements could be shown over another site. (CVE-2024-11692) CSP Bypass and XSS Exposure via Web Compatibility Shims. (CVE-2024-11694) URL Bar Spoofing via Manipulated Punycode and Whitespace Characters. (CVE-2024-11695) . MGASA-2024-0383 - Updated rootcerts, nss & firefox packages fix security vulnerabilities Publication date: 02 Dec 2024 URL: https://advisories.mageia.org/MGASA-2024-0383.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-11692, CVE-2024-11694, CVE-2024-11695, CVE-2024-11696, CVE-2024-11697, CVE-2024-11699 Select list elements could be shown over another site. (CVE-2024-11692) CSP Bypass and XSS Exposure via Web Compatibility Shims. (CVE-2024-11694) URL Bar Spoofing via Manipulated Punycode and Whitespace Characters. (CVE-2024-11695) Unhandled Exception in Add-on Signature Verification. (CVE-2024-11696) Improper Keypress Handling in Executable File Confirmation Dialog. (CVE-2024-11697) Memory safety bugs fixed in Firefox 133, Firefox ESR 128.5, and Thunderbird 128.5. (CVE-2024-11699) References: - https://bugs.mageia.org/show_bug.cgi?id=33804 - https://www.firefox.com/en-US/firefox/128.5.0/releasenotes/?redirect_source=mozilla-org - https://www.mozilla.org/en-US/security/advisories/mfsa2024-64/ - https://firefox-source-docs.mozilla.org/security/nss/releases/nss_3_107.html#mozilla-projects-nss-nss-3-107-release-notes - https://www.cve.org/CVERecord?id=CVE-2024-11692 - https://www.cve.org/CVERecord?id=CVE-2024-11694 - https://www.cve.org/CVERecord?id=CVE-2024-11695 - https://www.cve.org/CVERecord?id=CVE-2024-11696 - https://www.cve.org/CVERecord?id=CVE-2024-11697 - https://www.cve.org/CVERecord?id=CVE-2024-11699 SRPMS: - 9/core/rootcerts-20241119.00-1.mga9 - 9/core/nss-3.107.0-1.mga9 - 9/core/firefox-128.5.0-1.mga9 - 9/core/firefox-l10n-128.5.0-1.mga9 . MGASA-2024-0451 addresses vulnerabilities in openssl and glibc for Mageia 9, strengthening system integrity and performance.. mageia updates, security fixes, firefox vulnerabilities, xssprotection, rootcerts update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 02, 2024 Critical Mageia
203

Mageia 8 MGASA-2022-0462 Moderate: TrustCor Root Certificates Update

Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 . MGASA-2022-0462 - Updated rootcerts packages fix security vulnerability Publication date: 13 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0462.html Type: security Affected Mageia releases: 8 Set CKA_NSS_SERVER_DISTRUST_AFTER and CKA_NSS_EMAIL_DISTRUST_AFTER for 3 TrustCor Root Certificates. r=KathleenWilson References: - https://bugs.mageia.org/show_bug.cgi?id=31232 - https://phabricator.services.mozilla.com/D163527 - SRPMS: - 8/core/rootcerts-20221130.00-1.mga8 . MGASA-2022-0463 enhanced webserver packages addressing critical security issues, released on December 14, 2022.. Mageia Update, TrustCor Certificates, Security Fix, Root Certificates, Certificate Management. . LinuxSecurity.com Team

Calendar 2 Dec 13, 2022 Mageia
197

Debian: DLA-2593-1 Moderate: CA Certificates Reversion Update

This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2593-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta March 14, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ca-certificates Version : 20200601~deb9u2 Debian Bug : 962596 This update reverts the Symantec CA blacklist (which was originally #911289). The following root certificates were added back (+): + "GeoTrust Global CA" + "GeoTrust Primary Certification Authority" + "GeoTrust Primary Certification Authority - G2" + "GeoTrust Primary Certification Authority - G3" + "GeoTrust Universal CA" + "thawte Primary Root CA" + "thawte Primary Root CA - G2" + "thawte Primary Root CA - G3" + "VeriSign Class 3 Public Primary Certification Authority - G4" + "VeriSign Class 3 Public Primary Certification Authority - G5" + "VeriSign Universal Root Certification Authority" NOTE: due to bug #743339, CA certificates added back in this version won't automatically be trusted again on upgrade. Affected users may need to reconfigure the package to restore the desired state. For Debian 9 stretch, this problem has been fixed in version 20200601~deb9u2. We recommend that you upgrade your ca-certificates packages. For the detailed security status of ca-certificates please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ca-certificates Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2593-2 regarding ca-certificates whitelistupdate for root trust anchors.. Debian Security Update, CA Certificates, Certification Authority. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 13, 2021 Important Debian LTS
202

openSUSE 11.4 and 11.3: 2011:0935-1 Important: Mozilla NSS Patch

An update that contains security fixes can now be An update that contains security fixes can now be An update that contains security fixes can now be installed. It includes one version update. installed. It includes one version update.. openSUSE Security Update: mozilla-nss: Update to 3.12.11 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2011:0935-1 Rating: important References: #712224 Affected Products: openSUSE 11.4 openSUSE 11.3 ______________________________________________________________________________ An update that contains security fixes can now be installed. It includes one version update. Description: The mozilla NSS libraries were updated to 3.12.11 to align with newer Mozilla seamonkey and Firefox releases. Interesting changes are: - blacklisting malicious root certificates - several bugfixes Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4: zypper in -t patch libfreebl3-5023 - openSUSE 11.3: zypper in -t patch libfreebl3-5023 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4 (i586 x86_64) [New Version: 3.12.11]: libfreebl3-3.12.11-1.3.1 libsoftokn3-3.12.11-1.3.1 mozilla-nss-3.12.11-1.3.1 mozilla-nss-certs-3.12.11-1.3.1 mozilla-nss-devel-3.12.11-1.3.1 mozilla-nss-sysinit-3.12.11-1.3.1 mozilla-nss-tools-3.12.11-1.3.1 - openSUSE 11.4 (x86_64) [New Version: 3.12.11]: libfreebl3-32bit-3.12.11-1.3.1 libsoftokn3-32bit-3.12.11-1.3.1 mozilla-nss-32bit-3.12.11-1.3.1 mozilla-nss-certs-32bit-3.12.11-1.3.1 mozilla-nss-sysinit-32bit-3.12.11-1.3.1 - openSUSE 11.3 (i586 x86_64) [New Version: 3.12.11]: libfreebl3-3.12.11-1.2.1 libsoftokn3-3.12.11-1.2.1 mozilla-nss-3.12.11-1.2.1 mozilla-nss-certs-3.12.11-1.2.1 mozilla-nss-devel-3.12.11-1.2.1 mozilla-nss-sysinit-3.12.11-1.2.1 mozilla-nss-tools-3.12.11-1.2.1 - openSUSE 11.3 (x86_64) [New Version: 3.12.11]: libfreebl3-32bit-3.12.11-1.2.1 libsoftokn3-32bit-3.12.11-1.2.1 mozilla-nss-32bit-3.12.11-1.2.1 mozilla-nss-certs-32bit-3.12.11-1.2.1 mozilla-nss-sysinit-32bit-3.12.11-1.2.1 References: . OpenSUSE has released a security patch to tackle vulnerabilities within Mozilla NSS, implementing measures to revoke problematic root certificates.. openSUSE Security, Mozilla NSS Update, Security Patches. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 23, 2011 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here