Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
217

Oracle Linux 9 ELSA-2024-0108 moderate: nss timing attack

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-0108 https://linux.oracle.com/errata/ELSA-2024-0108.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: nspr-4.35.0-4.el9_3.i686.rpm nspr-4.35.0-4.el9_3.x86_64.rpm nspr-devel-4.35.0-4.el9_3.i686.rpm nspr-devel-4.35.0-4.el9_3.x86_64.rpm nss-3.90.0-4.el9_3.i686.rpm nss-3.90.0-4.el9_3.x86_64.rpm nss-devel-3.90.0-4.el9_3.i686.rpm nss-devel-3.90.0-4.el9_3.x86_64.rpm nss-softokn-3.90.0-4.el9_3.i686.rpm nss-softokn-3.90.0-4.el9_3.x86_64.rpm nss-softokn-devel-3.90.0-4.el9_3.i686.rpm nss-softokn-devel-3.90.0-4.el9_3.x86_64.rpm nss-softokn-freebl-3.90.0-4.el9_3.i686.rpm nss-softokn-freebl-3.90.0-4.el9_3.x86_64.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.i686.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.x86_64.rpm nss-sysinit-3.90.0-4.el9_3.x86_64.rpm nss-tools-3.90.0-4.el9_3.x86_64.rpm nss-util-3.90.0-4.el9_3.i686.rpm nss-util-3.90.0-4.el9_3.x86_64.rpm nss-util-devel-3.90.0-4.el9_3.i686.rpm nss-util-devel-3.90.0-4.el9_3.x86_64.rpm aarch64: nspr-4.35.0-4.el9_3.aarch64.rpm nspr-devel-4.35.0-4.el9_3.aarch64.rpm nss-3.90.0-4.el9_3.aarch64.rpm nss-devel-3.90.0-4.el9_3.aarch64.rpm nss-softokn-3.90.0-4.el9_3.aarch64.rpm nss-softokn-devel-3.90.0-4.el9_3.aarch64.rpm nss-softokn-freebl-3.90.0-4.el9_3.aarch64.rpm nss-softokn-freebl-devel-3.90.0-4.el9_3.aarch64.rpm nss-sysinit-3.90.0-4.el9_3.aarch64.rpm nss-tools-3.90.0-4.el9_3.aarch64.rpm nss-util-3.90.0-4.el9_3.aarch64.rpm nss-util-devel-3.90.0-4.el9_3.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol9/SRPMS-updates//nss-3.90.0-4.el9_3.src.rpm Related CVEs: CVE-2023-5388 Description of changes: [3.90.0-4] - CVE-2023-5388 nss: timing attack against RSA decryption. Make the final blinding multmod constant time. _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata .Oracle Linux 9 update addresses NSS timing attack vulnerability and enhances system protection.. Oracle Linux Security,NSS Update,Timing Attack. . LinuxSecurity.com Team

Calendar 2 Jan 13, 2024 Oracle
203

Mageia: 2023-0067 Critical: GnuTLS Timing Attack on RSA Decryption

Timing side channel in the RSA decryption implementation of the GNU TLS library. (CVE-2023-0361) References: - https://bugs.mageia.org/show_bug.cgi?id=31558 . MGASA-2023-0067 - Updated gnutls packages fix security vulnerability Publication date: 27 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0067.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-0361 Timing side channel in the RSA decryption implementation of the GNU TLS library. (CVE-2023-0361) References: - https://bugs.mageia.org/show_bug.cgi?id=31558 - https://lists.debian.org/debian-security-announce/2023/msg00038.html - https://lists.debian.org/debian-lts-announce/2023/02/msg00015.html - https://www.cve.org/CVERecord?id=CVE-2023-0361 SRPMS: - 8/core/gnutls-3.6.15-3.4.mga8 . The latest gnutls updates in Mageia resolve a critical timing attack vulnerability connected to RSA decryption. Find out more here.. timing Attack, GnuTLS Update, Mageia Security Fix, RSA Decryption Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 27, 2023 Critical Mageia
203

Mageia 8 MGASA-2022-0274 Moderate: Python-M2crypto Timing Attack

Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html . MGASA-2022-0274 - Updated python-m2crypto packages fix security vulnerability Publication date: 05 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0274.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-25657 Bleichenbacher timing attacks in the RSA decryption API (CVE-2020-25657) References: - https://bugs.mageia.org/show_bug.cgi?id=30661 - https://lists.suse.com/pipermail/sle-security-updates/2022-July/011631.html - - https://www.cve.org/CVERecord?id=CVE-2020-25657 SRPMS: - 8/core/python-m2crypto-0.38.0-4.mga8 . Recent updates to the python-m2crypto packages have effectively mitigated the Bleichenbacher timing attacks impacting the RSA decryption API on Mageia 8.. Bleichenbacher Attack, Python Security Update, Mageia Advisory. . LinuxSecurity.com Team

Calendar 2 Aug 05, 2022 Mageia
203

Mageia 6: MGASA-2019-0103 Moderate: gnutls Padding Oracle Attack

A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server. (CVE-2018-16868) . MGASA-2019-0103 - Updated gnutls packages fix security vulnerability Publication date: 07 Mar 2019 URL: https://advisories.mageia.org/MGASA-2019-0103.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16868 A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls handles verification of RSA decrypted PKCS#1 v1.5 data. An attacker who is able to run process on the same physical core as the victim process, could use this to extract plaintext or in some cases downgrade any TLS connections to a vulnerable server. (CVE-2018-16868) References: - https://bugs.mageia.org/show_bug.cgi?id=24066 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/INZ7O52ANE3RPKUWDI3TKPVVHQNKHVKY/ - https://www.cve.org/CVERecord?id=CVE-2018-16868 SRPMS: - 6/core/gnutls-3.5.13-1.2.mga6 . MGASA-2019-0103 - Updated gnutls packages fix security vulnerability Publication date: 07 Mar 2019 U. bleichenbacher, side-channel, based, padding, oracle, attack, found, gnutls, handles. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 07, 2019 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here