Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SUSE: 2022:1528-1 Important: MiTM Security Fixes for Client Tools

An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security Beta update for SUSE Manager Client Tools ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:1528-1 Rating: important References: #1197417 #1197533 #1197637 #1197689 Cross-References: CVE-2022-22934 CVE-2022-22935 CVE-2022-22936 CVE-2022-22941 CVSS scores: CVE-2022-22934 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-22934 (SUSE): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-22935 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-22935 (SUSE): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-22936 (NVD) : 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2022-22936 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2022-22941 (NVD) : 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-22941 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Manager Debian 10-CLIENT-TOOLS-BETA ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update fixes the following issues: Security fixes for salt (bsc#1197417): - CVE-2022-22935: Sign authentication replies to prevent MiTM. - CVE-2022-22934: Sign pillar data to prevent MiTM attacks. - CVE-2022-22936: Prevent job and fileserver replays. - CVE-2022-22941: Fixed targeting bug, especially visible when using syndic and user auth. Other non security fixes: salt: - Prevent data pollution between actions processed at the same time (bsc#1197637) - Fix regression preventing bootstrapping new clients caused by redundant dependency on psutil(bsc#1197533) - Fixes for Python 3.10 - Fix salt-ssh opts poisoning (bsc#1197637) spacecmd: - Version 4.3.10-1 * parse boolean paramaters correctly (bsc#1197689) * Add parameter to set containerized proxy SSH port Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Debian 10-CLIENT-TOOLS-BETA: zypper in -t patch SUSE-Debian-10-CLIENT-TOOLS-BETA-2022-1528=1 Package List: - SUSE Manager Debian 10-CLIENT-TOOLS-BETA (all): salt-common-3004+ds-1+2.39.1 salt-minion-3004+ds-1+2.39.1 spacecmd-4.3.10-2.32.1 References: https://www.suse.com/security/cve/CVE-2022-22934.html https://www.suse.com/security/cve/CVE-2022-22935.html https://www.suse.com/security/cve/CVE-2022-22936.html https://www.suse.com/security/cve/CVE-2022-22941.html https://bugzilla.suse.com/1197417 https://bugzilla.suse.com/1197533 https://bugzilla.suse.com/1197637 https://bugzilla.suse.com/1197689 . Critical patch resolves Man-in-the-Middle vulnerabilities in SUSE Manager Client Applications, highlighting key update information.. SUSE Manager Client Tools, Security Update, MiTM Risks, Patch Instructions, Salt Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 04, 2022 Important SuSE
100

SUSE: 2021:2105-1 Critical: Salt Update Fixes Major Security Issues

An update that solves 7 vulnerabilities, contains three features and has three fixes is now available. . SUSE Security Update: Security update for salt ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:2105-1 Rating: critical References: #1171257 #1176293 #1179831 #1181368 #1182281 #1182293 #1182382 #1185092 #1185281 #1186674 ECO-3212 SLE-18028 SLE-18033 Cross-References: CVE-2018-15750 CVE-2018-15751 CVE-2020-11651 CVE-2020-11652 CVE-2020-25592 CVE-2021-25315 CVE-2021-31607 CVSS scores: CVE-2018-15750 (NVD) : 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2018-15750 (SUSE): 8.7 CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N CVE-2018-15751 (NVD) : 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2018-15751 (SUSE): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2020-11651 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2020-11651 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2020-11652 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2020-11652 (SUSE): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2020-25592 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2020-25592 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-25315 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-25315 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE-2021-31607 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-31607 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Manager Server 4.0 SUSEManager Retail Branch Server 4.0 SUSE Manager Proxy 4.0 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that solves 7 vulnerabilities, contains three features and has three fixes is now available. Description: This update for salt fixes the following issues: Update to Salt release version 3002.2 (jsc#ECO-3212, jsc#SLE-18033, jsc#SLE-18028) - Check if dpkgnotify is executable (bsc#1186674) - Drop support for Python2. Obsoletes `python2-salt` package (jsc#SLE-18028) - virt module updates * network: handle missing ipv4 netmask attribute * more network support * PCI/USB host devices passthrough support - Set distro requirement to oldest supported version in requirements/base.txt - Bring missing part of async batch implementation back (bsc#1182382, CVE-2021-25315) - Always require python3-distro (bsc#1182293) - Remove deprecated warning that breaks minion execution when "server_id_use_crc" opts is missing - Fix pkg states when DEB package has "all" arch - Do not force beacons configuration to be a list. - Remove msgpack < 1.0.0 from base requirements (bsc#1176293) - msgpack support for version > = 1.0.0 (bsc#1171257) - Fix issue parsing errors in ansiblegate state module - Prevent command injection in the snapper module (bsc#1185281, CVE-2021-31607) - transactional_update: detect recursion in the executor - Add subpackage salt-transactional-update (jsc#SLE-18033) - Remove duplicate directories from specfile -Improvements on "ansiblegate" module (bsc#1185092): * New methods: ansible.targets / ansible.discover_playbooks - Add support for Alibaba Cloud Linux 2 (Aliyun Linux) - Regression fix of salt-ssh on processing targets - Update target fix for salt-ssh and avoiding race condition on salt-ssh event processing (bsc#1179831, bsc#1182281) - Add notify beacon for Debian/Ubuntu systems - Fix zmq bug that causes salt-call to freeze (bsc#1181368) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.0-2021-2105=1 - SUSE Manager Retail Branch Server 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.0-2021-2105=1 - SUSE Manager Proxy 4.0: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.0-2021-2105=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2021-2105=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2021-2105=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2021-2105=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2021-2105=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2021-2105=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2021-2105=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE ManagerServer 4.0 (ppc64le s390x x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Manager Server 4.0 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Manager Retail Branch Server 4.0 (x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Manager Retail Branch Server 4.0 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Manager Proxy 4.0 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Manager Proxy 4.0 (x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 - SUSE Enterprise Storage 6 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE CaaS Platform 4.0 (noarch): salt-bash-completion-3002.2-37.1 salt-fish-completion-3002.2-37.1 salt-zsh-completion-3002.2-37.1 - SUSE CaaS Platform 4.0 (x86_64): python3-salt-3002.2-37.1 salt-3002.2-37.1 salt-api-3002.2-37.1 salt-cloud-3002.2-37.1 salt-doc-3002.2-37.1 salt-master-3002.2-37.1 salt-minion-3002.2-37.1 salt-proxy-3002.2-37.1 salt-ssh-3002.2-37.1 salt-standalone-formulas-configuration-3002.2-37.1 salt-syndic-3002.2-37.1 salt-transactional-update-3002.2-37.1 References: https://www.suse.com/security/cve/CVE-2018-15750.html https://www.suse.com/security/cve/CVE-2018-15751.html https://www.suse.com/security/cve/CVE-2020-11651.html https://www.suse.com/security/cve/CVE-2020-11652.html https://www.suse.com/security/cve/CVE-2020-25592.html https://www.suse.com/security/cve/CVE-2021-25315.html https://www.suse.com/security/cve/CVE-2021-31607.html https://bugzilla.suse.com/1171257 https://bugzilla.suse.com/1176293 https://bugzilla.suse.com/1179831 https://bugzilla.suse.com/1181368 https://bugzilla.suse.com/1182281 https://bugzilla.suse.com/1182293 https://bugzilla.suse.com/1182382 https://bugzilla.suse.com/1185092 https://bugzilla.suse.com/1185281 https://bugzilla.suse.com/1186674 . SUSE's recent patch for salt addresses vital vulnerabilities across eight concerns and introduces enhancements aimed at elevating efficiency.. SUSE Salt Update, Security Issues, Critical Fixes, Salt Enhancements, SUSE CaaS Platform. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 21, 2021 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here