Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian LTS: DLA-4099-1: flatpak Security Advisory Updates

Access to files outside sandbox has been fixed in Flatpak, an application deployment framework for desktop apps. As a prerequisite for the fix, the bubblewrap package has also . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4099-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk March 31, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : flatpak Version : 1.10.8-0+deb11u3 CVE ID : CVE-2024-42472 Debian Bug : 1082927 Access to files outside sandbox has been fixed in Flatpak, an application deployment framework for desktop apps. As a prerequisite for the fix, the bubblewrap package has also been updated. For Debian 11 bullseye, this problem has been fixed in version 1.10.8-0+deb11u3. We recommend that you upgrade your flatpak packages. For the detailed security status of flatpak please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/flatpak Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Access to files outside the sandbox in Flatpak fixed in Debian LTS security advisory DLA-4099-1.. files, outside, sandbox, flatpak, application, deployment, framework. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 31, 2025 Critical Debian LTS
89

Fedora 40 Advisory: Firefox 125.0 Update with Sandboxing Feature

New upstream release (125.0) New upstream release (124.0.2). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-c6a1d4e0ec 2024-04-19 21:20:20.799642 -------------------------------------------------------------------------------- Name : firefox Product : Fedora 40 Version : 125.0 Release : 1.fc40 URL : https://www.firefox.com/en-US/?redirect_source=mozilla-org Summary : Mozilla Firefox Web browser Description : Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability. -------------------------------------------------------------------------------- Update Information: New upstream release (125.0) New upstream release (124.0.2) -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 9 2024 Martin Stransky - 125.0-1 - Updated to 125.0 * Thu Apr 4 2024 Martin Stransky - 124.0.2-2 - Updated to 124.0.2 * Thu Mar 28 2024 Jan Horak - 124.0.1-4 - Enable rlbox sandboxing -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-c6a1d4e0ec' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . The Fedora 40 release ushers in substantial security upgrades for Firefox, addressing critical vulnerabilities and enhancing overall stability, privacy, and performance.. Fedora Updates, Firefox Security, Software Improvements, Open Source Browser, Sandboxing Features. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 19, 2024 Critical Fedora
87

Debian: DSA-5107-1 Critical: php-twig Sandboxing Code Execution Risk

Marlon Starkloff discovered that twig, a template engine for PHP, did not correctly enforce sandboxing. This would allow a malicious user to execute arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5107-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond March 24, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : php-twig CVE ID : CVE-2022-23614 Marlon Starkloff discovered that twig, a template engine for PHP, did not correctly enforce sandboxing. This would allow a malicious user to execute arbitrary code. For the stable distribution (bullseye), this problem has been fixed in version 2.14.3-1+deb11u1. We recommend that you upgrade your php-twig packages. For the detailed security status of php-twig please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/php-twig Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . New release for php-twig resolves the sandbox vulnerability, enabling secure code execution in Debian's stable version.. php-twig Update, Debian Security Advisory, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 24, 2022 Critical Debian
87

Debian DSA-4539-2: OpenSSH Sandboxing Fix for Older Kernels

A change introduced in openssl 1.1.1d (which got released as DSA 4539-1) requires sandboxing features which are not available in Linux kernels before 3.19, resulting in OpenSSH rejecting connection attempts if running on an old kernel. This does not affect Linux kernels shipped in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4539-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 07, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssh Debian Bug : 941663 A change introduced in openssl 1.1.1d (which got released as DSA 4539-1) requires sandboxing features which are not available in Linux kernels before 3.19, resulting in OpenSSH rejecting connection attempts if running on an old kernel. This does not affect Linux kernels shipped in Debian oldstable/stable, but may affect buster systems which are running on an older kernel. For the stable distribution (buster), this problem has been fixed in version 1:7.9p1-10+deb10u1. We recommend that you upgrade your openssh packages. For the detailed security status of openssh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/openssh Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-4539-3 resolves vulnerabilities in OpenSSH related to sandboxing in legacy Linux kernels, prompting users to update their systems.. Debian OpenSSH Update, Security Advisory, Debian Security, Linux Kernel Sandboxing. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 07, 2019 Important Debian
89

Fedora 24: 2016-631737a49a Moderate: Tracker Sandboxing Improvement

This update adds security sandboxing to tracker-extract.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-631737a49a 2016-12-29 04:39:04.476415 -------------------------------------------------------------------------------- Name : tracker Product : Fedora 24 Version : 1.8.2 Release : 1.fc24 URL : Summary : Desktop-neutral search tool and indexer Description : Tracker is a powerful desktop-neutral first class object database, tag/metadata database, search tool and indexer. It consists of a common object database that allows entities to have an almost infinite number of properties, metadata (both embedded/harvested as well as user definable), a comprehensive database of keywords/tags and links to other entities. It provides additional features for file based objects including context linking and audit trails for a file object. It has the ability to index, store, harvest metadata. retrieve and search all types of files and other first class objects -------------------------------------------------------------------------------- Update Information: This update adds security sandboxing to tracker-extract. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tracker' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This enhancement brings advanced isolationmeasures for tracker-extract and improves overall system security for users of Fedora.. tracker extract, Fedora update, security sandboxing, software security, desktop indexing. . LinuxSecurity.com Team

Calendar 2 Dec 29, 2016 Fedora
200

SciLinux Advisory: SLSA-2013:1823-1 Critical: Thunderbird XSS Risk

Important: thunderbird security update. Date: Thu, 12 Dec 2013 09:38:38 -0600 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: thunderbird on SL5.x, i386/x86_64 MIME-Version: 1.0 Synopsis: Important: thunderbird security update Advisory ID: SLSA-2013:1823-1 Issue Date: 2013-12-11 CVE Numbers: CVE-2013-5609 CVE-2013-5612 CVE-2013-5614 CVE-2013-5616 CVE-2013-5618 CVE-2013-6671 CVE-2013-5613 -- Several flaws were found in the processing of malformed content. Malicious content could cause Thunderbird to crash or, potentially, execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2013-5609, CVE-2013-5616, CVE-2013-5618, CVE-2013-6671, CVE-2013-5613) A flaw was found in the way Thunderbird rendered web content with missing character encoding information. An attacker could use this flaw to possibly bypass same-origin inheritance and perform cross site-scripting (XSS) attacks. (CVE-2013-5612) It was found that certain malicious web content could bypass restrictions applied by sandboxed iframes. An attacker could combine this flaw with other vulnerabilities to execute arbitrary code with the privileges of the user running Thunderbird. (CVE-2013-5614) Note: All of the above issues cannot be exploited by a specially crafted HTML mail message as JavaScript is disabled by default for mail messages. They could be exploited another way in Thunderbird, for example, when viewing the full remote content of an RSS feed. After installing the update, Thunderbird must be restarted for the changes to take effect. -- SL5 x86_64 thunderbird-24.2.0-2.el5_10.x86_64.rpm thunderbird-debuginfo-24.2.0-2.el5_10.x86_64.rpm i386 thunderbird-24.2.0-2.el5_10.i386.rpm thunderbird-debuginfo-24.2.0-2.el5_10.i386.rpm - Scientific Linux Development Team . Significant Thunderbird patch rectifies major vulnerabilities, facilitating code execution through improperly formatted data in CentOS.. Thunderbird Update,Scientific Linux Security, Malicious Code, Email Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 12, 2013 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here