Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1,211 articles for you...
200

Scientific Linux SL7 SLSA-2023:6193 Moderate: Thunderbird Update

This update upgrades Thunderbird to version 115.4.1. --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6193 SL7 srpm thunderbird-0:115.4.1-1.el7_9.src x86_64 thunderbird-0:115.4.1-1.el7_9.x86_64 - Scientific Linux Development Team . Red Hat Security Advisory: thunderbird security update Advisory ID: SLSA-2023:6193 Issue Date: 2023-10-30 CVE Numbers: None -- Mozilla Thunderbird is a standalone mail and newsgroup client. This update upgrades Thunderbird to version 115.4.1. Security Fix(es): --- This content is derived from https://access.redhat.com/errata/RHSA-2023:6193 -- SL7 srpm thunderbird-0:115.4.1-1.el7_9.src x86_64 thunderbird-0:115.4.1-1.el7_9.x86_64 - Scientific Linux Development Team . Upgrade Thunderbird to version 115.4.1 on Scientific Linux to bolster email security measures.. thunderbird security update, scientific linux advisory, mail client upgrade. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2023 Scientific Linux
200

Scientific Linux 7: SLSA-2023:5477 Critical Firefox Update and Fixes

This update upgrades Firefox to version 115.3.1 ESR. * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-20 23-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 1 15.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE- [More...] . Red Hat Security Advisory: firefox security update Advisory ID: SLSA-2023:5477 Issue Date: 2023-10-05 CVE Numbers: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 -- Mozilla Firefox is an open-source web browser, designed for standards compliance, performance, and portability. This update upgrades Firefox to version 115.3.1 ESR. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) --- This content is derived from https://access.redhat.com/errata/RHSA-2023:5477 -- SL7 srpm firefox-0:115.3.1-1.el7_9.src x86_64 firefox-0:115.3.1-1.el7_9.x86_64 i386 firefox-0:115.3.1-1.el7_9.i686 - Scientific Linux Development Team . Red Hat Security Bulletin for Firefox enhancement on SL7 tackling severe memory integrity vulnerabilities and buffer overflow risks.. firefox update, critical vulnerabilities, scientific linux. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 09, 2023 Critical Scientific Linux
200

Scientific Linux 7.x SLSA-2023-5477-1 Critical: Firefox Heap Overflow Fix

This update upgrades Firefox to version 115.3.1 ESR. * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE- [More...]. Synopsis: Important: firefox security update Advisory ID: SLSA-2023:5477-1 Issue Date: 2023-10-05 CVE Numbers: CVE-2023-3600 CVE-2023-5169 CVE-2023-5171 CVE-2023-5176 CVE-2023-5217 -- This update upgrades Firefox to version 115.3.1 ESR. Security Fix(es): * firefox: use-after-free in workers (CVE-2023-3600) * Mozilla: Out-of-bounds write in PathOps (CVE-2023-5169) * Mozilla: Use-after-free in Ion Compiler (CVE-2023-5171) * Mozilla: Memory safety bugs fixed in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3 (CVE-2023-5176) * libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 firefox-115.3.1-1.el7_9.x86_64.rpm firefox-debuginfo-115.3.1-1.el7_9.x86_64.rpm firefox-115.3.1-1.el7_9.i686.rpm firefox-debuginfo-115.3.1-1.el7_9.i686.rpm - Scientific Linux Development Team . Urgent patch released for Firefox tackling major security vulnerabilities, impacting editions within Scientific Linux 7.x systems.. Firefox Update, Scientific Linux, Mozilla Issues, Security Advisory, Critical Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 10, 2023 Critical Scientific Linux
200

Scientific Linux 7 SLSA-2023-5461-1 Critical: ImageMagick DoS Issue

ImageMagick: Division by zero in ReadEnhMetaFile lead to DoS (CVE-2021-40211) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 ImageMagick-6.9.10.68-7.el7_9.i686.rpm ImageMagick-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-6 [More...]. Synopsis: Important: ImageMagick security update Advisory ID: SLSA-2023:5461-1 Issue Date: 2023-10-05 CVE Numbers: CVE-2021-40211 -- Security Fix(es): * ImageMagick: Division by zero in ReadEnhMetaFile lead to DoS (CVE-2021-40211) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 ImageMagick-6.9.10.68-7.el7_9.i686.rpm ImageMagick-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-debuginfo-6.9.10.68-7.el7_9.i686.rpm ImageMagick-debuginfo-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-c++-devel-6.9.10.68-7.el7_9.i686.rpm ImageMagick-c++-devel-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-devel-6.9.10.68-7.el7_9.i686.rpm ImageMagick-devel-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-doc-6.9.10.68-7.el7_9.x86_64.rpm ImageMagick-perl-6.9.10.68-7.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical patch released for ImageMagick resolves a denial-of-service vulnerability affecting Scientific Linux 7.x x86_64 environments.. ImageMagick, DoS Issue, Security Update, Scientific Linux, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 06, 2023 Critical Scientific Linux
200

Scientific Linux SL7 SLSA-2023:5191-1 Important: Thunderbird Heap Overflow

This update upgrades Thunderbird to version 102.15.1. * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm - Scientific Linux D [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:5191-1 Issue Date: 2023-09-19 CVE Numbers: CVE-2023-4863 -- This update upgrades Thunderbird to version 102.15.1. Security Fix(es): * libwebp: Heap buffer overflow in WebP Codec (CVE-2023-4863) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.15.1-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.1-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Significant Thunderbird upgrade for Scientific Linux addresses major buffer overflow vulnerability within WebP Codec.. Thunderbird Update, Scientific Linux Security, Buffer Overflow, Software Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 19, 2023 Important Scientific Linux
200

Scientific Linux 7: SLSA-2023-4945-1 Critical: Thunderbird IPC Issues

This update upgrades Thunderbird to version 102.15.0. * Mozilla: Memory corruption in IPC CanvasTranslator (CVE-2023-4573) * Mozilla: Memory corruption in IPC ColorPickerShownCallback (CVE-2023-4574) * Mozilla: Memory corruption in IPC FilePickerShownCallback (CVE-2023-4575) * Mozilla: Memory corruption in JIT UpdateRegExpStatics (CVE-2023-4577) * Mozilla: Memory safety bugs fixed in Firefo [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2023:4945-1 Issue Date: 2023-09-05 CVE Numbers: CVE-2023-4573 CVE-2023-4574 CVE-2023-4575 CVE-2023-4577 CVE-2023-4051 CVE-2023-4578 CVE-2023-4053 CVE-2023-4580 CVE-2023-4581 CVE-2023-4583 CVE-2023-4584 CVE-2023-4585 -- This update upgrades Thunderbird to version 102.15.0. Security Fix(es): * Mozilla: Memory corruption in IPC CanvasTranslator (CVE-2023-4573) * Mozilla: Memory corruption in IPC ColorPickerShownCallback (CVE-2023-4574) * Mozilla: Memory corruption in IPC FilePickerShownCallback (CVE-2023-4575) * Mozilla: Memory corruption in JIT UpdateRegExpStatics (CVE-2023-4577) * Mozilla: Memory safety bugs fixed in Firefox 117, Firefox ESR 102.15, Firefox ESR 115.2, Thunderbird 102.15, and Thunderbird 115.2 (CVE-2023-4584) * Mozilla: Memory safety bugs fixed in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2 (CVE-2023-4585) * Mozilla: Full screen notification obscured by file open dialog (CVE-2023-4051) * Mozilla: Full screen notification obscured by external program (CVE-2023-4053) * Mozilla: Error reporting methods in SpiderMonkey could have triggered an Out of Memory Exception (CVE-2023-4578) * Mozilla: Push notifications saved to disk unencrypted (CVE-2023-4580) * Mozilla: XLL file extensions were downloadable without warnings (CVE-2023-4581) * Mozilla: Browsing Context potentially notcleared when closing Private Window (CVE-2023-4583) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 thunderbird-102.15.0-1.el7_9.x86_64.rpm thunderbird-debuginfo-102.15.0-1.el7_9.x86_64.rpm - Scientific Linux Development Team . Important Thunderbird patch resolves various memory security vulnerabilities identified in Mozilla applications; recommended for SL7.x users.. Scientific Linux, Thunderbird, Memory Issues, Mozilla, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 05, 2023 Critical Scientific Linux
200

Urgent Security Update: Scientific Linux 7.0 OpenSSH RCE Vulnerability

openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE SL7 x86_64 openssh-7.4p1-23.el7_9.x86_64.rpm openssh-askpass-7.4p1-23.el7_9.x86_64.rpm openssh-clients-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1 [More...]. Synopsis: Important: openssh security update Advisory ID: SLSA-2023:4382-1 Issue Date: 2023-08-03 CVE Numbers: CVE-2023-38408 -- Security Fix(es): * openssh: Remote code execution in ssh-agent PKCS#11 support (CVE-2023-38408) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE -- SL7 x86_64 openssh-7.4p1-23.el7_9.x86_64.rpm openssh-askpass-7.4p1-23.el7_9.x86_64.rpm openssh-clients-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1-23.el7_9.x86_64.rpm openssh-keycat-7.4p1-23.el7_9.x86_64.rpm openssh-server-7.4p1-23.el7_9.x86_64.rpm openssh-cavs-7.4p1-23.el7_9.x86_64.rpm openssh-debuginfo-7.4p1-23.el7_9.i686.rpm openssh-ldap-7.4p1-23.el7_9.x86_64.rpm openssh-server-sysvinit-7.4p1-23.el7_9.x86_64.rpm pam_ssh_agent_auth-0.10.3-2.23.el7_9.i686.rpm pam_ssh_agent_auth-0.10.3-2.23.el7_9.x86_64.rpm - Scientific Linux Development Team . Critical security patch for OpenSSH mitigating remote execution vulnerabilities in SSH, identified by Advisory ID SLSA-2023:4382-2.. openssh update, remote code execution, scientific linux advisory, ssh-agent security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 03, 2023 Important Scientific Linux
200

Scientific Linux 7.x: SLSA-2023:4166-1 Moderate: OpenJDK Update

OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream releas [More...]. Synopsis: Moderate: java-1.8.0-openjdk security and bug fix update Advisory ID: SLSA-2023:4166-1 Issue Date: 2023-07-24 CVE Numbers: CVE-2023-22045 CVE-2023-22049 -- Security Fix(es): * OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) (CVE-2023-22049) * OpenJDK: array indexing integer overflow issue (8304468) (CVE-2023-22045) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE Bug Fix(es): * Prepare for the next quarterly OpenJDK upstream release (2023-07, 8u382) -- SL7 x86_64 java-1.8.0-openjdk-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.382.b05-1.el7_9.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.382.b05-1.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.382.b05-1.el7_9.x86_64.rpm noarch java-1.8.0-openjdk-javadoc-1.8.0.382.b05-1.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.382.b05-1.el7_9.noarch.rpm - Scientific Linux Development Team . Recent OpenJDK enhancements focused on URI management and indexing anomalies on Scientific Linux 7.x platforms. Explore for further insights.. OpenJDK Update, Java Fix, Scientific Linux Security, Security Update. . LinuxSecurity.com Team

Calendar%202 Jul 24, 2023 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200