Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
87

Debian: DSA-5436-1 Critical Update for HSQLDB Script Injection Risk

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5436-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany June 21, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hsqldb1.8.0 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For the oldstable distribution (bullseye), this problem has been fixed in version 1.8.0.10+dfsg-10+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 1.8.0.10+dfsg-11+deb12u1. We recommend that you upgrade your hsqldb1.8.0 packages. For the detailed security status of hsqldb1.8.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb1.8.0 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A crucial patch addressesHSQLDB weaknesses that allow harmful input execution, impacting Debian platforms.. HSQLDB Update, Debian Security, Script Injection, Database Issue, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 21, 2023 Critical Debian
203

Mageia 8: 2023-0103 Urgent: Liferea Remote Code Execution Vulnerability

Remote code execution on feed enrichment. If "Extract full content from HTML5 and Google AMP" has been enabled for one or more feed subscriptions it is possible for a an attacker to inject a script command that runs with user priveleges. (CVE-2023-1350) . MGASA-2023-0103 - Updated liferea packages fix security vulnerability Publication date: 18 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0103.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1350 Remote code execution on feed enrichment. If "Extract full content from HTML5 and Google AMP" has been enabled for one or more feed subscriptions it is possible for a an attacker to inject a script command that runs with user priveleges. (CVE-2023-1350) References: - https://bugs.mageia.org/show_bug.cgi?id=31664 - https://github.com/lwindolf/liferea/releases/tag/v1.12.10 - https://www.cve.org/CVERecord?id=CVE-2023-1350 SRPMS: - 8/core/liferea-1.12.10-1.1.mga8 . Essential liferea security patch mitigates remote code execution threat caused by script infiltration, affecting user permissions.. Mageia Update, Remote Code Execution, Liferea Security, Script Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2023 Critical Mageia
203

Mageia 8 MGASA-2023-0061 Critical: HTML Injection in Python-Twisted

When the host header does not match a configured host twisted.web.vhost.NameVirtualHost will return a NoResource resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. (CVE-2022-39348) . MGASA-2023-0061 - Updated python-twisted packages fix security vulnerability Publication date: 27 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0061.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-39348 When the host header does not match a configured host twisted.web.vhost.NameVirtualHost will return a NoResource resource which renders the Host header unescaped into the 404 response allowing HTML and script injection. (CVE-2022-39348) References: - https://bugs.mageia.org/show_bug.cgi?id=31140 - https://lists.suse.com/pipermail/sle-security-updates/2022-November/012932.html - - https://lists.debian.org/debian-lts-announce/2022/11/msg00038.html - https://www.cve.org/CVERecord?id=CVE-2022-39348 SRPMS: - 8/core/python-twisted-22.10.0-1.mga8 . MGASA-2023-0072 releases an update for python-flask, addressing severe vulnerabilities in configuration handling, strengthening application integrity.. Python Twisted Injection, Mageia Security Update, HTML Injection Prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 27, 2023 Critical Mageia
203

Mageia: 2021-0595 Moderate: Python-lxml HTML Cleaner Risk Fix

HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818) References: - https://bugs.mageia.org/show_bug.cgi?id=29817 . MGASA-2021-0595 - Updated python-lxml packages fix security vulnerability Publication date: 30 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0595.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43818 HTML Cleaner allows crafted and SVG embedded scripts to pass through (CVE-2021-43818) References: - https://bugs.mageia.org/show_bug.cgi?id=29817 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/ZQ4SPKJX3RRJK4UWA6FXCRHD2TVRQI44/ - https://www.cve.org/CVERecord?id=CVE-2021-43818 SRPMS: - 8/core/python-lxml-4.6.5-1.mga8 . Revised python-lxml libraries address security vulnerabilities. Mageia 8 encountered threats from malicious scripts through HTML Cleaner.. PythonLxml, SecurityAdvisory, Mageia, ScriptInjection, HTMLCleaner. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2021 Mageia
197

Debian LTS: DLA-2371-1 Moderate: WordPress Multiple Threats Addressed

Multiple vulnerabilities were discovered in Wordpress, a popular content management framework. CVE-2019-17670 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2371-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ September 11, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : wordpress Version : 4.7.18+dfsg-1+deb9u1 CVE ID : CVE-2019-17670 CVE-2020-4047 CVE-2020-4048 CVE-2020-4049 CVE-2020-4050 Debian Bug : 942459 962685 Multiple vulnerabilities were discovered in Wordpress, a popular content management framework. CVE-2019-17670 WordPress has a Server Side Request Forgery (SSRF) vulnerability because Windows paths are mishandled during certain validation of relative URLs. CVE-2020-4047 Authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. CVE-2020-4048 Due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. CVE-2020-4049 When uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. CVE-2020-4050 Misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. Additionally, this upload ensures latest comments can only be viewed from public posts, and fixes back the user activation procedure. For Debian 9 stretch, theseproblems have been fixed in version 4.7.18+dfsg-1+deb9u1. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/wordpress Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2373-1 addresses security issues in Joomla, mitigating risks such as XSS and command execution vulnerabilities.. Debian Updates, WordPress Security, SSRF Risk, Script Injection Fixes. . LinuxSecurity.com Team

Calendar%202 Sep 11, 2020 Debian LTS
100

SUSE: 2019:2436-1 Important: MozillaFirefox Memory Safety Issues Fix

An update that solves 8 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2436-1 Rating: important References: #1149294 #1149295 #1149296 #1149297 #1149298 #1149299 #1149303 #1149304 #1149324 Cross-References: CVE-2019-11740 CVE-2019-11742 CVE-2019-11743 CVE-2019-11744 CVE-2019-11746 CVE-2019-11752 CVE-2019-11753 CVE-2019-9812 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 7 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL SUSE Linux Enterprise Server 12-SP1-LTSS SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Desktop 12-SP4 SUSE Enterprise Storage 5 SUSE Enterprise Storage 4 HPE Helion Openstack 8 ______________________________________________________________________________ An update that solves 8 vulnerabilities and has one errata is now available. Description: This update for MozillaFirefox to ESR 60.9 fixes the following issues: Security issues fixed: -CVE-2019-11742: Fixed a same-origin policy violation involving SVG filters and canvas to steal cross-origin images. (bsc#1149303) - CVE-2019-11746: Fixed a use-after-free while manipulating video. (bsc#1149297) - CVE-2019-11744: Fixed an XSS caused by breaking out of title and textarea elements using innerHTML. (bsc#1149304) - CVE-2019-11753: Fixed a privilege escalation with Mozilla Maintenance Service in custom Firefox installation location. (bsc#1149295) - CVE-2019-11752: Fixed a use-after-free while extracting a key value in IndexedDB. (bsc#1149296) - CVE-2019-11743: Fixed a timing side-channel attack on cross-origin information, utilizing unload event attributes. (bsc#1149298) - CVE-2019-11740: Fixed several memory safety bugs. (bsc#1149299) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-2436=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2019-2436=1 - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2019-2436=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2019-2436=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-2436=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2019-2436=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2019-2436=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2019-2436=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2019-2436=1 - SUSE Linux Enterprise Server 12-SP4: zypper in -tpatch SUSE-SLE-SERVER-12-SP4-2019-2436=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2019-2436=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2019-2436=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2019-2436=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2019-2436=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2019-2436=1 - SUSE Linux Enterprise Desktop 12-SP5: zypper in -t patch SUSE-SLE-DESKTOP-12-SP5-2019-2436=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-2436=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2019-2436=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2019-2436=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2019-2436=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE OpenStack Cloud 8 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE OpenStack Cloud 7 (s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP4 (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Desktop 12-SP5 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - SUSE Enterprise Storage 4 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-devel-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 - HPE Helion Openstack 8 (x86_64): MozillaFirefox-60.9.0-109.86.1 MozillaFirefox-debuginfo-60.9.0-109.86.1 MozillaFirefox-debugsource-60.9.0-109.86.1 MozillaFirefox-translations-common-60.9.0-109.86.1 References: https://www.suse.com/security/cve/CVE-2019-11740.html https://www.suse.com/security/cve/CVE-2019-11742.html https://www.suse.com/security/cve/CVE-2019-11743.html https://www.suse.com/security/cve/CVE-2019-11744.html https://www.suse.com/security/cve/CVE-2019-11746.html https://www.suse.com/security/cve/CVE-2019-11752.html https://www.suse.com/security/cve/CVE-2019-11753.html https://www.suse.com/security/cve/CVE-2019-9812.html https://bugzilla.suse.com/1149294 https://bugzilla.suse.com/1149295 https://bugzilla.suse.com/1149296 https://bugzilla.suse.com/1149297 https://bugzilla.suse.com/1149298 https://bugzilla.suse.com/1149299 https://bugzilla.suse.com/1149303 https://bugzilla.suse.com/1149304 https://bugzilla.suse.com/1149324 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . The latest MozillaFirefox patch resolves 8 vulnerabilities aimed at improving system safety and reliability in multiple SUSE platforms.. MozillaFirefox Update,SUSE Security Advisory,SUSE Linux Enhancements,Open Source Browser Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 23, 2019 Important SuSE
203

Mageia: 2019-0272 Moderate: Thunderbird Memory Safety Fixes

This update provides an update to thunderbird 68.0, updates enigmail to 2.1.2 and fixes the following security issues: Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8, and Thunderbird 68. (CVE-2019-11709) . MGASA-2019-0272 - Updated thunderbird packages fix security vulnerabilities Publication date: 12 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0272.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-11709, CVE-2019-11710, CVE-2019-11711, CVE-2019-11712, CVE-2019-11713, CVE-2019-11714, CVE-2019-11715, CVE-2019-11716, CVE-2019-11717, CVE-2019-11719, CVE-2019-11720, CVE-2019-11721, CVE-2019-11723, CVE-2019-11724, CVE-2019-11725, CVE-2019-11727, CVE-2019-11728, CVE-2019-11729, CVE-2019-11730 This update provides an update to thunderbird 68.0, updates enigmail to 2.1.2 and fixes the following security issues: Memory safety bugs fixed in Firefox 68, Firefox ESR 60.8, and Thunderbird 68. (CVE-2019-11709) Memory safety bugs fixed in Firefox 68 and Thunderbird 68. (CVE-2019-11710) Script injection within domain through inner window reuse. (CVE-2019-11711) Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects. (CVE-2019-11712) Use-after-free with HTTP/2 cached stream. (CVE-2019-11713) NeckoChild can trigger crash when accessed off of main thread. (CVE-2019-11714) HTML parsing error can contribute to content XSS. (CVE-2019-11715) globalThis not enumerable until accessed. (CVE-2019-11716) Caret character improperly escaped in origins. (CVE-2019-11717) Out-of-bounds read when importing curve25519 private key. (CVE-2019-11719) Character encoding XSS vulnerability. (CVE-2019-11720) Domain spoofing through unicode latin 'kra' character. (CVE-2019-11721) Cookie leakage during add-on fetching across private browsing boundaries. (CVE-2019-11723) Retired site input.mozilla.org has remote troubleshooting permissions. (CVE-2019-11724) Websocket resources bypasssafebrowsing protections. (CVE-2019-11725) PKCS#1 v1.5 signatures can be used for TLS 1.3. (CVE-2019-11727) Port scanning through Alt-Svc header. (CVE-2019-11728) Empty or malformed p256-ECDH public keys may trigger a segmentation fault. (CVE-2019-11729) Same-origin policy treats all files in a directory as having the same-origin. (CVE-2019-11730) NOTE! If your lightning calendar disappears with this update, see the referenced support.mozilla.org link in the advisories. References: - https://bugs.mageia.org/show_bug.cgi?id=25396 - https://www.thunderbird.net/en-US/thunderbird/68.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2019-28/ - https://enigmail.net/index.php/en/download/changelog#enig2.1.2 - https://support.mozilla.org/en-US/kb/calendar-updates-issues-thunderbird - https://www.cve.org/CVERecord?id=CVE-2019-11709 - https://www.cve.org/CVERecord?id=CVE-2019-11710 - https://www.cve.org/CVERecord?id=CVE-2019-11711 - https://www.cve.org/CVERecord?id=CVE-2019-11712 - https://www.cve.org/CVERecord?id=CVE-2019-11713 - https://www.cve.org/CVERecord?id=CVE-2019-11714 - https://www.cve.org/CVERecord?id=CVE-2019-11715 - https://www.cve.org/CVERecord?id=CVE-2019-11716 - https://www.cve.org/CVERecord?id=CVE-2019-11717 - https://www.cve.org/CVERecord?id=CVE-2019-11719 - https://www.cve.org/CVERecord?id=CVE-2019-11720 - https://www.cve.org/CVERecord?id=CVE-2019-11721 - https://www.cve.org/CVERecord?id=CVE-2019-11723 - https://www.cve.org/CVERecord?id=CVE-2019-11724 - https://www.cve.org/CVERecord?id=CVE-2019-11725 - https://www.cve.org/CVERecord?id=CVE-2019-11727 - https://www.cve.org/CVERecord?id=CVE-2019-11728 - https://www.cve.org/CVERecord?id=CVE-2019-11729 - https://www.cve.org/CVERecord?id=CVE-2019-11730 SRPMS: - 7/core/thunderbird-68.0-1.3.mga7 - 7/core/thunderbird-l10n-68.0-1.mga7 . Notice regarding Thunderbird addressing essential security threats, particularly concerning memory safety and script injection flaws.. Thunderbird Security Update, Mageia Security Advisory, MemorySafety Issues. . LinuxSecurity.com Team

Calendar%202 Sep 12, 2019 Mageia
202

openSUSE: 2019:1990-1 Moderate: MozillaThunderbird Security Patch

An update that fixes 10 vulnerabilities is now available.. openSUSE Security Update: Security update for MozillaThunderbird ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1990-1 Rating: moderate References: #1137970 #1140868 Cross-References: CVE-2019-11709 CVE-2019-11711 CVE-2019-11712 CVE-2019-11713 CVE-2019-11715 CVE-2019-11717 CVE-2019-11719 CVE-2019-11729 CVE-2019-11730 CVE-2019-9811 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for MozillaThunderbird fixes the following issues: - Generate langpacks sequentially to avoid file corruption from racy file writes (boo#1137970) - Mozilla Thunderbird 60.8.0 * Calendar: Problems when editing event times, some related to AM/PM setting in non-English locales MFSA 2019-23 (boo#1140868) * CVE-2019-9811 (bmo#1538007, bmo#1539598, bmo#1563327) Sandbox escape via installation of malicious languagepack * CVE-2019-11711 (bmo#1552541) Script injection within domain through inner window reuse * CVE-2019-11712 (bmo#1543804) Cross-origin POST requests can be made with NPAPI plugins by following 308 redirects * CVE-2019-11713 (bmo#1528481) Use-after-free with HTTP/2 cached stream * CVE-2019-11729 (bmo#1515342) Empty or malformed p256-ECDH public keys may trigger a segmentation fault * CVE-2019-11715 (bmo#1555523) HTML parsing error can contribute to content XSS * CVE-2019-11717 (bmo#1548306) Caret character improperly escaped in origins * CVE-2019-11719 (bmo#1540541) Out-of-bounds read when importing curve25519 private key * CVE-2019-11730 (bmo#1558299) Same-origin policy treats all files in a directory as having the same-origin * CVE-2019-11709 (bmo#1547266, bmo#1540759, bmo#1548822, bmo#1550498 bmo#1515052, bmo#1539219, bmo#1547757, bmo#1550498, bmo#1533522) Memory safety bugs fixed in Firefox 68 and Firefox ESR 60.8 and Thunderbird 60.8 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2019-1990=1 Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (x86_64): MozillaThunderbird-60.8.0-88.1 MozillaThunderbird-buildsymbols-60.8.0-88.1 MozillaThunderbird-translations-common-60.8.0-88.1 MozillaThunderbird-translations-other-60.8.0-88.1 References: https://www.suse.com/security/cve/CVE-2019-11709.html https://www.suse.com/security/cve/CVE-2019-11711.html https://www.suse.com/security/cve/CVE-2019-11712.html https://www.suse.com/security/cve/CVE-2019-11713.html https://www.suse.com/security/cve/CVE-2019-11715.html https://www.suse.com/security/cve/CVE-2019-11717.html https://www.suse.com/security/cve/CVE-2019-11719.html https://www.suse.com/security/cve/CVE-2019-11729.html https://www.suse.com/security/cve/CVE-2019-11730.html https://www.suse.com/security/cve/CVE-2019-9811.html https://bugzilla.suse.com/1137970 https://bugzilla.suse.com/1140868 -- . Essential security patch for Mozilla Thunderbird on openSUSE tackling various concerns and threats. Upgrade immediately.. openSUSE Security, MozillaThunderbird Patch, moderate Security Fix. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2019 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200