Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 594
Alerts This Week
Warning Icon 1 594

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 43 articles for you...
219

Rocky Linux RLSA-2023-5259 mariadb Moderate Segmentation Fault Concerns

Moderate: mariadb:10.3 security, bug fix, and enhancement update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5259", "synopsis": "Moderate: mariadb:10.3 security, bug fix, and enhancement update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for module.mariadb, galera, Judy, module.galera, mariadb, module.Judy.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. \n\nThe following packages have been upgraded to a later upstream version: mariadb (10.3). (BZ#2223572, BZ#2223574, BZ#2223962, BZ#2223965)\n\nSecurity Fix(es):\n\n* mariadb: segmentation fault via the component sub_select (CVE-2022-32084)\n\n* mariadb: server crash in JOIN_CACHE::free or in copy_fields (CVE-2022-32091)\n\n* mariadb: compress_write() fails to release mutex on failure (CVE-2022-38791)\n\n* mariadb: NULL pointer dereference in spider_db_mbase::print_warnings() (CVE-2022-47015)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.\n\nBug Fix(es):\n\n* [MariaDB 10.3.32] socat: E Failed to set SNI host \"\" (SST failure) (BZ#2223961)", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2106034", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106034", "description": ""}, {"ticket": "2106042", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106042", "description": ""}, {"ticket": "2130105", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2130105", "description": ""}, {"ticket": "2163609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163609","description": ""}, {"ticket": "2240246", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2240246", "description": ""}], "cves": [{"name": "CVE-2022-32084", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32084", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-229"}, {"name": "CVE-2022-32091", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32091", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-229"}, {"name": "CVE-2022-38791", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-38791", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-667"}, {"name": "CVE-2022-47015", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-47015", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-476"}, {"name": "CVE-2023-5157", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5157", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-400"}], "references": [], "publishedAt": "2025-12-27T09:04:03.511459Z", "rpms": {"Rocky Linux 8": {"nvras": ["galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.src.rpm", "galera-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "galera-debuginfo-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-debuginfo-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "galera-debugsource-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "galera-debugsource-0:25.3.37-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm","Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.src.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1674+fa55eae9.src.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.src.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.src.rpm", "Judy-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "Judy-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.10.0+1925+356c22e8.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+431+26aaed18.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+431+26aaed18.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.10.0+1925+356c22e8.x86_64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.x86_64.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.src.rpm", "mariadb-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-backup-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-backup-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-backup-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-backup-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-common-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-common-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm","mariadb-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-debugsource-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-debugsource-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-embedded-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-embedded-devel-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-errmsg-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-errmsg-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-gssapi-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-gssapi-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-gssapi-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-gssapi-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-oqgraph-engine-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-oqgraph-engine-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-oqgraph-engine-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-oqgraph-engine-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-galera-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm","mariadb-server-galera-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-utils-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-utils-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-server-utils-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-server-utils-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-test-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-test-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm", "mariadb-test-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.aarch64.rpm", "mariadb-test-debuginfo-3:10.3.39-1.module+el8.8.0+1452+2a7eab68.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Updates available for Rocky Linux mariadb include security fixes for several vulnerabilities; important enhancements addressed.. moderate mariadb update security issues enhancements. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Dec 27, 2025 moderate Rocky Linux
197

Debian 11 bullseye DLA-4049-1 critical: rust-openssl memory leak

A vulnerability has been discovered in rust-openssl, a set of OpenSSL bindings for the Rust programming language. In affected versions ssl::select_next_proto can return a slice pointing . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4049-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andrej Shadura February 11, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : rust-openssl Version : 0.10.29-1+deb11u1 CVE ID : CVE-2025-24898 A vulnerability has been discovered in rust-openssl, a set of OpenSSL bindings for the Rust programming language. In affected versions ssl::select_next_proto can return a slice pointing into the server argument's buffer but with a lifetime bound to the client argument. In situations where the sever buffer's lifetime is shorter than the client buffer's, this can cause a use after free. This could cause the server to crash or to return arbitrary memory contents to the client. This security update fixes the signature of ssl::select_next_proto to properly constrain the output buffer's lifetime to that of both input buffers. In standard usage of ssl::select_next_proto in the callback passed to SslContextBuilder::set_alpn_select_callback, code is only affected if the server buffer is constructed within the callback. For Debian 11 bullseye, this problem has been fixed in version 0.10.29-1+deb11u1. We recommend that you upgrade your rust-openssl packages. For the detailed security status of rust-openssl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rust-openssl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-4050-1 concerns a vulnerability in thepython3-requests package, suggesting an essential update for users.. rust-openssl, server crash, memory safety issue, security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 11, 2025 Critical Debian LTS
100

SUSE: 2025:0283-1 important: nginx critical issues fixed

* bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 . # Security update for nginx Announcement ID: SUSE-SU-2025:0283-1 Release Date: 2025-01-29T12:33:31Z Rating: important References: * bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 * CVE-2024-7347 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7347 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-7347 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-7347 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for nginx fixes the following issues: * CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171) * CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-283=1 openSUSE-SLE-15.6-2025-283=1 * Server Applications Module 15-SP6 zypper in -t patchSUSE-SLE-Module-Server-Applications-15-SP6-2025-283=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.3.1 * nginx-debuginfo-1.21.5-150600.10.3.1 * nginx-1.21.5-150600.10.3.1 * Server Applications Module 15-SP6 (noarch) * nginx-source-1.21.5-150600.10.3.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2024-7347.html * https://bugzilla.suse.com/show_bug.cgi?id=1216171 * https://bugzilla.suse.com/show_bug.cgi?id=1229155 . Recent security enhancements for nginx highlight essential patches addressing multiple vulnerabilities in SUSE environments. It's important to implement them without delay.. nginx security, SUSE updates, HTTP2 vulnerabilities, software patches. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2025 Important SuSE
202

openSUSE: 2025:0282-1 important: nginx HTTP/2 attack and crash fix

An update that solves two vulnerabilities can now be installed.. # Security update for nginx Announcement ID: SUSE-SU-2025:0282-1 Release Date: 2025-01-29T08:04:15Z Rating: important References: * bsc#1216171 * bsc#1229155 Cross-References: * CVE-2023-44487 * CVE-2024-7347 CVSS scores: * CVE-2023-44487 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-44487 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7347 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-7347 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-7347 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-7347 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for nginx fixes the followingissues: * CVE-2023-44487: Mitigate HTTP/2 Rapid Reset Attack (bsc#1216171) * CVE-2024-7347: Fixed worker crashes on special crafted mp4 files containing invalid chunk information (bsc#1229155) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-282=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-282=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-282=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2025-282=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2025-282=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-282=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-282=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-282=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-282=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-282=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-2025-282=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-282=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 *nginx-debugsource-1.21.5-150400.3.6.1 * openSUSE Leap 15.4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) *nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Proxy 4.3 (x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Proxy 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Retail Branch Server 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * nginx-1.21.5-150400.3.6.1 * nginx-debuginfo-1.21.5-150400.3.6.1 * nginx-debugsource-1.21.5-150400.3.6.1 * SUSE Manager Server 4.3 (noarch) * nginx-source-1.21.5-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2023-44487.html * https://www.suse.com/security/cve/CVE-2024-7347.html * https://bugzilla.suse.com/show_bug.cgi?id=1216171 * https://bugzilla.suse.com/show_bug.cgi?id=1229155 . Crucial Apache security patch released for Fedora addressing HTTP/3 flaws and server instabilities. Keep your systems safe.. nginx security update, openSUSE patch, HTTP/2 vulnerabilities, Linux server security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 29, 2025 Important OpenSUSE
100

openSUSE Leap 15.3/15.4/15.5: 2023:4222-1 Moderate: libnbd Server Crash

* bsc#1215799 * jsc#ECO-3633 Cross-References: * CVE-2023-5215 . # Security update for libnbd Announcement ID: SUSE-SU-2023:4222-1 Rating: moderate References: * bsc#1215799 * jsc#ECO-3633 Cross-References: * CVE-2023-5215 CVSS scores: * CVE-2023-5215 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-5215 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.4 * openSUSE Leap 15.5 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for libnbd fixes the following issues: * Updated to version 1.18.1 * Updated to version 1.18.0: * CVE-2023-5215: Fixed an issue where an NBD server returning an unexpected block size might crash an application (bsc#1215799). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-4222=1 * openSUSE Leap 15.4 zypper in -t patch openSUSE-SLE-15.4-2023-4222=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4222=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 * libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * python3-libnbd-debuginfo-1.18.1-150300.8.15.1 * python3-libnbd-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.3 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 *libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.4 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * libnbd-debuginfo-1.18.1-150300.8.15.1 * libnbd0-1.18.1-150300.8.15.1 * libnbd-debugsource-1.18.1-150300.8.15.1 * libnbd-devel-1.18.1-150300.8.15.1 * python3-libnbd-debuginfo-1.18.1-150300.8.15.1 * python3-libnbd-1.18.1-150300.8.15.1 * nbdfuse-1.18.1-150300.8.15.1 * nbdfuse-debuginfo-1.18.1-150300.8.15.1 * libnbd-1.18.1-150300.8.15.1 * libnbd0-debuginfo-1.18.1-150300.8.15.1 * openSUSE Leap 15.5 (noarch) * libnbd-bash-completion-1.18.1-150300.8.15.1 ## References: * https://www.suse.com/security/cve/CVE-2023-5215.html * https://bugzilla.suse.com/show_bug.cgi?id=1215799 * https://idp-saml.suse.com/simplesaml/module.php/core/loginuserpass.php?AuthState=_2e768f13e6e4c5ee29e46ac966c3b389ab09d2f55a%3Ahttps%3A%2F%2Fidp-saml.suse.com%2Fsimplesaml%2Fsaml2%2Fidp%2FSSOService.php%3Fspentityid%3Dhttps%253A%252F%252Fjira.suse.com%26cookieTime%3D1766463876elayState%3D9fad1e36-be03-45bb-983f-bbd3f4c64b7c%26cookieTime%3D1762358357 . An update has been issued for a significant libnbd vulnerability affecting openSUSE Leap, addressing failures caused by irregular block dimensions.. openSUSE Update, libnbd Security Fix, moderate Issue, openSUSE Leap, software Patch. . LinuxSecurity.com Team

Calendar%202 Oct 27, 2023 SuSE
219

Rocky Linux 8 RLSA-2023:5683 Important: MariaDB Server Crash Issues

Important: mariadb:10.5 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5683", "synopsis": "Important: mariadb:10.5 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for mariadb, galera, module.Judy, module.mariadb, Judy, module.galera.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "MariaDB is a multi-user, multi-threaded SQL database server that is binary compatible with MySQL. \n\nThe following packages have been upgraded to a later upstream version: galera\n(26.4.14), mariadb (10.5.22).\n\nSecurity Fix(es):\n\n* mariadb: node crashes with Transport endpoint is not connected mysqld got signal 6 (CVE-2023-5157)\n\n* mariadb: use-after-poison in prepare_inplace_add_virtual in handler0alter.cc (CVE-2022-32081)\n\n* mariadb: assertion failure at table-> get_ref_count() == 0 in dict0dict.cc (CVE-2022-32082)\n\n* mariadb: segmentation fault via the component sub_select (CVE-2022-32084)\n\n* mariadb: server crash in st_select_lex_unit::exclude_level (CVE-2022-32089)\n\n* mariadb: server crash in JOIN_CACHE::free or in copy_fields (CVE-2022-32091)\n\n* mariadb: compress_write() fails to release mutex on failure (CVE-2022-38791)\n\n* mariadb: NULL pointer dereference in spider_db_mbase::print_warnings() (CVE-2022-47015)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2106028", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106028", "description": ""}, {"ticket": "2106030", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106030", "description": ""}, {"ticket": "2106034", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2106034", "description": ""}, {"ticket": "2106035", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106035", "description": ""}, {"ticket": "2106042", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2106042", "description": ""}, {"ticket": "2130105", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2130105", "description": ""}, {"ticket": "2163609", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2163609", "description": ""}, {"ticket": "2240246", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2240246", "description": ""}], "cves": [{"name": "CVE-2022-32081", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32081", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32082", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32082", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32084", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32084", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32089", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32089", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-32091", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-32091", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-38791", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-38791", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2022-47015", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-47015","cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2023-5157", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5157", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2023-10-14T02:08:04.577837Z", "rpms": {"Rocky Linux 8": {"nvras": ["galera-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "galera-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.src.rpm", "galera-debuginfo-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "galera-debugsource-0:26.4.14-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-0:1.0.5-18.module+el8.4.0+427+adf35707.src.rpm", "Judy-debuginfo-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "Judy-debugsource-0:1.0.5-18.module+el8.4.0+427+adf35707.aarch64.rpm", "mariadb-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.src.rpm", "mariadb-backup-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-backup-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-common-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-debugsource-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-devel-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-embedded-devel-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-errmsg-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-gssapi-server-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-gssapi-server-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-oqgraph-engine-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm","mariadb-oqgraph-engine-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-pam-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-pam-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-galera-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-utils-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-server-utils-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-test-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm", "mariadb-test-debuginfo-3:10.5.22-1.module+el8.8.0+1490+31c52b1f.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important announcement regarding MariaDB on Rocky Linux tackling crucial security vulnerabilities. Discover details about the enhancements and their implications.. Rocky Linux Security Advisory, MariaDB Crash Issues, Important Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 14, 2023 Important Rocky Linux
197

Debian 10 Buster DLA-3538-1 High: Zabbix Info Exposure Advisory

Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing to crash the server, information disclosure or Cross-Site-Scripting attacks. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3538-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost August 22, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : zabbix Version : 1:4.0.4+dfsg-1+deb10u2 CVE ID : CVE-2013-7484 CVE-2019-17382 CVE-2022-35229 CVE-2022-43515 CVE-2023-29450 CVE-2023-29451 CVE-2023-29454 CVE-2023-29455 CVE-2023-29456 CVE-2023-29457 Debian Bug : 1026847 Several security vulnerabilities have been discovered in zabbix, a network monitoring solution, potentially allowing to crash the server, information disclosure or Cross-Site-Scripting attacks. Important Notices: To mitigate CVE-2019-17382, on existing installations, the guest account needs to be manually disabled, for example by disabling the the "Guest group" in the UI: Administration -> User groups -> Guests -> Untick Enabled This update also fixes a regression with CVE-2022-35229, which broke the possiblity to edit and add discovery rules in the UI. CVE-2013-7484 Zabbix before version 4.4.0alpha2 stores credentials in the "users" table with the password hash stored as a MD5 hash, which is a known insecure hashing method. Furthermore, no salt is used with the hash. CVE-2019-17382 (Disputed, not seen by upstream as not a security issue) An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password(i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin. CVE-2022-35229 An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. CVE-2022-43515 Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range. CVE-2023-29450 JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. CVE-2023-29451 Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. CVE-2023-29454 A Stored or persistent cross-site scripting (XSS) vulnerability was found on “Users” section in “Media” tab in “Send to” form field. When new media is created with malicious code included into field “Send to” then it will execute when editing the same media. CVE-2023-29455 A Reflected XSS attacks, also known as non-persistent attacks, was found where an attacker can pass malicious code as GET request to graph.php and system will save it and will execute when current graph page is opened. CVE-2023-29456 URL validation scheme receives input from a user and thenparses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. CVE-2023-29457 A Reflected XSS attacks, also known as non-persistent attacks, was found where XSS session cookies could be revealed, enabling a perpetrator to impersonate valid users and abuse their private accounts. For Debian 10 buster, these problems have been fixed in version 1:4.0.4+dfsg-1+deb10u2. We recommend that you upgrade your zabbix packages. For the detailed security status of zabbix please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zabbix Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Several vulnerabilities identified in Zabbix according to Debian LTS Advisory DLA-3538-1, advising immediate upgrades to avert potential attacks.. Debian Security, Zabbix Exploits, Cyber Threats. . LinuxSecurity.com Team

Calendar%202 Aug 22, 2023 Debian LTS
197

Debian 10 Buster: DLA-3342-1 Moderate: Freeradius Server Crash Issues

Several flaws were found in freeradius, a high-performance and highly configurable RADIUS server. CVE-2022-41859 . -------------------------------------------------------------------------Debian LTS Advisory DLA-3342-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany February 24, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : freeradius Version : 3.0.17+dfsg-1.1+deb10u2 CVE ID : CVE-2022-41859 CVE-2022-41860 CVE-2022-41861 Several flaws were found in freeradius, a high-performance and highly configurable RADIUS server. CVE-2022-41859 In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack. CVE-2022-41860 In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash. CVE-2022-41861 A malicious RADIUS client or home server can send a malformed attribute which can cause the server to crash. For Debian 10 buster, these problems have been fixed in version 3.0.17+dfsg-1.1+deb10u2. We recommend that you upgrade your freeradius packages. For the detailed security status of freeradius please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freeradius Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4965-1 concerns vulnerabilities in the openvpn package. Prompt upgrade is advised toenhance system stability.. freeradius security update,debian lts advisory,radius server threats,information leak. . LinuxSecurity.com Team

Calendar%202 Feb 24, 2023 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200