Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 29: Critical Security Advisory 2019-32067d8b15 for Php-Symfony4

**Version 4.1.12** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [Cache][PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) *. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-32067d8b15 2019-04-27 23:10:05.598341 --------------------------------------------------------------------------------Name : php-symfony4 Product : Fedora 29 Version : 4.1.12 Release : 1.fc29 URL : https://symfony.com Summary : Symfony PHP framework (version 4) Description : Symfony PHP framework (version 4). NOTE: Does not require PHPUnit bridge. --------------------------------------------------------------------------------Update Information: **Version 4.1.12** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [Cache][PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 4.1.12-1 - update to 4.1.12 * Mon Feb 4 2019 Remi Collet - 4.1.11-1 - update to 4.1.11 - raise dependency on twig 1.37.1 * Sat Feb 2 2019 Fedora Release Engineering - 4.1.10-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Jan 7 2019 Remi Collet - 4.1.10-1 - update to 4.1.10 * Fri Dec 7 2018 Remi Collet - 4.1.9-1 - updateto 4.1.9 * Tue Nov 27 2018 Remi Collet - 4.1.8-1 - update to 4.1.8 * Mon Nov 5 2018 Remi Collet - 4.1.7-1 - update to 4.1.7 * Thu Oct 18 2018 Remi Collet - 4.1.6-2 - ignore doctrine/data-fixtures version * Wed Oct 3 2018 Remi Collet - 4.1.6-1 - update to 4.1.6 * Mon Oct 1 2018 Remi Collet - 4.1.5-1 - update to 4.1.5 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-32067d8b15' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Ubuntu 20.04 introduces essential nodejs-12 security patches addressing several flaws such as CSRF and session management.. php-symfony4 updates, Fedora security, critical update, XSS fix, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 27, 2019 Critical Fedora
89

Fedora 28 Critical Advisory: 2019-3ee6a7adf2 XSS Fix for Symfony

**Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-3ee6a7adf2 2019-04-27 21:35:40.510401 --------------------------------------------------------------------------------Name : php-symfony Product : Fedora 28 Version : 2.8.51 Release : 1.fc28 URL : https://symfony.com Summary : PHP framework for web projects Description : PHP framework for web projects --------------------------------------------------------------------------------Update Information: **Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 2.8.51-1 - update to 2.8.51 * Sat Feb 2 2019 Fedora Release Engineering - 2.8.49-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Fri Dec 7 2018 Remi Collet - 2.8.49-1 - update to 2.8.49 * Tue Nov 27 2018 Remi Collet - 2.8.48-1 - update to 2.8.48 * Mon Nov 5 2018 Remi Collet - 2.8.47-1 - update to 2.8.47 * Thu Oct 18 2018 Remi Collet - 2.8.46-2 - ignore doctrine/data-fixturesversion * Mon Oct 1 2018 Remi Collet - 2.8.46-1 - update to 2.8.46 * Tue Aug 28 2018 Remi Collet - 2.8.45-1 - update to 2.8.45 - debug and ldap: add missing dependency on common * Wed Aug 1 2018 Shawn Iwinski - 2.8.44-1 - Update to 2.8.44 (CVE-2018-14773 / CVE-2018-14774) * Fri Jul 13 2018 Fedora Release Engineering - 2.8.42-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Mon Jun 25 2018 Shawn Iwinski - 2.8.42-1 - Update to 2.8.42 * Mon May 28 2018 Remi Collet - 2.8.41-1 - update to 2.8.41 * Thu May 24 2018 Remi Collet - 2.8.40-1 - update to 2.8.40 * Fri May 4 2018 Remi Collet - 2.8.39-1 - update to 2.8.39 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-3ee6a7adf2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential security patch for php-symfony on Fedora 28 addresses XSS vulnerabilities and improves service authentication.. Php Framework, Fedora Security, Symfony Update, Software Patch, Package Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 27, 2019 Critical Fedora
89

Fedora 30: FEDORA-2019-0ef4149687 Moderate: php-symfony Security Update

**Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0ef4149687 2019-04-27 21:22:10.074172 --------------------------------------------------------------------------------Name : php-symfony Product : Fedora 30 Version : 2.8.51 Release : 1.fc30 URL : https://symfony.com Summary : PHP framework for web projects Description : PHP framework for web projects --------------------------------------------------------------------------------Update Information: **Version 2.8.50** (2019-04-17) * security #cve-2019-10910 [DI] Check service IDs are valid (nicolas-grekas) * security #cve-2019-10909 [FrameworkBundle][Form] Fix XSS issues in the form theme of the PHP templating engine (stof) * security #cve-2019-10912 [PHPUnit Bridge] Prevent destructors with side-effects from being unserialized (nicolas-grekas) * security #cve-2019-10911 [Security] Add a separator in the remember me cookie hash (pborreli) * security #cve-2019-10913 [HttpFoundation] reject invalid method override (nicolas-grekas) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 18 2019 Remi Collet - 2.8.51-1 - update to 2.8.51 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0ef4149687' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPGkey. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Recent php-symfony update tackles critical vulnerabilities such as cross-site scripting (XSS) and validates service IDs. Urgent action is advised.. php framework,XSS patch,Fedora update notification,service ID validation,php-symfony update. . LinuxSecurity.com Team

Calendar 2 Apr 27, 2019 Fedora
202

openSUSE 13.2: 2016:1659-1 Important: Code Injection Risk Fixed

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for obs-service-source_validator ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1659-1 Rating: important References: #967265 #967610 Cross-References: CVE-2016-4007 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: obs-service-source_validator was updated to fix one security issue. This security issue was fixed: - CVE-2016-4007: Several maintained source services are vulnerable to code/paramter injection (bsc#967265). This non-security issue was fixed: - bsc#967610: Several occurrences of uninitialized value. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-758=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (noarch): obs-service-source_validator-0.6+git20160531.fbfe336-9.1 References: https://www.suse.com/security/cve/CVE-2016-4007.html https://bugzilla.suse.com/967265 https://bugzilla.suse.com/967610 -- . Important revision for obs-service_source_validator mitigates potential code execution vulnerabilities in openSUSE environments.. openSUSE Update, Code Injection, Service Validator, Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 22, 2016 Important OpenSUSE
200

Scientific Linux SL5/SL6: SLSA-2013:0942-1 Moderate: krb5 Of Network Attack

Moderate: krb5 security update. Date: Thu, 13 Jun 2013 21:45:23 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Bonnie King Subject: Security ERRATA Moderate: krb5 on SL5.x, SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: krb5 security update Advisory ID: SLSA-2013:0942-1 Issue Date: 2013-06-12 CVE Numbers: CVE-2002-2443 -- It was found that kadmind's kpasswd service did not perform any validation on incoming network packets, causing it to reply to all requests. A remote attacker could use this flaw to send spoofed packets to a kpasswd service that appear to come from kadmind on a different server, causing the services to keep replying packets to each other, consuming network bandwidth and CPU. (CVE-2002-2443) After installing the updated packages, the krb5kdc and kadmind daemons will be restarted automatically. -- SL5 x86_64 krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.x86_64.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.x86_64.rpm krb5-workstation-1.6.1-70.el5_9.2.x86_64.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-ldap-1.6.1-70.el5_9.2.x86_64.rpm i386 krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-workstation-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-server-1.6.1-70.el5_9.2.i386.rpm krb5-server-ldap-1.6.1-70.el5_9.2.i386.rpm SL6 x86_64 krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm i386 krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.i686.rpm krb5-workstation-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-server-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm - Scientific Linux Development Team . A significant security patch for krb5 in Scientific Linux SL5.x and SL6.x has been issued to mitigate risks associated with possible network vulnerabilities.. krb5 Security Update, Scientific Linux, Network Attack, Security Advisory, Moderate Severity. . LinuxSecurity.com Team

Calendar 2 Jun 13, 2013 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here