Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

RedHat OpenShift Service Mesh 1.1.2 Important: Servicemesh-Proxy DoS Threat

An update for servicemesh-proxy is now available for OpenShift Service Mesh 1.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Service Mesh 1.1.2 servicemesh-proxy security update Advisory ID: RHSA-2020:2523-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2020:2523 Issue date: 2020-06-11 CVE Names: CVE-2020-11080 ==================================================================== 1. Summary: An update for servicemesh-proxy is now available for OpenShift Service Mesh 1.1. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: OpenShift Service Mesh 1.1 - x86_64 3. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. Security Fix(es): * nghttp2: overly large SETTINGS frames can lead to DoS (CVE-2020-11080) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: The OpenShift Service Mesh release notes provide information on the features and known issues: 5. Bugs fixed (https://bugzilla.redhat.com/): 1844929 - CVE-2020-11080 nghttp2: overly large SETTINGS frames can lead to DoS 6. Package List: OpenShift Service Mesh1.1: Source: servicemesh-proxy-1.1.2-3.el8.src.rpm x86_64: servicemesh-proxy-1.1.2-3.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-11080 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXuHT7tzjgjWX9erEAQgvuQ//U2YKvV9yU8Ig1ecceDEgW011Yn4aEh37 FcQ4Sg32/PEWszOthel8+UKt33mnAUMj+jU31wcyyN1172H0fGOyJeL6KKi1IL45 d3DxTZdv22DKjD3JurFVaMsDPayKx+oV8DcPtIV8G9gy7WvNSn9S4z/+VcP22N0z dczah9a+Ps2u/Daf+/iBi33FOKkTZo+tqSJ4pSNZ1ixs7F36tWqaQh5zE4A193vB OsabrgvnlXy+efwVKbwlpcLSo1EZcSEWHE2PodQxU8qpRoCwMxgidAqsja5+q9/9 Q78XqgyC5MFG4YT4/ldBXoURFs91x60tHHVTI/O/e4Xu+Ffh0ef70Wsq9gbMmoj1 y9tr/ShjAtIfqaXypDgXsCz5Ud4ZNWfDHucqrgwu6FdBdRm4YB7Pa2n4vJNi0XUP SGNl0V7fs8qVnHE96EPBpK3FDnzmiTrORjnwJx8mJeDohm3HcQj5lytKEPNE/sJq mIAlkvxKY77+2IQnVIOxTqcCeUs+RcZhwXPsQhY8iHeGHAd2YEjjoeY8FkwDb/bw V5zWJUSh05/A1ofsdEgNgXHxbks0CTVkviYIG8+jdl+q3PQL8l60fAb6ZNZsycAq xNuMIcMczzpQ2R1D/NTUKzlxyMzvRSdR2xMKOkVpH3oJ4nynH1K0oNd/le1kimOY UOXakJtvbPs=16CT -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The security bulletin issued by Red Hat for OpenShift Service Mesh version 1.1.2 highlights a critical Denial of Service vulnerability present in servicemesh-proxy.. OpenShift, ServiceMesh, Important Update, RedHat Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 11, 2020 Important Red Hat
98

RedHat: RHSA-2020-0477 Critical Update for OpenShift Service Mesh 1.0.7

Red Hat OpenShift Service Mesh 1.0.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: Red Hat OpenShift Service Mesh 1.0.7 servicemesh-proxy security update Advisory ID: RHSA-2020:0477-01 Product: Red Hat OpenShift Service Mesh Advisory URL: https://access.redhat.com/errata/RHSA-2020:0477 Issue date: 2020-02-12 CVE Names: CVE-2020-8595 ==================================================================== 1. Summary: Red Hat OpenShift Service Mesh 1.0.7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: OpenShift Service Mesh 1.0 - x86_64 3. Description: Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation. This advisory covers the RPM packages for the OpenShift Service Mesh 1.0.7 release. Security Fix(es): * istio: unauthorised access to JWT protected HTTP path (CVE-2020-8595) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.redhat.com/en/documentation/openshift_container_platform/4.3/html/service_mesh/service-mesh-1-x 5. Bugs fixed(https://bugzilla.redhat.com/): 1798247 - CVE-2020-8595 istio: unauthorised access to JWT protected HTTP path 6. Package List: OpenShift Service Mesh 1.0: Source: servicemesh-proxy-1.0.7-1.el8.src.rpm x86_64: servicemesh-proxy-1.0.7-1.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-8595 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXkNCnNzjgjWX9erEAQg9rQ//dsEQmNpAzQW5H6jlTfnY6XPH1OufVrlM R4i2ZYBGLTLm4bk52DT4fLtsM6D3kYjuXwgoLTQg+DtJiXyqes1sZEQQhVIcuu8a QPT+Tcs2RDdCLCI8VvEjcj2NP6/XznmJh9VwAW55iaR3RCfPNvMZ237a7igDbWqw ugHfTW266TCfBjIlY4McA/OudFpCSsiHeW0t+MiOkyminZ05umrngmRPBe5xjd36 pG+GQy0tmge8Lzv0H7X7PFcKN/FEqf4umy6J0O3e/ZJOMBcYNfVoriRULkUxrjOa NyruFGnHX1zGNn8rbOBYbdj21ShMybOkI1Ox2qUF4nwvw9y98S8JTBgR8N69Jb6f FL0blykINzmtXW9RiYT94UaIhwUqOeTp4lbxRL8qwHc2UH4pMtMBnvZVia34FnWw Iv9nmciGrz/snYTd5xIfPmdTTKAQ7PYBqmVdwtINdHMkv8rnoOQWlMcg6XgLaC4P PkiE38iDqwjihBkzdSnPAcek5v5Zhtl3p43nzzjChr2AmAU6ZGoJ+ussbXK8jqSt ReTbONgqYF7xbQCAaEXoHkgm2xnoFuHZyj/aDaEEYzScrIkgNVTugU5PDrzt+300 iutWShMfT/RzRv6EZhfCjaFLcqZAMmdLgDaC4EfCbnhVVpT6V/WuSE5aRdxPEcgg b2hJKwd8Bqw=n6KW -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The Red Hat OpenShift Service Mesh 1.0.7 update tackles a critical security concern, classified as Important, prioritizing fixes for unauthorized access vulnerabilities. Red Hat, OpenShift, Service Mesh, Security Update, Threat. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 11, 2020 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here