Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 27 Shellinabox Security Update: Disable SSHv1 and Enhance Security

Disable SSHv1 options.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a95dd74301 2017-12-28 01:13:53.258874 --------------------------------------------------------------------------------Name : shellinabox Product : Fedora 27 Version : 2.20 Release : 5.fc27 URL : https://github.com/shellinabox/shellinabox Summary : Web based AJAX terminal emulator Description : Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator. This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins. --------------------------------------------------------------------------------Update Information: Disable SSHv1 options. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade shellinabox' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Shellinabox update removes SSHv1 support to boost security in Fedora 27. Users are advised to implement this update urgently.. Fedora Security, Shellinabox Update, SSH Options. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 28, 2017 Important Fedora
89

Fedora 26: Security Advisory for Shell In A Box SSHv1 Options Update

Disable SSHv1 options.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-1dc71e1acd 2017-12-26 15:02:57.896848 --------------------------------------------------------------------------------Name : shellinabox Product : Fedora 26 Version : 2.20 Release : 5.fc26 URL : https://github.com/shellinabox/shellinabox Summary : Web based AJAX terminal emulator Description : Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator. This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins. --------------------------------------------------------------------------------Update Information: Disable SSHv1 options. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade shellinabox' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 enhances Shell In A Box security with vital update, disabling SSHv1 protocols.. Fedora Shell In A Box Update, SSH Security Configuration, Remote Access Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 26, 2017 Critical Fedora
89

Fedora 23: 2015-1c773e8702 moderate: Shellinabox DNS Rebinding

* Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1c773e8702 2016-01-07 16:45:29.330389 -------------------------------------------------------------------------------- Name : shellinabox Product : Fedora 23 Version : 2.19 Release : 1.fc23 URL : https://github.com/shellinabox/shellinabox Summary : Web based AJAX terminal emulator Description : Shell In A Box implements a web server that can export arbitrary command line tools to a web based terminal emulator. This emulator is accessible to any JavaScript and CSS enabled web browser and does not require any additional browser plugins. -------------------------------------------------------------------------------- Update Information: * Added support for middle-click paste * Improved iOS support * New logic to enable soft keyboard icon * Disable HTTPS fallback using the URL /plain. Consequently disables automatic upgrades from HTTP to HTTPS (CVE-2015-8400) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1287579 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287579 [ 2 ] Bug #1287578 - CVE-2015-8400 shellinabox: DNS rebinding attack due to HTTP fallback [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287578 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update shellinabox' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . The latest Shellinabox security patch for Fedora 23 addresses the HTTP to HTTPS fallback issue, significantly improving the security of browser-based terminal access.. ShellInABox, Fedora23, SecurityUpdate. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 07, 2016 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here