Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
172

Ubuntu 25.10: Major Authentication Vulnerability in KDE Connect USN-7905-1

KDE Connect could allow authentication of impersonated devices.. ========================================================================== Ubuntu Security Notice USN-7905-1 December 03, 2025 kdeconnect vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: KDE Connect could allow authentication of impersonated devices. Software Description: - kdeconnect: connect smartphones to your desktop devices Details: It was discovered that KDE Connect incorrectly handled device IDs. An attacker could possibly use this issue to bypass authentication and connect an unpaired device. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 kdeconnect 25.08.1-0ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7905-1 CVE-2025-66270 Package Information: https://launchpad.net/ubuntu/+source/kdeconnect/25.08.1-0ubuntu2.1 . KDE Connect vulnerability in Ubuntu allows impersonated device authentication, a security issue requiring immediate updates.. KDE Connect security, Ubuntu security update, authentication bypass. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 03, 2025 Important Ubuntu
100

SUSE: 2023:4575-1 important: gstreamer-plugins-bad integer overflow

* bsc#1215793 * bsc#1215796 Cross-References: * CVE-2023-40474 . # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2023:4575-1 Rating: important References: * bsc#1215793 * bsc#1215796 Cross-References: * CVE-2023-40474 * CVE-2023-40476 CVSS scores: * CVE-2023-40474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-40476 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * Basesystem Module 15-SP4 * Desktop Applications Module 15-SP4 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 * SUSE Package Hub 15 15-SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues: * CVE-2023-40474: Fixed integer overflow causing out of bounds writes when handling invalid uncompressed video (bsc#1215796). * CVE-2023-40476: Fixed possible overflow using max_sub_layers_minus1 (bsc#1215793). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4575=1 * Basesystem Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2023-4575=1 * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-4575=1 * SUSE Package Hub 15 15-SP4 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP4-2023-4575=1 ## Package List: * openSUSE Leap 15.4(aarch64 ppc64le s390x x86_64 i586) * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstplay-1_0-0-1.20.1-150400.3.9.1 * typelib-1_0-GstVulkan-1_0-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.9.1 * libgsttranscoder-1_0-0-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.9.1 * gstreamer-transcoder-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.9.1 * libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-1.20.1-150400.3.9.1 * typelib-1_0-GstVulkanWayland-1_0-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.9.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-1.20.1-150400.3.9.1 * gstreamer-transcoder-devel-1.20.1-150400.3.9.1 *gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstTranscoder-1_0-1.20.1-150400.3.9.1 * gstreamer-transcoder-1.20.1-150400.3.9.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.9.1 * libgstva-1_0-0-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-1.20.1-150400.3.9.1 * typelib-1_0-GstVulkanXCB-1_0-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.9.1 * openSUSE Leap 15.4 (x86_64) * libgstvulkan-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstplay-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-32bit-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-32bit-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstplay-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstva-1_0-0-32bit-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-32bit-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstva-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-32bit-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-32bit-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.20.1-150400.3.9.1 * openSUSE Leap 15.4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.9.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgstsctp-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstva-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 *libgstwebrtc-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-64bit-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-64bit-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-64bit-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstplay-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstplay-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstva-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-64bit-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-64bit-1.20.1-150400.3.9.1 * Basesystem Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libgstphotography-1_0-0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstplayer-1_0-0-1.20.1-150400.3.9.1 * libgstplay-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.9.1 * libgstplay-1_0-0-1.20.1-150400.3.9.1 * libgstphotography-1_0-0-debuginfo-1.20.1-150400.3.9.1 * DesktopApplications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GstCodecs-1_0-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstWebRTC-1_0-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-1.20.1-150400.3.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstPlayer-1_0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-devel-1.20.1-150400.3.9.1 * libgstcodecs-1_0-0-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstInsertBin-1_0-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstmpegts-1_0-0-1.20.1-150400.3.9.1 * libgstcodecparsers-1_0-0-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-1.20.1-150400.3.9.1 * libgstadaptivedemux-1_0-0-1.20.1-150400.3.9.1 * libgstsctp-1_0-0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-1.20.1-150400.3.9.1 * libgstinsertbin-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.9.1 * libgstva-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstPlay-1_0-1.20.1-150400.3.9.1 * libgstwebrtc-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgstbadaudio-1_0-0-debuginfo-1.20.1-150400.3.9.1 * libgsturidownloader-1_0-0-1.20.1-150400.3.9.1 * libgstva-1_0-0-1.20.1-150400.3.9.1 * libgstwayland-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstBadAudio-1_0-1.20.1-150400.3.9.1 * libgstisoff-1_0-0-1.20.1-150400.3.9.1 *libgstcodecparsers-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.9.1 * libgstvulkan-1_0-0-debuginfo-1.20.1-150400.3.9.1 * typelib-1_0-GstMpegts-1_0-1.20.1-150400.3.9.1 * Desktop Applications Module 15-SP4 (noarch) * gstreamer-plugins-bad-lang-1.20.1-150400.3.9.1 * SUSE Package Hub 15 15-SP4 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-debugsource-1.20.1-150400.3.9.1 * libgsttranscoder-1_0-0-1.20.1-150400.3.9.1 * libgsttranscoder-1_0-0-debuginfo-1.20.1-150400.3.9.1 * gstreamer-plugins-bad-debuginfo-1.20.1-150400.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40474.html * https://www.suse.com/security/cve/CVE-2023-40476.html * https://bugzilla.suse.com/show_bug.cgi?id=1215793 * https://bugzilla.suse.com/show_bug.cgi?id=1215796 . Important security update for gstreamer-plugins-bad addresses major vulnerabilities in multiple SUSE editions.. GStreamer Plugins, SUSE Security Update, Software Vulnerability, Patch Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 27, 2023 Important SuSE
202

openSUSE 15.3: 2023:4174-1 Important: Xen Crash Issues Fix

This update for xen fixes the following issues: CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744).. # Security update for xen Announcement ID: SUSE-SU-2023:4174-1 Rating: important References: * bsc#1215744 * bsc#1215746 * bsc#1215747 * bsc#1215748 Cross-References: * CVE-2023-34323 * CVE-2023-34325 * CVE-2023-34326 * CVE-2023-34327 * CVE-2023-34328 CVSS scores: * CVE-2023-34323 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-34325 ( SUSE ): 5.5 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2023-34326 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-34327 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-34328 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Proxy 4.2 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Server 4.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2023-34323: Fixed a potential crash in C Xenstored due to an incorrect assertion (XSA-440) (bsc#1215744). * CVE-2023-34326: Fixed a missing IOMMU TLB flush on x86 AMD systems with IOMMU hardware and PCI passthrough enabled (XSA-442) (bsc#1215746). * CVE-2023-34325: Fixed multiple parsing issues in libfsimage (XSA-443) (bsc#1215747). * CVE-2023-34327, CVE-2023-34328: Fixed multipleissues with AMD x86 debugging functionality for guests (XSA-444) (bsc#1215748). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2023-4174=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4174=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4174=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4174=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4174=1 * SUSE Manager Proxy 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.2-2023-4174=1 * SUSE Manager Retail Branch Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.2-2023-4174=1 * SUSE Manager Server 4.2 zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.2-2023-4174=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4174=1 * SUSE Linux Enterprise Micro 5.1 zypper in -t patch SUSE-SUSE-MicroOS-5.1-2023-4174=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4174=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2023-4174=1 ## Package List: * openSUSE Leap 15.3 (aarch64 x86_64 i586) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 *xen-devel-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (x86_64) * xen-libs-32bit-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-32bit-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (aarch64 x86_64) * xen-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-doc-html-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * openSUSE Leap 15.3 (aarch64_ilp32) * xen-libs-64bit-4.14.6_06-150300.3.57.1 * xen-libs-64bit-debuginfo-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 *xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Proxy 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Proxy 4.2 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Retail Branch Server 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Retail Branch Server 4.2 (noarch) *xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Manager Server 4.2 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Manager Server 4.2 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Enterprise Storage 7.1 (x86_64) * xen-tools-domU-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-tools-domU-4.14.6_06-150300.3.57.1 * xen-tools-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * xen-devel-4.14.6_06-150300.3.57.1 * xen-4.14.6_06-150300.3.57.1 * SUSE Enterprise Storage 7.1 (noarch) * xen-tools-xendomains-wait-disk-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro 5.1 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro 5.2 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (x86_64) * xen-libs-debuginfo-4.14.6_06-150300.3.57.1 * xen-libs-4.14.6_06-150300.3.57.1 * xen-debugsource-4.14.6_06-150300.3.57.1 ## References: * https://www.suse.com/security/cve/CVE-2023-34323.html * https://www.suse.com/security/cve/CVE-2023-34325.html * https://www.suse.com/security/cve/CVE-2023-34326.html * https://www.suse.com/security/cve/CVE-2023-34327.html * https://www.suse.com/security/cve/CVE-2023-34328.html * https://bugzilla.suse.com/show_bug.cgi?id=1215744 *https://bugzilla.suse.com/show_bug.cgi?id=1215746 * https://bugzilla.suse.com/show_bug.cgi?id=1215747 * https://bugzilla.suse.com/show_bug.cgi?id=1215748 . Urgent advisory for openSUSE regarding significant vulnerabilities in xen that could lead to system instability and various parsing failures. Ensure you update immediately.. xen Security Update, openSUSE Update, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 24, 2023 Important OpenSUSE
199

CentOS 6 CESA-2020-2613 Important: Thunderbird Security Update

Upstream details at : https://access.redhat.com/errata/RHSA-2020:2613. CentOS Errata and Security Advisory 2020:2613 Important Upstream details at : https://access.redhat.com/errata/RHSA-2020:2613 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) i386: a3c0238b4566d90fd029bc2edabb1b0c27a40c7833397c2c0f1a954f7baee5bb thunderbird-68.9.0-1.el6.centos.i686.rpm x86_64: 42720ce2acc09a86bfe1d5b0b1343be2bb52dae65776683e8163086419f5f825 thunderbird-68.9.0-1.el6.centos.x86_64.rpm Source: b9c6e2e8e9f5ddbde45f72058b6ddb4ded9ff2d7ddbbd7f1f3c240d83fddb200 thunderbird-68.9.0-1.el6.centos.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-2021-1503 offers essential patches for Firefox, enhancing overall stability.. CentOS Advisory, Thunderbird Update, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 19, 2020 Important CentOS
89

Fedora: 2018-2c965abb15 Critical: DPDK Data Exposure Issue

Update to latest 17.11 LTS (fixes bz 1571352). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2c965abb15 2018-05-25 15:04:57.639208 --------------------------------------------------------------------------------Name : dpdk Product : Fedora 28 Version : 17.11.2 Release : 1.fc28 URL : https://www.dpdk.org/ Summary : Set of libraries and drivers for fast packet processing Description : The Data Plane Development Kit is a set of libraries and drivers for fast packet processing in the user space. --------------------------------------------------------------------------------Update Information: Update to latest 17.11 LTS (fixes bz 1571352) --------------------------------------------------------------------------------ChangeLog: * Tue Apr 24 2018 Neil Horman - 2:17.11.2-1 - Update to latest 17.11 LTS (fixes bz 1571352) * Tue Apr 10 2018 Timothy Redaelli - 2:17.11.1-2 - Fix Requires dpdk by adding epoch (bz 1564215) * Mon Apr 9 2018 Neil Horman - 17.11.1-1 - sync rawhide updates (including LTS shift) with f28 (bz 1564215) * Thu Apr 5 2018 Neil Horman - 18.02-6 - Remove some debug checks (bz 1548404) * Thu Apr 5 2018 Neil Horman - 18.02-5 - Fix compiler flag error (bz 1548404) * Tue Mar 20 2018 Neil Horman - 18.02-4 - Update ldflags (bz 1548404) - bump release to keep it in line with rawhide --------------------------------------------------------------------------------References: [ 1 ] Bug #1571352 - CVE-2018-1059 dpdk: Information exposure in unchecked guest physical to host virtual address translations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1571352 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-2c965abb15' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/CTAUWRKCKA6VXWDRDGQST6C5CVCDKNKK/ . Critical vulnerability alert for Fedora's dpdk, concerning potential data leakage due to improper validation of address translations.. Fedora Security, dpdk Update, Fast Packet Processing, Information Exposure, Linux Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 25, 2018 Critical Fedora
200

Critical Alert for Scientific Linux 5x: SLSA-2014:0594-1 GnuTLS Issue

Important: gnutls security update. Date: Tue, 3 Jun 2014 09:02:41 -0500 Reply-To: Bonnie King Sender: Security Errata for Scientific Linux From: Bonnie King Subject: FASTBUGS for SL 5x i386, x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. In-Reply-To: MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: gfs2-utils-0.1.62-39.el5_10.3.i386.rpm java-1.7.0-openjdk-1.7.0.55-2.4.7.2.el5_10.i386.rpm java-1.7.0-openjdk-demo-1.7.0.55-2.4.7.2.el5_10.i386.rpm java-1.7.0-openjdk-devel-1.7.0.55-2.4.7.2.el5_10.i386.rpm java-1.7.0-openjdk-javadoc-1.7.0.55-2.4.7.2.el5_10.i386.rpm java-1.7.0-openjdk-src-1.7.0.55-2.4.7.2.el5_10.i386.rpm tzdata-2014d-1.el5.i386.rpm tzdata-java-2014d-1.el5.i386.rpm x86_64: gfs2-utils-0.1.62-39.el5_10.3.x86_64.rpm java-1.7.0-openjdk-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm java-1.7.0-openjdk-javadoc-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm java-1.7.0-openjdk-src-1.7.0.55-2.4.7.2.el5_10.x86_64.rpm Date: Tue, 3 Jun 2014 09:02:56 -0500 Reply-To: Bonnie King Sender: Security Errata for Scientific Linux From: Bonnie King Subject: FASTBUGS for SL 6x i386, x86_64 now available Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. In-Reply-To: MIME-Version: 1.0 The following FASTBUGS have been uploadedto i386: 389-ds-base-1.2.11.15-33.el6_5.i686.rpm 389-ds-base-devel-1.2.11.15-33.el6_5.i686.rpm 389-ds-base-libs-1.2.11.15-33.el6_5.i686.rpm audispd-plugins-2.2-4.el6_5.i686.rpm audit-2.2-4.el6_5.i686.rpm audit-libs-2.2-4.el6_5.i686.rpm audit-libs-devel-2.2-4.el6_5.i686.rpm audit-libs-python-2.2-4.el6_5.i686.rpm audit-libs-static-2.2-4.el6_5.i686.rpm finger-0.17-40.el6.i686.rpm finger-server-0.17-40.el6.i686.rpm gettext-0.17-18.el6.i686.rpm gettext-devel-0.17-18.el6.i686.rpm gettext-libs-0.17-18.el6.i686.rpm gvfs-1.4.3-16.el6_5.i686.rpm gvfs-afc-1.4.3-16.el6_5.i686.rpm gvfs-archive-1.4.3-16.el6_5.i686.rpm gvfs-devel-1.4.3-16.el6_5.i686.rpm gvfs-fuse-1.4.3-16.el6_5.i686.rpm gvfs-gphoto2-1.4.3-16.el6_5.i686.rpm gvfs-obexftp-1.4.3-16.el6_5.i686.rpm gvfs-smb-1.4.3-16.el6_5.i686.rpm ibus-table-1.2.0.20100111-5.el6.noarch.rpm ibus-table-additional-1.2.0.20100111-5.el6.noarch.rpm ibus-table-devel-1.2.0.20100111-5.el6.noarch.rpm iproute-2.6.32-32.el6_5.i686.rpm iproute-devel-2.6.32-32.el6_5.i686.rpm iproute-doc-2.6.32-32.el6_5.i686.rpm openmotif-2.3.3-7.1.el6_5.i686.rpm openmotif-devel-2.3.3-7.1.el6_5.i686.rpm pango-1.28.1-10.el6.i686.rpm pango-devel-1.28.1-10.el6.i686.rpm perl-WWW-Curl-4.09-4.el6.i686.rpm tzdata-2014d-1.el6.noarch.rpm tzdata-java-2014d-1.el6.noarch.rpm x86_64: 389-ds-base-1.2.11.15-33.el6_5.x86_64.rpm 389-ds-base-devel-1.2.11.15-33.el6_5.i686.rpm 389-ds-base-devel-1.2.11.15-33.el6_5.x86_64.rpm 389-ds-base-libs-1.2.11.15-33.el6_5.i686.rpm 389-ds-base-libs-1.2.11.15-33.el6_5.x86_64.rpm audispd-plugins-2.2-4.el6_5.x86_64.rpm audit-2.2-4.el6_5.x86_64.rpm audit-libs-2.2-4.el6_5.i686.rpm audit-libs-2.2-4.el6_5.x86_64.rpm audit-libs-devel-2.2-4.el6_5.i686.rpm audit-libs-devel-2.2-4.el6_5.x86_64.rpm audit-libs-python-2.2-4.el6_5.x86_64.rpm audit-libs-static-2.2-4.el6_5.x86_64.rpm finger-0.17-40.el6.x86_64.rpm finger-server-0.17-40.el6.x86_64.rpm gettext-0.17-18.el6.i686.rpm gettext-0.17-18.el6.x86_64.rpm gettext-devel-0.17-18.el6.i686.rpm gettext-devel-0.17-18.el6.x86_64.rpm gettext-libs-0.17-18.el6.i686.rpm gettext-libs-0.17-18.el6.x86_64.rpm gvfs-1.4.3-16.el6_5.i686.rpm gvfs-1.4.3-16.el6_5.x86_64.rpm gvfs-afc-1.4.3-16.el6_5.x86_64.rpm gvfs-archive-1.4.3-16.el6_5.x86_64.rpm gvfs-devel-1.4.3-16.el6_5.i686.rpm gvfs-devel-1.4.3-16.el6_5.x86_64.rpm gvfs-fuse-1.4.3-16.el6_5.x86_64.rpm gvfs-gphoto2-1.4.3-16.el6_5.x86_64.rpm gvfs-obexftp-1.4.3-16.el6_5.x86_64.rpm gvfs-smb-1.4.3-16.el6_5.x86_64.rpm ibus-table-1.2.0.20100111-5.el6.noarch.rpm ibus-table-additional-1.2.0.20100111-5.el6.noarch.rpm ibus-table-devel-1.2.0.20100111-5.el6.noarch.rpm iproute-2.6.32-32.el6_5.x86_64.rpm iproute-devel-2.6.32-32.el6_5.i686.rpm iproute-devel-2.6.32-32.el6_5.x86_64.rpm iproute-doc-2.6.32-32.el6_5.x86_64.rpm openmotif-2.3.3-7.1.el6_5.i686.rpm openmotif-2.3.3-7.1.el6_5.x86_64.rpm openmotif-devel-2.3.3-7.1.el6_5.i686.rpm openmotif-devel-2.3.3-7.1.el6_5.x86_64.rpm pango-1.28.1-10.el6.i686.rpm pango-1.28.1-10.el6.x86_64.rpm pango-devel-1.28.1-10.el6.i686.rpm pango-devel-1.28.1-10.el6.x86_64.rpm perl-WWW-Curl-4.09-4.el6.x86_64.rpm tzdata-2014d-1.el6.noarch.rpm tzdata-java-2014d-1.el6.noarch.rpm Date: Tue, 3 Jun 2014 17:12:32 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: gnutls on SL5.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: gnutls security update Advisory ID: SLSA-2014:0594-1 Issue Date: 2014-06-03 CVE Numbers: CVE-2014-3466 CVE-2014-3467 CVE-2014-3468 CVE-2014-3469 -- A flaw was found in the way GnuTLS parsed session IDs from ServerHello messages of the TLS/SSL handshake. A malicious server could use this flaw to send an excessively long session ID value, which would trigger a buffer overflow in a connecting TLS/SSL client application using GnuTLS, causing the client application to crash or, possibly, execute arbitrary code. (CVE-2014-3466) It was discovered that the asn1_get_bit_der() function of the libtasn1 library incorrectly reported the length of ASN.1-encoded data. Specially crafted ASN.1 input could cause an applicationusing libtasn1 to perform an out-of-bounds access operation, causing the application to crash or, possibly, execute arbitrary code. (CVE-2014-3468) Multiple incorrect buffer boundary check issues were discovered in libtasn1. Specially crafted ASN.1 input could cause an application using libtasn1 to crash. (CVE-2014-3467) Multiple NULL pointer dereference flaws were found in libtasn1's asn1_read_value() function. Specially crafted ASN.1 input could cause an application using libtasn1 to crash, if the application used the aforementioned function in a certain way. (CVE-2014-3469) For the update to take effect, all applications linked to the GnuTLS or libtasn1 library must be restarted. -- SL5 x86_64 gnutls-1.4.1-16.el5_10.i386.rpm gnutls-1.4.1-16.el5_10.x86_64.rpm gnutls-debuginfo-1.4.1-16.el5_10.i386.rpm gnutls-debuginfo-1.4.1-16.el5_10.x86_64.rpm gnutls-utils-1.4.1-16.el5_10.x86_64.rpm gnutls-devel-1.4.1-16.el5_10.i386.rpm gnutls-devel-1.4.1-16.el5_10.x86_64.rpm i386 gnutls-1.4.1-16.el5_10.i386.rpm gnutls-debuginfo-1.4.1-16.el5_10.i386.rpm gnutls-utils-1.4.1-16.el5_10.i386.rpm gnutls-devel-1.4.1-16.el5_10.i386.rpm - Scientific Linux Development Team . Significant OpenSSL security patch for CentOS addresses severe memory leak vulnerabilities and potential threats.. gnutls security update, scientific linux advisory, gnutls critical fix, buffer overflow risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 03, 2014 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here