Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia: 2021-0551 Moderate: Firefox Memory Corruption and Spoofing Risks

Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL (CVE-2021-43536). An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash due to a . MGASA-2021-0551 - Updated firefox packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0551.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43536, CVE-2021-43537, CVE-2021-43538, CVE-2021-43539, CVE-2021-43541, CVE-2021-43542, CVE-2021-43543, CVE-2021-43545, CVE-2021-43546 Under certain circumstances, asynchronous functions could have caused a navigation to fail but expose the target URL (CVE-2021-43536). An incorrect type conversion of sizes from 64bit to 32bit integers allowed an attacker to corrupt memory leading to a potentially exploitable crash due to a heap buffer overflow when using structured clone (CVE-2021-43537). By misusing a race in our notification code, an attacker could have forcefully hidden the notification for pages that had received both full screen and pointer lock access, which could have been used for spoofing attacks (CVE-2021-43538). Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash (CVE-2021-43539). When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped (CVE-2021-43541). Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols (CVE-2021-43542). Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content (CVE-2021-43543). Using the Location API in a loopcould have caused severe application hangs and crashes (CVE-2021-43545). It was possible to recreate previous cursor spoofing attacks against userswith a zoomed native cursor (CVE-2021-43546). Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox ESR 91.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (MOZ-2021-0009). References: - https://bugs.mageia.org/show_bug.cgi?id=29734 - https://www.mozilla.org/en-US/security/advisories/mfsa2021-53/ - https://access.redhat.com/errata/RHSA-2021:5013 - https://www.cve.org/CVERecord?id=CVE-2021-43536 - https://www.cve.org/CVERecord?id=CVE-2021-43537 - https://www.cve.org/CVERecord?id=CVE-2021-43538 - https://www.cve.org/CVERecord?id=CVE-2021-43539 - https://www.cve.org/CVERecord?id=CVE-2021-43541 - https://www.cve.org/CVERecord?id=CVE-2021-43542 - https://www.cve.org/CVERecord?id=CVE-2021-43543 - https://www.cve.org/CVERecord?id=CVE-2021-43545 - https://www.cve.org/CVERecord?id=CVE-2021-43546 SRPMS: - 8/core/firefox-91.4.0-1.mga8 - 8/core/firefox-l10n-91.4.0-1.mga8 . The security notice MGASA-2021-0551 regarding the Firefox update for Mageia highlights urgent vulnerabilities that must be addressed without delay.. Mageia Firefox Memory, Memory Corruption Risks, Firefox Security Update. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Dec 10, 2021 Medium Mageia
200

Scientific Linux: 2009-01-08 Moderate: BIND Spoofing Risk Advisory

Moderate: bind security update. Date: Thu, 8 Jan 2009 16:08:24 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for bind on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: bind security update Issue date: 2009-01-08 CVE Names: CVE-2009-0025 A flaw was discovered in the way BIND checked the return value of the OpenSSL DSA_do_verify function. On systems using DNSSEC, a malicious zone could present a malformed DSA certificate and bypass proper certificate validation, allowing spoofing attacks. (CVE-2009-0025) For users of Red Hat Enterprise Linux 3 this update also addresses a bug which can cause BIND to occasionally exit with an assertion failure. After installing theupdate, BIND daemon will be restarted automatically. SL 3.0.x SRPMS: bind-9.2.4-23.el3.src.rpm i386: bind-9.2.4-23.el3.i386.rpm bind-chroot-9.2.4-23.el3.i386.rpm bind-devel-9.2.4-23.el3.i386.rpm bind-libs-9.2.4-23.el3.i386.rpm bind-utils-9.2.4-23.el3.i386.rpm x86_64: bind-9.2.4-23.el3.x86_64.rpm bind-chroot-9.2.4-23.el3.x86_64.rpm bind-devel-9.2.4-23.el3.x86_64.rpm bind-libs-9.2.4-23.el3.x86_64.rpm bind-utils-9.2.4-23.el3.x86_64.rpm SL 4.x SRPMS: bind-9.2.4-30.el4_7.1.src.rpm i386: bind-9.2.4-30.el4_7.1.i386.rpm bind-chroot-9.2.4-30.el4_7.1.i386.rpm bind-devel-9.2.4-30.el4_7.1.i386.rpm bind-libs-9.2.4-30.el4_7.1.i386.rpm bind-utils-9.2.4-30.el4_7.1.i386.rpm x86_64: bind-9.2.4-30.el4_7.1.x86_64.rpm bind-chroot-9.2.4-30.el4_7.1.x86_64.rpm bind-devel-9.2.4-30.el4_7.1.x86_64.rpm bind-libs-9.2.4-30.el4_7.1.i386.rpm bind-libs-9.2.4-30.el4_7.1.x86_64.rpm bind-utils-9.2.4-30.el4_7.1.x86_64.rpm SL 5.x SRPMS: bind-9.3.4-6.0.3.P1.el5_2.src.rpm i386: bind-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-chroot-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-devel-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-libbind-devel-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-libs-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-sdb-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-utils-9.3.4-6.0.3.P1.el5_2.i386.rpm caching-nameserver-9.3.4-6.0.3.P1.el5_2.i386.rpm x86_64: bind-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-chroot-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-devel-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-devel-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-libbind-devel-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-libbind-devel-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-libs-9.3.4-6.0.3.P1.el5_2.i386.rpm bind-libs-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-sdb-9.3.4-6.0.3.P1.el5_2.x86_64.rpm bind-utils-9.3.4-6.0.3.P1.el5_2.x86_64.rpm caching-nameserver-9.3.4-6.0.3.P1.el5_2.x86_64.rpm -Connie Sieh -Troy Dawson . BIND undergoes a significant security enhancement aimed at addressing a vulnerability associated with flawed certificate authentication.. BIND Update, Scientific Linux Security, Bind Security Advisory. . LinuxSecurity.com Team

Calendar 2 Jan 08, 2009 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here