Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 7 & 8: 2021-0293 Critical: Tor Spoofing and DoS Threats

Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell on half-closed streams. Previously, clients failed to validate which hop sent these cells: this would allow a relay on a circuit to end a stream that wasn't actually built with it (CVE-2021-34548). . MGASA-2021-0293 - Updated tor package fixes security vulnerabilities Publication date: 28 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0293.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-34548, CVE-2021-34549, CVE-2021-34550 Don't allow relays to spoof RELAY_END or RELAY_RESOLVED cell on half-closed streams. Previously, clients failed to validate which hop sent these cells: this would allow a relay on a circuit to end a stream that wasn't actually built with it (CVE-2021-34548). hashtable-based CPU denial-of-service attack against relays (CVE-2021-34549). out-of-bounds memory access in v3 onion service descriptor parsing (CVE-2021-34550). See also upstream release notes for included other bugfixes. This package also fixes an error in tor package's un-install script (mga#29158). References: - https://bugs.mageia.org/show_bug.cgi?id=29136 - https://bugs.mageia.org/show_bug.cgi?id=29158 - https://blog.torproject.org/new-stable-security-releases-03515-0449-0459-0465/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/RST7YTNTKJURIR2QVIJMEBXWW2YHETRX/ - https://www.cve.org/CVERecord?id=CVE-2021-34548 - https://www.cve.org/CVERecord?id=CVE-2021-34549 - https://www.cve.org/CVERecord?id=CVE-2021-34550 SRPMS: - 8/core/tor-0.3.5.15-1.1.mga8 - 7/core/tor-0.3.5.15-1.1.mga7 . An important security patch for the firefox package on Fedora tackling various security flaws released on 15 Jul 2021.. Mageia Security Update, Tor Spoofing Issue, Denial of Service Attack, Memory Access Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 28, 2021 Critical Mageia
87

Debian Wheezy: DSA-3492-2 Moderate: Gajim Dependency Spoofing Risk

The wheezy part of the previous gajim update, DSA-3492-1, was incorrectly built resulting in an unsatisfiable dependency. This update corrects that problem. For reference, the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3492-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso February 28, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gajim Debian Bug : 816158 The wheezy part of the previous gajim update, DSA-3492-1, was incorrectly built resulting in an unsatisfiable dependency. This update corrects that problem. For reference, the original advisory text follows. Daniel Gultsch discovered a vulnerability in Gajim, an XMPP/jabber client. Gajim didn't verify the origin of roster update, allowing an attacker to spoof them and potentially allowing her to intercept messages. For the oldstable distribution (wheezy), this problem has been fixed in version 0.15.1-4.1+deb7u2. We recommend that you upgrade your gajim packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-3492-2 highlights a dependency problem in gajim stemming from a flawed build process.. Gajim Security Update, Debian Wheezy Advisory, Security Flaws. . LinuxSecurity.com Team

Calendar 2 Feb 28, 2016 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here