Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 21.10 USN-5145-1 Moderate: PostgreSQL Network Access Issue

PostgreSQL could allow unintended access to network services.. =========================================================================Ubuntu Security Notice USN-5145-1 November 11, 2021 postgresql-10, postgresql-12, postgresql-13 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: PostgreSQL could allow unintended access to network services. Software Description: - postgresql-13: Object-relational SQL database - postgresql-12: Object-relational SQL database - postgresql-10: Object-relational SQL database Details: Jacob Champion discovered that PostgreSQL incorrectly handled SSL certificate verification and encryption. A remote attacker could possibly use this issue to inject arbitrary SQL queries when a connection is first established. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: postgresql-13 13.5-0ubuntu0.21.10.1 Ubuntu 21.04: postgresql-13 13.5-0ubuntu0.21.04.1 Ubuntu 20.04 LTS: postgresql-12 12.9-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: postgresql-10 10.19-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5145-1 CVE-2021-23214, CVE-2021-23222 Package Information: https://launchpad.net/ubuntu/+source/postgresql-13/13.5-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/postgresql-13/13.5-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/postgresql-12/12.9-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/postgresql-10/10.19-0ubuntu0.18.04.1 . Uncover how utilizing PostgreSQL on Ubuntumight unintentionally grant unauthorized network entry. Explore the risks and their remedies.. PostgreSQL vulnerabilities, Ubuntu security notice, network service access, SSL certificate issues, software updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 11, 2021 Important Ubuntu
89

Fedora 25 sscg Security Update 2017-19b5c9f1c6: Critical SSL Enhancements

Update to the latest upstream release. This release reduces dependencies considerably and tightens security. It is recommended that everyone upgrade to this release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-19b5c9f1c6 2017-03-17 13:16:04.566682 -------------------------------------------------------------------------------- Name : sscg Product : Fedora 25 Version : 2.0.3 Release : 1.fc25 URL : https://github.com/sgallagher/sscg Summary : Simple SSL certificate generator Description : A utility to aid in the creation of more secure "self-signed" certificates. The certificates created by this tool are generated in a way so as to create a CA certificate that can be safely imported into a client machine to trust the service certificate without needing to set up a full PKI environment and without exposing the machine to a risk of false signatures from the service certificate. -------------------------------------------------------------------------------- Update Information: Update to the latest upstream release. This release reduces dependencies considerably and tightens security. It is recommended that everyone upgrade to this release. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sscg' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The latestFedora 25 sscg update boosts protection through dependency minimization. Users are advised to upgrade for better security.. Fedora 25 Update, sscg Security Patch, Software Security Update, SSL Certificate Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 17, 2017 Critical Fedora
87

Debian: DSA-2798-1 Critical Curl SSL Issue - Remote Threat

Scott Cantor discovered that curl, a file retrieval tool, would disable the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting was disabled. This would also disable ssl certificate host name checks when it should have only disabled verification of the certificate trust . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2798-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Gilbert November 17, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : curl Vulnerability : unchecked ssl certificate host name Problem type : remote Debian-specific: no CVE ID : CVE-2013-4545 Scott Cantor discovered that curl, a file retrieval tool, would disable the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting was disabled. This would also disable ssl certificate host name checks when it should have only disabled verification of the certificate trust chain. The default configuration for the curl package is not affected by this issue since CURLOPT_SSLVERIFYPEER is enabled by default. For the oldstable distribution (squeeze), this problem has been fixed in version 7.21.0-2.1+squeeze5. For the stable distribution (wheezy), this problem has been fixed in version 7.26.0-1+wheezy5. For the testing (jessie) and unstable (sid) distributions, this problem has been fixed in version 7.33.0-1. We recommend that you upgrade your curl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5100-1 details a vital OpenSSL vulnerability resolution. Ensure your safety by performing an update.. curl update, Debian security, ssl issue. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Nov 17, 2013 Critical Debian
87

Debian: DSA-2200-1 Critical: nss Compromised Certificate Issue

Several unauthorised SSL certificates have been found in the wild issued for the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2200-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff August 31, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nss Vulnerability : comprimised certificate authority Problem type : local(remote) Debian-specific: no CVE ID : not available Several unauthorised SSL certificates have been found in the wild issued for the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar Root CA by default in the NSS crypto libraries. For the oldstable distribution (lenny), this problem has been fixed in version 3.12.3.1-0lenny5. For the stable distribution (squeeze), this problem has been fixed in version 3.12.8-1+squeeze2. For the unstable distribution (sid), this problem has been fixed in version 3.12.11-2. We recommend that you upgrade your nss packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-2201-2 addresses vulnerabilities in the openSSL package prompted by insecure certificate validation relating to Symantec certificates.. Debian Security Advisory,nss Package Update,DigiNotar SSL Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 31, 2011 Critical Debian
87

Debian: DSA-2299-1 Critical Advisory: Disable DigiNotar CA

An unauthorized SSL certificate has been found in the wild issued the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2299-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst August 31, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ca-certificates Vulnerability : comprimised certificate authority Problem type : local/remote Debian-specific: no Debian Bug : 639744 An unauthorized SSL certificate has been found in the wild issued the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar Root CA by default in its ca-certificates bundle. For other software in Debian that ships a CA bundle, like the Mozilla suite, updates are forthcoming. For the oldstable distribution (lenny), the ca-certificates package does not contain this root CA. For the stable distribution (squeeze), the root CA has been disabled starting ca-certificates version 20090814+nmu3. For the testing distribution (wheezy) and unstable distribution (sid), the root CA has been disabled starting ca-certificates version 20110502+nmu1. We recommend that you upgrade your ca-certificates packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . An unapproved SSL certificate issued by DigiNotar has prompted Debian to remove it through a ca-certificates revision. Immediate attention advised.. DigiNotar Compromise,Debian Security Advisory, CA Certificates Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 31, 2011 Critical Debian
89

Fedora 11: FEDORA-2009-11740 Critical Wget SSL Certificate Issue

. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-11740 2009-11-20 04:23:22 -------------------------------------------------------------------------------- Name : wget Product : Fedora 11 Version : 1.12 Release : 2.fc11 URL : Summary : A utility for retrieving files using the HTTP or FTP protocols Description : GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 18 2009 Karsten Hopp 1.12-2 - don't provide /usr/share/info/dir * Tue Nov 17 2009 Karsten Hopp 1.12-1 - update to wget-1.12 - fixes CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name * Fri Aug 21 2009 Tomas Mraz - 1.11.4-5 - rebuilt with new openssl * Mon Jul 27 2009 Fedora Release Engineering - 1.11.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #520454 - CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name https://bugzilla.redhat.com/show_bug.cgi?id=520454 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wget' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Critical security patch released for Fedora 11 addressing vulnerabilities in wget's SSL certificate handling.. Fedora Update, Wget Security, SSL Fix, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 03, 2009 Critical Fedora
87

Debian DSA-1943-1 Critical: OpenLDAP SSL Certificate Spoofing

It was discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1943 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano December 02, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Packages : openldap openldap2.3 Vulnerability : insufficient input validation Problem type : remote Debian-specific: no Debian bug : 553432 CVE ID : CVE-2009-3767 It was discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. For the oldstable distribution (etch), this problem has been fixed in version 2.3.30-5+etch3 for openldap2.3. For the stable distribution (lenny), this problem has been fixed in version 2.4.11-1+lenny1 for openldap. For the testing distribution (squeeze), and the unstable distribution (sid), this problem has been fixed in version 2.4.17-2.1 for openldap. We recommend that you upgrade your openldap2.3/openldap packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-getupgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 2971126 c40bcc23fa65908b8d7a86a4a6061251 Size/MD5 checksum: 1214 36efc1cf2a98c54d4b1da0910e273843 Size/MD5 checksum: 315058 310ce752b78ff3227d78dcd8c1bd60a5 alpha architecture (DEC Alpha) Size/MD5 checksum: 293108 2172048d5f8b8b7f379b3414fc5c2e37 Size/MD5 checksum: 1280772 ab65f162a40607c1787f9b03783a7563 Size/MD5 checksum: 193768 602a6da790648dd8b0af7d9f386b5c6e amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 285554 42480b47018eb1d70b9e62d05b925a5b Size/MD5 checksum: 1244570 b88256f8259516b09c51f166ff6b4aea Size/MD5 checksum: 184652 716cc53985a031d1fe03fede778d6ae5 arm architecture (ARM) Size/MD5 checksum: 1190314 8686c6a9a9240e6113f92c8bb20d7e1a Size/MD5 checksum: 254828 49d9c9a250fb4a5a828de5791ee92380 Size/MD5 checksum: 155876 bb45d3104fe4b9811fdb3063da42d3b1 hppa architecture (HP PA RISC) Size/MD5 checksum: 1307146 698d7416e4cc544522ce2e25ac9c0fce Size/MD5 checksum: 292798 eb9d6d19560a1153cc58ccae3f354a4e Size/MD5 checksum: 182568 caade74265ee9d7b8ac77c844c23b413 i386 architecture (Intel ia32) Size/MD5 checksum: 1177552 f3ccf11b82474593af5e30a272f9edb9 Size/MD5 checksum: 148744 168e58797e74f9b3b6d3c337b6369ca7 Size/MD5 checksum: 266538 3be52b8402d06913624a3e808be58ecb ia64 architecture (Intel ia64) Size/MD5 checksum: 239248 78d1537b3a106824ff5d076e828a0312 Size/MD5 checksum: 379904 dbc96e1a44dce4bb5f79b9c043823293 Size/MD5 checksum: 1660854 fcc2873ffd50e45c956d9bcc81d83c51 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 258210 298f5a83a1efd8c035644fd58df21f2c Size/MD5 checksum: 185598 b6c67ee072f2de03820e7ce11edb39c3 Size/MD5 checksum: 1205768 3f312958af5ea129384513e5fab72208 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 258852 d7ba57787989e3fb5035fce34b04965d Size/MD5 checksum: 187100 46910e3923926ac060c13a7a53f8cac4 Size/MD5 checksum: 1188878 5698884b42d7206c2b0c134602861354 powerpc architecture (PowerPC) Size/MD5 checksum: 188914 e03855167b8e13bdb72e47baa9644f86 Size/MD5 checksum: 272378 f5741b7ac8f4172e7481f5c2e699231b Size/MD5 checksum: 1243754 2a8b933e956e5ac4bc29028688bb09ec s390 architecture (IBM S/390) Size/MD5 checksum: 291822 6b47ac5b7fbc269c1973c494d5dadbc2 Size/MD5 checksum: 168716 f72b023d98d61565c624f7acbf953baf Size/MD5 checksum: 1241532 0167eb506b063de5435181f40c6cf809 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 1177712 770a58d0c60ad11e5ca4cf25159fe2c7 Size/MD5 checksum: 153682 d8bf20f2a94456451d4ea29d3237d280 Size/MD5 checksum: 258560 4bfd77d56852608813f158ecfd91b42b Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 148075 024b717169f42734ee5650ebe2978631 Size/MD5 checksum: 1831 ca4cb86b4847a59f95275ff2f4d0e173 Size/MD5 checksum: 4193523 d4e8669e2c9b8d981e371e97e3cf92d9 alpha architecture (DEC Alpha) Size/MD5 checksum: 3624752 5b4e467360ecd8cc897b03b5aca57dad Size/MD5 checksum: 205526 3b083869976ab4d8d8df69d27fe9480e Size/MD5 checksum: 280526 4ed333757fef7e98d89c5edda6589b04 Size/MD5 checksum: 1537448 98d6aeab748560a491e0b526d930fc0c Size/MD5 checksum: 1013148 cc656603f7ae0eacc2b3c22dd1fae967 Size/MD5 checksum: 285128 e526e547a4af2c13bf3ae90dfdf023a2 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 1493300 31c077d63cc2ff159927939cadb29808 Size/MD5 checksum: 299612e148216f77a9136adb19acd8df026d6d Size/MD5 checksum: 267470 f903f46433faa1d2b6b203e50aaed3d8 Size/MD5 checksum: 881074 de337737dd93af0b81bd90e3c6f23377 Size/MD5 checksum: 3664994 8ad4581bd54e1ed7a8f3c1c8bf210c17 Size/MD5 checksum: 204896 c0dba3b62aa14392d29f831d6c87206d arm architecture (ARM) Size/MD5 checksum: 280140 ccaed923684d35304f50f27fc6b868b3 Size/MD5 checksum: 248918 a08cf9fd18ce8806be437c364179c2b3 Size/MD5 checksum: 877400 614df898211cc5311a62159f6ee21b93 Size/MD5 checksum: 1405962 5e1e62d6f0a5984486fa2eaa478eab38 Size/MD5 checksum: 180520 96b5fe5d50b9a1d59eb5ab03489a1b90 Size/MD5 checksum: 3572646 a8e804a9e966a57306a9229acd11ff80 hppa architecture (HP PA RISC) Size/MD5 checksum: 1533292 8d5c2d83596b10c9d3ee7a4dcb692026 Size/MD5 checksum: 3619256 2ad8452962291b553fadc8bb6398f834 Size/MD5 checksum: 200874 27205d8a86701cb133f7507eeef5e76a Size/MD5 checksum: 283816 1163f67e39b08c10cf492b24bd526f24 Size/MD5 checksum: 264158 905749f1e385f9d93c2358b05dc42dfb Size/MD5 checksum: 999386 6a071952604a9c30483fca7f3a3754ec i386 architecture (Intel ia32) Size/MD5 checksum: 189442 879dac84b581979646c49bde9743c630 Size/MD5 checksum: 286808 2dcb4f8e5514d9e4d9072b4853da322d Size/MD5 checksum: 892068 449ba5d6037617e4e93dfd6bcb093549 Size/MD5 checksum: 3560322 c6a6fbc66944bd05585c1065ab012c93 Size/MD5 checksum: 244952 5a5b31ebb9098059e62eb57d209a6846 Size/MD5 checksum: 1404266 a3bffb93ec3b0d0d130a6a7e29091a9b ia64 architecture (Intel ia64) Size/MD5 checksum: 3589108 d34afb06a3b21ad7267ef5d31b6ad322 Size/MD5 checksum: 932026 1194a002673f8a73cf382c2333c7882b Size/MD5 checksum: 352020 e40c570396514fee0c6eee3920be2607 Size/MD5 checksum: 269084 1720388cc8102f33122375034a703a05 Size/MD5 checksum: 259018 658248f4329555e81896800709302575 Size/MD5 checksum: 2006532 6ad20563d8999759f32445576fd69856 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 3712752 8d48a2797c1f4e6b5dea203698e4b31c Size/MD5 checksum: 180956 88613b463fcdba79539048ce681d4f5e Size/MD5 checksum: 260240 f6fa5402a6fc03aef4b87735030969c5 Size/MD5 checksum: 854756 76ad64ab6fe85c5bfc654266101e024a Size/MD5 checksum: 1394436 4930b2b56c642182c8ccd69d5bc53685 Size/MD5 checksum: 302106 3672bab4d2c0c037a1d9c0a61fa16139 powerpc architecture (PowerPC) Size/MD5 checksum: 3718584 7b120292ce66e7ea85b3ad623da0bb4e Size/MD5 checksum: 295146 f131ea5cdbab25c2416ff06f6697bc08 Size/MD5 checksum: 199248 c683d506deb5fadabea906c9dec36c9f Size/MD5 checksum: 1536614 b5c37ae6f72127bdf6910100edeb06e5 Size/MD5 checksum: 907106 6af4614c092e6ccda8580e6a73cb8728 Size/MD5 checksum: 284952 b75e2ddab46ddab036ef40b21cec63ee sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 872178 a7739e034d0df26a69e0cb569802d594 Size/MD5 checksum: 249022 334ecf73608e20ec6cff79716cf10fde Size/MD5 checksum: 1387990 4935db487abd61e04adb3a846ed7aadc Size/MD5 checksum: 260980 006fdd6b90293fdf1331442ccabde568 Size/MD5 checksum: 182822 73c3edfab6b52e772ed36c990c13f210 Size/MD5 checksum: 3502906 c19b8875ae915cec344bb74a5e462e44 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . OpenLDAP security notice regarding SSL vulnerabilities enables spoofing, which could result in possible breaches. Update is advised.. OpenLDAP Advisory, Debian OpenLDAP Fix, SSL Certificate Issue, Security Advisory DSA-1943, Remote Input Validation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 02, 2009 Critical Debian
89

Fedora: 11 FEDORA-2009-9231 Moderate: Qt SSL Certificate Issue

security fix for CVE-2009-2700. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-9231 2009-09-03 00:09:58 --------------------------------------------------------------------------------Name : qt Product : Fedora 11 Version : 4.5.2 Release : 3.fc11 URL : https://qtsoftware.info/?v=0b3b97fa6688 Summary : Qt toolkit Description : Qt is a software toolkit for developing applications. This package contains base tools, like string, xml, and network handling. --------------------------------------------------------------------------------Update Information: security fix for CVE-2009-2700 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2009 Than Ngo - 4.5.2-3 - fix for CVE-2009-2700 * Tue Aug 18 2009 Than Ngo - 4.5.2-2 - security fix for CVE-2009-1725 * Tue Aug 18 2009 Rex Dieter 4.5.2-1.2 - kde-qt: 287-qmenu-respect-minwidth - kde-qt: 0288-more-x-keycodes (#475247) * Wed Aug 5 2009 Rex Dieter 4.5.2-1.1 - use linker scripts for _debug targets (#510246) - apply upstream patch to fix issue in Copy and paste - optimize (icon-mostly) scriptlets - -x11: Requires(post,postun): /sbin/ldconfig * Thu Jul 2 2009 Than Ngo - 4.5.2-1 - 4.5.2 * Sat May 30 2009 Rex Dieter - 4.5.1-13 - -doc: Obsoletes: qt-doc < 1:4.5.1-4 (workaround bug #502401) * Sat May 23 2009 Rex Dieter - 4.5.1-12 - +phonon_internal macro to toggle packaging of qt's phonon (default off) * Fri May 22 2009 Rex Dieter - 4.5.1-11 - qt-copy-patches-20090522 * Wed May 20 2009 Rex Dieter - 4.5.1-10.2 - full (non-bootstrap) build * Wed May 20 2009 Rex Dieter - 4.5.1-10.1 - allow for minimal bootstrap build (*cough* arm *cough*) * Wed May 6 2009 Rex Dieter - 4.5.1-10 - improved kde4_plugins patch, skip expensive/unneeded canonicalPath * Wed May 6 2009 Rex Dieter - 4.5.1-9 - include kde4 plugin path by default (#498809) * Mon May 4 2009Rex Dieter - 4.5.1-8 - fix invalid assumptions about mysql_config --libs (bug #440673) - fix %files breakage from 4.5.1-5 * Wed Apr 29 2009 Rex Dieter - 4.5.1-7 - -devel: Provides: qt4-devel%{?_isa} ... * Mon Apr 27 2009 Than Ngo - 4.5.1-6 - drop useless hunk of qt-x11-opensource-src-4.5.1-enable_ft_lcdfilter.patch * Mon Apr 27 2009 Rex Dieter - 4.5.1-5 - -devel: Provides: *-static for libQtUiTools.a * Fri Apr 24 2009 Rex Dieter - 4.5.1-4 - qt-doc noarch - qt-demos, qt-examples (split from -doc) - (cosmetic) re-order subpkgs in alphabetical order - drop unused profile.d bits * Fri Apr 24 2009 Rex Dieter - 4.5.1-3 - enable FT_LCD_FILTER (uses freetype subpixel filters if available at runtime) * Fri Apr 24 2009 Than Ngo - 4.5.1-2 - apply upstream patch to fix the svg rendering regression * Thu Apr 23 2009 Than Ngo - 4.5.1-1 - 4.5.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #520435 - CVE-2009-2700 Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520435 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update qt' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A critical update for the Qt toolkit on Fedora addresses a severe SSL vulnerability that may expose users to security risks fromman-in-the-middle attacks. Fedora Update, Qt Security Fix, SSL Verification Issue. . LinuxSecurity.com Team

Calendar%202 Sep 02, 2009 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200