Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 589
Alerts This Week
Warning Icon 1 589

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
172

Ubuntu 7280-1 Moderate Security Issue: Python3 SSRF Vulnerability Alert

Python could allow Server-Side Request Forgery attacks.. ========================================================================== Ubuntu Security Notice USN-7280-1 February 20, 2025 python3.10, python3.12, python3.8 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Python could allow Server-Side Request Forgery attacks. Software Description: - python3.12: An interactive high-level object-oriented language - python3.10: An interactive high-level object-oriented language - python3.8: An interactive high-level object-oriented language Details: It was discovered that Python incorrectly handled parsing domain names that included square brackets. A remote attacker could possibly use this issue to perform a Server-Side Request Forgery (SSRF) attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 python3.12 3.12.7-1ubuntu2 python3.12-minimal 3.12.7-1ubuntu2 Ubuntu 24.04 LTS python3.12 3.12.3-1ubuntu0.5 python3.12-minimal 3.12.3-1ubuntu0.5 Ubuntu 22.04 LTS python3.10 3.10.12-1~22.04.9 python3.10-minimal 3.10.12-1~22.04.9 Ubuntu 20.04 LTS python3.8 3.8.10-0ubuntu1~20.04.15 python3.8-minimal 3.8.10-0ubuntu1~20.04.15 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7280-1 CVE-2025-0938 Package Information: https://launchpad.net/ubuntu/+source/python3.12/3.12.7-1ubuntu2 https://launchpad.net/ubuntu/+source/python3.12/3.12.3-1ubuntu0.5 https://launchpad.net/ubuntu/+source/python3.10/3.10.12-1~22.04.9 https://launchpad.net/ubuntu/+source/python3.8/3.8.10-0ubuntu1~20.04.15 . A vulnerability in Python has sparked concerns over Server-Side Request Forgery threats within Ubuntu distributions. It is advised to apply updates promptly for enhanced protection.. Python SSRF risk, Ubuntu security update, Server-Side Request Forgery. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 20, 2025 Important Ubuntu
100

SUSE: 2024:4109-1 moderate security update for libuv addressing SSRF

* bsc#1219724 Cross-References: * CVE-2024-24806 . # Security update for libuv Announcement ID: SUSE-SU-2024:4109-1 Release Date: 2024-11-28T16:15:50Z Rating: moderate References: * bsc#1219724 Cross-References: * CVE-2024-24806 CVSS scores: * CVE-2024-24806 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N * CVE-2024-24806 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * Basesystem Module 15-SP5 * Basesystem Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for libuv fixes the following issues: * CVE-2024-24806: Fixed improper Domain Lookup that potentially leads to SSRF attacks (bsc#1219724) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-4109=1 openSUSE-SLE-15.5-2024-4109=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-4109=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-4109=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-4109=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-4109=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) *libuv1-debuginfo-1.44.2-150500.3.5.1 * libuv1-1.44.2-150500.3.5.1 * libuv-debugsource-1.44.2-150500.3.5.1 * libuv-devel-1.44.2-150500.3.5.1 * openSUSE Leap 15.5 (x86_64) * libuv1-32bit-1.44.2-150500.3.5.1 * libuv1-32bit-debuginfo-1.44.2-150500.3.5.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libuv1-64bit-debuginfo-1.44.2-150500.3.5.1 * libuv1-64bit-1.44.2-150500.3.5.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libuv1-debuginfo-1.44.2-150500.3.5.1 * libuv1-1.44.2-150500.3.5.1 * libuv-debugsource-1.44.2-150500.3.5.1 * libuv-devel-1.44.2-150500.3.5.1 * openSUSE Leap 15.6 (x86_64) * libuv1-32bit-1.44.2-150500.3.5.1 * libuv1-32bit-debuginfo-1.44.2-150500.3.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64) * libuv-debugsource-1.44.2-150500.3.5.1 * libuv-devel-1.44.2-150500.3.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libuv1-debuginfo-1.44.2-150500.3.5.1 * libuv1-1.44.2-150500.3.5.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * libuv1-debuginfo-1.44.2-150500.3.5.1 * libuv1-1.44.2-150500.3.5.1 * libuv-debugsource-1.44.2-150500.3.5.1 * libuv-devel-1.44.2-150500.3.5.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * libuv1-debuginfo-1.44.2-150500.3.5.1 * libuv1-1.44.2-150500.3.5.1 * libuv-debugsource-1.44.2-150500.3.5.1 * libuv-devel-1.44.2-150500.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2024-24806.html * https://bugzilla.suse.com/show_bug.cgi?id=1219724 . Major libuv revision tackles SSRF vulnerability. Timely application of recommended updates is essential to avoid security threats.. SUSE Libuv Update, SSRF Security Fix, Moderate Severity Advisory, Linux Security Updates. . LinuxSecurity.com Team

Calendar%202 Nov 28, 2024 SuSE
100

openSUSE: 2024:2405-1 Important: apache2 Null Pointer and SSRF Fixes

* bsc#1227270 * bsc#1227271 Cross-References: * CVE-2024-38477 . # Security update for apache2 Announcement ID: SUSE-SU-2024:2405-1 Rating: important References: * bsc#1227270 * bsc#1227271 Cross-References: * CVE-2024-38477 * CVE-2024-39573 CVSS scores: * CVE-2024-38477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-39573 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N Affected Products: * Basesystem Module 15-SP6 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues: * CVE-2024-38477: Fixed null pointer dereference in mod_proxy (bsc#1227270) * CVE-2024-39573: Fixed potential SSRF in mod_rewrite (bsc#1227271) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-2405=1 SUSE-2024-2405=1 * Basesystem Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP6-2024-2405=1 * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2024-2405=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-2405=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * apache2-prefork-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-event-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-utils-2.4.58-150600.5.11.1 * apache2-utils-debuginfo-2.4.58-150600.5.11.1 * apache2-event-debuginfo-2.4.58-150600.5.11.1 * apache2-utils-debugsource-2.4.58-150600.5.11.1 * apache2-event-debugsource-2.4.58-150600.5.11.1 * apache2-2.4.58-150600.5.11.1 * apache2-devel-2.4.58-150600.5.11.1 * apache2-prefork-debuginfo-2.4.58-150600.5.11.1 * apache2-worker-2.4.58-150600.5.11.1 * apache2-worker-debugsource-2.4.58-150600.5.11.1 * apache2-worker-debuginfo-2.4.58-150600.5.11.1 * apache2-prefork-debugsource-2.4.58-150600.5.11.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.58-150600.5.11.1 * Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-prefork-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-2.4.58-150600.5.11.1 * apache2-prefork-debuginfo-2.4.58-150600.5.11.1 * apache2-prefork-debugsource-2.4.58-150600.5.11.1 * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-event-2.4.58-150600.5.11.1 * apache2-debuginfo-2.4.58-150600.5.11.1 * apache2-debugsource-2.4.58-150600.5.11.1 * apache2-event-debuginfo-2.4.58-150600.5.11.1 * apache2-event-debugsource-2.4.58-150600.5.11.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * apache2-utils-2.4.58-150600.5.11.1 * apache2-utils-debuginfo-2.4.58-150600.5.11.1 * apache2-utils-debugsource-2.4.58-150600.5.11.1 * apache2-worker-2.4.58-150600.5.11.1 * apache2-devel-2.4.58-150600.5.11.1 * apache2-worker-debugsource-2.4.58-150600.5.11.1 * apache2-worker-debuginfo-2.4.58-150600.5.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38477.html * https://www.suse.com/security/cve/CVE-2024-39573.html * https://bugzilla.suse.com/show_bug.cgi?id=1227270 * https://bugzilla.suse.com/show_bug.cgi?id=1227271 . Important patches for apache2 focusing on vital security vulnerabilities such as null pointer dereference and SSRF attacks.. apache2 Security Updates,SUSE Advisory,Server Security,CriticalUpdate,Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 11, 2024 Important SuSE
197

Debian 10 Buster DLA-3619-1 Moderate: SSRF Issues in Batik Fixed

Batik is a toolkit for applications or applets that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3619-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès October 14, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : batik Version : 1.10-2+deb10u3 CVE ID : CVE-2020-11987 CVE-2022-38398 CVE-2022-38648 CVE-2022-40146 CVE-2022-44729 CVE-2022-44730 Debian Bug : 984829 1020589 Batik is a toolkit for applications or applets that want to use images in the Scalable Vector Graphics (SVG) format for various purposes, such as viewing, generation or manipulation. CVE-2020-11987 A server-side request forgery was found, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. CVE-2022-38398 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to load a url thru the jar protocol. CVE-2022-38648 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to fetch external resources. CVE-2022-40146 A Server-Side Request Forgery (SSRF) vulnerability was found that allows an attacker to access files using a Jar url. CVE-2022-44729 A Server-Side Request Forgery (SSRF) vulnerability was found. A malicious SVG could trigger loading external resources by default, causing resource consumption or in some cases even information disclosure. CVE-2022-44730 A Server-Side Request Forgery (SSRF) vulnerability was found. A malicious SVG can probe user profile /data and send it directly as parameter to a URL. For Debian 10 buster, these problems have been fixed in version 1.10-2+deb10u3. We recommend that you upgrade your batik packages. For the detailed security status of batik please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/batik Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5072-1 tackles various remote code execution vulnerabilities in the libxml2 library. Upgrade advised for enhanced protection.. Batik Security, SSRF Exploits, Debian Advisory, Debian Security Updates. . LinuxSecurity.com Team

Calendar%202 Oct 14, 2023 Debian LTS
197

Debian LTS: DLA-3590-1 Critical: python-reportlab SSRF and Execution Issue

Security issues were discovered in python-reportlab, a Python library for generating PDFs and graphics, which could lead to remote code execution or authorization bypass. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3590-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Guilhem Moulin September 29, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : python-reportlab Version : 3.5.13-1+deb10u2 CVE ID : CVE-2019-19450 CVE-2020-28463 Security issues were discovered in python-reportlab, a Python library for generating PDFs and graphics, which could lead to remote code execution or authorization bypass. CVE-2019-19450 Ravi Prakash Giri discovered a remote code execution vulnerability via crafted XML document where ‘

Calendar%202 Sep 29, 2023 Critical Debian LTS
89

Fedora 38: FEDORA-2023-e4a4ea43d8 Critical: Python-Cairosvg DoS Threat

``` - Update python-cairosvg version 2.7.0 - Disable isort flake8 patch updated - Fix CVE-2023-27586 - BZ#2180272 BZ#2180271 ```. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-e4a4ea43d8 2023-03-30 00:18:30.537295 --------------------------------------------------------------------------------Name : python-cairosvg Product : Fedora 38 Version : 2.7.0 Release : 1.fc38 URL : https://cairosvg.org/ Summary : A Simple SVG Converter for Cairo Description : CairoSVG is a SVG 1.1 to PNG, PDF, PS and SVG converter which can also be used as a Python library. --------------------------------------------------------------------------------Update Information: ``` - Update python-cairosvg version 2.7.0 - Disable isort flake8 patch updated - Fix CVE-2023-27586 - BZ#2180272 BZ#2180271 ``` --------------------------------------------------------------------------------ChangeLog: * Tue Mar 21 2023 Onuralp SEZER - 2.7.0-1 - Update python-cairosvg version 2.7.0 - Disable isort flake8 patch updated - Fix CVE-2023-27586 - BZ#2180272 BZ#2180271 --------------------------------------------------------------------------------References: [ 1 ] Bug #2160532 - python-cairosvg-2.7.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2160532 [ 2 ] Bug #2180272 - CVE-2023-27586 python-cairosvg: SSRF & DOS vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180272 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-e4a4ea43d8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Ubuntu 20.04 issues a security notice for libxml2, tackling XML External Entity (XXE) vulnerabilities and Denial of Service risks after the latest patch.. Fedora Security, python-cairosvg Update, SSRF DoS Fix, Python Conversion Tool. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 30, 2023 Critical Fedora
197

Debian 10: DLA-3141-1 Moderate: WordPress SSRF and XSS Issue Fix

Several security vulnerabilities were discovered in Wordpress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3141-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany October 10, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : wordpress Version : 5.0.17+dfsg1-0+deb10u1 CVE ID : CVE-2019-17670 Debian Bug : 942459 Several security vulnerabilities were discovered in Wordpress, a popular content management framework. Server Side Request Forgery and cross-site scripting (XSS) attacks may facilitate the bypass of access controls or the injection of client-side scripts. For Debian 10 buster, this problem has been fixed in version 5.0.17+dfsg1-0+deb10u1. We recommend that you upgrade your wordpress packages. For the detailed security status of wordpress please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/wordpress Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance WordPress components to address vulnerabilities related to server-side request forgery and cross-site scripting. Refer to document DLA-3141-1 for specifics.. Debian Security Update, WordPress Fix, CMS Security Advisory. . LinuxSecurity.com Team

Calendar%202 Oct 10, 2022 Debian LTS
100

SUSE: 2022:0119-1 Important Apache2 Buffer Overflow And SSRF

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for apache2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0119-1 Rating: important References: #1193942 #1193943 Cross-References: CVE-2021-44224 CVE-2021-44790 CVSS scores: CVE-2021-44224 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-44790 (SUSE): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Enterprise Storage 6 SUSE CaaS Platform 4.0 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for apache2 fixes the following issues: - CVE-2021-44224: Fixed NULL dereference or SSRF in forward proxy configurations. (bsc#1193943) - CVE-2021-44790: Fixed buffer overflow when parsing multipart content in mod_lua. (bsc#1193942) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-SP1-2022-119=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2022-119=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-119=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-119=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2022-119=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-119=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-119=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-119=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-119=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-119=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise Server for SAP 15 (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise Server 15-LTSS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise High PerformanceComputing 15-SP1-LTSS (aarch64 x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (noarch): apache2-doc-2.4.33-3.61.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 - SUSE Enterprise Storage 6 (noarch): apache2-doc-2.4.33-3.61.1 - SUSE CaaS Platform 4.0 (noarch): apache2-doc-2.4.33-3.61.1 - SUSE CaaS Platform 4.0 (x86_64): apache2-2.4.33-3.61.1 apache2-debuginfo-2.4.33-3.61.1 apache2-debugsource-2.4.33-3.61.1 apache2-devel-2.4.33-3.61.1 apache2-prefork-2.4.33-3.61.1 apache2-prefork-debuginfo-2.4.33-3.61.1 apache2-utils-2.4.33-3.61.1 apache2-utils-debuginfo-2.4.33-3.61.1 apache2-worker-2.4.33-3.61.1 apache2-worker-debuginfo-2.4.33-3.61.1 References: https://www.suse.com/security/cve/CVE-2021-44224.html https://www.suse.com/security/cve/CVE-2021-44790.html https://bugzilla.suse.com/1193942 https://bugzilla.suse.com/1193943 . SUSE Security Patch tackles severe vulnerabilities in Nginx, featuring essential updates. Ensure your system remains safe and current!. SUSE Security, Apache2 Update, Security Fixes, SUSE Linux. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 18, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200