Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian Stretch: DLA-2836-2 Severe NSS Regression Impacting SSL Connections

DLA-2836-1 was rolled out, fixing CVE-2021-43527 in nss, but that lead to a regression, preventing SSL connections in Chromium. The complete bug report could be found here: . . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2836-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta December 08, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : nss Version : 2:3.26.2-1.1+deb9u4 Debian Bug : 1001219 DLA-2836-1 was rolled out, fixing CVE-2021-43527 in nss, but that lead to a regression, preventing SSL connections in Chromium. The complete bug report could be found here: . For Debian 9 stretch, this problem has been fixed in version 2:3.26.2-1.1+deb9u4. We recommend that you upgrade your nss packages. For the detailed security status of nss please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nss Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Addresses severe bug in NSS impacting SSL links within Chromium. Recommended update for users on Debian 9 stretch.. Debian LTS, NSS, SSL Issue, Security Advisory, Regression Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 07, 2021 Critical Debian LTS
197

Debian 9 Stretch: DLA-2703-1 Fix for Ieee-Data Crash Issues

The ieee-data package, which provides the OUI and IAB listings of identifiers assigned by IEEE Standards Association, ships a script (update-ieee-data) which queries ieee.org to download the most recent dataset and save it to /var/lib/ieee-data/. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2703-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta July 04, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ieee-data Version : 20160613.1+deb9u1 Debian Bug : 908623 932711 The ieee-data package, which provides the OUI and IAB listings of identifiers assigned by IEEE Standards Association, ships a script (update-ieee-data) which queries ieee.org to download the most recent dataset and save it to /var/lib/ieee-data/. This script broke for stretch at the end of 2018 when the URL changed. For Debian 9 stretch, this problem has been fixed in version 20160613.1+deb9u1. We recommend that you upgrade your ieee-data packages. For the detailed security status of ieee-data please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ieee-data Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-2107-1 reveals a vulnerability patch for libxml2 concerning parsing issues and security identifiers.. Debian LTS, ieee-data, crash fix, software update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 04, 2021 Important Debian LTS
197

Debian 9 Stretch: DLA-2409-1 Critical MariaDB Security Issue

A security issue was discovered in the MariaDB database server. For Debian 9 stretch, this problem has been fixed in version 10.1.47-0+deb9u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2409-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort October 21, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mariadb-10.1 Version : 10.1.47-0+deb9u1 CVE ID : CVE-2020-15180 A security issue was discovered in the MariaDB database server. For Debian 9 stretch, this problem has been fixed in version 10.1.47-0+deb9u1. We recommend that you upgrade your mariadb-10.1 packages. For the detailed security status of mariadb-10.1 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security vulnerability addressed in MariaDB for Debian 9 stretch. It is advisable to upgrade to reduce potential threats.. Debian Security Advisory, MariaDB Update, Database Security Issue, Debian LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 21, 2020 Critical Debian LTS
197

Debian 9 Stretch: DLA-2393-1 Moderate: SNMP Trap Translator Risk

It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2393-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA October 01, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : snmptt Version : 1.4-1+deb9u1 CVE ID : CVE-2020-24361 It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the process or cause a Denial of Service condition. For Debian 9 stretch, this problem has been fixed in version 1.4-1+deb9u1. We recommend that you upgrade your snmptt packages. For the detailed security status of snmptt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/snmptt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance security on Debian 9 Stretch by upgrading SNMPTT to fix SNMP trap vulnerabilities. Follow these steps to ensure system safety and stability. SNMP Trap Translator, Debian LTS, security patch, remote execution. . LinuxSecurity.com Team

Calendar%202 Oct 02, 2020 Debian LTS
87

Debian: DSA-4399-1 Critical: Ikiwiki Server-Side Request Forgery

Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4399-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 28, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ikiwiki CVE ID : CVE-2019-9187 Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service. For the stable distribution (stretch), this problem has been fixed in version 3.20170111.1. We recommend that you upgrade your ikiwiki packages. For the detailed security status of ikiwiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ikiwiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --------------------------------------------------. aggregate, plugin, ikiwiki, compiler, susceptible, serve. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2019 Critical Debian
87

Debian 9 Stretch DSA-3959-1: Critical Libgcrypt ECDH Attack Fix

Daniel Genkin, Luke Valenta and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack against the ECDH encryption with Curve25519, allowing recovery of the private key. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3959-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 29, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libgcrypt20 CVE ID : CVE-2017-0379 Debian Bug : 873383 Daniel Genkin, Luke Valenta and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack against the ECDH encryption with Curve25519, allowing recovery of the private key. See https://eprint.iacr.org/2017/806 for details. For the stable distribution (stretch), this problem has been fixed in version 1.7.6-2+deb9u2. For the unstable distribution (sid), this problem has been fixed in version 1.7.9-1. We recommend that you upgrade your libgcrypt20 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . New vulnerability identified in Libgcrypt related to side-channel attacks that can lead to exposure of private keys. Immediate patching advised.. Debian Security, Libgcrypt Update, Encryption Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 29, 2017 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200