Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
DLA-2836-1 was rolled out, fixing CVE-2021-43527 in nss, but that lead to a regression, preventing SSL connections in Chromium. The complete bug report could be found here: . . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2836-2
The ieee-data package, which provides the OUI and IAB listings of identifiers assigned by IEEE Standards Association, ships a script (update-ieee-data) which queries ieee.org to download the most recent dataset and save it to /var/lib/ieee-data/. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2703-1
A security issue was discovered in the MariaDB database server. For Debian 9 stretch, this problem has been fixed in version 10.1.47-0+deb9u1. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2409-1
It was found that SNMP Trap Translator does not drop privileges as configured and does not properly escape shell commands in certain functions. A remote attacker, by sending a malicious crafted SNMP trap, could possibly execute arbitrary shell code with the privileges of the . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2393-1
Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4399-1
Daniel Genkin, Luke Valenta and Yuval Yarom discovered that Libgcrypt is prone to a local side-channel attack against the ECDH encryption with Curve25519, allowing recovery of the private key. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3959-1
Get the latest Linux and open source security news straight to your inbox.