Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
100

SUSE OpenStack Cloud: 2022:0285-1 Important: Python-Django1 XSS & DoS

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for python-Django1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0285-1 Rating: important References: #1195086 #1195088 Cross-References: CVE-2022-22818 CVE-2022-23833 CVSS scores: CVE-2022-22818 (SUSE): 5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L CVE-2022-23833 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for python-Django1 fixes the following issues: - CVE-2022-22818: Fixed possible XSS via {% debug %} template tag (bsc#1195086) - CVE-2022-23833: Fixed denial-of-service possibility in file uploads. (bsc#1195088) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-285=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-285=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): python-Django1-1.11.29-3.37.1 - SUSE OpenStack Cloud 9 (noarch): python-Django1-1.11.29-3.37.1 venv-openstack-barbican-x86_64-7.0.1~dev24-3.30.1 venv-openstack-cinder-x86_64-13.0.10~dev23-3.33.1 venv-openstack-designate-x86_64-7.0.2~dev2-3.30.1 venv-openstack-glance-x86_64-17.0.1~dev30-3.28.1 venv-openstack-heat-x86_64-11.0.4~dev4-3.30.1 venv-openstack-horizon-x86_64-14.1.1~dev11-4.34.2 venv-openstack-ironic-x86_64-11.1.5~dev17-4.28.1 venv-openstack-keystone-x86_64-14.2.1~dev7-3.31.1 venv-openstack-magnum-x86_64-7.2.1~dev1-4.30.1 venv-openstack-manila-x86_64-7.4.2~dev60-3.36.1 venv-openstack-monasca-ceilometer-x86_64-1.8.2~dev3-3.30.1 venv-openstack-monasca-x86_64-2.7.1~dev10-3.32.1 venv-openstack-neutron-x86_64-13.0.8~dev164-6.34.1 venv-openstack-nova-x86_64-18.3.1~dev91-3.34.1 venv-openstack-octavia-x86_64-3.2.3~dev7-4.30.1 venv-openstack-sahara-x86_64-9.0.2~dev15-3.30.1 venv-openstack-swift-x86_64-2.19.2~dev48-2.25.1 References: https://www.suse.com/security/cve/CVE-2022-22818.html https://www.suse.com/security/cve/CVE-2022-23833.html https://bugzilla.suse.com/1195086 https://bugzilla.suse.com/1195088 . A critical patch for python-Django1 tackles major security flaws within SUSE OpenStack. Ensure your protection!. Python Django XSS Fix, SUSE OpenStack Security, Denial of Service Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 01, 2022 Important SuSE
100

SUSE: 2021:0954-2 Critical: OpenSSL-1_1 Denial Of Service

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openssl-1_1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0954-1 Rating: important References: #1183852 Cross-References: CVE-2021-3449 CVSS scores: CVE-2021-3449 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl-1_1 fixes the following security issue: * CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension but includes a signature_algorithms_cert extension, then a NULL pointer dereference will result, leading to a crash and a denial of service attack. OpenSSL TLS clients are not impacted by this issue. [bsc#1183852] Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-954=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-954=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-954=1 - SUSE Linux EnterpriseServer for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-954=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-954=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-954=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): libopenssl1_1-1.1.1d-2.33.1 libopenssl1_1-32bit-1.1.1d-2.33.1 libopenssl1_1-debuginfo-1.1.1d-2.33.1 libopenssl1_1-debuginfo-32bit-1.1.1d-2.33.1 openssl-1_1-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE OpenStack Cloud 9 (x86_64): libopenssl1_1-1.1.1d-2.33.1 libopenssl1_1-32bit-1.1.1d-2.33.1 libopenssl1_1-debuginfo-1.1.1d-2.33.1 libopenssl1_1-debuginfo-32bit-1.1.1d-2.33.1 openssl-1_1-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libopenssl-1_1-devel-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (s390x x86_64): libopenssl-1_1-devel-32bit-1.1.1d-2.33.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): libopenssl1_1-1.1.1d-2.33.1 libopenssl1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (x86_64): libopenssl1_1-32bit-1.1.1d-2.33.1 libopenssl1_1-debuginfo-32bit-1.1.1d-2.33.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): libopenssl1_1-1.1.1d-2.33.1 libopenssl1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE Linux Enterprise Server 12-SP5(s390x x86_64): libopenssl1_1-32bit-1.1.1d-2.33.1 libopenssl1_1-debuginfo-32bit-1.1.1d-2.33.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): libopenssl1_1-1.1.1d-2.33.1 libopenssl1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-1.1.1d-2.33.1 openssl-1_1-debuginfo-1.1.1d-2.33.1 openssl-1_1-debugsource-1.1.1d-2.33.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): libopenssl1_1-32bit-1.1.1d-2.33.1 libopenssl1_1-debuginfo-32bit-1.1.1d-2.33.1 References: https://www.suse.com/security/cve/CVE-2021-3449.html https://bugzilla.suse.com/1183852 . SUSE releases a vital security patch for openssl-1_1 to tackle a significant denial of service vulnerability.. SUSE OpenStack Cloud, OpenSSL Update, Denial Of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2021 Important SuSE
100

SUSE OpenStack Cloud Security Advisory: python-Django1 XSS Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for python-Django1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:2034-1 Rating: moderate References: #1136468 Cross-References: CVE-2019-12308 Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for python-Django1 fixes the following issues: - CVE-2019-12308: Fixed an improper validatation of the clickable "Current URL" link in AdminURLFieldWidget which could have allowed attackers to perform XSS attacks (bsc#1136468). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2019-2034=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2019-2034=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): python-Django1-1.11.20-3.6.1 - SUSE OpenStack Cloud 9 (noarch): python-Django1-1.11.20-3.6.1 References: https://www.suse.com/security/cve/CVE-2019-12308.html https://bugzilla.suse.com/1136468 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . A new version has been released for python-Django1 that resolves a significant security vulnerability linked to XSS threats on SUSE platforms.. SUSE OpenStack Cloud, python-Django1, Security Fix, XSS Attack. . LinuxSecurity.com Team

Calendar%202 Aug 01, 2019 SuSE
100

SUSE: 2018:2217-1 Moderate Advisory: rubygem-sprockets-2_12 Path Traversal

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-sprockets-2_12 ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2217-1 Rating: moderate References: #1098369 Cross-References: CVE-2018-3760 Affected Products: SUSE OpenStack Cloud 7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-sprockets-2_12 fixes the following issues: Security issue fixed: - CVE-2018-3760: Fix path traversal in sprockets/server.rb:forbidden_request?() that can allow remote attackers to read arbitrary files (bsc#1098369). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-1500=1 Package List: - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): ruby2.1-rubygem-sprockets-2_12-2.12.5-1.3.1 References: https://www.suse.com/security/cve/CVE-2018-3760.html https://bugzilla.suse.com/1098369 . SUSE has released a security update addressing a critical directory traversal flaw in rubygem-sprockets-2_12 for SUSE OpenStack Cloud.. SUSE OpenStack Cloud, rubygem, security advisory, moderate update, path traversal. . LinuxSecurity.com Team

Calendar%202 Aug 06, 2018 SuSE
100

SUSE: 2018:0902-1 Critical OpenSSL Denial Of Service Vulnerability

An update that fixes one vulnerability is now available.. SUSE Security Update: Security update for openssl ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:0902-1 Rating: important References: #1087102 Cross-References: CVE-2018-0739 Affected Products: SUSE OpenStack Cloud 6 SUSE Linux Enterprise Server for SAP 12-SP1 SUSE Linux Enterprise Server 12-SP1-LTSS ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openssl fixes the following issues: - CVE-2018-0739: Constructed ASN.1 types with a recursive definition could exceed the stack. This could result in a Denial Of Service attack. (bsc#1087102) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 6: zypper in -t patch SUSE-OpenStack-Cloud-6-2018-601=1 - SUSE Linux Enterprise Server for SAP 12-SP1: zypper in -t patch SUSE-SLE-SAP-12-SP1-2018-601=1 - SUSE Linux Enterprise Server 12-SP1-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP1-2018-601=1 Package List: - SUSE OpenStack Cloud 6 (x86_64): libopenssl1_0_0-1.0.1i-54.11.1 libopenssl1_0_0-32bit-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-32bit-1.0.1i-54.11.1 libopenssl1_0_0-hmac-1.0.1i-54.11.1 libopenssl1_0_0-hmac-32bit-1.0.1i-54.11.1 openssl-1.0.1i-54.11.1 openssl-debuginfo-1.0.1i-54.11.1 openssl-debugsource-1.0.1i-54.11.1 - SUSE OpenStack Cloud 6 (noarch): openssl-doc-1.0.1i-54.11.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (ppc64le x86_64): libopenssl1_0_0-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-1.0.1i-54.11.1 libopenssl1_0_0-hmac-1.0.1i-54.11.1 openssl-1.0.1i-54.11.1 openssl-debuginfo-1.0.1i-54.11.1 openssl-debugsource-1.0.1i-54.11.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (x86_64): libopenssl1_0_0-32bit-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-32bit-1.0.1i-54.11.1 libopenssl1_0_0-hmac-32bit-1.0.1i-54.11.1 - SUSE Linux Enterprise Server for SAP 12-SP1 (noarch): openssl-doc-1.0.1i-54.11.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (ppc64le s390x x86_64): libopenssl1_0_0-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-1.0.1i-54.11.1 libopenssl1_0_0-hmac-1.0.1i-54.11.1 openssl-1.0.1i-54.11.1 openssl-debuginfo-1.0.1i-54.11.1 openssl-debugsource-1.0.1i-54.11.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (s390x x86_64): libopenssl1_0_0-32bit-1.0.1i-54.11.1 libopenssl1_0_0-debuginfo-32bit-1.0.1i-54.11.1 libopenssl1_0_0-hmac-32bit-1.0.1i-54.11.1 - SUSE Linux Enterprise Server 12-SP1-LTSS (noarch): openssl-doc-1.0.1i-54.11.1 References: https://www.suse.com/security/cve/CVE-2018-0739.html https://bugzilla.suse.com/1087102 -- . SUSE reveals critical patch for openssl tackling Denial of Service vulnerability affecting various products.. SUSE OpenStack Cloud, Linux Enterprise Server, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 09, 2018 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200