Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available. An update that fixes three vulnerabilities is now available.. SUSE Security Update: Security update for OpenSSL ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:1387-2 Rating: important References: #901223 #901277 Cross-References: CVE-2014-3566 CVE-2014-3567 CVE-2014-3568 Affected Products: SUSE Studio Onsite 1.3 SUSE Manager 1.7 for SLE 11 SP2 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This OpenSSL update fixes the following issues: * Session Ticket Memory Leak (CVE-2014-3567) * Build option no-ssl3 is incomplete (CVE-2014-3568) * Add support for TLS_FALLBACK_SCSV to mitigate CVE-2014-3566 (POODLE) Security Issues: * CVE-2014-3567 * CVE-2014-3566 * CVE-2014-3568 Indications: Everybody should update. Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-libopenssl-devel-9908 - SUSE Manager 1.7 for SLE 11 SP2: zypper in -t patch sleman17sp2-libopenssl-devel-9908 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.3 (x86_64): libopenssl-devel-0.9.8j-0.66.1 - SUSE Manager 1.7 for SLE 11 SP2 (x86_64): libopenssl0_9_8-0.9.8j-0.66.1 libopenssl0_9_8-32bit-0.9.8j-0.66.1 libopenssl0_9_8-hmac-0.9.8j-0.66.1 libopenssl0_9_8-hmac-32bit-0.9.8j-0.66.1 openssl-0.9.8j-0.66.1 openssl-doc-0.9.8j-0.66.1 References: https://www.suse.com/security/cve/CVE-2014-3566.html https://www.suse.com/security/cve/CVE-2014-3567.html https://www.suse.com/security/cve/CVE-2014-3568.html https://bugzilla.suse.com/show_bug.cgi?id=901223 https://bugzilla.suse.com/show_bug.cgi?id=901277 https://scc.suse.com:443/patches/ . SUSE has released a security update for OpenSSL addressing several critical vulnerabilities; please update promptly to safeguard your system.. SUSE Security Update, OpenSSL Issues, Patch Instruction, TLS Support. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is An update that solves one vulnerability and has 5 fixes is now available. now available.. SUSE Security Update: Security update for Ruby 1.9 ______________________________________________________________________________ Announcement ID: SUSE-SU-2013:0647-1 Rating: important References: #783511 #789983 #791199 #796757 #802406 #803342 Cross-References: CVE-2013-0269 Affected Products: SUSE Studio Onsite 1.3 ______________________________________________________________________________ An update that solves one vulnerability and has 5 fixes is now available. Description: The Ruby script interpreter 1.9 has been updated to 1.9.3 p392 fixing various bugs and security issues: This release includes security fixes about bundled JSON and REXML. * Denial of Service and Unsafe Object Creation Vulnerability in JSON (CVE-2013-0269) * Entity expansion DoS vulnerability in REXML (XML bomb) * XSS exploit of RDoc documentation generated by rdoc (CVE-2013-0256) And some small bugfixes are also included see /usr/share/doc/packages/ruby19/Changelog for more details Also the following bugfix was added: * added bind_stack.patch: (bnc#796757) Fixes stack boundary issues when embedding Ruby into threaded C code (Ruby bug #229) Security Issue reference: * CVE-2013-0269 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.3: zypper in -t patch slestso13-ruby19-7496 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.3 (x86_64): ruby19-1.9.3.p392-0.7.1 ruby19-devel-1.9.3.p392-0.7.1 ruby19-devel-extra-1.9.3.p392-0.7.1 References: https://www.suse.com/security/cve/CVE-2013-0269.html . SUSE Security Patch for Ruby 1.9 addresses urgent issues. Find out more about the security flaws and how to implement the updates.. SUSE Studio,Ruby 1.9,Security Update,DoS Vulnerability,Update Instructions. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.