Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 13 articles for you...
89

Fedora 41: FEDORA-2024-88ad2bee84 critical: sympa remote code execution

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-88ad2bee84 2024-12-26 01:20:11.418870+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 41 Version : 6.2.74 Release : 1.fc41 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-88ad2bee84' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The sympa update for Fedora 41 resolves critical issues like CVE-2024-55919. Find the full changelog and installation details.. Fedora 41, sympa updates, mailing list security, open source security, system update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 26, 2024 Critical Fedora
89

Fedora 40: FEDORA-2024-14c006b8bb critical: sympa denial of service

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40 users should promptly update sympa software for crucial security updates pertaining to CVE-2024-55919. Use the command: dnf update sympa to secure your system. Fedora Updates, sympa Security, Mailing List Management, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 25, 2024 Critical Fedora
203

Mageia 9: 2024-0052 Critical: Sympa CVE-2021-32850 Security Patch

Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: . MGASA-2024-0052 - Updated sympa packages fix security vulnerabilities Publication date: 29 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0052.html Type: security Affected Mageia releases: 9 CVE: CVE-2021-32850 Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: - https://bugs.mageia.org/show_bug.cgi?id=32896 - https://github.com/sympa-community/sympa/releases/tag/6.2.72 - https://www.cve.org/CVERecord?id=CVE-2021-32850 - https://www.cve.org/CVERecord?id=CVE-2021-32850 SRPMS: - 9/core/sympa-6.2.72-4.mga9 . Mageia enhances Sympa 6.2.72 for security vulnerabilities. A manual execution is necessary post-update. Essential patches implemented.. Mageia Security Update, Sympa Bug Fix, Mageia Advisory, Sympa Security, Open Source Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 29, 2024 Critical Mageia
89

Fedora 38: FEDORA-2023-271b912b2b Moderate: Sympa XSS Issue

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-271b912b2b 2023-06-11 02:01:36.946071 --------------------------------------------------------------------------------Name : sympa Product : Fedora 38 Version : 6.2.72 Release : 2.fc38 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-271b912b2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Ubuntu 22.04 revision with nginx 1.22.1 addresses SQL injection vulnerabilities, improving safety and performance.. Fedora Security Advisory, Sympa Update, Cross-Site Scripting Fix. . LinuxSecurity.com Team

Calendar 2 Jun 11, 2023 Fedora
89

Fedora 37: FEDORA-2023-419ca55dd3 Critical: sympa XSS Security Fix

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-419ca55dd3 2023-06-11 01:58:02.674345 --------------------------------------------------------------------------------Name : sympa Product : Fedora 37 Version : 6.2.72 Release : 2.fc37 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX * Sat Jan 21 2023 Fedora Release Engineering - 6.2.70-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-419ca55dd3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Patch addressing CVE-2021-32850 in sympa version 6.2.72 has been released for Fedora 37. Implement this update to enhance your system's security.. Fedora Security Update, Sympa Mailing List, XSS Threat Mitigation, Mailing List Manager. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 11, 2023 Critical Fedora
89

Fedora 33: FEDORA-2021-11cb6626e2 Critical: Remote Access in Sympa

Update to 6.2.60 Fixes CVE-2020-29668. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-11cb6626e2 2021-01-13 01:58:21.870854 --------------------------------------------------------------------------------Name : sympa Product : Fedora 33 Version : 6.2.60 Release : 1.fc33 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to 6.2.60 Fixes CVE-2020-29668 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 4 2021 Xavier Bachelot 6.2.60-1 - Update to 6.2.60 - Fixes CVE-2020-29668 (RHBZ#1906576) * Sat Nov 7 2020 Xavier Bachelot 6.2.58-2 - Add BR: perl-Test-Net-LDAP - Remove all of EL6 thus sysvinit support --------------------------------------------------------------------------------References: [ 1 ] Bug #1906577 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1906577 [ 2 ] Bug #1906578 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1906578 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2021-11cb6626e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important notice regarding sympa for Fedora 33 addressing remote exploit risk CVE-2020-29668. Please update immediately!. Fedora Update,sympa security fix,remote access issue,mailing list manager. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 12, 2021 Critical Fedora
87

Debian: DSA-4818-1 Local Escalation Risk In Sympa Software

Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4818-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso December 23, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sympa CVE ID : CVE-2020-9369 CVE-2020-10936 CVE-2020-26932 CVE-2020-29668 Debian Bug : 952428 961491 971904 976020 Several vulnerabilities were discovered in Sympa, a mailing list manager, which could result in local privilege escalation, denial of service or unauthorized access via the SOAP API. Additionally to mitigate CVE-2020-26880 the sympa_newaliases-wrapper is no longer installed setuid root by default. A new Debconf question is introduced to allow setuid installations in setups where it is needed. For the stable distribution (buster), these problems have been fixed in version 6.2.40~dfsg-1+deb10u1. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sympa Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Numerous weaknesses identified in Sympa may result in elevated local privileges and unauthorized entries. Updating is recommended.. Sympa Security, Debian Update, Local Escalation Risk, Mailing List Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 23, 2020 Important Debian
197

Debian 9: DLA-2499-1 Urgent: Sympa API Access Vulnerability Mitigation

Sympa, a modern mailing list manager, grants full SOAP API access by sending invalid string as the cookie value, if the SOAP endpoint was enabled. An attacker could manipulate the mailing lists, including subscribing e-mails or getting the list of subscribers. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2499-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ December 17, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sympa Version : 6.2.16~dfsg-3+deb9u5 CVE ID : CVE-2020-29668 Debian Bug : 976020 Sympa, a modern mailing list manager, grants full SOAP API access by sending invalid string as the cookie value, if the SOAP endpoint was enabled. An attacker could manipulate the mailing lists, including subscribing e-mails or getting the list of subscribers. For Debian 9 stretch, this problem has been fixed in version 6.2.16~dfsg-3+deb9u5. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sympa Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4895-1 addresses serious flaw in APT. Urgent patch advised to enhance protection.. Sympa Update, Debian Security, API Exposure, Mailing List Manager. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 17, 2020 Important Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here