Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
202

openSUSE Leap 15.6: SUSE-SU-2024:4416-1 moderate: vhostmd advisory

An update that has five security fixes can now be installed.. # Security update for vhostmd Announcement ID: SUSE-SU-2024:4416-1 Release Date: 2024-12-24T08:21:06Z Rating: moderate References: * bsc#1129772 * bsc#1152803 * bsc#1154838 * bsc#1181400 * bsc#1230961 Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has five security fixes can now be installed. ## Description: This update for vhostmd fixes the following issues: Updated to version 1.2 * Fix actions using the 'free' command * Fix buffer accounting when generating metric XML * Change actions to retrieve vendor and product info * Add a 'unit' attribute to the metrics element * vif-stats.py: convert to Python3 * conf: Update the 'VirtualizationVendor' action to strip any URLs that may follow the vendor name (bsc#1230961) * Fix virtio transport to work with libvirt > = 9.7.0 * Added hardening to systemd service (bsc#1181400) * spec: Don't replace user-modified dtd in /etc/vhostmd/ (bsc#1154838) * Relax virtio requirement in config file (bsc#1152803) Updated to version 1.1 (bsc#1129772) * Merge libserialclient with libmetrics * Misc bug fixes and improvements ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-4416=1 openSUSE-SLE-15.6-2024-4416=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2024-4416=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * vhostmd-1.2-150600.17.3.1 * vm-dump-metrics-debuginfo-1.2-150600.17.3.1 * vhostmd-debugsource-1.2-150600.17.3.1 *libmetrics0-debuginfo-1.2-150600.17.3.1 * vm-dump-metrics-1.2-150600.17.3.1 * libmetrics-devel-1.2-150600.17.3.1 * libmetrics0-1.2-150600.17.3.1 * vhostmd-debuginfo-1.2-150600.17.3.1 * Server Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * vhostmd-1.2-150600.17.3.1 * vm-dump-metrics-debuginfo-1.2-150600.17.3.1 * vhostmd-debugsource-1.2-150600.17.3.1 * vm-dump-metrics-1.2-150600.17.3.1 * vhostmd-debuginfo-1.2-150600.17.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1129772 * https://bugzilla.suse.com/show_bug.cgi?id=1152803 * https://bugzilla.suse.com/show_bug.cgi?id=1154838 * https://bugzilla.suse.com/show_bug.cgi?id=1181400 * https://bugzilla.suse.com/show_bug.cgi?id=1230961 . This release tackles several vulnerabilities in vhostmd for openSUSE. Strengthen your system's defenses with the newest patches.. Security Update, openSUSE, vhostmd Security, Patch Instructions. . LinuxSecurity.com Team

Calendar 2 Dec 24, 2024 OpenSUSE
100

SUSE: 2022:3457-1 Critical Vsftpd Access Control Security Update

An update that solves one vulnerability, contains two features and has 6 fixes is now available. . SUSE Security Update: Security update for vsftpd ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3457-1 Rating: important References: #1021387 #1052900 #1181400 #1187678 #1187686 #786024 #971784 PM-3322 SLE-23896 Cross-References: CVE-2021-3618 CVSS scores: CVE-2021-3618 (NVD) : 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N CVE-2021-3618 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Storage 7.1 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Retail Branch Server 4.2 SUSE Manager Server 4.1 SUSE Manager Server 4.2 openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves one vulnerability, contains two features and has 6 fixes is now available. Description: This update for vsftpd fixes the following issues: - CVE-2021-3618: Enforced security checks againstALPACA attack (PM-3322, jsc#SLE-23896, bsc#1187686, bsc#1187678). - Added hardening to systemd services (bsc#1181400). Bugfixes: - Fixed a seccomp failure in FIPS mode when SSL was enabled (bsc#1052900). - Allowed wait4() to be called so that the broker can wait for its child processes (bsc#1021387). - Fixed hang when using seccomp and syslog (bsc#971784). - Allowed sendto() syscall when /dev/log support is enabled (bsc#786024). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-3457=1 - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-3457=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-3457=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-3457=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-3457=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-3457=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-3457=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-3457=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-3457=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-3457=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-3457=1 Package List: - openSUSE Leap 15.3 (aarch64ppc64le s390x x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Manager Server 4.1 (ppc64le s390x x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Manager Proxy 4.1 (x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 ppc64le s390x x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): vsftpd-3.0.5-150200.12.9.1 vsftpd-debuginfo-3.0.5-150200.12.9.1 vsftpd-debugsource-3.0.5-150200.12.9.1 References: https://www.suse.com/security/cve/CVE-2021-3618.html https://bugzilla.suse.com/1021387 https://bugzilla.suse.com/1052900 https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1187678 https://bugzilla.suse.com/1187686 https://bugzilla.suse.com/786024 https://bugzilla.suse.com/971784 . Essential security patch for vsftpd resolves a specific vulnerability and introduces significant improvements and corrections for SUSE platforms.. vsftpd security,SUSE update,access control,important fixes,systemd hardening. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 28, 2022 Important SuSE
100

SUSE: 2022:0872-1 Critical: Security Update for Stunnel Software

An update that contains security fixes and contains one feature can now be installed. . SUSE Security Update: Security update for stunnel ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0872-1 Rating: important References: #1181400 #1182529 SLE-20679 Affected Products: SUSE Enterprise Storage 7 SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Server Applications 15-SP3 SUSE Linux Enterprise Module for Server Applications 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 ______________________________________________________________________________ An update that contains security fixes and contains one feature can now be installed. Description: This update for stunnel fixes the following issues: Update to 5.62 including new features and bugfixes: * Security bugfixes - The "redirect" option was fixed to properly handle unauthenticated requests (bsc#1182529). - Fixed a double free with OpenSSL older than 1.1.0. - Added hardening to systemd service (bsc#1181400). * New features - Added new "protocol = capwin" and "protocol = capwinctrl" configuration file options. - Added support for the new SSL_set_options() values. - Added a bash completion script. - New 'sessionResume' service-level option to allow or disallow session resumption - Download fresh ca-certs.pem for each new release. - New 'protocolHeader' service-level option to insert custom 'connect' protocol negotiation headers. This feature can be used to impersonate other software (e.g. web browsers). - 'protocolHost' can also be used to control the client SMTP protocol negotiation HELO/EHLO value. - Initial FIPS 3.0 support. - Client-side "protocol = ldap" support * Bugfixes - Fixed a transfer() loop bug. - Fixed reloading configuration with "systemctl reload stunnel.service". - Fixed incorrect messages logged for OpenSSL errors. - Fixed 'redirect' with 'protocol'. This combination is not supported by 'smtp', 'pop3' and 'imap' protocols. - X.509v3 extensions required by modern versions of OpenSSL are added to generated self-signed test certificates. - Fixed a tiny memory leak in configuration file reload error handling. - Fixed engine initialization. - FIPS TLS feature is reported when a provider or container is available, and not when FIPS control API is available. - Fix configuration reload when compression is used - Fix test suite fixed not to require external connectivity Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patchSUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-872=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-872=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-872=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-872=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-872=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-BCL-2022-872=1 - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-872=1 - SUSE Linux Enterprise Module for Server Applications 15-SP4: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP4-2022-872=1 - SUSE Linux Enterprise Module for Server Applications 15-SP3: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP3-2022-872=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-872=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-872=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-872=1 Package List: - SUSE Manager Server 4.1 (ppc64le s390x x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Manager Proxy 4.1 (x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Module for Server Applications 15-SP4 (aarch64 ppc64le s390x x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise Module for Server Applications 15-SP3 (aarch64 ppc64le s390x x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): stunnel-5.62-3.14.1 stunnel-debuginfo-5.62-3.14.1 stunnel-debugsource-5.62-3.14.1 References: https://bugzilla.suse.com/1181400 https://bugzilla.suse.com/1182529 . The latest update for stunnel addresses significant vulnerabilities and integrates essential patches. Protect your installations immediately!. SUSE Stunnel Update, Security Fixes, Systemd Hardening. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 16, 2022 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here