Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian: DSA-3436-2 Critical: gnutls26 Man-In-The-Middle Exploit

Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw in the TLS 1.2 protocol which could allow the MD5 hash function to be used for signing ServerKeyExchange and Client Authentication packets during a TLS handshake. A man-in-the-middle attacker could exploit this flaw to . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3437-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 09, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : gnutls26 CVE ID : CVE-2015-7575 Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw in the TLS 1.2 protocol which could allow the MD5 hash function to be used for signing ServerKeyExchange and Client Authentication packets during a TLS handshake. A man-in-the-middle attacker could exploit this flaw to conduct collision attacks to impersonate a TLS server or an authenticated TLS client. More information can be found at https://www.mitls.org/pages/attacks/SLOTH For the oldstable distribution (wheezy), this problem has been fixed in version 2.12.20-8+deb7u5. We recommend that you upgrade your gnutls26 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial update for gnutls26 to mitigate man-in-the-middle vulnerabilities and guarantee secure TLS connections. Urgent upgrade advised!. gnutls26 update,tls security,debian advisory,md5 collision attack. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 09, 2016 Critical Debian
87

Debian 9: DSA-4567-2 Urgent: OpenSSL SSL Vulnerability Addressed

Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw in the TLS 1.2 protocol which could allow the MD5 hash function to be used for signing ServerKeyExchange and Client Authentication packets during a TLS handshake. A man-in-the-middle attacker could exploit this flaw to . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3436-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso January 08, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : openssl CVE ID : CVE-2015-7575 Karthikeyan Bhargavan and Gaetan Leurent at INRIA discovered a flaw in the TLS 1.2 protocol which could allow the MD5 hash function to be used for signing ServerKeyExchange and Client Authentication packets during a TLS handshake. A man-in-the-middle attacker could exploit this flaw to conduct collision attacks to impersonate a TLS server or an authenticated TLS client. More information can be found at https://www.mitls.org/pages/attacks/SLOTH For the oldstable distribution (wheezy), this problem has been fixed in version 1.0.1e-2+deb7u19. For the stable distribution (jessie), the testing distribution (stretch) and the unstable distribution (sid), this issue was already addressed in version 1.0.1f-1. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian has issued updates for OpenSSL addressing crucial TLS vulnerabilities, potentially allowing attackers to perform man-in-the-middle attacks, impersonating clients and servers.. Debian Security Advisory, TLS Protocol Flaw, OpenSSL Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 08, 2016 Important Debian
172

Ubuntu 12.04 LTS: USN-1628-1 Critical: Qt Network Exposure Flaw

Qt applications could be made to expose sensitive information overthe network.. =========================================================================Ubuntu Security Notice USN-1628-1 November 08, 2012 qt4-x11 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS - Ubuntu 11.10 - Ubuntu 10.04 LTS Summary: Qt applications could be made to expose sensitive information over the network. Software Description: - qt4-x11: Qt 4 libraries Details: Juliano Rizzo and Thai Duong discovered a flaw in the Transport Layer Security (TLS) protocol when it is used with data compression. If an attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to view sensitive information. This update disables TLS data compression in Qt by default. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libqt4-network 4:4.8.1-0ubuntu4.3 Ubuntu 11.10: libqt4-network 4:4.7.4-0ubuntu8.2 Ubuntu 10.04 LTS: libqt4-network 4:4.6.2-0ubuntu5.5 After a standard system update you need to restart any KDE sessions or applications linked against Qt to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1628-1 CVE-2012-4929 Package Information: https://launchpad.net/ubuntu/+source/qt4-x11/4:4.8.1-0ubuntu4.3 https://launchpad.net/ubuntu/+source/qt4-x11/4:4.7.4-0ubuntu8.2 https://launchpad.net/ubuntu/+source/qt4-x11/4:4.6.2-0ubuntu5.5 . Qt applications running on Ubuntu are at risk of revealing confidential data due to a TLS vulnerability. It is important to install an update to address this security issue.. Qt Security, Ubuntu Update, Network Protection, TLS Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 08, 2012 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here