Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat Enterprise Linux 9 RHSA-2023-4331-01 Moderate Nodejs Fix

An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: nodejs security, bug fix, and enhancement update Advisory ID: RHSA-2023:4331-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:4331 Issue date: 2023-07-31 CVE Names: CVE-2023-30581 CVE-2023-30588 CVE-2023-30589 CVE-2023-30590 ===================================================================== 1. Summary: An update for nodejs is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AppStream (v. 9) - aarch64, noarch, ppc64le, s390x, x86_64 3. Description: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. The package has been upgraded to a later upstream version: nodejs (16.20.1). (BZ#2223334, BZ#2223336, BZ#2223338, BZ#2223340, BZ#2223342, BZ#2223344) Security Fix(es): * nodejs: mainModule.proto bypass experimental policy mechanism (CVE-2023-30581) * nodejs: process interuption due to invalid Public Key information in x509 certificates (CVE-2023-30588) * nodejs: HTTP Request Smuggling via Empty headers separated by CR (CVE-2023-30589) * nodejs: DiffieHellman do not generate keys after setting a privatekey (CVE-2023-30590) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2219824 - CVE-2023-30581 nodejs: mainModule.proto bypass experimental policy mechanism 2219838 - CVE-2023-30588 nodejs: process interuption due to invalid Public Key information in x509 certificates 2219841 - CVE-2023-30589 nodejs: HTTP Request Smuggling via Empty headers separated by CR 2219842 - CVE-2023-30590 nodejs: DiffieHellman do not generate keys after setting a private key 2223334 - nodejs: Rebase to the latest Nodejs 16 release [rhel-9] [rhel-9.2.0.z] 2223344 - nodejs: npm's /usr/etc/ softlink to /etc/ is preventing osbuild from creating Edge images. [rhel-9] [rhel-9.2.0.z] 6. Package List: Red Hat Enterprise Linux AppStream (v.9): Source: nodejs-16.20.1-1.el9_2.src.rpm aarch64: nodejs-16.20.1-1.el9_2.aarch64.rpm nodejs-debuginfo-16.20.1-1.el9_2.aarch64.rpm nodejs-debugsource-16.20.1-1.el9_2.aarch64.rpm nodejs-full-i18n-16.20.1-1.el9_2.aarch64.rpm nodejs-libs-16.20.1-1.el9_2.aarch64.rpm nodejs-libs-debuginfo-16.20.1-1.el9_2.aarch64.rpm npm-8.19.4-1.16.20.1.1.el9_2.aarch64.rpm noarch: nodejs-docs-16.20.1-1.el9_2.noarch.rpm ppc64le: nodejs-16.20.1-1.el9_2.ppc64le.rpm nodejs-debuginfo-16.20.1-1.el9_2.ppc64le.rpm nodejs-debugsource-16.20.1-1.el9_2.ppc64le.rpm nodejs-full-i18n-16.20.1-1.el9_2.ppc64le.rpm nodejs-libs-16.20.1-1.el9_2.ppc64le.rpm nodejs-libs-debuginfo-16.20.1-1.el9_2.ppc64le.rpm npm-8.19.4-1.16.20.1.1.el9_2.ppc64le.rpm s390x: nodejs-16.20.1-1.el9_2.s390x.rpm nodejs-debuginfo-16.20.1-1.el9_2.s390x.rpm nodejs-debugsource-16.20.1-1.el9_2.s390x.rpm nodejs-full-i18n-16.20.1-1.el9_2.s390x.rpm nodejs-libs-16.20.1-1.el9_2.s390x.rpm nodejs-libs-debuginfo-16.20.1-1.el9_2.s390x.rpm npm-8.19.4-1.16.20.1.1.el9_2.s390x.rpm x86_64: nodejs-16.20.1-1.el9_2.x86_64.rpm nodejs-debuginfo-16.20.1-1.el9_2.i686.rpm nodejs-debuginfo-16.20.1-1.el9_2.x86_64.rpm nodejs-debugsource-16.20.1-1.el9_2.i686.rpm nodejs-debugsource-16.20.1-1.el9_2.x86_64.rpm nodejs-full-i18n-16.20.1-1.el9_2.x86_64.rpm nodejs-libs-16.20.1-1.el9_2.i686.rpm nodejs-libs-16.20.1-1.el9_2.x86_64.rpm nodejs-libs-debuginfo-16.20.1-1.el9_2.i686.rpm nodejs-libs-debuginfo-16.20.1-1.el9_2.x86_64.rpm npm-8.19.4-1.16.20.1.1.el9_2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-30581 https://access.redhat.com/security/cve/CVE-2023-30588 https://access.redhat.com/security/cve/CVE-2023-30589 https://access.redhat.com/security/cve/CVE-2023-30590 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJkx8MoAAoJENzjgjWX9erENmAP+wQYcM3guk8vt1iLbWZun3nt vv24zXWFgnWLkER482kfYXBpKV8QczIAgRK6REOOe7titcWjTvc6eVCT6dhRrNxe hiAB1hW8H0wQhXMKPFB1lWYvghxVHLuLkjFoK2ITex5e/slwKBlc1tEaEf0ljr5s 4m/a3oP2Yt/k8RZv5IR68cdRdn1fOTGya06/gMkz2OydOb6s+vxQcMtX5yOfU/Mk UJWU1Ey2XALRAFOuC6DIB/G7ic1+G5QGFqVuVrmXecTChncliJEFhACGo9JHa3Y4 NkxAp6b27IXoaOX+sbRzhE2rnequ7yWHM2OBrEcs/SYqGMXrO8cbtfR5SGqn7QX7 geCgst75yBBSlEJWHsUcZ6xRUFG3igPe7bbhbwc3AVEJFijjg2qOC0V72PLn86rt cUzxiuXPyiRmzdUjbrLQGUq2a+/efwvq3909UL/iWYXYWJtE9yReIS/F0eWeiS4z +tUlL9BPCGbvdZUZ3mNlg1lWFJTsnDAH+QmYkLYbgp49GCH9COBOeQHGy0QBN052 NRs4Y8wJf12RFBPirI0BddCWARrFAOqV2si1nehf1J95ej/uqoKrAXALXD3e2VhU YRnurCXgAbqcY6+LGz1k0ucrisDXRG2PzXRWnlCx3mI4YH0BubYgA7JFjEQGtpNh BVkzXu4g13lrTdfATKty =QBcD -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A minor patch release for nodejs has been rolled out on Red Hat Enterprise Linux 9, targeting several vulnerabilities.. Red Hat Enterprise Linux,nodejs update,security patch,moderate severity,nodejs security. . LinuxSecurity.com Team

Calendar 2 Jul 31, 2023 Red Hat
89

Fedora 22: 2015-4685 Critical: QtWebKit Tracking In Private Browsing

QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-4685 2015-03-26 16:44:33 -------------------------------------------------------------------------------- Name : qtwebkit Product : Fedora 22 Version : 2.3.4 Release : 6.fc22 URL : https://trac.webkit.org/wiki/QtWebKit Summary : Qt WebKit bindings Description : Qt WebKit bindings -------------------------------------------------------------------------------- Update Information: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1204795 - qt5-qtwebkit: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode https://bugzilla.redhat.com/show_bug.cgi?id=1204795 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update qtwebkit' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Latest QtWebKit patch for Fedora 22 tackles privacy issue in incognito mode by preventing tracking of accessed URLs.. QtWebKit Update, Fedora Security, Browser Privacy, Linux Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 21, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here