Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
202

openSUSE Leap 15.4/15.5 Moderate: Emacs Trust Issues Advisory 2024:1294-1

This update for emacs fixes the following issues: CVE-2024-30203: Fixed treating inline MIME contents as trusted (bsc#1222053) CVE-2024-30204: Fixed LaTeX preview enabled by default for e-mail. # Security update for emacs Announcement ID: SUSE-SU-2024:1294-1 Rating: moderate References: * bsc#1222050 * bsc#1222052 * bsc#1222053 Cross-References: * CVE-2024-30203 * CVE-2024-30204 * CVE-2024-30205 CVSS scores: * CVE-2024-30203 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-30204 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-30205 ( SUSE ): 2.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP5 * Desktop Applications Module 15-SP5 * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for emacs fixes the following issues: * CVE-2024-30203: Fixed treating inline MIME contents as trusted (bsc#1222053) * CVE-2024-30204: Fixed LaTeX preview enabled by default for e-mail attachments (bsc#1222052) * CVE-2024-30205: Fixed Org mode considering contents of remote files as trusted (bsc#1222050) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-1294=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-1294=1 * Basesystem Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP5-2024-1294=1 * Desktop Applications Module 15-SP5 zypper in -t patchSUSE-SLE-Module-Desktop-Applications-15-SP5-2024-1294=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * emacs-x11-27.2-150400.3.11.1 * etags-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * openSUSE Leap 15.4 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * emacs-x11-27.2-150400.3.11.1 * etags-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * openSUSE Leap 15.5 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * Basesystem Module 15-SP5 (aarch64 ppc64le s390x x86_64) * etags-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * etags-debuginfo-27.2-150400.3.11.1 * emacs-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-nox-27.2-150400.3.11.1 * emacs-nox-debuginfo-27.2-150400.3.11.1 * Basesystem Module 15-SP5 (noarch) * emacs-el-27.2-150400.3.11.1 * emacs-info-27.2-150400.3.11.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * emacs-x11-27.2-150400.3.11.1 * emacs-debugsource-27.2-150400.3.11.1 * emacs-debuginfo-27.2-150400.3.11.1 * emacs-x11-debuginfo-27.2-150400.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2024-30203.html * https://www.suse.com/security/cve/CVE-2024-30204.html * https://www.suse.com/security/cve/CVE-2024-30205.html * https://bugzilla.suse.com/show_bug.cgi?id=1222050 *https://bugzilla.suse.com/show_bug.cgi?id=1222052 * https://bugzilla.suse.com/show_bug.cgi?id=1222053 . This emacs upgrade addresses several security concerns related to embedded MIME and LaTeX rendering configurations, classified as moderate.. emacs trust issues, openSUSE security patch, emacs content fix. . LinuxSecurity.com Team

Calendar%202 Apr 15, 2024 OpenSUSE
202

openSUSE: 2023:0171-1 Important: Nextcloud Desktop HTML Injection Fix

An update that fixes 5 vulnerabilities is now available. . openSUSE Security Update: Security update for nextcloud-desktop ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0171-1 Rating: important References: #1205798 #1205799 #1205800 #1205801 #1207976 Cross-References: CVE-2022-39331 CVE-2022-39332 CVE-2022-39333 CVE-2022-39334 CVE-2023-23942 CVSS scores: CVE-2022-39331 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2022-39332 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE-2022-39333 (NVD) : 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2022-39334 (NVD) : 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N CVE-2023-23942 (NVD) : 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for nextcloud-desktop fixes the following issues: Update ot 3.8.0 - Resize WebView widget once the loginpage rendered - Feature/secure file drop - Check German translation for wrong wording - L10n: Correct word - Fix displaying of file details button for local syncfileitem activities - Improve config upgrade warning dialog - Only accept folder setup page if overrideLocalDir is set - Update CHANGELOG. - Prevent ShareModel crash from accessing bad pointers - Bugfix/init value for pointers - Log to stdout when built in Debug config - Clean up account creation and deletion code - L10n: Added dot to end of sentence - L10n: Fixed grammar - Fix "Create new folder" menu entries in settings not working correctly on macOS - Ci/clang tidy checks initvariables - Fix share dialog infinite loading - Fix edit locally job not finding the user account: wrong user id - Skip e2e encrypted files with empty filename in metadata - Use new connect syntax - Fix avatars not showing up in settings dialog account actions until clicked on - Always discover blacklisted folders to avoid data loss when modifying selectivesync list. - Fix infinite loading in the share dialog when public link shares are disabled on the server - With cfapi when dehydrating files add missing flag - Fix text labels in Sync Status component - Display 'Search globally' as the last sharees list element - Fix display of 2FA notification. - Bugfix/do not restore virtual files - Show server name in tray main window - Add Ubuntu Lunar - Debian build classification 'beta' cannot override 'release'. - Update changelog - Follow shouldNotify flag to hide notifications when needed - Bugfix/stop after creating config file - E2EE cut extra zeroes from derypted byte array. - When local sync folder is overriden, respect this choice - Feature/e2ee fixes - This update also fixes security issues: - (boo#1205798, CVE-2022-39331) - Arbitrary HyperText Markup Language injection in notifications - (boo#1205799, CVE-2022-39332) - Arbitrary HyperText Markup Language injection in user status and information - (boo#1205800, CVE-2022-39333) - Arbitrary HyperText Markup Language injection in desktop client application - (boo#1205801, CVE-2022-39334) - Client incorrectly trusts invalid TLS certificates - (boo#1207976, CVE-2023-23942) - missing sanitisation on qml labels leading to javascript injection Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for yourproduct: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-171=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 x86_64): libnextcloudsync-devel-3.8.0-bp155.2.3.1 libnextcloudsync0-3.8.0-bp155.2.3.1 nextcloud-desktop-3.8.0-bp155.2.3.1 nextcloud-desktop-dolphin-3.8.0-bp155.2.3.1 - openSUSE Backports SLE-15-SP5 (noarch): caja-extension-nextcloud-3.8.0-bp155.2.3.1 cloudproviders-extension-nextcloud-3.8.0-bp155.2.3.1 nautilus-extension-nextcloud-3.8.0-bp155.2.3.1 nemo-extension-nextcloud-3.8.0-bp155.2.3.1 nextcloud-desktop-doc-3.8.0-bp155.2.3.1 nextcloud-desktop-lang-3.8.0-bp155.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-39331.html https://www.suse.com/security/cve/CVE-2022-39332.html https://www.suse.com/security/cve/CVE-2022-39333.html https://www.suse.com/security/cve/CVE-2022-39334.html https://www.suse.com/security/cve/CVE-2023-23942.html https://bugzilla.suse.com/1205798 https://bugzilla.suse.com/1205799 https://bugzilla.suse.com/1205800 https://bugzilla.suse.com/1205801 https://bugzilla.suse.com/1207976 . Nextcloud-desktop has undergone a crucial security enhancement aimed at addressing HTML injection vulnerabilities and problems with TLS trust.. Nextcloud Desktop Security, openSUSE HTML Injection, Important Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2023 Important OpenSUSE
89

Fedora 36: 2023-7ed04fe4a7 Moderate: Certifi Library Trust Issue

Update to 2022.12.7, fixes CVE-2022-23491.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-7ed04fe4a7 2023-03-30 01:14:14.931077 --------------------------------------------------------------------------------Name : mingw-python-certifi Product : Fedora 36 Version : 2022.12.7 Release : 1.fc36 URL : https://certifi.io/ Summary : MinGW Windows Python certifi library Description : MinGW Windows Python certifi. --------------------------------------------------------------------------------Update Information: Update to 2022.12.7, fixes CVE-2022-23491. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 21 2023 Sandro Mani - 2022.12.7-1 - Update to 2022.12.7 * Thu Jul 21 2022 Fedora Release Engineering - 2021.10.8-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild * Mon Feb 14 2022 Sandro Mani - 2021.10.8-1 - Update to 2021.10.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #2180096 - CVE-2022-23491 mingw-python-certifi: python-certifi: untrusted root certificates [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2180096 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-7ed04fe4a7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribesend an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . MinGW Windows Python ssl-cert updated to resolve untrusted root certificates issue on Fedora 37, crucial for safeguarding system integrity.. Fedora, Certifi Update, Software Fix, Python Dependency. . LinuxSecurity.com Team

Calendar%202 Mar 30, 2023 Fedora
197

Debian 8: DLA-1417-1 Critical Security Update For CA Certificates

There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. . Package : ca-certificates Version : 20141019+deb8u4 Debian Bugs : #858064 #858539 #867461 #894070 There have been a number of updates to the set of Certificate Authority (CA) certificates that are considered "valid" or otherwise should be trusted. For Debian 8 "Jessie", these issues have been fixed in ca-certificates version 20141019+deb8u4. We recommend that you upgrade your ca-certificates packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Keep informed about the newest security patch for ca-certificates in Debian 8, resolving trust concerns and additional vulnerabilities.. Debian Security, CA Certificates, Security Updates, Trusted Certificates, Trust Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 07, 2018 Critical Debian LTS
87

Debian DSA-3953-1: Aodh Trust Vulnerability Update - Moderate Severity

Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3953-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Luciano Bello August 23, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : aodh CVE ID : CVE-2017-12440 Debian Bug : 872605 Zane Bitter from Red Hat discovered a vulnerability in Aodh, the alarm engine for OpenStack. Aodh does not verify that the user creating the alarm is the trustor or has the same rights as the trustor, nor that the trust is for the same project as the alarm. The bug allows that an authenticated users without a Keystone token with knowledge of trust IDs to perform unspecified authenticated actions by adding alarm actions. For the stable distribution (stretch), this problem has been fixed in version 3.0.0-4+deb9u1. We recommend that you upgrade your aodh packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Debian advisory DSA-3954-2 highlights a vulnerability in Aodh, specifically related to its authentication mechanism when connected to OpenStack.. Debian Aodh Update, OpenStack Security, Trust Verification Issue. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2017 Debian
87

Debian 2.2: DSA-061-1 Moderate: GnuPG Format Attack & Trust Issue

A printf format string attack and "web of trust" pollution vulnerabilities have been fixed.. ------------------------------------------------------------------------ Debian Security Advisory DSA-061-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman June 16, 2001 ------------------------------------------------------------------------ Package : gnupg Problem type : printf format attack web of trust pollution Debian-specific: no The version of GnuPG (GNU Privacy Guard, an OpenPGP implementation) as distributed in Debian GNU/Linux 2.2 suffers from two problems: fish stiqz reported on bugtraq that there was a printf format problem in the do_get() function: it printed a prompt which included the filename that was being decrypted without checking for possible printf format attacks. This could be exploited by tricking someone into decrypting a file with a specially crafted filename. The second bug is related to importing secret keys: when gnupg imported a secret key it would immediately make the associated public key fully trusted which changes your web of trust without asking for a confirmation. To fix this you now need a special option to import a secret key. Both problems have been fixed in version 1.0.6-0potato1. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 4928a4a589c11cadea852347d23edf5a MD5 checksum: e6057febed9106dfc9f77fb61fbd0ca4 MD5 checksum: 7c319a9e5e70ad9bc3bf0d7b5008a508 Alpha architecture: MD5 checksum: 76c3f586b91bba1c69a6fb6ea93a2fbd ARM architecture: MD5 checksum: 84a47897a38f44b07180e9a9ec16ab49 Intel IA-32 architecture: MD5 checksum: d3a91ccc9d1c951b80afe17e59190db3 Motorola680x0 architecture: MD5 checksum: 6b12f23b3c3840574af826db147ed9cd PowerPC architecture: MD5 checksum: a5a9bffdce2abf112c2058097f48f784 Sun Sparc architecture: MD5 checksum: 487c0d605ff5b3fdce2212d4e9c07bf0 These packages will be moved into the stable distribution on its next revision. For not yet released architectures please refer to the appropriate directory . -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The software package GnuPG on Debian has resolved two critical security issues, including a format string vulnerability and a weakness in trust management mechanisms.. Debian GnuPG Security Update, Format String Attack, Trust Management Issue. . LinuxSecurity.com Team

Calendar%202 Jun 18, 2001 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200