Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
98

Red Hat 2.1: RHSA-2003:178-01 Severe up2date Connectivity Problem

This release also includes an updated RHNS-CA-CERT file, which contains an additional CA certificate. This is needed so that up2date can continue to communicate with Red Hat Network once the current CA certificate reaches its August 2003 expiration date. . --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated up2date and rhn_register clients available Advisory ID: RHSA-2003:177-01 Issue date: 2003-05-27 Updated on: 2003-05-27 Product: Red Hat Enterprise Linux Keywords: up2date rhn_register rpm Red Hat Network up2date-gnome update agent Cross references: Obsoletes: ---------------------------------------------------------------------1. Topic: Updated versions of the rhn_register and up2date packages are now available. The new packages include many bug fixes, and a few new features. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: The rhn_register and up2date packages contain the software necessary to take advantage of Red Hat Network functionality. The up2date package incorporates improvements in handling package dependencies and "obsoletes" processing, along with many other bug fixes. This release also includes an updated RHNS-CA-CERT file, which contains an additional CA certificate. This is needed so that up2date can continue to communicate with Red Hat Network once the current CA certificate reaches its August 2003 expiration date. All users of Red Hat Network should therefore upgrade to these erratum packages. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture,run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 67865 - "up2date --version" does NOT display version 65423 - "up2date -f" does not update skipped packages on first attempt 64851 - Non fatal Gtk errors when up2date hits a package already in its cache 64796 - up2date segfaults during Migration 64791 - Typo in manpage of up2date 64771 - Updating from 7.2 to 7.3 then using up2date yields 557 "outdated" packages in RHN 63921 - "kb" for file sizes should probably be "kB" 63917 - "toverify" typo in up2date 63907 - "Overrite" typo in up2date 63484 - Can't only select skipped files 63301 - unknown signatures aren't warned 53247 - up2date -u -nox fails 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: i386: Available from Red Hat Network: up2date-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: up2date-gnome-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-2.8.34-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm ia64: Available from Red Hat Network: up2date-2.8.45-1.2.1AS.ia64.rpm Available from Red Hat Network: up2date-gnome-2.8.45-1.2.1AS.ia64.rpm Available from Red Hat Network: rhn_register-2.8.34-1.2.1AS.ia64.rpm Available from Red Hat Network: rhn_register-gnome-2.8.34-1.2.1AS.ia64.rpm Red Hat LinuxAdvanced Workstation 2.1: SRPMS: ia64: Available from Red Hat Network: up2date-2.8.45-1.2.1AS.ia64.rpm Available from Red Hat Network: up2date-gnome-2.8.45-1.2.1AS.ia64.rpm Available from Red Hat Network: rhn_register-2.8.34-1.2.1AS.ia64.rpm Available from Red Hat Network: rhn_register-gnome-2.8.34-1.2.1AS.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: i386: Available from Red Hat Network: up2date-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: up2date-gnome-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-2.8.34-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: i386: Available from Red Hat Network: up2date-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: up2date-gnome-2.8.45-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-2.8.34-1.2.1AS.i386.rpm Available from Red Hat Network: rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm 7. Verification: MD5 sum Package Name --------------------------------------------------------------------------e10930d8965ac2a685e1482ba8c0e9af 2.1AS/en/os/SRPMS/rhn_register-2.8.34-1.2.1AS.src.rpm 5e64b82944c7ccd62986551c3244cb6f 2.1AS/en/os/SRPMS/up2date-2.8.45-1.2.1AS.src.rpm e3362186968d6e6da916a967d8d3655f 2.1AS/en/os/i386/rhn_register-2.8.34-1.2.1AS.i386.rpm 019b32631452559245ce70e26f2ed928 2.1AS/en/os/i386/rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm 42f3379722023af4412c79e686a04c89 2.1AS/en/os/i386/up2date-2.8.45-1.2.1AS.i386.rpm b0897084ce6ba6e4ae15ffa070739776 2.1AS/en/os/i386/up2date-gnome-2.8.45-1.2.1AS.i386.rpm 88b85b602b3651cc3364b992c8e99f04 2.1AS/en/os/ia64/rhn_register-2.8.34-1.2.1AS.ia64.rpm fdd03e41d5eb74d520a6f0d8cb969fba 2.1AS/en/os/ia64/rhn_register-gnome-2.8.34-1.2.1AS.ia64.rpm fdf5c0ca850486b13288287e8d776e16 2.1AS/en/os/ia64/up2date-2.8.45-1.2.1AS.ia64.rpm 296d91a647c0ac255fe77e4a2b602d0a2.1AS/en/os/ia64/up2date-gnome-2.8.45-1.2.1AS.ia64.rpm e10930d8965ac2a685e1482ba8c0e9af 2.1AW/en/os/SRPMS/rhn_register-2.8.34-1.2.1AS.src.rpm 5e64b82944c7ccd62986551c3244cb6f 2.1AW/en/os/SRPMS/up2date-2.8.45-1.2.1AS.src.rpm 88b85b602b3651cc3364b992c8e99f04 2.1AW/en/os/ia64/rhn_register-2.8.34-1.2.1AS.ia64.rpm fdd03e41d5eb74d520a6f0d8cb969fba 2.1AW/en/os/ia64/rhn_register-gnome-2.8.34-1.2.1AS.ia64.rpm fdf5c0ca850486b13288287e8d776e16 2.1AW/en/os/ia64/up2date-2.8.45-1.2.1AS.ia64.rpm 296d91a647c0ac255fe77e4a2b602d0a 2.1AW/en/os/ia64/up2date-gnome-2.8.45-1.2.1AS.ia64.rpm e10930d8965ac2a685e1482ba8c0e9af 2.1ES/en/os/SRPMS/rhn_register-2.8.34-1.2.1AS.src.rpm 5e64b82944c7ccd62986551c3244cb6f 2.1ES/en/os/SRPMS/up2date-2.8.45-1.2.1AS.src.rpm e3362186968d6e6da916a967d8d3655f 2.1ES/en/os/i386/rhn_register-2.8.34-1.2.1AS.i386.rpm 019b32631452559245ce70e26f2ed928 2.1ES/en/os/i386/rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm 42f3379722023af4412c79e686a04c89 2.1ES/en/os/i386/up2date-2.8.45-1.2.1AS.i386.rpm b0897084ce6ba6e4ae15ffa070739776 2.1ES/en/os/i386/up2date-gnome-2.8.45-1.2.1AS.i386.rpm e10930d8965ac2a685e1482ba8c0e9af 2.1WS/en/os/SRPMS/rhn_register-2.8.34-1.2.1AS.src.rpm 5e64b82944c7ccd62986551c3244cb6f 2.1WS/en/os/SRPMS/up2date-2.8.45-1.2.1AS.src.rpm e3362186968d6e6da916a967d8d3655f 2.1WS/en/os/i386/rhn_register-2.8.34-1.2.1AS.i386.rpm 019b32631452559245ce70e26f2ed928 2.1WS/en/os/i386/rhn_register-gnome-2.8.34-1.2.1AS.i386.rpm 42f3379722023af4412c79e686a04c89 2.1WS/en/os/i386/up2date-2.8.45-1.2.1AS.i386.rpm b0897084ce6ba6e4ae15ffa070739776 2.1WS/en/os/i386/up2date-gnome-2.8.45-1.2.1AS.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available at https://www.redhat.com/en/products You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. Contact: The Red Hat securitycontact is . More contact details at https://www.redhat.com/en/products Copyright 2003 Red Hat, Inc. . Updated up2date and rhn_register tools for Red Hat 2.1 to address severe connectivity issues and enhance performance.. Red Hat Security, Up2date Connectivity, Network Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 08, 2023 Important Red Hat
98

Red Hat Linux 7.x RHSA-2003:267-01 Critical SSL Update for Network Access

New versions of the up2date and rhn_register clients are available andare required for continued access to Red Hat Network.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: New up2date available with updated SSL certificate authority file Advisory ID: RHSA-2003:267-01 Issue date: 2003-08-29 Updated on: 2003-08-29 Product: Red Hat Linux Keywords: up2date Red Hat Network rhn_register Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: New versions of the up2date and rhn_register clients are available and are required for continued access to Red Hat Network. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 Red Hat Linux 9 - i386 3. Problem description: The rhn_register and up2date packages contain the software necessary to take advantage of Red Hat Network functionality. This erratum includes an updated RHNS-CA-CERT file, which contains a new CA certificate. This new certificate is needed so that up2date can continue to communicate with Red Hat Network after 28 August 2003. Without this updated certificate, users will see SSL Connection Errors reported by up2date or rhn_register. All users must upgrade to these erratum packages in order to continue to use Red Hat Network. This includes both interactive use of up2date, as well as actions scheduled by the RHN website. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if yourcurrent directory *only* contains the desired RPMs. Because the previous Certificate Authority has expired, up2date will present 'SSL Certificate Errors' if you attempt to use it to apply this errata. Therefore, this update cannot be applied directly with up2date and instead must be applied as indicated above. In addition to the Red Hat FTP site, the latest versions of up2date and rhn_register are also available at For users who would prefer to install the new certificate directly, it is available at: 5. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- b67ea5065c3115d523e17561aac5cb7c 7.1/en/os/SRPMS/up2date-2.8.40-1.7.1.src.rpm 71f2f6e4bfcdee8f4f46ef037c7a1c8d 7.1/en/os/i386/up2date-2.8.40-1.7.1.i386.rpm 2205d1e5832dbb67d60103104eb59fec 7.1/en/os/i386/up2date-gnome-2.8.40-1.7.1.i386.rpm 3deea256b106e71ee6d5890639d872b3 7.2/en/os/SRPMS/up2date-2.8.40-2.7.2.src.rpm 21bc8e1f03e9f28590d46df60a9458b5 7.2/en/os/i386/up2date-2.8.40-2.7.2.i386.rpm 3d3d7c6dca73d521a0f541b859f13eb3 7.2/en/os/i386/up2date-gnome-2.8.40-2.7.2.i386.rpm ac5161a5bbe122896eccbc312bef9273 7.2/en/os/ia64/up2date-2.8.40-2.7.2.ia64.rpm c789fbf88d7faf82504eb4189b767f90 7.2/en/os/ia64/up2date-gnome-2.8.40-2.7.2.ia64.rpm 23d8868920cb7df21925669f04fb2ad2 7.3/en/os/SRPMS/up2date-2.8.40-3.7.3.src.rpm 3643d7774d7e60a1aeb79c8fecbf624c 7.3/en/os/i386/up2date-2.8.40-3.7.3.i386.rpm 89977334ec0d3a2a720c3303602fc8dd 7.3/en/os/i386/up2date-gnome-2.8.40-3.7.3.i386.rpm 17ad92db4579d046d84c84a16784ba98 8.0/en/os/SRPMS/up2date-3.0.7.2-1.src.rpm 15bc5dc918916bca3a5c29148979716e 8.0/en/os/i386/up2date-3.0.7.2-1.i386.rpm 1ae89cf79880f3bc5de7b86eb1d47a2b8.0/en/os/i386/up2date-gnome-3.0.7.2-1.i386.rpm b8a5b2d548869a846cbaf373f3637555 9/en/os/SRPMS/up2date-3.1.23.2-1.src.rpm 3faabcb9cc610627fe378b88d0b2b928 9/en/os/i386/up2date-3.1.23.2-1.i386.rpm 733d0aca17c15af0b1fa709ba86337dc 9/en/os/i386/up2date-gnome-3.1.23.2-1.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. . Update your configuration to re-establish connection to the Oracle Network; includes a revised SSL certification authority database.. Red Hat Update, SSL Issues, Up2date Clients, Red Hat Network, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 29, 2003 Critical Red Hat
98

Red Hat Linux 8.0 RHSA-2003:255-01 Moderate GPG Signature Exploit

up2date versions 3.0.7 and 3.1.23 incorrectly check RPM GPG signatures. These are the versions found in Red Hat Linux 8.0 and 9.. --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: up2date improperly checks GPG signature of packages Advisory ID: RHSA-2003:255-01 Issue date: 2003-08-08 Updated on: 2003-08-08 Product: Red Hat Linux Keywords: up2date gpg Red Hat Network RHN rpm Cross references: Obsoletes: CVE Names: CAN-2003-0546 --------------------------------------------------------------------- 1. Topic: Updated up2date packages for Red Hat Linux 8.0 and 9 fix RPM GPG signature verification. 2. Relevant releases/architectures: Red Hat Linux 8.0 - i386 Red Hat Linux 9 - i386 3. Problem description: The Red Hat Update Agent, up2date, automatically queries the Red Hat Network servers and determines which packages need to be updated on your machine. up2date versions 3.0.7 and 3.1.23 incorrectly check RPM GPG signatures. These are the versions found in Red Hat Linux 8.0 and 9. This bug allows packages which have no GPG signature to be installed by up2date if they are provided by the Red Hat Network servers. The intended behaviour is that only packages signed with the Red Hat package signing key will be installed. For an attacker to make use of this flaw, they would have to make unsigned packages appear on the Red Hat Network. Connections to the Red Hat Network servers are authenticated and verified by the use of SSL, so it is not possible to intercept the connection to Red Hat Network servers and give unsigned packages. To make use of this flaw, an attacker would have to compromise the Red Hat Network servers at Red Hat. Because of these factors, the risk of exploiting this bug is low. However, we advise that all users of up2date update to these erratum packages. Note that all other variations of package signature checks work correctly. The fix was to change the codeso that packages with no GPG signature are rejected in the same way as those with bad GPG signatures (the up2date client refuses to install them). Red Hat would like to thank Barry Nathan for finding and reporting this error. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 8.0: SRPMS: i386: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 606193c00a7fb419b4952b68f1245082 8.0/en/os/SRPMS/up2date-3.0.7.1-2.src.rpm be91944cf454244846a96b94a3efaa74 8.0/en/os/i386/up2date-3.0.7.1-2.i386.rpm 0adeb9cf7fff1754d183894fa40111bc 8.0/en/os/i386/up2date-gnome-3.0.7.1-2.i386.rpm 99d3b05223b596cf8d949c27b48e2ebd 9/en/os/SRPMS/up2date-3.1.23.1-5.src.rpm c6e89c3f118b5734a34d7275d8156596 9/en/os/i386/up2date-3.1.23.1-5.i386.rpm bf0b79cfeaaa6ed947609a27da5c2d65 9/en/os/i386/up2date-gnome-3.1.23.1-5.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from Product Signing Keys - Red Hat Customer Portal You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each packagehas not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2003-0546 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. . Investigate the security risks of Red Hat's up2date tool related to GPG signature validation issues. Discover strategies to enhance system security and mitigate these vulnerabilities. GPG Signature, Red Hat Update, System Update, Package Signing. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 08, 2003 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here