Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
100

SUSE: 2025:1157-1 important: MozillaThunderbird Memory Issues

* bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029 . # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2025:1157-1 Release Date: 2025-04-07T08:27:15Z Rating: important References: * bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029 * CVE-2025-3030 CVSS scores: * CVE-2025-3028 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-3028 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-3029 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-3029 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-3030 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-3030 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: * Mozilla Thunderbird ESR 128.9 MFSA 2025-24 (bsc#1240083) * CVE-2025-3028: Use-after-free triggered by XSLTProcessor * CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters * CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9 Other fixes: * new: Thunderbird now has a notification system for real-time desktop alerts * fixed: Data corruption occurred when compacting IMAP Drafts folder after saving a message * fixed: Right-clicking "Decrypt and Save As..." on an attachment file failed. * fixed: Thunderbird could crash when importing mail * fixed: Sort indicators were missing on the calendar events list. ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1157=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1157=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1157=1 ## Package List: * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3028.html * https://www.suse.com/security/cve/CVE-2025-3029.html * https://www.suse.com/security/cve/CVE-2025-3030.html * https://bugzilla.suse.com/show_bug.cgi?id=1240083 . The latest security patch for Mozilla Thunderbird resolves various vulnerabilities such as memory safety concerns and URL deception in SUSE distributions.. MozillaThunderbird, SUSE Update, Security Issues, Memory Safety. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Apr 07, 2025 Important SuSE
202

openSUSE 15.6: 2025:1157-1 critical: MozillaThunderbird vulnerabilities

An update that solves three vulnerabilities can now be installed.. # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2025:1157-1 Release Date: 2025-04-07T08:27:15Z Rating: important References: * bsc#1240083 Cross-References: * CVE-2025-3028 * CVE-2025-3029 * CVE-2025-3030 CVSS scores: * CVE-2025-3028 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-3028 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-3029 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-3029 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-3030 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-3030 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Workstation Extension 15 SP6 * SUSE Package Hub 15 15-SP6 An update that solves three vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: * Mozilla Thunderbird ESR 128.9 MFSA 2025-24 (bsc#1240083) * CVE-2025-3028: Use-after-free triggered by XSLTProcessor * CVE-2025-3029: URL Bar Spoofing via non-BMP Unicode characters * CVE-2025-3030: Memory safety bugs fixed in Firefox 137, Thunderbird 137, Firefox ESR 128.9, and Thunderbird 128.9 Other fixes: * new: Thunderbird now has a notification system for real-time desktop alerts * fixed: Data corruption occurred when compacting IMAP Drafts folder after saving a message * fixed: Right-clicking "Decrypt and Save As..." on an attachment file failed. * fixed: Thunderbird could crash when importing mail * fixed: Sort indicators were missing on the calendar events list. ## Patch Instructions: To install this SUSE update use the SUSErecommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP6 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP6-2025-1157=1 * SUSE Linux Enterprise Workstation Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-WE-15-SP6-2025-1157=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1157=1 ## Package List: * SUSE Package Hub 15 15-SP6 (aarch64 ppc64le s390x) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 * SUSE Linux Enterprise Workstation Extension 15 SP6 (x86_64) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-debuginfo-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-common-128.9.0-150200.8.206.1 * MozillaThunderbird-translations-other-128.9.0-150200.8.206.1 * MozillaThunderbird-debugsource-128.9.0-150200.8.206.1 * MozillaThunderbird-128.9.0-150200.8.206.1 ## References: * https://www.suse.com/security/cve/CVE-2025-3028.html * https://www.suse.com/security/cve/CVE-2025-3029.html * https://www.suse.com/security/cve/CVE-2025-3030.html * https://bugzilla.suse.com/show_bug.cgi?id=1240083 . This essential upgrade tackles various vulnerabilities in Mozilla Firefox enhancing overall security and efficiency.. SUSE MozillaThunderbird Security Update April 2025. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 07, 2025 Important OpenSUSE
87

Debian DSA-4562-1: Chromium Security Update for Multiple Issues

Several vulnerabilities have been discovered in the chromium web browser. CVE-2019-5869 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - -------------------------------------------------------------------------- Debian Security Advisory DSA-4562-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert November 10, 2019 https://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : chromium CVE ID : CVE-2019-5869 CVE-2019-5870 CVE-2019-5871 CVE-2019-5872 CVE-2019-5874 CVE-2019-5875 CVE-2019-5876 CVE-2019-5877 CVE-2019-5878 CVE-2019-5879 CVE-2019-5880 CVE-2019-13659 CVE-2019-13660 CVE-2019-13661 CVE-2019-13662 CVE-2019-13663 CVE-2019-13664 CVE-2019-13665 CVE-2019-13666 CVE-2019-13667 CVE-2019-13668 CVE-2019-13669 CVE-2019-13670 CVE-2019-13671 CVE-2019-13673 CVE-2019-13674 CVE-2019-13675 CVE-2019-13676 CVE-2019-13677 CVE-2019-13678 CVE-2019-13679 CVE-2019-13680 CVE-2019-13681 CVE-2019-13682 CVE-2019-13683 CVE-2019-13685 CVE-2019-13686 CVE-2019-13687 CVE-2019-13688 CVE-2019-13691 CVE-2019-13692 CVE-2019-13693 CVE-2019-13694 CVE-2019-13695 CVE-2019-13696 CVE-2019-13697 CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2019-13713 CVE-2019-13714 CVE-2019-13715 CVE-2019-13716 CVE-2019-13717 CVE-2019-13718 CVE-2019-13719 CVE-2019-13720 CVE-2019-13721 Several vulnerabilities have been discovered in the chromium web browser. CVE-2019-5869 Zhe Jin discovered a use-after-free issue. CVE-2019-5870 Guang Gong discovered a use-after-freeissue. CVE-2019-5871 A buffer overflow issue was discovered in the skia library. CVE-2019-5872 Zhe Jin discovered a use-after-free issue. CVE-2019-5874 James Lee discovered an issue with external Uniform Resource Identifiers. CVE-2019-5875 Khalil Zhani discovered a URL spoofing issue. CVE-2019-5876 Man Yue Mo discovered a use-after-free issue. CVE-2019-5877 Guang Gong discovered an out-of-bounds read issue. CVE-2019-5878 Guang Gong discovered an use-after-free issue in the v8 javascript library. CVE-2019-5879 Jinseo Kim discover that extensions could read files on the local system. CVE-2019-5880 Jun Kokatsu discovered a way to bypass the SameSite cookie feature. CVE-2019-13659 Lnyas Zhang discovered a URL spoofing issue. CVE-2019-13660 Wenxu Wu discovered a user interface error in full screen mode. CVE-2019-13661 Wenxu Wu discovered a user interface spoofing issue in full screen mode. CVE-2019-13662 David Erceg discovered a way to bypass the Content Security Policy. CVE-2019-13663 Lnyas Zhang discovered a way to spoof Internationalized Domain Names. CVE-2019-13664 Thomas Shadwell discovered a way to bypass the SameSite cookie feature. CVE-2019-13665 Jun Kokatsu discovered a way to bypass the multiple file download protection feature. CVE-2019-13666 Tom Van Goethem discovered an information leak. CVE-2019-13667 Khalil Zhani discovered a URL spoofing issue. CVE-2019-13668 David Erceg discovered an information leak. CVE-2019-13669 Khalil Zhani discovered an authentication spoofing issue. CVE-2019-13670 Guang Gong discovered a memory corruption issue in the v8 javascript library. CVE-2019-13671 xisigr discovered a user interface error. CVE-2019-13673 David Erceg discovered an information leak. CVE-2019-13674 Khalil Zhani discovered a way to spoof Internationalized Domain Names. CVE-2019-13675 Jun Kokatsu discovered a way to disableextensions. CVE-2019-13676 Wenxu Wu discovered an error in a certificate warning. CVE-2019-13677 Jun Kokatsu discovered an error in the chrome web store. CVE-2019-13678 Ronni Skansing discovered a spoofing issue in the download dialog window. CVE-2019-13679 Conrad Irwin discovered that user activation was not required for printing. CVE-2019-13680 Thijs Alkamade discovered an IP address spoofing issue. CVE-2019-13681 David Erceg discovered a way to bypass download restrictions. CVE-2019-13682 Jun Kokatsu discovered a way to bypass the site isolation feature. CVE-2019-13683 David Erceg discovered an information leak. CVE-2019-13685 Khalil Zhani discovered a use-after-free issue. CVE-2019-13686 Brendon discovered a use-after-free issue. CVE-2019-13687 Man Yue Mo discovered a use-after-free issue. CVE-2019-13688 Man Yue Mo discovered a use-after-free issue. CVE-2019-13691 David Erceg discovered a user interface spoofing issue. CVE-2019-13692 Jun Kokatsu discovered a way to bypass the Same Origin Policy. CVE-2019-13693 Guang Gong discovered a use-after-free issue. CVE-2019-13694 banananapenguin discovered a use-after-free issue. CVE-2019-13695 Man Yue Mo discovered a use-after-free issue. CVE-2019-13696 Guang Gong discovered a use-after-free issue in the v8 javascript library. CVE-2019-13697 Luan Herrera discovered an information leak. CVE-2019-13699 Man Yue Mo discovered a use-after-free issue. CVE-2019-13700 Man Yue Mo discovered a buffer overflow issue. CVE-2019-13701 David Erceg discovered a URL spoofing issue. CVE-2019-13702 Phillip Langlois and Edward Torkington discovered a privilege escalation issue in the installer. CVE-2019-13703 Khalil Zhani discovered a URL spoofing issue. CVE-2019-13704 Jun Kokatsu discovered a way to bypass the Content Security Policy. CVE-2019-13705 Luan Herrera discovered a way to bypass extensionpermissions. CVE-2019-13706 pdknsk discovered an out-of-bounds read issue in the pdfium library. CVE-2019-13707 Andrea Palazzo discovered an information leak. CVE-2019-13708 Khalil Zhani discovered an authentication spoofing issue. CVE-2019-13709 Zhong Zhaochen discovered a way to bypass download restrictions. CVE-2019-13710 bernardo.mrod discovered a way to bypass download restrictions. CVE-2019-13711 David Erceg discovered an information leak. CVE-2019-13713 David Erceg discovered an information leak. CVE-2019-13714 Jun Kokatsu discovered an issue with Cascading Style Sheets. CVE-2019-13715 xisigr discovered a URL spoofing issue. CVE-2019-13716 Barron Hagerman discovered an error in the service worker implementation. CVE-2019-13717 xisigr discovered a user interface spoofing issue. CVE-2019-13718 Khalil Zhani discovered a way to spoof Internationalized Domain Names. CVE-2019-13719 Khalil Zhani discovered a user interface spoofing issue. CVE-2019-13720 Anton Ivanov and Alexey Kulaev discovered a use-after-free issue. CVE-2019-13721 banananapenguin discovered a use-after-free issue in the pdfium library. For the oldstable distribution (stretch), support for chromium has been discontinued. Please upgrade to the stable release (buster) to continue receiving chromium updates or switch to firefox, which continues to be supported in the oldstable release. For the stable distribution (buster), these problems have been fixed in version 78.0.3904.97-1~deb10u1. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/chromium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security NoticeDSA-4562-1 outlines several vulnerabilities discovered in chromium software, along with the recommended patches. Users are advised to update urgently.. debian security, chromium updates, browser issues, advisory DSA-4562-1. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 10, 2019 Critical Debian
98

Red Hat: RHSA-2019-3759-01 Important: Chromium Browser Security Fix

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2019:3759-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2019:3759 Issue date: 2019-11-06 CVE Names: CVE-2019-13699 CVE-2019-13700 CVE-2019-13701 CVE-2019-13702 CVE-2019-13703 CVE-2019-13704 CVE-2019-13705 CVE-2019-13706 CVE-2019-13707 CVE-2019-13708 CVE-2019-13709 CVE-2019-13710 CVE-2019-13711 CVE-2019-13713 CVE-2019-13714 CVE-2019-13715 CVE-2019-13716 CVE-2019-13717 CVE-2019-13718 CVE-2019-13719 ==================================================================== 1. Summary: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux HPC Node Supplementary (v. 6) - i686, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, i686, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, i686, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). This update upgrades Chromium toversion 78.0.3904.70. Security Fix(es): * chromium-browser: Use-after-free in media (CVE-2019-13699) * chromium-browser: Buffer overrun in Blink (CVE-2019-13700) * chromium-browser: URL spoof in navigation (CVE-2019-13701) * chromium-browser: Privilege elevation in Installer (CVE-2019-13702) * chromium-browser: URL bar spoofing (CVE-2019-13703) * chromium-browser: CSP bypass (CVE-2019-13704) * chromium-browser: Extension permission bypass (CVE-2019-13705) * chromium-browser: Out-of-bounds read in PDFium (CVE-2019-13706) * chromium-browser: File storage disclosure (CVE-2019-13707) * chromium-browser: HTTP authentication spoof (CVE-2019-13708) * chromium-browser: File download protection bypass (CVE-2019-13709) * chromium-browser: File download protection bypass (CVE-2019-13710) * chromium-browser: Cross-context information leak (CVE-2019-13711) * chromium-browser: Cross-origin data leak (CVE-2019-13713) * chromium-browser: CSS injection (CVE-2019-13714) * chromium-browser: Address bar spoofing (CVE-2019-13715) * chromium-browser: Service worker state error (CVE-2019-13716) * chromium-browser: Notification obscured (CVE-2019-13717) * chromium-browser: IDN spoof (CVE-2019-13718) * chromium-browser: Notification obscured (CVE-2019-13719) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Chromium must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1764756 - CVE-2019-13699 chromium-browser: Use-after-free in media 1764757 - CVE-2019-13700 chromium-browser: Buffer overrun in Blink 1764758 - CVE-2019-13701 chromium-browser: URL spoof in navigation 1764759 -CVE-2019-13702 chromium-browser: Privilege elevation in Installer 1764760 - CVE-2019-13703 chromium-browser: URL bar spoofing 1764761 - CVE-2019-13704 chromium-browser: CSP bypass 1764762 - CVE-2019-13705 chromium-browser: Extension permission bypass 1764763 - CVE-2019-13706 chromium-browser: Out-of-bounds read in PDFium 1764764 - CVE-2019-13707 chromium-browser: File storage disclosure 1764765 - CVE-2019-13708 chromium-browser: HTTP authentication spoof 1764766 - CVE-2019-13709 chromium-browser: File download protection bypass 1764767 - CVE-2019-13710 chromium-browser: File download protection bypass 1764768 - CVE-2019-13711 chromium-browser: Cross-context information leak 1764769 - CVE-2019-13713 chromium-browser: Cross-origin data leak 1764770 - CVE-2019-13714 chromium-browser: CSS injection 1764771 - CVE-2019-13715 chromium-browser: Address bar spoofing 1764772 - CVE-2019-13716 chromium-browser: Service worker state error 1764773 - CVE-2019-13717 chromium-browser: Notification obscured 1764774 - CVE-2019-13718 chromium-browser: IDN spoof 1764775 - CVE-2019-13719 chromium-browser: Notification obscured 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm i686: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm x86_64: chromium-browser-78.0.3904.70-1.el6_10.x86_64.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.x86_64.rpm Red Hat Enterprise Linux HPC Node Supplementary (v. 6): i686: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm x86_64: chromium-browser-78.0.3904.70-1.el6_10.x86_64.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v.6): i386: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm i686: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm x86_64: chromium-browser-78.0.3904.70-1.el6_10.x86_64.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm i686: chromium-browser-78.0.3904.70-1.el6_10.i686.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.i686.rpm x86_64: chromium-browser-78.0.3904.70-1.el6_10.x86_64.rpm chromium-browser-debuginfo-78.0.3904.70-1.el6_10.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2019-13699 https://access.redhat.com/security/cve/CVE-2019-13700 https://access.redhat.com/security/cve/CVE-2019-13701 https://access.redhat.com/security/cve/CVE-2019-13702 https://access.redhat.com/security/cve/CVE-2019-13703 https://access.redhat.com/security/cve/CVE-2019-13704 https://access.redhat.com/security/cve/CVE-2019-13705 https://access.redhat.com/security/cve/CVE-2019-13706 https://access.redhat.com/security/cve/CVE-2019-13707 https://access.redhat.com/security/cve/CVE-2019-13708 https://access.redhat.com/security/cve/CVE-2019-13709 https://access.redhat.com/security/cve/CVE-2019-13710 https://access.redhat.com/security/cve/CVE-2019-13711 https://access.redhat.com/security/cve/CVE-2019-13713 https://access.redhat.com/security/cve/CVE-2019-13714 https://access.redhat.com/security/cve/CVE-2019-13715 https://access.redhat.com/security/cve/CVE-2019-13716 https://access.redhat.com/security/cve/CVE-2019-13717 https://access.redhat.com/security/cve/CVE-2019-13718 https://access.redhat.com/security/cve/CVE-2019-13719 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPGv1 iQIVAwUBXcL4GtzjgjWX9erEAQj7kQ//daOoT6aqzMDSnHS0Z/sKuk360v8umf0X JgKjOSQ9q9nNOVxAD+3u0kh5tT1DCX+ojUNp4Fc1lcV/7w6QV/9wnwrCC5r5Qdrk uYeF6thDFJ4AlSKApCkw/IoG0WUIfywmJrg/mtjQ3IwD7HqVhee/c5ndqqLL50V5 dqD37iUOi9MeK2kX8a4jPpu/YPe3OmbWLCbuKmm3LGcnwavUytoiX5/vyaV52ZNK lgU/qUR/Id375XGGLzBcTI11GqrnXCifR6sjWvnp6ScI568imnT7g44BnW/dXGFi nmSNw837LTaAgU92z0EvyutAUL8CMS4aLhozBB5osxzVYea0VF99Osr2+3EdqDUo +CZVODbooMRnGoRnBuTSeoxrzsyJqDfKNy60F97hkMKuUzY54Gy6Uw+UI6vwfftH VqfgijtfY/lMc2yLA7CCzod5hB5x0NjykvL3IDFXiO8rv8zTfZKziuuZpCWCrAYl 1OrfUAi3O/sdNoExh3ELfkzCP7aYxIyq1o4PQutsR66JgCIZtwWZK54DG5Ypmtth pS0MQw2EyHDQGJLjOch3aQBEQrUlWEuwWeMqTjMwahCpCaC32CoW38km81ziNnXn yQabgEYJYTTU73Q+rSe3UqzP8WcShDVXzeMsfo1LxICIQqfPbAcBCo4h+N797hq2 wuzmaga3OpI=gFEG -----END PGP SIGNATURE-------RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 =====================================================. update, chromium-browser, enterprise, linux, supplementary. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 06, 2019 Important Red Hat
87

Debian 9: DSA-4229-2 High: Firefox Security Vulnerabilities Addressed

Several vulnerabilites have been discovered in the chromium web browser. CVE-2016-5139 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3645-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert August 09, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium-browser CVE ID : CVE-2016-5139 CVE-2016-5140 CVE-2016-5141 CVE-2016-5142 CVE-2016-5143 CVE-2016-5144 Several vulnerabilites have been discovered in the chromium web browser. CVE-2016-5139 GiWan Go discovered a use-after-free issue in the pdfium library. CVE-2016-5140 Ke Liu discovered a use-after-free issue in the pdfium library. CVE-2016-5141 Sergey Glazunov discovered a URL spoofing issue. CVE-2016-5142 Sergey Glazunov discovered a use-after-free issue. CVE-2016-5143 Gregory Panakkal discovered an issue in the developer tools. CVE-2016-5144 Gregory Panakkal discovered another issue in the developer tools. CVE-2016-5146 The chrome development team found and fixed various issues during internal auditing. For the stable distribution (jessie), these problems have been fixed in version 52.0.2743.116-1~deb8u1. For the testing distribution (stretch), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 52.0.2743.116-1. We recommend that you upgrade your chromium-browser packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu patches address severe threats in the Firefox browser, enhancing protections against various exploits.. Debian Security, Chromium Browser Update, Critical Flaw Protection. .Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 09, 2016 Important Debian
89

Fedora 7: 2007-1699 Critical Update For Kdelibs URL Spoofing Issues

This update primarily addresses problems with URL spoofing and consolekit/session permissions.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2007-1699 2007-08-20 09:03:20.204438 --------------------------------------------------------------------------------Name : kdelibs Product : Fedora 7 Version : 3.5.7 Release : 20.fc7 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------------------Update Information: This update primarily addresses problems with URL spoofing and consolekit/session permissions. --------------------------------------------------------------------------------ChangeLog: * Wed Aug 15 2007 Rex Dieter 6:3.5.7-20 - CVE-2007-3820, CVE-2007-4224, CVE-2007-4225 - clarify licensing * Tue Aug 14 2007 Rex Dieter 6:3.5.7-19 - ConsoleKit-related patch (#244065) * Sun Aug 12 2007 Florian La Roche 6:3.5.7-18 - fix apidocs subpackage requires * Mon Aug 6 2007 Than Ngo - 6:3.5.7-17 - cleanup * Fri Aug 3 2007 Rex Dieter - 6:3.5.7-16 - undo kdelibs3 rename (for now, anyway) - move to -devel: checkXML, kconfig_compiler, (make)kdewidgets, ksgmltools2, ksvgtopng, kunittestmodrunner - set KDE_IS_PRELINKED unconditionally (#244065) - License: LGPLv2+ * Fri Jul 20 2007 Rex Dieter - 6:3.5.7-15 - Obsoletes/Provides: kdelibs-apidocs (kdelibs3) * Fri Jul 20 2007 Rex Dieter - 6:3.5.7-14 - toggle kdelibs3 (f8+) * Wed Jul 18 2007 Rex Dieter - 6:3.5.7-13 - build fails against cups-1.3 (#248717) - incorporate kdelibs3 bits (not enabled... yet) * Wed Jul 18 2007 Rex Dieter - 6:3.5.7-10 - +Requires:kde-filesystem * Mon Jul 9 2007 Rex Dieter - 6:3.5.7-9 - omit ICEauthority patch (kde#147454, rh#243560, rh#247455) * Wed Jun 20 2007 Rex Dieter - 6:3.5.7-8 - rework previously botched openssl patch * Wed Jun 20 2007 Rex Dieter - 6:3.5.7-7 - -devel: Provides: kdelibs3-devel = ... - openssl patch update (portability) - drop deprecated ssl-krb5 patch * Sat Jun 16 2007 Rex Dieter - 6:3.5.7-6 - Provides: kdelibs3 = %version-%release * Sat Jun 16 2007 Rex Dieter - 6:3.5.7-5 - -devel: +Requires: libutempter-devel * Fri Jun 15 2007 Rex Dieter - 6:3.5.7-4 - omit lib_loader patch (doesn't apply cleanly) * Fri Jun 15 2007 Rex Dieter - 6:3.5.7-3 - include experimental libtool patches * Mon Jun 11 2007 Rex Dieter - 6:3.5.7-2 - kdesu: sudo support (kde bug #20914), Requires(hint): sudo * Wed Jun 6 2007 Than Ngo - 6:3.5.7-0.1.fc7 - 3.5.7 * Thu May 24 2007 Than Ngo 6:3.5.6-10.fc7 - don't change permission .ICEauthority by sudo KDE programs - apply patch to fix locale issue - apply upstream patch to fix kde#146105 --------------------------------------------------------------------------------References: [ 1 ] Bug #248717 https://bugzilla.redhat.com/show_bug.cgi?id=248717 [ 2 ] Bug #244065 https://bugzilla.redhat.com/show_bug.cgi?id=244065 [ 3 ] CVE-2007-3820 [ 4 ] CVE-2007-4224 [ 5 ] CVE-2007-4225 --------------------------------------------------------------------------------Updated packages: da99b0c84992e7ddba7402d0b664b86644fc740f kdelibs-3.5.7-20.fc7.ppc64.rpm 2bbe1e5a48f17b17042e4a005df186d0c5200fb9 kdelibs-devel-3.5.7-20.fc7.ppc64.rpm 60145619267321a5b5a07a0ca75fc218712682af kdelibs-debuginfo-3.5.7-20.fc7.ppc64.rpm fea397416fcddf526b3f298ba80e617c45e4c910 kdelibs-apidocs-3.5.7-20.fc7.ppc64.rpm 53578888d43d22a5fd07eff396fed9a3b09c22d8 kdelibs-apidocs-3.5.7-20.fc7.i386.rpm 459ef9591b3db30e753de1ac80e4770624ec11f3 kdelibs-devel-3.5.7-20.fc7.i386.rpm 89476ee168de0f491a26315d4ccec61d5735db95kdelibs-debuginfo-3.5.7-20.fc7.i386.rpm cedf5461e69ed9351754470b40db02cedea9808e kdelibs-3.5.7-20.fc7.i386.rpm 87db2cae70d5f174b94ccaefd4cb1063f30955c7 kdelibs-3.5.7-20.fc7.x86_64.rpm f6dcc07324d042b4da805ccd4fe9f5e8f84019bf kdelibs-debuginfo-3.5.7-20.fc7.x86_64.rpm 69d46644da6f6095d780aa4b8d26844b4d26a387 kdelibs-apidocs-3.5.7-20.fc7.x86_64.rpm 4a3e81fa59e126243e5534bdd4165dc3fd8c6a3f kdelibs-devel-3.5.7-20.fc7.x86_64.rpm d86e0364ccdcbf81665fb7eca25fe25e6f0940fc kdelibs-3.5.7-20.fc7.ppc.rpm a9d5456dd26c8189bdd495213520e155f2c5cc9b kdelibs-apidocs-3.5.7-20.fc7.ppc.rpm 9bf77515e5a19079a9ba486468f8e00967ef2de8 kdelibs-devel-3.5.7-20.fc7.ppc.rpm 87bfc77c4ba5c39e012478ff70eaf03790d58abb kdelibs-debuginfo-3.5.7-20.fc7.ppc.rpm b5d7faa3f87ad00efa2dc6fccfb29d99e5dc14da kdelibs-3.5.7-20.fc7.src.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Update for Fedora focusing on HTTP redirect vulnerabilities and ConsoleKit access control gaps within kdelibs in the 3.5.7 release.. KDE Libraries Update,Fedora 7 Security,Kdelibs Permissions Fix,URL Spoofing Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 27, 2007 Critical Fedora
89

Fedora 7: kdebase 3.5.7-13 Moderate URL Spoofing Threat

This update primarily addresses security issues around URL spoofing.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2007-1700 2007-08-20 09:03:56.378694 --------------------------------------------------------------------------------Name : kdebase Product : Fedora 7 Version : 3.5.7 Release : 13.fc7 Summary : K Desktop Environment - core files Description : Core applications for the K Desktop Environment. Included are: kdm (replacement for xdm), kwin (window manager), konqueror (filemanager, web browser, ftp client, ...), konsole (xterm replacement), kpanel (application starter and desktop pager), kaudio (audio server), kdehelp (viewer for kde help files, info and man pages), kthememgr (system for managing alternate theme packages) plus other KDE components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind, kfontmanager, kmenuedit). --------------------------------------------------------------------------------Update Information: This update primarily addresses security issues around URL spoofing. --------------------------------------------------------------------------------ChangeLog: * Wed Aug 15 2007 Rex Dieter 6:3.5.7-13 - CVE-2007-3820, CVE-2007-4224, CVE-2007-4225 - License: GPLv2 - Requires: kdelibs3(-devel) * Fri Jul 20 2007 Rex Dieter - 6:3.5.7-12 - fix unpackaged files * Fri Jul 20 2007 Rex Dieter - 6:3.5.7-9 - %ifnarch s390 s390x: BR: lm_sensors * Thu Jul 19 2007 Rex Dieter - 6:3.5.7-7 - omit dirs owned by kde-filesystem * Mon Jul 2 2007 Than Ngo - 6:3.5.7-6 - fix bz#244906 * Wed Jun 20 2007 Rex Dieter - 6:3.5.7-5 - Provides: kdebase3(-devel) * Wed Jun 20 2007 Rex Dieter - 6:3.5.7-4 - -devel: Requires: %name... - portability++ * Fri Jun 15 2007 Rex Dieter - 6:3.5.7-3 - specfile portability * Mon Jun 11 2007 Rex Dieter - 6:3.5.7-2 - fix BR: kdelibs-devel - cleanup Req's wrt kde-settings * Mon Jun 11 2007 Than Ngo - 6:3.5.7-1.fc7.1 -remove kdebase-3.4.2-npapi-64bit-fixes.patch, it's included in new upstream * Wed Jun 6 2007 Than Ngo - 6:3.5.7-0.1 - 3.5.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #244906 https://bugzilla.redhat.com/show_bug.cgi?id=244906 [ 2 ] CVE-2007-3820 [ 3 ] CVE-2007-4224 [ 4 ] CVE-2007-4225 --------------------------------------------------------------------------------Updated packages: e4bd55857163dd2c6da5ddd09a9e3b1a49488591 kdebase-devel-3.5.7-13.fc7.ppc64.rpm 19bcc8edb674fe9dea062eae5e94b0d4fc6e323e kdebase-debuginfo-3.5.7-13.fc7.ppc64.rpm 2c609ff611f3d9700b5459adcda9d44c390a7998 kdebase-3.5.7-13.fc7.ppc64.rpm 5f2b7a612c7db6c3d0787997b8ce4fc8791f06f0 kdebase-extras-3.5.7-13.fc7.ppc64.rpm 877e9f1e8d31f3f0634105958fe33aa94436db7f kdebase-3.5.7-13.fc7.i386.rpm 773cc39dd34f0ce208dbf3493563b69bf0f403de kdebase-debuginfo-3.5.7-13.fc7.i386.rpm 5935a1a1e6ae7865ba2c03c05e31a7e7172266a8 kdebase-extras-3.5.7-13.fc7.i386.rpm e1848bcfec04c9238c1ef41116f85ad28160d3d3 kdebase-devel-3.5.7-13.fc7.i386.rpm 56f0e6bf6b5a26c00617db465ac7113c2cbbb574 kdebase-debuginfo-3.5.7-13.fc7.x86_64.rpm afa554ac4d7aea98eff69c97fa4990d344dcbdca kdebase-3.5.7-13.fc7.x86_64.rpm 60cde6a1ce8905309568b506774ede609482f045 kdebase-extras-3.5.7-13.fc7.x86_64.rpm 25f5dafa61aa689e215b2d25cd6ed782d6b89030 kdebase-devel-3.5.7-13.fc7.x86_64.rpm 0cbde41479c3d1aaa247bd616b59efed3b6906aa kdebase-3.5.7-13.fc7.ppc.rpm 5994edd2fe49f7fa9e89e5bf5f3edff82e4d6490 kdebase-extras-3.5.7-13.fc7.ppc.rpm 2eb488eb1bb0c041d614a8c365a4a29eaeca0cfc kdebase-debuginfo-3.5.7-13.fc7.ppc.rpm 4113f1ef4056f66aba4781cd289bafda4165030b kdebase-devel-3.5.7-13.fc7.ppc.rpm 26f1d049c88e196c256f9edc6089b1660fb717d7 kdebase-3.5.7-13.fc7.src.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at. --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent GNOME patch for Ubuntu mitigates phishing exploits, enhancing system resilience against potential threats.. Fedora Security Update,KDE Update,url spoofing issues,security patch,kdebase. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 27, 2007 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200