Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 44 kf6-kirigami Update 2026-fe3d8d4767 with QtQuick Plugins

Frameworks 6.25.0 + KDE Plasma 6.6.4. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fe3d8d4767 2026-04-16 23:40:54.273526+00:00 -------------------------------------------------------------------------------- Name : kf6-kirigami Product : Fedora 44 Version : 6.25.0 Release : 1.fc44 URL : https://invent.kde.org/frameworks/kirigami Summary : QtQuick plugins to build user interfaces based on the KDE UX guidelines Description : QtQuick plugins to build user interfaces based on the KDE UX guidelines. -------------------------------------------------------------------------------- Update Information: Frameworks 6.25.0 + KDE Plasma 6.6.4 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 9 2026 Steve Cossette - 6.25.0-1 - 6.25.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455469 - Configuring WifI network via Network pane appears to not work https://bugzilla.redhat.com/show_bug.cgi?id=2455469 [ 2 ] Bug #2457573 - FE: KDE Frameworks 6.25.0 + Plasma 6.6.4 https://bugzilla.redhat.com/show_bug.cgi?id=2457573 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fe3d8d4767' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Discover the latest update for kf6-kirigami in Fedora 44 with QtQuick plugins and KDE Plasma enhancements.. KDE Frameworks, Fedora updates, QtQuick, user interface plugins. . Severity: Informational. LinuxSecurity.com Team

Calendar 2 Apr 16, 2026 Informational Fedora
89

Fedora 39: 2024-81c9a3fe50 Critical: Thunderbird Security Update

Update to 115.10.1 https://www.thunderbird.net/en-US/thunderbird/115.10.1/releasenotes/ Fix https://bugzilla.redhat.com/show_bug.cgi?id=2276078 Including security update to 115.10.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-81c9a3fe50 2024-04-25 01:19:12.575148 -------------------------------------------------------------------------------- Name : thunderbird Product : Fedora 39 Version : 115.10.1 Release : 4.fc39 URL : https://wiki.mozilla.org/Thunderbird:Home Summary : Mozilla Thunderbird mail/newsgroup client Description : Mozilla Thunderbird is a standalone mail and newsgroup client. -------------------------------------------------------------------------------- Update Information: Update to 115.10.1 https://www.thunderbird.net/en-US/thunderbird/115.10.1/releasenotes/ Fix https://bugzilla.redhat.com/show_bug.cgi?id=2276078 Including security update to 115.10.0 https://www.mozilla.org/en-US/security/advisories/mfsa2024-20/ https://www.thunderbird.net/en-US/thunderbird/115.10.0/releasenotes/ -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 23 2024 Jan Horak - 115.10.1-4 - Move the MOZ_APP_REMOTINGNAME from the startup script to the build options. * Tue Apr 23 2024 Jan Horak - 115.10.1-3 - Fixed startup script * Mon Apr 22 2024 Eike Rathke - 115.10.1-2 - Resolves: rhbz#2276078 Set MOZ_APP_REMOTINGNAME to firefox * Mon Apr 22 2024 Eike Rathke - 115.10.1-1 - Update to 115.10.1 * Tue Apr 16 2024 Eike Rathke - 115.10.0-1 - Update to 115.10.0 - Revert expat CVE-2023-52425 fix * Fri Mar 22 2024 Jan Horak - 115.9.0-2 - Use wayland backend on Fedora 40+ -------------------------------------------------------------------------------- References: [ 1 ] Bug #2276078 - Opening links in emails with Firefox fails if FF is already running https://bugzilla.redhat.com/show_bug.cgi?id=2276078 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-81c9a3fe50' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . New Thunderbird update released for Fedora 39 to fix several security vulnerabilities. Make sure to apply the latest patch immediately.. Thunderbird Update,Fedora 39,Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 25, 2024 Critical Fedora
203

Mageia 8 MGASA-2023-0057 Moderate: Thunderbird Memory Safety Issues

User Interface lockup with messages combining S/MIME and OpenPGP. (CVE-2023-0616) Content security policy leak in violation reports using iframes. (CVE-2023-25728) . MGASA-2023-0057 - Updated thunderbird packages fix security vulnerability Publication date: 20 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0057.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-0616, CVE-2023-0767, CVE-2023-25728, CVE-2023-25729, CVE-2023-25730, CVE-2023-25732, CVE-2023-25735, CVE-2023-25737, CVE-2023-25739, CVE-2023-25742, CVE-2023-25746 User Interface lockup with messages combining S/MIME and OpenPGP. (CVE-2023-0616) Content security policy leak in violation reports using iframes. (CVE-2023-25728) Screen hijack via browser fullscreen mode. (CVE-2023-25730) Arbitrary memory write via PKCS 12 in NSS. (CVE-2023-0767) Potential use-after-free from compartment mismatch in SpiderMonkey. (CVE-2023-25735) Invalid downcast in SVGUtils::SetupStrokeGeometry. (CVE-2023-25737) Use-after-free in mozilla::dom::ScriptLoadContext::~ScriptLoadContext. (CVE-2023-25739) Extensions could have opened external schemes without user knowledge. (CVE-2023-25729) Out of bounds memory write from EncodeInputStream. (CVE-2023-25732) Web Crypto ImportKey crashes tab. (CVE-2023-25742) Memory safety bugs fixed in Thunderbird 102.8. (CVE-2023-25746) References: - https://bugs.mageia.org/show_bug.cgi?id=31561 - https://www.thunderbird.net/en-US/thunderbird/102.8.0/releasenotes/ - https://www.mozilla.org/en-US/security/advisories/mfsa2023-07/ - https://www.cve.org/CVERecord?id=CVE-2023-0616 - https://www.cve.org/CVERecord?id=CVE-2023-0767 - https://www.cve.org/CVERecord?id=CVE-2023-25728 - https://www.cve.org/CVERecord?id=CVE-2023-25729 - https://www.cve.org/CVERecord?id=CVE-2023-25730 - https://www.cve.org/CVERecord?id=CVE-2023-25732 - https://www.cve.org/CVERecord?id=CVE-2023-25735 - https://www.cve.org/CVERecord?id=CVE-2023-25737 -https://www.cve.org/CVERecord?id=CVE-2023-25739 - https://www.cve.org/CVERecord?id=CVE-2023-25742 - https://www.cve.org/CVERecord?id=CVE-2023-25746 SRPMS: - 8/core/thunderbird-102.8.0-1.mga8 - 8/core/thunderbird-l10n-102.8.0-1.mga8 . Recent updates to the Thunderbird application address various security vulnerabilities, improving both the user experience and adherence to memory management protocols.. Mageia 8 Update, Thunderbird Security Fixes, Memory Safety Issues. . LinuxSecurity.com Team

Calendar 2 Feb 20, 2023 Mageia
197

Debian 10 Buster: DLA-3230-1 Critical: jQuery-UI Code Execution

jQuery-UI, the official jQuery user interface library, is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery were reported to have the following vulnerabilities. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3230-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta December 07, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : jqueryui Version : 1.12.1+dfsg-5+deb10u1 CVE ID : CVE-2021-41182 CVE-2021-41183 CVE-2021-41184 CVE-2022-31160 Debian Bug : 1015982 jQuery-UI, the official jQuery user interface library, is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery were reported to have the following vulnerabilities. CVE-2021-41182 jQuery-UI was accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. This has been fixed and now any string value passed to the `altField` option is now treated as a CSS selector. CVE-2021-41183 jQuery-UI was accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. This has been fixed and now the values passed to various `*Text` options are now always treated as pure text, not HTML. CVE-2021-41184 jQuery-UI was accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. This has been fixed and now any string value passed to the `of` option is now treated as a CSS selector. CVE-2022-31160 jQuery-UI was potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. For Debian 10 buster, these problems have been fixed in version 1.12.1+dfsg-5+deb10u1. We recommend that you upgrade your jqueryui packages. For the detailed security status of jqueryui please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jqueryui Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your Debian system's security by upgrading the jqeryui package in response to vulnerabilities in Advisory DLA-3230-1 to mitigate risks effectively. Debian, jQuery-UI, security update, XSS risk, code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 07, 2022 Critical Debian LTS
197

Debian 10: DLA-3183-1 Critical: WebKitGTK User Interface Spoofing

The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42799 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3183-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort November 09, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : webkit2gtk Version : 2.38.2-1~deb10u1 CVE ID : CVE-2022-42799 CVE-2022-42823 CVE-2022-42824 The following vulnerabilities have been discovered in the WebKitGTK web engine: CVE-2022-42799 Jihwan Kim and Dohyun Lee discovered that visiting a malicious website may lead to user interface spoofing. CVE-2022-42823 Dohyun Lee discovered that processing maliciously crafted web content may lead to arbitrary code execution. CVE-2022-42824 Abdulrahman Alqabandi, Ryan Shin and Dohyun Lee discovered that processing maliciously crafted web content may disclose sensitive user information. For Debian 10 buster, these problems have been fixed in version 2.38.2-1~deb10u1. We recommend that you upgrade your webkit2gtk packages. For the detailed security status of webkit2gtk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/webkit2gtk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5198-1 tackles various vulnerabilities in OpenSSH, boosting overall system security and improving remote access functionality.. Debian LTS, WebKitGTK, User Interface Spoofing, Code Execution, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 09, 2022 Critical Debian LTS
89

Fedora 35: 2022-3969b64d4b Critical: Podman-TUI Golang Update

Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3969b64d4b 2022-07-17 00:57:11.020145 --------------------------------------------------------------------------------Name : podman-tui Product : Fedora 35 Version : 0.2.1 Release : 2.fc35 URL : https://github.com/containers/podman-tui Summary : Podman Terminal User Interface Description : podman-tui is a terminal user interface for Podman v3 (> = 3.1). it is using podman.socket service to communicate with podman machine. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode -CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -CVE-2022-29526 golang: syscall: faccessat checks wrong group (There are some Go CVEs that are a little bit older that will also be mitigated by the rebuild for packages that haven't been updated recently) CVEs in other golang libraries that affect a subset of Go packages: - CVE-2022-21698 golang-github-prometheus-client: prometheus/client_golang: Denial of service using InstrumentHandlerCounter - CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled Key ---- Initial import for golang-github-a8m-envsubst Resolves: rhbz#2074406 ---- Initial package Resolves: rhbz#2074438 ----Update to v3.14.0 (close rhbz#2105612) ---- Fix merge ---- Update to 1.22.1 - Close: rhbz#2077577 --------------------------------------------------------------------------------ChangeLog: * Sat Jul 9 2022 Maxwell G 0.2.1-2 - Rebuild for CVE-2022-{24675,28327,29526} in golang --------------------------------------------------------------------------------References: [ 1 ] Bug #2074406 - Review Request: golang-github-a8m-envsubst - Environment variables substitution for Go https://bugzilla.redhat.com/show_bug.cgi?id=2074406 [ 2 ] Bug #2074438 - Review Request: golang-github-goccy-yaml - YAML support for the Go language https://bugzilla.redhat.com/show_bug.cgi?id=2074438 [ 3 ] Bug #2077577 - powerline-go-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2077577 [ 4 ] Bug #2105612 - golang-github-task-3.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2105612 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3969b64d4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Podman-tui has been enhanced to address significant Golang vulnerabilities, particularly concerning stack overflow risks. Fedora users are advised to perform the upgrade.. Podman-TUI Update, Golang CVE Fixes, Fedora Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 16, 2022 Critical Fedora
100

SUSE: 2022:4102-2 Critical: GoogleChrome Vulnerability Fixes

An update that fixes 14 vulnerabilities is now available. . SUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:3191-1 Rating: important References: #1188891 #1189547 #1190269 #1190274 Cross-References: CVE-2021-29980 CVE-2021-29981 CVE-2021-29982 CVE-2021-29983 CVE-2021-29984 CVE-2021-29985 CVE-2021-29986 CVE-2021-29987 CVE-2021-29988 CVE-2021-29989 CVE-2021-29990 CVE-2021-29991 CVE-2021-38492 CVE-2021-38495 CVSS scores: CVE-2021-29980 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-29984 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-29985 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVE-2021-29986 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-29988 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-29989 (SUSE): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-29991 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2021-38492 (SUSE): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server 12-SP4-LTSS SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Linux Enterprise Server 12-SP2-BCL HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes 14 vulnerabilities is now available. Description: This update for MozillaFirefox fixes the following issues: This update contains the Firefox Extended Support Release 91.1.0 ESR. * Fixed: Various stability, functionality, and security fixes MFSA 2021-40 (bsc#1190269, bsc#1190274): * CVE-2021-38492: Navigating to `mk:` URL scheme could load Internet Explorer * CVE-2021-38495: Memory safety bugs fixed in Firefox 92 and Firefox ESR 91.1 Firefox 91.0.1esr ESR * Fixed: Fixed an issue causing buttons on the tab bar to be resized when loading certain websites (bug 1704404) * Fixed: Fixed an issue which caused tabs from private windows to be visible in non-private windows when viewing switch-to- tab results in the address bar panel (bug 1720369) * Fixed: Various stability fixes * Fixed: Security fix MFSA 2021-37 (bsc#1189547) * CVE-2021-29991 (bmo#1724896) Header Splitting possible with HTTP/3 Responses Firefox Extended Support Release 91.0 ESR * New: Some of the highlights of the new Extended Support Release are: - A number of user interface changes. For more information, see the Firefox 89 release notes. - Firefox now supports logging into Microsoft, work, and school accounts using Windows single sign-on. Learn more - On Windows, updates can now be applied in the background while Firefox is not running. - Firefox for Windows now offers a new page about:third-party to help identify compatibility issues caused by third-party applications - Version 2 of Firefox's SmartBlock feature further improves private browsing. Third party Facebook scripts are blocked to prevent you from being tracked, but are now automatically loaded "just in time" if you decide to "Log in withFacebook" on any website. - Enhanced the privacy of the Firefox Browser's Private Browsing mode with Total Cookie Protection, which confines cookies to the site where they were created, preventing companis from using cookies to track your browsing across sites. This feature was originally launched in Firefox's ETP Strict mode. - PDF forms now support JavaScript embedded in PDF files. Some PDF forms use JavaScript for validation and other interactive features. - You'll encounter less website breakage in Private Browsing and Strict Enhanced Tracking Protection with SmartBlock, which provides stand-in scripts so that websites load properly. - Improved Print functionality with a cleaner design and better integration with your computer's printer settings. - Firefox now protects you from supercookies, a type of tracker that can stay hidden in your browser and track you online, even after you clear cookies. By isolating supercookies, Firefox prevents them from tracking your web browsing from one site to the next. - Firefox now remembers your preferred location for saved bookmarks, displays the bookmarks toolbar by default on new tabs, and gives you easy access to all of your bookmarks via a toolbar folder. - Native support for macOS devices built with Apple Silicon CPUs brings dramatic performance improvements over the non- native build that was shipped in Firefox 83: Firefox launches over 2.5 times faster and web apps are now twice as responsive (per the SpeedoMeter 2.0 test). If you are on a new Apple device, follow these steps to upgrade to the latest Firefox. - Pinch zooming will now be supported for our users with Windows touchscreen devices and touchpads on Mac devices. Firefox users may now use pinch to zoom on touch-capable devices to zoom in and out of webpages. - We’ve improved functionality anddesign for a number of Firefox search features: * Selecting a search engine at the bottom of the search panel now enters search mode for that engine, allowing you to see suggestions (if available) for your search terms. The old behavior (immediately performing a search) is available with a shift-click. * When Firefox autocompletes the URL of one of your search engines, you can now search with that engine directly in the address bar by selecting the shortcut in the address bar results. * We’ve added buttons at the bottom of the search panel to allow you to search your bookmarks, open tabs, and history. - Firefox supports AcroForm, which will allow you to fill in, print, and save supported PDF forms and the PDF viewer also has a new fresh look. - For our users in the US and Canada, Firefox can now save, manage, and auto-fill credit card information for you, making shopping on Firefox ever more convenient. - In addition to our default, dark and light themes, with this release, Firefox introduces the Alpenglow theme: a colorful appearance for buttons, menus, and windows. You can update your Firefox themes under settings or preferences. * Changed: Firefox no longer supports Adobe Flash. There is no setting available to re-enable Flash support. * Enterprise: Various bug fixes and new policies have been implemented in the latest version of Firefox. See more details in the Firefox for Enterprise 91 Release Notes. MFSA 2021-33 (bsc#1188891): * CVE-2021-29986: Race condition when resolving DNS names could have led to memory corruption * CVE-2021-29981: Live range splitting could have led to conflicting assignments in the JIT * CVE-2021-29988: Memory corruption as a result of incorrect style treatment * CVE-2021-29983: Firefox for Android could get stuck in fullscreen mode * CVE-2021-29984: Incorrect instruction reorderingduring JIT optimization * CVE-2021-29980: Uninitialized memory in a canvas object could have led to memory corruption * CVE-2021-29987: Users could have been tricked into accepting unwanted permissions on Linux * CVE-2021-29985: Use-after-free media channels * CVE-2021-29982: Single bit data leak due to incorrect JIT optimization and type confusion * CVE-2021-29989: Memory safety bugs fixed in Firefox 91 and Firefox ESR 78.13 * CVE-2021-29990: Memory safety bugs fixed in Firefox 91 Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-3191=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2021-3191=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-3191=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2021-3191=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2021-3191=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-3191=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2021-3191=1 - SUSE Linux Enterprise Server 12-SP5: zypper in -t patch SUSE-SLE-SERVER-12-SP5-2021-3191=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-3191=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2021-3191=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2021-3191=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2021-3191=1 - HPE HelionOpenstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2021-3191=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE OpenStack Cloud 9 (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE OpenStack Cloud 8 (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server 12-SP5 (aarch64 ppc64le s390x x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 - HPE Helion Openstack 8 (x86_64): MozillaFirefox-91.1.0-112.71.1 MozillaFirefox-branding-SLE-91-35.6.6 MozillaFirefox-debuginfo-91.1.0-112.71.1 MozillaFirefox-debugsource-91.1.0-112.71.1 MozillaFirefox-devel-91.1.0-112.71.1 MozillaFirefox-translations-common-91.1.0-112.71.1 References: https://www.suse.com/security/cve/CVE-2021-29980.html https://www.suse.com/security/cve/CVE-2021-29981.html https://www.suse.com/security/cve/CVE-2021-29982.html https://www.suse.com/security/cve/CVE-2021-29983.html https://www.suse.com/security/cve/CVE-2021-29984.html https://www.suse.com/security/cve/CVE-2021-29985.html https://www.suse.com/security/cve/CVE-2021-29986.html https://www.suse.com/security/cve/CVE-2021-29987.html https://www.suse.com/security/cve/CVE-2021-29988.html https://www.suse.com/security/cve/CVE-2021-29989.html https://www.suse.com/security/cve/CVE-2021-29990.html https://www.suse.com/security/cve/CVE-2021-29991.html https://www.suse.com/security/cve/CVE-2021-38492.html https://www.suse.com/security/cve/CVE-2021-38495.html https://bugzilla.suse.com/1188891 https://bugzilla.suse.com/1189547 https://bugzilla.suse.com/1190269 https://bugzilla.suse.com/1190274 . Crucial SUSE Security Patch for MozillaFirefox tackles 14 security flaws, enhancing overall protection and reliability.. SUSE MozillaFirefox Update, Security Fixes, Linux Patch Management. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 22, 2021 Important SuSE
89

Fedora 34: Critical Patch for Vulnerability in Thunderbird Email Client

Update to 2.53.8.1 Includes fixes for mailnews archiving, as well as account creation after news subscribing. Show just an icon (instead of a big image etc.) when moving in drag-and-drop operations to make sure the target is visible. (You can change it back by toggling boolean preference "nglayout.enable_drag_images" in about:config).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-424a36ea0f 2021-08-02 01:06:02.549784 --------------------------------------------------------------------------------Name : seamonkey Product : Fedora 33 Version : 2.53.8.1 Release : 1.fc33 URL : https://www.seamonkey-project.org/ Summary : Web browser, e-mail, news, IRC client, HTML editor Description : SeaMonkey is an all-in-one Internet application suite (previously made popular by Netscape and Mozilla). It includes an Internet browser, advanced e-mail, newsgroup and feed client, a calendar, IRC client, HTML editor and a tool to inspect the DOM for web pages. It is derived from the application formerly known as Mozilla Application Suite. --------------------------------------------------------------------------------Update Information: Update to 2.53.8.1 Includes fixes for mailnews archiving, as well as account creation after news subscribing. Show just an icon (instead of a big image etc.) when moving in drag-and-drop operations to make sure the target is visible. (You can change it back by toggling boolean preference "nglayout.enable_drag_images" in about:config). --------------------------------------------------------------------------------ChangeLog: * Thu Jul 22 2021 Dmitry Butskoy 2.53.8.1-1 - update to 2.53.8.1 - no more set nglayout.enable_drag_images by default - fix mailnews account creation after subscribing by a news URL (mozbz#521861) - avoid staring drag-and-drop in full mailnews's Wide View (mozbz#1720968) - fix clearing in download manager(mozbz#1501277) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-424a36ea0f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The latest release brings enhancements for email and news functionalities along with a refined graphical interface in SeaMonkey on Fedora 33.. Fedora Updates, Seamonkey Fixes, Mailnews Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 01, 2021 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here