Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
197

Debian 9: DLA-2768-2 Fixes uwsgi Regression Issue for Apache2

A regression was introduced in DLA-2768-1, where the uwsgi proxy module for Apache2 (mod_proxy_uwsgi) interprets incorrect Apache configurations in a less forgiving way, causing existing setups to fail after upgrade. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2768-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler October 20, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : uwsgi Version : 2.0.14+20161117-3+deb9u5 CVE ID : CVE-2021-36160 Debian Bug : 995368 A regression was introduced in DLA-2768-1, where the uwsgi proxy module for Apache2 (mod_proxy_uwsgi) interprets incorrect Apache configurations in a less forgiving way, causing existing setups to fail after upgrade. For Debian 9 stretch, this problem has been fixed in version 2.0.14+20161117-3+deb9u5. We recommend that you upgrade your uwsgi packages. For the detailed security status of uwsgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/uwsgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2769-3 tackles nginx security vulnerabilities to maintain secure setups post updates.. Debian LTS Advisory, uwsgi regression, Apache configurations, mod_proxy_uwsgi. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 20, 2021 Important Debian LTS
197

Debian 9 DLA-2768-1 Moderate: uwsgi DoS Attack from Memory Issue

It was discovered that the uwsgi proxy module for Apache2 (mod_proxy_uwsgi) can read above the allocated memory when processing a request with a carefully crafted uri-path. An attacker may cause the server to crash (DoS). . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2768-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler September 29, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : uwsgi Version : 2.0.14+20161117-3+deb9u4 CVE ID : CVE-2021-36160 It was discovered that the uwsgi proxy module for Apache2 (mod_proxy_uwsgi) can read above the allocated memory when processing a request with a carefully crafted uri-path. An attacker may cause the server to crash (DoS). For Debian 9 stretch, this problem has been fixed in version 2.0.14+20161117-3+deb9u4. We recommend that you upgrade your uwsgi packages. For the detailed security status of uwsgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/uwsgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade uWSGI on your Debian 9 system to address security vulnerabilities and prevent denial-of-service attacks with these essential steps. debian lts, uwsgi exploit, dos vulnerability, security patch, apache2 issues. . LinuxSecurity.com Team

Calendar 2 Sep 29, 2021 Debian LTS
197

Debian 9: DLA-2362-1 Critical: uwsgi Resource Exhaustion Issue

Apache HTTP Server versions before 2.4.32 uses src:uwsgi where a flaw was discovered. The uwsgi protocol does not let us serialize more than 16K of HTTP header leading to resource exhaustion and denial of service. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2362-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta September 03, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : uwsgi Version : 2.0.14+20161117-3+deb9u3 CVE ID : CVE-2020-11984 Apache HTTP Server versions before 2.4.32 uses src:uwsgi where a flaw was discovered. The uwsgi protocol does not let us serialize more than 16K of HTTP header leading to resource exhaustion and denial of service. For Debian 9 stretch, this problem has been fixed in version 2.0.14+20161117-3+deb9u3. We recommend that you upgrade your uwsgi packages. For the detailed security status of uwsgi please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/uwsgi Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS USN-1234-1 resolves nginx vulnerabilities leading to potential breaches. Update nginx for improved stability.. uwsgi, apache server, security update, debian advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 03, 2020 Critical Debian LTS
89

Fedora 21 uwsgi Emergency Security Update: Critical Issues Resolved

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12032 2015-07-28 22:48:37 -------------------------------------------------------------------------------- Name : uwsgi Product : Fedora 21 Version : 2.0.11.1 Release : 1.fc21 URL : https://github.com/unbit/uwsgi Summary : Fast, self-healing, application container server Description : uWSGI is a fast (pure C), self-healing, developer/sysadmin-friendly application container server. Born as a WSGI-only server, over time it has evolved in a complete stack for networked/clustered web applications, implementing message/object passing, caching, RPC and process management. It uses the uwsgi (all lowercase, already included by default in the Nginx and Cherokee releases) protocol for all the networking/interprocess communications. Can be run in preforking mode, threaded, asynchronous/evented and supports various form of green threads/co-routine (like uGreen and Fiber). Sysadmin will love it as it can be configured via command line, environment variables, xml, .ini and yaml files and via LDAP. Being fully modular can use tons of different technology on top of the same core. -------------------------------------------------------------------------------- Update Information: New emergency security release -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 21 2015 Jorge A Gallegos - 2.0.11.1-1 - New emergency security release * Thu Jul 2 2015 Jorge A Gallegos - 2.0.11-1 - Adding the dummy and notfound plugins (Jorge Gallegos) - License is license (Jorge Gallegos) - Mark config files as %config (Jorge Gallegos) - Adding sources for new version (Jorge Gallegos) - uwsgi_fix_glibc_compatibility merged upstream (Jorge Gallegos) * Tue Jun 23 2015 Thomas Spura - 2.0.9-11 - rebuilt for new zeromq 4.1.2 * Fri Jun 19 2015 Fedora Release Engineering - 2.0.9-10 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Sat Jun 6 2015 Jitka Plesnikova - 2.0.9-9 - Perl 5.22 rebuild * Mon May 18 2015 Peter Robinson 2.0.9-8 - Rebuild (mono4) * Thu Apr 23 2015 Jorge A Gallegos - 2.0.9-7 - Disabled java related plugins (jvm, jwsgi, ring) in el6 ppc64 * Tue Apr 21 2015 Jorge A Gallegos - 2.0.9-6 - Reworked the conditionals in the spec file - Updated documentation - Disabled PSGI for epel, builds fine but requirement is missing - Reenabled systemd for epel7, dunno how I missed that one * Fri Apr 17 2015 Dan Horák - 2.0.9-5 - conditionalize various subpackages depending on architectures (patch by Jakub Cajka) - #1211616 * Tue Apr 14 2015 Vít Ondruch - 2.0.9-4 - Fix glibc and MongoDB compatibility. * Fri Mar 13 2015 Jorge A Gallegos - 2.0.9-3 - Adding missing dist tag, have no clue at what point this got dropped :( * Thu Mar 12 2015 Jorge A Gallegos - 2.0.9-2 - Making it arch specific due to missing dependencies in PPC (as per https://fedoraproject.org/wiki/Packaging:Guidelines#BuildRequires) * Wed Mar 11 2015 Jorge A Gallegos - 2.0.9-1 - EPEL 6 and EPEL 7 compatible - Plugins not compatible with epel 6 are systemd, go, python3 based, ruby19 based, gridfs and tuntap - Plugins not compatible with epel 7 are python3 based, zeromq, greenlet, coroae, glusterfs and gridfs * Fri Feb 27 2015 Jorge A Gallegos - 2.0.9-0 - New version * Fri Jan 16 2015 Mamoru TASAKA - 2.0.7-3 - Rebuild for https://fedoraproject.org/wiki/Changes/Ruby_2.2 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update uwsgi' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . New emergency security release . Fedora 21 has announced an updated security patch for the uwsgi application server, targeting significant vulnerabilities.. Fedora Security, uwsgi Update, Emergency Release, Application Server, Critical Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 18, 2015 Critical Fedora
89

Fedora 22: Critical Emergency Security Update for uwsgi Released

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12020 2015-07-28 22:48:04 -------------------------------------------------------------------------------- Name : uwsgi Product : Fedora 22 Version : 2.0.11.1 Release : 1.fc22 URL : https://github.com/unbit/uwsgi Summary : Fast, self-healing, application container server Description : uWSGI is a fast (pure C), self-healing, developer/sysadmin-friendly application container server. Born as a WSGI-only server, over time it has evolved in a complete stack for networked/clustered web applications, implementing message/object passing, caching, RPC and process management. It uses the uwsgi (all lowercase, already included by default in the Nginx and Cherokee releases) protocol for all the networking/interprocess communications. Can be run in preforking mode, threaded, asynchronous/evented and supports various form of green threads/co-routine (like uGreen and Fiber). Sysadmin will love it as it can be configured via command line, environment variables, xml, .ini and yaml files and via LDAP. Being fully modular can use tons of different technology on top of the same core. -------------------------------------------------------------------------------- Update Information: New emergency security release -------------------------------------------------------------------------------- ChangeLog: * Tue Jul 21 2015 Jorge A Gallegos - 2.0.11.1-1 - New emergency security release * Thu Jul 2 2015 Jorge A Gallegos - 2.0.11-1 - Adding the dummy and notfound plugins (Jorge Gallegos) - License is license (Jorge Gallegos) - Mark config files as %config (Jorge Gallegos) - Adding sources for new version (Jorge Gallegos) - uwsgi_fix_glibc_compatibility merged upstream (Jorge Gallegos) * Tue Jun 23 2015 Thomas Spura - 2.0.9-11 - rebuilt for new zeromq 4.1.2 * Fri Jun 19 2015 Fedora Release Engineering - 2.0.9-10 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Sat Jun 6 2015 Jitka Plesnikova - 2.0.9-9 - Perl 5.22 rebuild * Mon May 18 2015 Peter Robinson 2.0.9-8 - Rebuild (mono4) * Thu Apr 23 2015 Jorge A Gallegos - 2.0.9-7 - Disabled java related plugins (jvm, jwsgi, ring) in el6 ppc64 * Tue Apr 21 2015 Jorge A Gallegos - 2.0.9-6 - Reworked the conditionals in the spec file - Updated documentation - Disabled PSGI for epel, builds fine but requirement is missing - Reenabled systemd for epel7, dunno how I missed that one * Fri Apr 17 2015 Dan Horák - 2.0.9-5 - conditionalize various subpackages depending on architectures (patch by Jakub Cajka) - #1211616 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update uwsgi' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . New emergency security release . A recent security patch for uwsgi on Fedora 22 tackles severe vulnerabilities; make sure your system has been updated. Discover additional information here.. uwsgi Update, Fedora 22 Security, emergency release notification, application server security, process management patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 18, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here