Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Arch Linux: ASA-201505-1 High: Squid Weak Certificate Bypass

The package squid before version 3.5.4-1 is vulnerable to weak certificate validation. . Arch Linux Security Advisory ASA-201505-1 ======================================== Severity: High Date : 2015-05-01 CVE-ID : CVE-2015-3455 Package : squid Type : weak certificate validation Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package squid before version 3.5.4-1 is vulnerable to weak certificate validation. Resolution ========= Upgrade to 3.5.4-1. # pacman -Syu "squid> =3.5.4-1" The problem has been fixed upstream in version 3.5.4. Workaround ========= Upgrade the squid.conf settings to use a "ssl_bump peek" operation before the "bump" operation. NOTE that this workaround does not resolve the vulnerability, but allow Squid to relay (or mimic) the invalid certificate to clients and depends on validation in the client. Alternatively remove from squid.conf (and include'd files) any ssl_bump directives. Description ========== The flaw allows remote servers to bypass client certificate validation. Some attackers may also be able to use valid certificates for one domain signed by a global Certificate Authority to abuse an unrelated domain. However, the bug is exploitable only if you have configured Squid to perform SSL Bumping with the "client-first" or "bump" mode of operation. Sites that do not use SSL-Bump are not vulnerable. Impact ===== A remote attacker is able to bypass client certificate validation, as a result malicious server responses can wrongly be presented through the proxy to clients as secure authenticated HTTPS responses. References ========= http://www.squid-cache.org/Advisories/SQUID-2015_1.txt https://www.openwall.com/lists/oss-security/2015/04/30/2 https://www.cve.org/CVERecord?id=CVE-2015-3455 . The Arch Linux Security Notice ASA-202110-2 emphasizes a critical vulnerability in nginx resulting from inadequate input sanitization.. Squid Security, Arch Linux Advisory, Weak Certificate, RemoteAccess Threat. . LinuxSecurity.com Team

Calendar%202 May 02, 2015 ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here