Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
219

Rocky Linux 9: RLSA-2025:3713 Webkit2gtk3 Important Denial of Service Risks

Important: webkit2gtk3 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2025:3713", "synopsis": "Important: webkit2gtk3 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for webkit2gtk3.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "WebKitGTK is the port of the portable web rendering engine WebKit to the GTK platform.\n\nSecurity Fix(es):\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2024-44192)\n\n* webkitgtk: A malicious website may exfiltrate data cross-origin (CVE-2024-54467)\n\n* webkitgtk: Processing web content may lead to a denial-of-service (CVE-2024-54551)\n\n* webkitgtk: Loading a malicious iframe may lead to a cross-site scripting attack (CVE-2025-24208)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected process crash (CVE-2025-24209)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-24216)\n\n* webkitgtk: Processing maliciously crafted web content may lead to an unexpected Safari crash (CVE-2025-30427)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2353871", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2353871", "description": ""}, {"ticket": "2353872", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2353872", "description": ""}, {"ticket": "2357909", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357909", "description": ""}, {"ticket": "2357910", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2357910", "description": ""}, {"ticket": "2357911", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357911", "description": ""}, {"ticket": "2357917", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357917", "description": ""}, {"ticket": "2357919", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2357919", "description": ""}], "cves": [{"name": "CVE-2024-44192", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-44192", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-20"}, {"name": "CVE-2024-54467", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-54467", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N", "cvss3BaseScore": "6.5", "cwe": "CWE-200"}, {"name": "CVE-2024-54551", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-54551", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "cvss3BaseScore": "6.5", "cwe": "CWE-119"}, {"name": "CVE-2025-24208", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24208", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "cvss3BaseScore": "6.1", "cwe": "CWE-79"}, {"name": "CVE-2025-24209", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24209", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-120"}, {"name": "CVE-2025-24216", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-24216", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-119"}, {"name": "CVE-2025-30427", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-30427", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore":"8.8", "cwe": "CWE-416"}], "references": [], "publishedAt": "2025-07-29T13:40:19.644888Z", "rpms": {"Rocky Linux 9": {"nvras": ["webkit2gtk3-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.src.rpm", "webkit2gtk3-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-debugsource-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-devel-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-devel-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.i686.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-devel-0:2.48.1-1.el9_5.x86_64.rpm","webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.aarch64.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.ppc64le.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.s390x.rpm", "webkit2gtk3-jsc-devel-debuginfo-0:2.48.1-1.el9_5.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical patches for webkit2gtk3 on Rocky Linux released to address vulnerabilities that could lead to sensitive data leaks and service disruptions.. webkit2gtk3 update, Rocky Linux security, web content vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 29, 2025 Important Rocky Linux
98

Red Hat: RHSA-2016:2919-01 Important: Chromium Browser Security Fix

An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security update Advisory ID: RHSA-2016:2919-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2016:2919.html Issue date: 2016-12-07 CVE Names: CVE-2016-5203 CVE-2016-5204 CVE-2016-5205 CVE-2016-5206 CVE-2016-5207 CVE-2016-5208 CVE-2016-5209 CVE-2016-5210 CVE-2016-5211 CVE-2016-5212 CVE-2016-5213 CVE-2016-5214 CVE-2016-5215 CVE-2016-5216 CVE-2016-5217 CVE-2016-5218 CVE-2016-5219 CVE-2016-5220 CVE-2016-5221 CVE-2016-5222 CVE-2016-5223 CVE-2016-5224 CVE-2016-5225 CVE-2016-5226 CVE-2016-9650 CVE-2016-9651 CVE-2016-9652 ==================================================================== 1. Summary: An update for chromium-browser is now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). This update upgrades Chromium to version55.0.2883.75. Security Fix(es): * Multiple flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash, execute arbitrary code, or disclose sensitive information when visited by the victim. (CVE-2016-5203, CVE-2016-5204, CVE-2016-5205, CVE-2016-5206, CVE-2016-5207, CVE-2016-5208, CVE-2016-5209, CVE-2016-5210, CVE-2016-5211, CVE-2016-5212, CVE-2016-5213, CVE-2016-9651, CVE-2016-9652, CVE-2016-5214, CVE-2016-5215, CVE-2016-5216, CVE-2016-5217, CVE-2016-5218, CVE-2016-5219, CVE-2016-5220, CVE-2016-5221, CVE-2016-5222, CVE-2016-5223, CVE-2016-5224, CVE-2016-5225, CVE-2016-5226, CVE-2016-9650) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing the update, Chromium must be restarted for the changes to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1400850 - CVE-2016-9651 chromium-browser: private property access in v8 1400851 - CVE-2016-5208 chromium-browser: universal xss in blink 1400852 - CVE-2016-5207 chromium-browser: universal xss in blink 1400853 - CVE-2016-5206 chromium-browser: same-origin bypass in pdfium 1400854 - CVE-2016-5205 chromium-browser: universal xss in blink 1400855 - CVE-2016-5204 chromium-browser: universal xss in blink 1400856 - CVE-2016-5209 chromium-browser: out of bounds write in blink 1400857 - CVE-2016-5203 chromium-browser: use after free in pdfium 1400859 - CVE-2016-5210 chromium-browser: out of bounds write in pdfium 1400861 - CVE-2016-5212 chromium-browser: local file disclosure in devtools 1400862 - CVE-2016-5211 chromium-browser: use after free in pdfium 1400863 - CVE-2016-5213 chromium-browser: use after free in v8 1400864 - CVE-2016-5214 chromium-browser: file download protection bypass 1400865 - CVE-2016-5216 chromium-browser: use after free in pdfium 1400866 - CVE-2016-5215 chromium-browser: use after free in webaudio 1400867 - CVE-2016-5217 chromium-browser: use ofunvalidated data in pdfium 1400868 - CVE-2016-5218 chromium-browser: address spoofing in omnibox 1400869 - CVE-2016-5219 chromium-browser: use after free in v8 1400870 - CVE-2016-5221 chromium-browser: integer overflow in angle 1400871 - CVE-2016-5220 chromium-browser: local file access in pdfium 1400872 - CVE-2016-5222 chromium-browser: address spoofing in omnibox 1400873 - CVE-2016-9650 chromium-browser: csp referrer disclosure 1400875 - CVE-2016-5223 chromium-browser: integer overflow in pdfium 1400876 - CVE-2016-5226 chromium-browser: limited xss in blink 1400877 - CVE-2016-5225 chromium-browser: csp bypass in blink 1400878 - CVE-2016-5224 chromium-browser: same-origin bypass in svg 1400879 - CVE-2016-9652 chromium-browser: various fixes from internal audits 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): i386: chromium-browser-55.0.2883.75-1.el6.i686.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.i686.rpm x86_64: chromium-browser-55.0.2883.75-1.el6.x86_64.rpm chromium-browser-debuginfo-55.0.2883.75-1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2016-5203 https://access.redhat.com/security/cve/CVE-2016-5204 https://access.redhat.com/security/cve/CVE-2016-5205 https://access.redhat.com/security/cve/CVE-2016-5206 https://access.redhat.com/security/cve/CVE-2016-5207 https://access.redhat.com/security/cve/CVE-2016-5208 https://access.redhat.com/security/cve/CVE-2016-5209 https://access.redhat.com/security/cve/CVE-2016-5210 https://access.redhat.com/security/cve/CVE-2016-5211 https://access.redhat.com/security/cve/CVE-2016-5212 https://access.redhat.com/security/cve/CVE-2016-5213 https://access.redhat.com/security/cve/CVE-2016-5214 https://access.redhat.com/security/cve/CVE-2016-5215 https://access.redhat.com/security/cve/CVE-2016-5216 https://access.redhat.com/security/cve/CVE-2016-5217 https://access.redhat.com/security/cve/CVE-2016-5218 https://access.redhat.com/security/cve/CVE-2016-5219 https://access.redhat.com/security/cve/CVE-2016-5220 https://access.redhat.com/security/cve/CVE-2016-5221 https://access.redhat.com/security/cve/CVE-2016-5222 https://access.redhat.com/security/cve/CVE-2016-5223 https://access.redhat.com/security/cve/CVE-2016-5224 https://access.redhat.com/security/cve/CVE-2016-5225 https://access.redhat.com/security/cve/CVE-2016-5226 https://access.redhat.com/security/cve/CVE-2016-9650 https://access.redhat.com/security/cve/CVE-2016-9651 https://access.redhat.com/security/cve/CVE-2016-9652 https://access.redhat.com/security/updates/classification/#important https://chromereleases.googleblog.com/2016/12/stable-channel-update-for-desktop.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYSGRcXlSAg2UNWIIRAiHmAJ9Nl7uHXgQUjZU81KybHyCCHmCi8QCgr8fs CEnkb1YITLftO/cJ3o/KLWA=cu2B -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An update for the chromium-browser resolvescritical security vulnerabilities affecting users of Red Hat Enterprise Linux 6.. Red Hat Security, Chromium Browser Fix, Linux Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 07, 2016 Important Red Hat
98

Red Hat 6: RHSA-2015:0921-01 Important: Chromium Security Issues

Updated chromium-browser packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: chromium-browser security and bug fix update Advisory ID: RHSA-2015:0921-01 Product: Red Hat Enterprise Linux Supplementary Advisory URL: https://access.redhat.com/errata/RHSA-2015:0921.html Issue date: 2015-04-30 CVE Names: CVE-2015-1243 CVE-2015-1250 ==================================================================== 1. Summary: Updated chromium-browser packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 6 Supplementary. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Server Supplementary (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Supplementary (v. 6) - i386, x86_64 3. Description: Chromium is an open-source web browser, powered by WebKit (Blink). Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Chromium to crash or, potentially, execute arbitrary code with the privileges of the user running Chromium. (CVE-2015-1243, CVE-2015-1250) This update also fixes the following bug: * Prior to this update, Chromium did not accept GNOME's system proxy settings due to having GConf support disabled. This issue has beenresolved in this update. (BZ#1217065) All Chromium users should upgrade to these updated packages, which contain Chromium version 42.0.2311.135, which corrects these issues. After installing the update, Chromium must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1216920 - CVE-2015-1243 chromium-browser: use-after-free in DOM 1216921 - CVE-2015-1250 chromium-browser: various unspecified flaws 1217065 - Chromium-browser not accepting gnome system proxy settings in RHEL6. 6. Package List: Red Hat Enterprise Linux Desktop Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Server Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm Red Hat Enterprise Linux Workstation Supplementary (v. 6): Source: chromium-browser-42.0.2311.135-1.el6_6.src.rpm i386: chromium-browser-42.0.2311.135-1.el6_6.i686.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.i686.rpm x86_64: chromium-browser-42.0.2311.135-1.el6_6.x86_64.rpm chromium-browser-debuginfo-42.0.2311.135-1.el6_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2015-1243 https://access.redhat.com/security/cve/CVE-2015-1250 https://access.redhat.com/security/updates/classification/#important https://chromereleases.googleblog.com/2015/04/stable-channel-update_28.html 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVQopnXlSAg2UNWIIRAgQLAKCzVoixHduhi3H16D16uWNNhvdvcQCgqNj0 LvRH19/Se7OKiVYg1eoWKXA=+RnW -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest chromium-browser update resolves several critical vulnerabilities affecting Red Hat Enterprise Linux 6.. chromium browser update, red hat enterprise linux, security issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 30, 2015 Important Red Hat
200

SciLinux: CVE-2010-0174 Critical: Firefox Security Flaw Impact

Critical: firefox security update. Date: Wed, 31 Mar 2010 17:06:44 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: firefox security update Issue date: 2010-03-30 CVE Names: CVE-2010-0174 CVE-2010-0175 CVE-2010-0176 CVE-2010-0177 CVE-2010-0178 CVE-2010-0179 Several use-after-free flaws were found in Firefox. Visiting a web page containing malicious content could result in Firefox executing arbitrary code with the privileges of the user running Firefox. (CVE-2010-0175, CVE-2010-0176, CVE-2010-0177) A flaw was found in Firefox that could allow an applet to generate a drag and drop action from a mouse click. Such an action could be used to execute arbitrary JavaScript with the privileges of the user running Firefox. (CVE-2010-0178) A privilege escalation flaw was found in Firefox when the Firebug add-on is in use. The XMLHttpRequestSpy module in the Firebug add-on exposes a Chrome privilege escalation flaw that could be used to execute arbitrary JavaScript with the privileges of the user running Firefox. (CVE-2010-0179) Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2010-0174) After installing the update, Firefox must be restarted for the changes to take effect. SL 4.x SRPMS: firefox-3.0.19-1.el4.src.rpm i386: firefox-3.0.19-1.el4.i386.rpm x86_64: firefox-3.0.19-1.el4.i386.rpm firefox-3.0.19-1.el4.x86_64.rpm -Connie Sieh -Troy Dawson lastline . Important security patch for Firefox resolves various vulnerabilities within Scientific Linux 4.x. A restart is necessary following the installation.. firefox exploits, security patch, Scientific Linux 4, critical updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 31, 2010 Critical Scientific Linux
200

Scientific Linux: Critical Firefox Update for SL4.x and SL5.x - Web Threats

Critical: firefox security update. Date: Wed, 4 Feb 2009 14:09:04 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA Critical: firefox on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: firefox security update Issue date: 2009-02-04 CVE Names: CVE-2009-0352 CVE-2009-0353 CVE-2009-0354 CVE-2009-0355 CVE-2009-0356 CVE-2009-0357 CVE-2009-0358 Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code as the user running Firefox. (CVE-2009-0352, CVE-2009-0353, CVE-2009-0356) Several flaws were found in the way malformed content was processed. A website containing specially-crafted content could, potentially, trick a Firefox user into surrendering sensitive information. (CVE-2009-0354, CVE-2009-0355) A flaw was found in the way Firefox treated HTTPOnly cookies. An attacker able to execute arbitrary JavaScript on a target site using HTTPOnly cookies may be able to use this flaw to steal the cookie. (CVE-2009-0357) A flaw was found in the way Firefox treated certain HTTP page caching directives. A local attacker could steal the contents of sensitive pages which the page author did not intend to be cached. (CVE-2009-0358) After installing the update, Firefox must be restarted for the changes to take effect. SL 4.x SRPMS: firefox-3.0.6-1.el4.src.rpm nss-3.12.2.0-3.el4.src.rpm i386: firefox-3.0.6-1.el4.i386.rpm nss-3.12.2.0-3.el4.i386.rpm nss-devel-3.12.2.0-3.el4.i386.rpm nss-tools-3.12.2.0-3.el4.i386.rpm x86_64: firefox-3.0.6-1.el4.i386.rpm firefox-3.0.6-1.el4.x86_64.rpm nss-3.12.2.0-3.el4.i386.rpm nss-3.12.2.0-3.el4.x86_64.rpm nss-devel-3.12.2.0-3.el4.x86_64.rpm nss-tools-3.12.2.0-3.el4.x86_64.rpm SL 5.x SRPMS: firefox-3.0.6-1.el5.src.rpm nss-3.12.2.0-4.el5.src.rpm xulrunner-1.9.0.6-1.el5.src.rpm i386: firefox-3.0.6-1.el5.i386.rpm nss-3.12.2.0-4.el5.i386.rpm nss-devel-3.12.2.0-4.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-4.el5.i386.rpm nss-tools-3.12.2.0-4.el5.i386.rpm xulrunner-1.9.0.6-1.el5.i386.rpm xulrunner-devel-1.9.0.6-1.el5.i386.rpm xulrunner-devel-unstable-1.9.0.6-1.el5.i386.rpm x86_64: firefox-3.0.6-1.el5.i386.rpm firefox-3.0.6-1.el5.x86_64.rpm nss-3.12.2.0-4.el5.i386.rpm nss-3.12.2.0-4.el5.x86_64.rpm nss-devel-3.12.2.0-4.el5.i386.rpm nss-devel-3.12.2.0-4.el5.x86_64.rpm nss-pkcs11-devel-3.12.2.0-4.el5.i386.rpm nss-pkcs11-devel-3.12.2.0-4.el5.x86_64.rpm nss-tools-3.12.2.0-4.el5.x86_64.rpm xulrunner-1.9.0.6-1.el5.i386.rpm xulrunner-1.9.0.6-1.el5.x86_64.rpm xulrunner-devel-1.9.0.6-1.el5.i386.rpm xulrunner-devel-1.9.0.6-1.el5.x86_64.rpm xulrunner-devel-unstable-1.9.0.6-1.el5.x86_64.rpm -Connie Sieh -Troy Dawson . Urgent security patch for Chrome on Ubuntu, tackling several vulnerabilities that may result in arbitrary code execution.. firefox security update, scientific linux vulnerabilities, critical firefox flaws, security errata. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 04, 2009 Critical Scientific Linux
200

Scientific Linux: Vital Update for Firefox Security in SL4.x and SL5.x

Critical: firefox security update. Date: Fri, 8 Feb 2008 14:21:06 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for firefox on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Critical: firefox security update Issue date: 2008-02-07 CVE Names: CVE-2008-0412 CVE-2008-0413 CVE-2008-0415 CVE-2008-0417 CVE-2008-0418 CVE-2008-0419 CVE-2008-0591 CVE-2008-0592 CVE-2008-0593 Several flaws were found in the way Firefox processed certain malformed web content. A webpage containing malicious content could cause Firefox to crash, or potentially execute arbitrary code as the user running Firefox. (CVE-2008-0412, CVE-2008-0413, CVE-2008-0415, CVE-2008-0419) Several flaws were found in the way Firefox displayed malformed web content. A webpage containing specially-crafted content could trick a user into surrendering sensitive information. (CVE-2008-0591, CVE-2008-0593) A flaw was found in the way Firefox stored password data. If a user saves login information for a malicious website, it could be possible to corrupt the password database, preventing the user from properly accessing saved password data. (CVE-2008-0417) A flaw was found in the way Firefox handles certain chrome URLs. If a user has certain extensions installed, it could allow a malicious website to steal sensitive session data. Note: this flaw does not affect a default installation of Firefox. (CVE-2008-0418) A flaw was found in the way Firefox saves certain text files. If a website offers a file of type "plain/text", rather than "text/plain", Firefox will not show future "text/plain" content to the user in the browser, forcing them to save those files locally to view the content. (CVE-2008-0592) SL 4.x SRPMS: firefox-1.5.0.12-0.10.el4.src.rpm i386: firefox-1.5.0.12-0.10.el4.i386.rpm x86_64: firefox-1.5.0.12-0.10.el4.i386.rpm firefox-1.5.0.12-0.10.el4.x86_64.rpm SL 5.x SRPMS: firefox-1.5.0.12-9.el5.src.rpm i386: firefox-1.5.0.12-9.el5.i386.rpm firefox-devel-1.5.0.12-9.el5.i386.rpm x86_64: firefox-1.5.0.12-9.el5.i386.rpm firefox-1.5.0.12-9.el5.x86_64.rpm firefox-devel-1.5.0.12-9.el5.i386.rpm firefox-devel-1.5.0.12-9.el5.x86_64.rpm -Connie Sieh -Troy Dawson . An important security patch for Firefox on Scientific Linux SL4.x and SL5.x has been released to fix several significant vulnerabilities.. Scientific Linux, Firefox Update, Security Issue, Critical Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 08, 2008 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here