Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0148-1 Rating: important References: #1242717 Cross-References: CVE-2025-4372 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chromium fixes the following issues: Chromium 136.0.7103.92 (boo#1242717) * CVE-2025-4372: Use after free in WebAudio Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-148=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): chromedriver-136.0.7103.92-bp156.2.116.1 chromium-136.0.7103.92-bp156.2.116.1 References: https://www.suse.com/security/cve/CVE-2025-4372.html https://bugzilla.suse.com/1242717 . Essential openSUSE upgrade for firefox tackles CVE-2025-4373, bolstering user safety with significant improvements.. openSUSE update, chromium patch, web security, threat management. . Severity: Important. LinuxSecurity.com Team
* bsc#1234326 Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2024:4324-1 Release Date: 2024-12-16T12:06:05Z Rating: important References: * bsc#1234326 Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 128.5.1 ESR (bsc#1234326): \- Fixed an issue thatprevented some websites from loading when using SSL Inspection. (bmo#1933747) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Desktop 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP2 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-4324=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-4324=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4324=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-4324=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-4324=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-4324=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patchSUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-4324=1 ## Package List: * SUSE Linux Enterprise Desktop 15 SP4 LTSS (x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP2 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) *MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Enterprise Storage 7.1 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) *MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-branding-upstream-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * openSUSE Leap 15.5 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-branding-upstream-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * openSUSE Leap 15.6 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP5 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP6 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 *MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1234326 . A security patch for Mozilla Firefox tackles SSL vulnerabilities affecting various SUSE releases. Make sure your systems stay secure.. MozillaFirefoxUpdate, SUSE Security, Firefox Update, Linux Security Advisories, Linux Application Security. . Severity: Important. LinuxSecurity.com Team
It was discovered that there was a sanitisation bypass issue in python-html-sanitizer, a library used ensure that user-specified content cannot inject HTML or JavaScript into a webpage. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3856-1
Two security issues have been discovered in python2.7: CVE-2019-16935 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2628-1
An update for pki-core is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pki-core security update Advisory ID: RHSA-2021:0975-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0975 Issue date: 2021-03-23 CVE Names: CVE-2019-10146 CVE-2019-10179 CVE-2019-10221 CVE-2020-1721 CVE-2020-25715 CVE-2021-20179 ==================================================================== 1. Summary: An update for pki-core is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - noarch, ppc64, ppc64le, s390x 3. Description: The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System. Security Fix(es): * pki-core: Unprivileged users can renew any certificate (CVE-2021-20179) * pki-core: XSS in the certificate search results (CVE-2020-25715) * pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page (CVE-2019-10146) * pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab (CVE-2019-10179) * pki-core: Reflected XSS ingetcookies?url= endpoint in CA (CVE-2019-10221) * pki-core: KRA vulnerable to reflected XSS via the getPk12 page (CVE-2020-1721) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1695901 - CVE-2019-10179 pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab 1710171 - CVE-2019-10146 pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page 1732565 - CVE-2019-10221 pki-core: Reflected XSS in getcookies?url= endpoint in CA 1777579 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page 1891016 - CVE-2020-25715 pki-core: XSS in the certificate search results 1914379 - CVE-2021-20179 pki-core: Unprivileged users can renew any certificate 6. Package List: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-javadoc-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm x86_64: pki-core-debuginfo-10.5.16-7.el7_7.x86_64.rpm pki-symkey-10.5.16-7.el7_7.x86_64.rpm pki-tools-10.5.16-7.el7_7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm ppc64le: pki-core-debuginfo-10.5.16-7.el7_7.ppc64le.rpm pki-tools-10.5.16-7.el7_7.ppc64le.rpm x86_64: pki-core-debuginfo-10.5.16-7.el7_7.x86_64.rpm pki-symkey-10.5.16-7.el7_7.x86_64.rpm pki-tools-10.5.16-7.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-javadoc-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm ppc64: pki-core-debuginfo-10.5.16-7.el7_7.ppc64.rpm pki-symkey-10.5.16-7.el7_7.ppc64.rpm pki-tools-10.5.16-7.el7_7.ppc64.rpm ppc64le: pki-core-debuginfo-10.5.16-7.el7_7.ppc64le.rpm pki-symkey-10.5.16-7.el7_7.ppc64le.rpm s390x: pki-core-debuginfo-10.5.16-7.el7_7.s390x.rpm pki-symkey-10.5.16-7.el7_7.s390x.rpm pki-tools-10.5.16-7.el7_7.s390x.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-10146 https://access.redhat.com/security/cve/CVE-2019-10179 https://access.redhat.com/security/cve/CVE-2019-10221 https://access.redhat.com/security/cve/CVE-2020-1721 https://access.redhat.com/security/cve/CVE-2020-25715 https://access.redhat.com/security/cve/CVE-2021-20179 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYFob0tzjgjWX9erEAQgAuQ/+JmPmJG+Q3Ct5nMbJQEFhGWN6RnVWfX8R Oqt1QXekRSD8cLOcLc4xCpO/B80a282tglOkPu3KY+A438nhbn2GtInDc+8e/v2e m5DbD6r8ozIyrOWx+65kHLo7go7YOVNkTk4tw/3wns5A6ryglDKBoO3ePPoWXRjr bJQl2wkBnbn2Ng+z/orYfS16Y89Aax1NZWPpi1nn0lTat2K/6aLznA8e+gR8sYcq XE3i4Pb25Z7KVIAfCWCXOeRv1Mk7cCjn5lzoBtYS7tuIp7E++4qFK1S9aDdZMmQ9 5YN0ffHRYVvsyhcHkITRTcA30TakBkM5MDA/wfnranzWl4GMCdHemhjQa0oAZaED kw2lzp92l9u+tlegPYY0g3TZ5TL1+8ach1AOYcVLkwpTVicIFbuvYdb9lW+gvbdz +T3SA4wNfjUTe+/hEqIP0KsJgdJP4iELMWG4gNdHcy9ORCIxvh7e6GiR6ky9jVXp ZC+Hs5ZzhwuWkVenyBI0tZsebRozpdBRS+km8z1cy1zTULTNJo58OXOf3DdXRVdM M7d1yRbMj+Id56WBGYFrwoUOZgTmmJ7x79DWy5tnGkQ2eddA8+wUDERP0DiL+Tk/ V1+ryLEIY7RjZd59WyoYkeGNe0/YZv35L96UrXAmcrlsRrWRAPgnzcCDZzAydinr IvOKpetILcg=SMWO -----END PGP SIGNATURE----- -- RHSA-announce mailing list
libapache2-mod-auth-mellon could be made to redirect users to malicious sites.. =========================================================================Ubuntu Security Notice USN-4291-1 February 24, 2020 libapache2-mod-auth-mellon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 18.04 LTS Summary: libapache2-mod-auth-mellon could be made to redirect users to malicious sites. Software Description: - libapache2-mod-auth-mellon: SAML 2.0 authentication module for Apache Details: It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to redirect a user to a malicious URL. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libapache2-mod-auth-mellon 0.14.2-1ubuntu1.19.10.1 Ubuntu 18.04 LTS: libapache2-mod-auth-mellon 0.13.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4291-1 CVE-2019-13038 Package Information: https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon/0.14.2-1ubuntu1.19.10.1 https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon/0.13.1-1ubuntu0.2 . Ubuntu Security Notice USN-4292-1 addresses a cross-site scripting vulnerability in libapache2-mod-auth-saml, posing risks to user security.. libapache2-mod-auth-mellon, redirect vulnerability, Ubuntu security, web application threat. . Severity: Critical. LinuxSecurity.com Team
Chromium 77.0.3865.90 update. See the official announcement on https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html and https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop_18.html . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-df4fb49ef7 2019-09-28 00:00:59.188823 --------------------------------------------------------------------------------Name : chromium Product : Fedora 31 Version : 77.0.3865.90 Release : 2.fc31 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Chromium 77.0.3865.90 update. See the official announcement on https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html and https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop_18.html --------------------------------------------------------------------------------References: [ 1 ] Bug #1754914 - Weird black icon is used for Chromium https://bugzilla.redhat.com/show_bug.cgi?id=1754914 [ 2 ] Bug #1754179 - All pages fail to load with "Aw, Snap!" https://bugzilla.redhat.com/show_bug.cgi?id=1754179 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-df4fb49ef7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
**Horde_Core 2.31.6** * [mjr] SECURITY: Fix XSS vulnerability when rendering a colorpicker (Bug #14857).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1f64819623 2018-10-07 21:10:49.841477 --------------------------------------------------------------------------------Name : php-horde-Horde-Core Product : Fedora 27 Version : 2.31.6 Release : 1.fc27 URL : http://pear.horde.org Summary : Horde Core Framework libraries Description : These classes provide the core functionality of the Horde Application Framework. --------------------------------------------------------------------------------Update Information: **Horde_Core 2.31.6** * [mjr] SECURITY: Fix XSS vulnerability when rendering a colorpicker (Bug #14857). --------------------------------------------------------------------------------ChangeLog: * Wed Sep 26 2018 Remi Collet - 2.31.6-1 - update to 2.31.6 * Thu Aug 16 2018 Remi Collet - 2.31.5-1 - update to 2.31.5 * Mon Jun 11 2018 Remi Collet - 2.31.3-1 - update to 2.31.3 * Mon Feb 12 2018 Remi Collet - 2.31.2-1 - Update to 2.31.2 * Mon Nov 27 2017 Remi Collet - 2.31.1-1 - Update to 2.31.1 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1f64819623' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.