Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 498
Alerts This Week
Warning Icon 1 498

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
202

openSUSE: 2025:0148-1 important: chromium use after free

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for chromium ______________________________________________________________________________ Announcement ID: openSUSE-SU-2025:0148-1 Rating: important References: #1242717 Cross-References: CVE-2025-4372 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for chromium fixes the following issues: Chromium 136.0.7103.92 (boo#1242717) * CVE-2025-4372: Use after free in WebAudio Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2025-148=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 x86_64): chromedriver-136.0.7103.92-bp156.2.116.1 chromium-136.0.7103.92-bp156.2.116.1 References: https://www.suse.com/security/cve/CVE-2025-4372.html https://bugzilla.suse.com/1242717 . Essential openSUSE upgrade for firefox tackles CVE-2025-4373, bolstering user safety with significant improvements.. openSUSE update, chromium patch, web security, threat management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 09, 2025 Important OpenSUSE
100

SUSE: 2024:4324-1 important: MozillaFirefox SSL loading issue

* bsc#1234326 Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 . # Security update for MozillaFirefox Announcement ID: SUSE-SU-2024:4324-1 Release Date: 2024-12-16T12:06:05Z Rating: important References: * bsc#1234326 Affected Products: * Desktop Applications Module 15-SP5 * Desktop Applications Module 15-SP6 * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 128.5.1 ESR (bsc#1234326): \- Fixed an issue thatprevented some websites from loading when using SSL Inspection. (bmo#1933747) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Desktop 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLED-15-SP4-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP2 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP3 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2024-4324=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2024-4324=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2024-4324=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2024-4324=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2024-4324=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2024-4324=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2024-4324=1 * Desktop Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP6-2024-4324=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patchSUSE-SLE-Product-HPC-15-SP4-ESPOS-2024-4324=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2024-4324=1 ## Package List: * SUSE Linux Enterprise Desktop 15 SP4 LTSS (x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Desktop 15 SP4 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP2 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP2 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP3 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) *MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Enterprise Storage 7.1 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) *MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-branding-upstream-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * openSUSE Leap 15.5 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-branding-upstream-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * openSUSE Leap 15.6 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP5 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP6 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * Desktop Applications Module 15-SP6 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 *MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-128.5.1-150200.152.164.1 * MozillaFirefox-debuginfo-128.5.1-150200.152.164.1 * MozillaFirefox-translations-common-128.5.1-150200.152.164.1 * MozillaFirefox-debugsource-128.5.1-150200.152.164.1 * MozillaFirefox-translations-other-128.5.1-150200.152.164.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-128.5.1-150200.152.164.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1234326 . A security patch for Mozilla Firefox tackles SSL vulnerabilities affecting various SUSE releases. Make sure your systems stay secure.. MozillaFirefoxUpdate, SUSE Security, Firefox Update, Linux Security Advisories, Linux Application Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 16, 2024 Important SuSE
197

Debian 11 Bullseye DLA-3856-1 Critical: HTML Sanitization Bypass Fix

It was discovered that there was a sanitisation bypass issue in python-html-sanitizer, a library used ensure that user-specified content cannot inject HTML or JavaScript into a webpage. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3856-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb August 26, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python-html-sanitizer Version : 1.9.1-2+deb11u1 CVE ID : CVE-2024-34078 Debian Bug : 1070710 It was discovered that there was a sanitisation bypass issue in python-html-sanitizer, a library used ensure that user-specified content cannot inject HTML or JavaScript into a webpage. If the default "keep_typographic_whitespace=False" value was set, malicous users could have exploited the fact that some Unicode characters normalise to chevrons, which allowed specially-crafted HTML to escape sanitization. For Debian 11 bullseye, this problem has been fixed in version 1.9.1-2+deb11u1. We recommend that you upgrade your python-html-sanitizer packages. For the detailed security status of python-html-sanitizer please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-html-sanitizer Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Safeguard your environment utilizing the Debian LTS Advisory DLA-3857-1, which focuses on remediating a security loophole in python-sanitizer-html.. Debian Security Update, Python Library Issue, Web Threat Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 26, 2024 Critical Debian LTS
197

Debian 9 DLA-2628-1 Critical: Python2.7 XSS And Cache Poisoning

Two security issues have been discovered in python2.7: CVE-2019-16935 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2628-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky April 17, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : python2.7 Version : 2.7.13-2+deb9u5 CVE ID : CVE-2019-16935 CVE-2021-23336 Two security issues have been discovered in python2.7: CVE-2019-16935 The documentation XML-RPC server in Python 2.7 has XSS via the server_title field. This occurs in Lib/DocXMLRPCServer.py in Python 2.x, and in Lib/xmlrpc/server.py in Python 3.x. If set_server_title is called with untrusted input, arbitrary JavaScript can be delivered to clients that visit the http URL for this server. CVE-2021-23336 The Python2.7 vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.parse.parse_qs by using a vector called parameter cloaking. When the attacker can separate query parameters using a semicolon (;), they can cause a difference in the interpretation of the request between the proxy (running with default configuration) and the server. This can result in malicious requests being cached as completely safe ones, as the proxy would usually not see the semicolon as a separator, and therefore would not include it in a cache key of an unkeyed parameter. **Attention, API-change!** Please be sure your software is working properly if it uses `urllib.parse.parse_qs` or `urllib.parse.parse_qsl`, `cgi.parse` or `cgi.parse_multipart`. Earlier Python versions allowed using both ``;`` and ``&`` as query parameter separators in `urllib.parse.parse_qs` and `urllib.parse.parse_qsl`. Due to security concerns, and to conform with newer W3C recommendations, this has been changed to allowonly a single separator key, with ``&`` as the default. This change also affects `cgi.parse` and `cgi.parse_multipart` as they use the affected functions internally. For more details, please see their respective documentation. For Debian 9 stretch, these problems have been fixed in version 2.7.13-2+deb9u5. We recommend that you upgrade your python2.7 packages. For the detailed security status of python2.7 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python2.7 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Upgrade advised for Debian 9 (Stretch) due to Python2.7 vulnerabilities, including XSS and cache injection risks.. Debian Security Update, Python Issues, XSS Exploit, Cache Poisoning. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2021 Critical Debian LTS
98

Red Hat Enterprise Linux 7.7: RHSA-2021:0975-01 Critical XSS Issues

An update for pki-core is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pki-core security update Advisory ID: RHSA-2021:0975-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0975 Issue date: 2021-03-23 CVE Names: CVE-2019-10146 CVE-2019-10179 CVE-2019-10221 CVE-2020-1721 CVE-2020-25715 CVE-2021-20179 ==================================================================== 1. Summary: An update for pki-core is now available for Red Hat Enterprise Linux 7.7 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7) - noarch, x86_64 Red Hat Enterprise Linux Server EUS (v. 7.7) - noarch, ppc64le, x86_64 Red Hat Enterprise Linux Server Optional EUS (v. 7.7) - noarch, ppc64, ppc64le, s390x 3. Description: The Public Key Infrastructure (PKI) Core contains fundamental packages required by Red Hat Certificate System. Security Fix(es): * pki-core: Unprivileged users can renew any certificate (CVE-2021-20179) * pki-core: XSS in the certificate search results (CVE-2020-25715) * pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page (CVE-2019-10146) * pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab (CVE-2019-10179) * pki-core: Reflected XSS ingetcookies?url= endpoint in CA (CVE-2019-10221) * pki-core: KRA vulnerable to reflected XSS via the getPk12 page (CVE-2020-1721) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1695901 - CVE-2019-10179 pki-core/pki-kra: Reflected XSS in recoveryID search field at KRA's DRM agent page in authorize recovery tab 1710171 - CVE-2019-10146 pki-core: Reflected XSS in 'path length' constraint field in CA's Agent page 1732565 - CVE-2019-10221 pki-core: Reflected XSS in getcookies?url= endpoint in CA 1777579 - CVE-2020-1721 pki-core: KRA vulnerable to reflected XSS via the getPk12 page 1891016 - CVE-2020-25715 pki-core: XSS in the certificate search results 1914379 - CVE-2021-20179 pki-core: Unprivileged users can renew any certificate 6. Package List: Red Hat Enterprise Linux ComputeNode Optional EUS (v. 7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-javadoc-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm x86_64: pki-core-debuginfo-10.5.16-7.el7_7.x86_64.rpm pki-symkey-10.5.16-7.el7_7.x86_64.rpm pki-tools-10.5.16-7.el7_7.x86_64.rpm Red Hat Enterprise Linux Server EUS (v.7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm ppc64le: pki-core-debuginfo-10.5.16-7.el7_7.ppc64le.rpm pki-tools-10.5.16-7.el7_7.ppc64le.rpm x86_64: pki-core-debuginfo-10.5.16-7.el7_7.x86_64.rpm pki-symkey-10.5.16-7.el7_7.x86_64.rpm pki-tools-10.5.16-7.el7_7.x86_64.rpm Red Hat Enterprise Linux Server Optional EUS (v. 7.7): Source: pki-core-10.5.16-7.el7_7.src.rpm noarch: pki-base-10.5.16-7.el7_7.noarch.rpm pki-base-java-10.5.16-7.el7_7.noarch.rpm pki-ca-10.5.16-7.el7_7.noarch.rpm pki-javadoc-10.5.16-7.el7_7.noarch.rpm pki-kra-10.5.16-7.el7_7.noarch.rpm pki-server-10.5.16-7.el7_7.noarch.rpm ppc64: pki-core-debuginfo-10.5.16-7.el7_7.ppc64.rpm pki-symkey-10.5.16-7.el7_7.ppc64.rpm pki-tools-10.5.16-7.el7_7.ppc64.rpm ppc64le: pki-core-debuginfo-10.5.16-7.el7_7.ppc64le.rpm pki-symkey-10.5.16-7.el7_7.ppc64le.rpm s390x: pki-core-debuginfo-10.5.16-7.el7_7.s390x.rpm pki-symkey-10.5.16-7.el7_7.s390x.rpm pki-tools-10.5.16-7.el7_7.s390x.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-10146 https://access.redhat.com/security/cve/CVE-2019-10179 https://access.redhat.com/security/cve/CVE-2019-10221 https://access.redhat.com/security/cve/CVE-2020-1721 https://access.redhat.com/security/cve/CVE-2020-25715 https://access.redhat.com/security/cve/CVE-2021-20179 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBYFob0tzjgjWX9erEAQgAuQ/+JmPmJG+Q3Ct5nMbJQEFhGWN6RnVWfX8R Oqt1QXekRSD8cLOcLc4xCpO/B80a282tglOkPu3KY+A438nhbn2GtInDc+8e/v2e m5DbD6r8ozIyrOWx+65kHLo7go7YOVNkTk4tw/3wns5A6ryglDKBoO3ePPoWXRjr bJQl2wkBnbn2Ng+z/orYfS16Y89Aax1NZWPpi1nn0lTat2K/6aLznA8e+gR8sYcq XE3i4Pb25Z7KVIAfCWCXOeRv1Mk7cCjn5lzoBtYS7tuIp7E++4qFK1S9aDdZMmQ9 5YN0ffHRYVvsyhcHkITRTcA30TakBkM5MDA/wfnranzWl4GMCdHemhjQa0oAZaED kw2lzp92l9u+tlegPYY0g3TZ5TL1+8ach1AOYcVLkwpTVicIFbuvYdb9lW+gvbdz +T3SA4wNfjUTe+/hEqIP0KsJgdJP4iELMWG4gNdHcy9ORCIxvh7e6GiR6ky9jVXp ZC+Hs5ZzhwuWkVenyBI0tZsebRozpdBRS+km8z1cy1zTULTNJo58OXOf3DdXRVdM M7d1yRbMj+Id56WBGYFrwoUOZgTmmJ7x79DWy5tnGkQ2eddA8+wUDERP0DiL+Tk/ V1+ryLEIY7RjZd59WyoYkeGNe0/YZv35L96UrXAmcrlsRrWRAPgnzcCDZzAydinr IvOKpetILcg=SMWO -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://listman.redhat.com/mailman/listinfo/rhsa-announce . A significant security patch for pki-core resolves several XSS vulnerabilities in Red Hat Enterprise Linux to bolster defense.. pki-core Update, Red Hat Security, Important Threat, Enterprise Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 23, 2021 Important Red Hat
172

Ubuntu 4291-1 Critical: Mod-Auth-Mellon Redirect to Malicious Sites

libapache2-mod-auth-mellon could be made to redirect users to malicious sites.. =========================================================================Ubuntu Security Notice USN-4291-1 February 24, 2020 libapache2-mod-auth-mellon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 18.04 LTS Summary: libapache2-mod-auth-mellon could be made to redirect users to malicious sites. Software Description: - libapache2-mod-auth-mellon: SAML 2.0 authentication module for Apache Details: It was discovered that mod_auth_mellon incorrectly handled certain requests. An attacker could possibly use this issue to redirect a user to a malicious URL. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: libapache2-mod-auth-mellon 0.14.2-1ubuntu1.19.10.1 Ubuntu 18.04 LTS: libapache2-mod-auth-mellon 0.13.1-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4291-1 CVE-2019-13038 Package Information: https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon/0.14.2-1ubuntu1.19.10.1 https://launchpad.net/ubuntu/+source/libapache2-mod-auth-mellon/0.13.1-1ubuntu0.2 . Ubuntu Security Notice USN-4292-1 addresses a cross-site scripting vulnerability in libapache2-mod-auth-saml, posing risks to user security.. libapache2-mod-auth-mellon, redirect vulnerability, Ubuntu security, web application threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 24, 2020 Critical Ubuntu
89

Fedora 31: FEDORA-2019-df4fb49ef7 Moderate: Chromium Web Browser Update

Chromium 77.0.3865.90 update. See the official announcement on https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html and https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop_18.html . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-df4fb49ef7 2019-09-28 00:00:59.188823 --------------------------------------------------------------------------------Name : chromium Product : Fedora 31 Version : 77.0.3865.90 Release : 2.fc31 URL : https://www.chromium.org/Home/ Summary : A WebKit (Blink) powered web browser Description : Chromium is an open-source web browser, powered by WebKit (Blink). --------------------------------------------------------------------------------Update Information: Chromium 77.0.3865.90 update. See the official announcement on https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop.html and https://chromereleases.googleblog.com/2019/09/stable-channel-update-for-desktop_18.html --------------------------------------------------------------------------------References: [ 1 ] Bug #1754914 - Weird black icon is used for Chromium https://bugzilla.redhat.com/show_bug.cgi?id=1754914 [ 2 ] Bug #1754179 - All pages fail to load with "Aw, Snap!" https://bugzilla.redhat.com/show_bug.cgi?id=1754179 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-df4fb49ef7' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Firefox 83.0.1 is now available for Ubuntu 20.04, fixing various bugs and improving privacy features. Find out more info here.. Chromium Update, Fedora 31, Web Browser Security, Open Source Update. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2019 Fedora
89

Fedora 27: Security Advisory for Php-Horde-Horde-Core XSS Threat

**Horde_Core 2.31.6** * [mjr] SECURITY: Fix XSS vulnerability when rendering a colorpicker (Bug #14857).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-1f64819623 2018-10-07 21:10:49.841477 --------------------------------------------------------------------------------Name : php-horde-Horde-Core Product : Fedora 27 Version : 2.31.6 Release : 1.fc27 URL : http://pear.horde.org Summary : Horde Core Framework libraries Description : These classes provide the core functionality of the Horde Application Framework. --------------------------------------------------------------------------------Update Information: **Horde_Core 2.31.6** * [mjr] SECURITY: Fix XSS vulnerability when rendering a colorpicker (Bug #14857). --------------------------------------------------------------------------------ChangeLog: * Wed Sep 26 2018 Remi Collet - 2.31.6-1 - update to 2.31.6 * Thu Aug 16 2018 Remi Collet - 2.31.5-1 - update to 2.31.5 * Mon Jun 11 2018 Remi Collet - 2.31.3-1 - update to 2.31.3 * Mon Feb 12 2018 Remi Collet - 2.31.2-1 - Update to 2.31.2 * Mon Nov 27 2017 Remi Collet - 2.31.1-1 - Update to 2.31.1 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-1f64819623' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora provides a security patch addressing a Cross-Site Scripting vulnerability present in php-horde-Horde-Core, which affects the rendering of colorpickers.. Horde Update, Fedora Security Fix, XSS Threat, Web Application Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 07, 2018 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200