Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 42: 2025-853e37285c critical: mingw-python-flask session issue

Update to flask-3.1.1.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-853e37285c 2025-05-30 01:14:13.237014+00:00 -------------------------------------------------------------------------------- Name : mingw-python-flask Product : Fedora 42 Version : 3.1.1 Release : 1.fc42 URL : https://palletsprojects.com/projects/itsdangerous/ Summary : MinGW Windows Python flask library Description : MinGW Windows Python flask. -------------------------------------------------------------------------------- Update Information: Update to flask-3.1.1. -------------------------------------------------------------------------------- ChangeLog: * Tue May 20 2025 Sandro Mani - 3.1.1-1 - Update to 3.1.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2366239 - CVE-2025-47278 mingw-python-flask: Flask Session Signing Fallback Key Vulnerability [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2366239 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-853e37285c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 42 release of mingw-python-flask enhances session management with update 3.1.1.. mingw-python-flask update, Fedora security, Python flask library. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 30, 2025 Critical Fedora
89

Fedora 31: FEDORA-2019-5b062c4a3b Critical: Mingw OpenEXR Memory Leak

This update backports fixes for CVE-2018-18443 and CVE-2018-18444.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5b062c4a3b 2019-11-22 00:46:48.106823 --------------------------------------------------------------------------------Name : mingw-OpenEXR Product : Fedora 31 Version : 2.3.0 Release : 3.fc31 URL : https://openexr.com/en/latest/ Summary : MinGW Windows OpenEXR library Description : MinGW Windows OpenEXR library. --------------------------------------------------------------------------------Update Information: This update backports fixes for CVE-2018-18443 and CVE-2018-18444. --------------------------------------------------------------------------------ChangeLog: * Wed Nov 13 2019 Sandro Mani - 2.3.0-3 - Backport fix for CVE-2018-18444 --------------------------------------------------------------------------------References: [ 1 ] Bug #1643094 - CVE-2018-18444 OpenEXR: Out-of-bounds write in makeMultiView.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1643094 [ 2 ] Bug #1643093 - CVE-2018-18443 OpenEXR: Memory leak in ThreadPool in in IlmBase/IlmThread/IlmThreadPool.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1643093 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5b062c4a3b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe sendan email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . This release for Fedora 31 tackles essential corrections concerning memory management flaws and vulnerabilities in Mingw OpenEXR.. mingw OpenEXR updates, Fedora security patches, memory leak fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 21, 2019 Critical Fedora
89

Ubuntu 20.04: 2020-a5c77e8c2e Major: ImageMagick Memory Leak

Update to LibRaw-0.18.10, see for details. ---- Update to LibRaw-0.18.9, see for details.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-d3b44e5574 2018-05-16 13:05:35.606735 --------------------------------------------------------------------------------Name : mingw-LibRaw Product : Fedora 28 Version : 0.18.10 Release : 1.fc28 URL : https://www.libraw.org/ Summary : Library for reading RAW files obtained from digital photo cameras Description : MinGW Windows LibRaw library. --------------------------------------------------------------------------------Update Information: Update to LibRaw-0.18.10, see for details. ---- Update to LibRaw-0.18.9, see for details. --------------------------------------------------------------------------------ChangeLog: * Mon May 7 2018 Sandro Mani - 0.18.10-1 - Update to 0.18.10 * Wed Apr 25 2018 Sandro Mani - 0.18.9-1 - Update to 0.18.9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1574327 - CVE-2018-10529 mingw-LibRaw: LibRaw: Out-of-bounds read in X3F property table list functionality in libraw_x3f.cpp and libraw_cxx.cpp [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1574327 [ 2 ] Bug #1574319 - CVE-2018-10528 mingw-LibRaw: LibRaw: Stack-based buffer overflow in libraw_cxx.cpp:utf2char() allows for potential code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1574319 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-d3b44e5574' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can befound at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important news regarding mingw-LibRaw on Fedora 28 fixes several security issues. Protect your system immediately.. LibRaw Update, Fedora Security, Buffer Overflow, Critical Patch, MinGW Library. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 16, 2018 Important Fedora
89

Fedora 23: Update for Mingw-PCRE 8.38 Critical Buffer Overflow Fix

Update to 8.38 and fix various CVE's. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-fd1199dbe2 2016-02-16 23:32:09.946597 -------------------------------------------------------------------------------- Name : mingw-pcre Product : Fedora 23 Version : 8.38 Release : 1.fc23 URL : / Summary : MinGW Windows pcre library Description : Cross compiled Perl-compatible regular expression library for use with mingw32. PCRE has its own native API, but a set of "wrapper" functions that are based on the POSIX API are also supplied in the library libpcreposix. Note that this just provides a POSIX calling interface to PCRE: the regular expressions themselves still follow Perl syntax and semantics. The header file for the POSIX-style functions is called pcreposix.h. -------------------------------------------------------------------------------- Update Information: Update to 8.38 and fix various CVE's -------------------------------------------------------------------------------- References: [ 1 ] Bug #1287720 - CVE-2015-8395 mingw-pcre: pcre: Buffer overflow caused by certain references [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287720 [ 2 ] Bug #1287704 - CVE-2015-8394 mingw-pcre: pcre: Integer overflow caused by missing check for certain conditions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287704 [ 3 ] Bug #1287698 - CVE-2015-8393 mingw-pcre: pcre: Information leak when running pcgrep -q on crafted binary [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287698 [ 4 ] Bug #1287692 - CVE-2015-8392 mingw-pcre: pcre: Buffer overflow caused by certain patterns with duplicated named groups [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287692 [ 5 ] Bug #1287673 - CVE-2015-8391 mingw-pcre: pcre: Some pathological patterns causes pcre_compile() to run for a very long time [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287673 [ 6 ] Bug #1287668 - CVE-2015-8390 mingw-pcre: pcre: Reading from uninitialized memory when processing certain patterns [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287668 [ 7 ] Bug #1287661 - CVE-2015-8389 mingw-pcre: pcre: Infinite recursion in JIT compiler when processing certain patterns [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287661 [ 8 ] Bug #1287656 - CVE-2015-8388 mingw-pcre: pcre: Buffer overflow caused by certain patterns with an unmatched closing parenthesis [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287656 [ 9 ] Bug #1287648 - CVE-2015-8387 mingw-pcre: pcre: Integer overflow in subroutine calls [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287648 [ 10 ] Bug #1287640 - CVE-2015-8386 mingw-pcre: pcre: Buffer overflow caused by lookbehind assertion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287640 [ 11 ] Bug #1287631 - CVE-2015-8385 mingw-pcre: pcre: Buffer overflow caused by forward reference by name to certain group [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287631 [ 12 ] Bug #1287626 - CVE-2015-8384 mingw-pcre: pcre: Buffer overflow caused by recursive back reference by name within certain group [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287626 [ 13 ] Bug #1287616 - CVE-2015-8383 mingw-pcre: pcre: Buffer overflow caused by repeated conditional group [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1287616 [ 14 ] Bug #1256453 - mingw-pcre: pcre: Heap Overflow in compile_regex() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1256453 [ 15 ] Bug #1250947 - mingw-pcre: pcre: heap buffer overflow with a crafted regular expression [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1250947 [ 16 ] Bug #1249905 - mingw-pcre: php: Regular Expression Uninitialized Pointer Information Disclosure Vulnerability (ZDI-CAN-2547) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1249905 [ 17 ] Bug #1237225 - CVE-2015-5073 mingw-pcre: pcre: heap buffer overflow in find_fixedlength() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1237225 [ 18 ] Bug #1236660 - CVE-2015-3210 mingw-pcre: pcre: heap buffer overflow in pcre_compile2() / compile_regex() [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1236660 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mingw-pcre' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Upgrade to version 8.38 for mingw-pcre in Fedora 23 to enhance security protocols and fix identified vulnerabilities. Discover additional information here.. Fedora Security Update,Mingw-Pcre Fix,Buffer Overflow Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 17, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here