Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga. CVE-2024-38866 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4233-1
Template injection that can lead to XSS has been fixed in node-send, a Node.js module for streaming files over HTTP. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4224-1
An update that solves one vulnerability can now be installed.. # Security update for rabbitmq-server Announcement ID: SUSE-SU-2025:1466-1 Release Date: 2025-05-06T06:06:40Z Rating: moderate References: * bsc#1240071 Cross-References: * CVE-2025-30219 CVSS scores: * CVE-2025-30219 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-30219 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L * CVE-2025-30219 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:L Affected Products: * openSUSE Leap 15.3 * openSUSE Leap 15.6 * Server Applications Module 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for rabbitmq-server fixes the following issues: * CVE-2025-30219: Fixed XSS in an error message in Management UI (bsc#1240071) Other fixes: \- Disable parallel make, this causes build failures ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2025-1466=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1466=1 * Server Applications Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP6-2025-1466=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 * Server Applications Module 15-SP6 (aarch64 ppc64les390x x86_64) * rabbitmq-server-plugins-3.8.11-150300.3.19.1 * erlang-rabbitmq-client-3.8.11-150300.3.19.1 * rabbitmq-server-3.8.11-150300.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2025-30219.html * https://bugzilla.suse.com/show_bug.cgi?id=1240071 . An important patch for rabbitmq-server on openSUSE fixes a severe XSS vulnerability, enhancing the safety of user experiences.. openSUSE, security update, rabbitmq-server, xss fix, patch instructions. . LinuxSecurity.com Team
Unretireing the package.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-d611c8d114 2025-04-17 19:46:50.126382+00:00 -------------------------------------------------------------------------------- Name : workrave Product : Fedora 41 Version : 1.11.0~rc.1 Release : 1.fc41 URL : https://workrave.org/ Summary : Program that assists in the recovery and prevention of RSI Description : Workrave is a program that assists in the recovery and prevention of Repetitive Strain Injury (RSI). The program frequently alerts you to take micro-pauses, rest breaks and restricts you to your daily limit. -------------------------------------------------------------------------------- Update Information: Unretireing the package. -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 8 2025 Åukasz WojniÅowicz - 1.11.0~rc.1-1 - Unretirement import (fedora#2351398). -------------------------------------------------------------------------------- References: [ 1 ] Bug #2322802 - GNOME applet incompatible with GNOME 47 https://bugzilla.redhat.com/show_bug.cgi?id=2322802 [ 2 ] Bug #2328917 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2328917 [ 3 ] Bug #2328918 - CVE-2023-2142 workrave: Nunjucks autoescape bypass leads to cross site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2328918 [ 4 ] Bug #2351398 - Review Request: workrave - Program that assists in the recovery and prevention of RSI https://bugzilla.redhat.com/show_bug.cgi?id=2351398 [ 5 ] Bug #2358210 - F42FailsToInstall: workrave https://bugzilla.redhat.com/show_bug.cgi?id=2358210 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2025-d611c8d114' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- . Ubuntu 23.10 maintainer patch addresses privilege escalation vulnerability, crucial for system security.. Fedora 41 Update, workrave, security advisory, autoescape bypass, XSS risk. . Severity: Critical. LinuxSecurity.com Team
An XSS vulnerability was discovered in Horde IMP, the webmail component of the Horde groupware platform. An attacker could hijack a user session by sending a crafted e-mail to an IMP user. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4113-1
Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-2cb3145f8d 2024-12-25 01:50:07.031361+00:00 -------------------------------------------------------------------------------- Name : tomcat Product : Fedora 41 Version : 9.0.98 Release : 1.fc41 URL : http://tomcat.apache.org/ Summary : Apache Servlet/JSP Engine, RI for Servlet 4.0/JSP 2.3 API Description : Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. -------------------------------------------------------------------------------- Update Information: Automatic update for tomcat-9.0.98-1.fc41. Changelog for tomcat * Mon Dec 09 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168 * Mon Dec 02 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 Automatic update for tomcat-9.0.97-1.fc41. Changelog for tomcat * Mon Dec 02 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 9 2024 Packit - 1:9.0.98-1 - Update to version 9.0.98 - Resolves: rhbz#2331168 * Mon Dec 2 2024 Dimitris Soumis - 1:9.0.97-1 - Update to version 9.0.97 - Resolves: rhbz#2327090 -------------------------------------------------------------------------------- References: [ 1] Bug #2327090 - CVE-2024-52318 tomcat: incorrect JSP tag recycling leads to XSS [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2327090 [ 2 ] Bug #2331168 - tomcat-9.0.98 is available https://bugzilla.redhat.com/show_bug.cgi?id=2331168 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-2cb3145f8d' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was discovered that there was a potential XSS vulnerability in php-horde-mime-viewer, a MIME viewer library for the Horde groupware platform. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3924-1
Update to 2.46.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-92d80d7f9a 2024-10-10 00:15:44.893528 -------------------------------------------------------------------------------- Name : webkit2gtk4.0 Product : Fedora 41 Version : 2.46.1 Release : 2.fc41 URL : https://www.webkitgtk.org/ Summary : WebKitGTK for GTK 3 and libsoup 2 Description : WebKitGTK is the port of the WebKit web rendering engine to the GTK platform. This package contains WebKitGTK for GTK 3 and libsoup 2. -------------------------------------------------------------------------------- Update Information: Update to 2.46.1 -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 3 2024 Michael Catanzaro - 2.46.1-2 - Add patch to fix build with LLVM 19 * Tue Oct 1 2024 Pete Walter - 2.46.1-1 - Update to 2.46.1 * Tue Oct 1 2024 Pete Walter - 2.46.0-2 - Add missing sysprof-capture-4 BuildRequires * Wed Sep 18 2024 Pete Walter - 2.46.0-1 - Update to 2.46.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2314731 - CVE-2024-44187 webkit2gtk4.0: A malicious website may exfiltrate data cross-origin [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314731 [ 2 ] Bug #2314733 - CVE-2024-40857 webkit2gtk4.0: Processing maliciously crafted web content may lead to universal cross site scripting [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314733 [ 3 ] Bug #2314743 - CVE-2024-27851 webkit2gtk4.0: Processing maliciously crafted web content may lead to arbitrary code execution [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314743 [ 4 ] Bug #2314747 - CVE-2024-23271 webkit2gtk4.0: A malicious website may cause unexpected cross-origin behavior [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314747 [ 5 ] Bug #2314749 -CVE-2024-27838 webkit2gtk4.0: A maliciously crafted webpage may be able to fingerprint the user [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314749 [ 6 ] Bug #2314752 - CVE-2024-27833 webkit2gtk4.0: Processing maliciously crafted web content may lead to arbitrary code execution [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2314752 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-92d80d7f9a' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.