Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 21 articles for you...
210

HAProxy: Critical Risk Advisory - Remote Data Leak Threat

It was discovered that the HAProxy load balancing reverse proxy incorrectly handled URI components containing the hash character ( CVE-2023-45539 ). This vulnerability is very straightforward for a remote attacker to exploit and severely threatens impacted users’ sensitive information, making it among the worst bugs we’ve seen in a while! . How Do These Vulnerabilities Affect Linux Systems & What Can You Do to Stay Safe? With over 44% of the proxy server market share, this flaw has a widespread impact on Linux users’ security. A remote attacker could easily exploit this bug to steal impacted users’ sensitive data. An important HAProxy update has been released to mitigate this severe bug. Given this vulnerability's damaging repercussions on impacted systems, if left unpatched, we urge all affected users to apply the updates issued by Debian , Debian LTS , SUSE , and Ubuntu immediately to protect against data leakage. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on X for real-time updates on advisories for your distro(s) . . Remain informed about the HAProxy vulnerability and protect confidential information by implementing essential updates for improved security.. HAProxy Exploit, Linux Security Updates, Remote Data Theft. . Brittany Day

Calendar%202 Dec 31, 2023 User Avatar Brittany Day Security Vulnerabilities
210

Ubuntu, Arch, Manjaro: Critical Firefox Vulnerabilities Resolved

Eleven severe vulnerabilities have been found in Chromium, including multiple Type Confusion bugs in V8, use-after-frees in Cast, Blink Task Scheduling and WebRTC, a heap buffer overflow in Visuals, out-of-bounds read and write in WebGL, out-of-bounds memory access in ANGLE, and insufficient data validation and inappropriate implementation in Extensions. These bugs have received a National Vulnerability Database severity rating of “High” due to their ease of exploitation and the significant threat they pose to impacted systems' confidentiality, integrity, and availability. . These issues have allowed a remote attacker to potentially exploit heap corruption and perform arbitrary read/write via a crafted HTML page. They also enabled an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. Important updates have been released for Chromium that fix these dangerous flaws. We urge all impacted users to apply the updates issued by Debian , Fedora and openSUSE to protect against potential security threats. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical vulnerabilities in Chromium jeopardize platforms to distant attacks and memory corruption. Ensure updates are applied to safeguard against risks.. Chromium Flaws, High Severity Advisory, Remote Exploits, Security Update. . Brittany Day

Calendar%202 Aug 09, 2023 User Avatar Brittany Day Security Vulnerabilities
210

Chromium Remotely Exploitable High Severity Flaws Fixed

Three important vulnerabilities were discovered in Chromium, including a type confusion in V8 (CVE-2023-3420) and use after frees in Media (CVE-2023-3421) and Guest View (CVE-2023-3422). With a low attack complexity and a high confidentiality, integrity and availability impact, these flaws have received a National Vulnerability Database severity rating of 8.8 out of 10 (“High” severity). . These bugs could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. An update is available for Chromium that fixes these severe issues. We strongly recommend that all impacted users apply the Chromium updates issued by their distro(s) now to protect against attacks leading to potential system downtime and compromise. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Malicious entities may take advantage of critical vulnerabilities in Chromium through specially designed HTML content. Ensure you update without delay.. Chromium Exploit Issues, Remote Exploitation, High Severity Vulnerability. . Brittany Day

Calendar%202 Jul 06, 2023 User Avatar Brittany Day Security Vulnerabilities
210

Debian: Critical Advisory for Chromium Heap Corruption Fix

Four critical security vulnerabilities have been discovered in Chromium, including use after free bugs in Autofill payments, WebRTC and WebXR, and a type confusion flaw in V8. . These issues could allow a remote attacker to exploit heap corruption via a crafted HTML page. An important update for Chromium that fixes these severe vulnerabilities is now available. We strongly encourage all impacted users to apply the Chromium updates issued by their distro(s) as soon as possible to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Four significant security flaws in Chromium have been patched, which could enable malicious actors to trigger heap corruption through specially designed web pages.. Chromium Updates, Heap Corruption Threat, Type Confusion Issue, Remote Exploit Fixes, Critical Security Patch. . Brittany Day

Calendar%202 Jun 27, 2023 User Avatar Brittany Day Security Vulnerabilities
210

Chromium: 14 Critical Issues Fixed - High Severity Exploits

Fourteen important vulnerabilities have been discovered in Chromium, including multiple use-after-free and type confusion bugs. With a low attack complexity and a high confidentiality, integrity and availability impact, these issues have received a National Vulnerability Database severity rating of “High”. . These vulnerabilities could allow a remote attacker to potentially exploit heap corruption via a crafted PDF file or a crafted HTML page. An update for Chromium that fixes these severe vulnerabilities has been released. We strongly recommend that all impacted users apply the Chromium updates issued by their distro(s) now to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical vulnerabilities in chromium could enable attackers to execute remote heap corruption through specially designed files. Update is advised.. Chromium Bugs, Security Enhancements, High-Severity Issues, Open Source Security. . Brittany Day

Calendar%202 Jun 22, 2023 User Avatar Brittany Day Security Vulnerabilities
210

Django 3.2: Critical Advisory for Remote Exploit Risk - CVE-2023-31047

It was discovered that Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1 incorrectly handled uploading multiple files using one form field (CVE-2023-31047). With a low attack complexity, no privileges required to exploit, and a high confidentiality, integrity and availability impact, this vulnerability has been rated as “Critical” by the National Vulnerability Database (NVD). . A remote attacker could possibly use this issue to bypass certain validations, potentially leading to the compromise of confidential information and loss of access to critical systems. An important update for Django that fixes this bug has been released. We strongly recommend that all impacted users apply the Django updates issued by their distro(s) as soon as possible to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . A severe Django security issue exposed file upload weaknesses, risking remote attacks. Upgrade immediately to secure your environments!. Django Security, Remotely Exploitable Flaw, Security Update. . Brittany Day

Calendar%202 Jun 01, 2023 User Avatar Brittany Day Security Vulnerabilities
74

Fortinet: Critical Advisory - FortiOS Remote Exploit By Attackers

In December network security vendor Fortinet disclosed that a critical vulnerability in its FortiOS operating system was being exploited by attackers in the wild. This week, after additional analysis, the company released more details about a sophisticated malware implant that those attackers deployed through the flaw. . Based on currently available information, the original zero-day attack was highly targeted to government-related entities. However, since the vulnerability has been known for over a month, all customers should patch it as soon as possible as more attackers could start using it. The vulnerability, tracked as CVE-2022-42475 , is in the SSL-VPN functionality of FortiOS and can be exploited by remote attackers without authentication. Successful exploitation can result in the execution of arbitrary code and commands. . A newly discovered vulnerability exploited a major weakness in Palo Alto's operating systems, jeopardizing vital network infrastructure relied upon by public sector entities.. Fortinet Security, FortiOS Vulnerability, Network Exploit, Linux Malware. . Brittany Day

Calendar%202 Jan 17, 2023 User Avatar Brittany Day Network Security
210

RHEL 8: Magellan 2 Security Risk And Ongoing SQLite Issues

Are you a RHEL user? Severe bugs in the ubiquitous SQLite engine – used in thousands of software applications – continue to pose a major security threat, security researchers say, with Red Hat admitting that its flagship Red Hat Enterprise Linux (RHEL) 8 remains vulnerable, despite patching other products this week. . Red Hat said in a security update it had now inoculated RHEL 7 and its “RHEL 8.0 Update Services for SAP Solutions”, but RHEL 8 itself remains affected by one of the vulnerabilities, first disclosed to the Chromium team by China’s Tencent Blade – which dubbed them “Magellan 2.0” – in October 2019. The vulnerability in question, CVE-2019-13734 , was reported by Tencent Blade in early December as one of a series of exploitable holes in the SQLite engine. It is described as “out of bounds write in SQLite… [that] allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.” The link for this article located at CBR Online is no longer available. . RHEL 8 continues to face vulnerabilities linked to severe SQLite issues, even after patches were applied to other software that impact its overall security.. RHEL 8 Security Threat, SQLite Bugs, Remote Exploit Risks. . Brittany Day

Calendar%202 Jan 28, 2020 User Avatar Brittany Day Security Vulnerabilities
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200