Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
It was discovered that the HAProxy load balancing reverse proxy incorrectly handled URI components containing the hash character ( CVE-2023-45539 ). This vulnerability is very straightforward for a remote attacker to exploit and severely threatens impacted users’ sensitive information, making it among the worst bugs we’ve seen in a while! . How Do These Vulnerabilities Affect Linux Systems & What Can You Do to Stay Safe? With over 44% of the proxy server market share, this flaw has a widespread impact on Linux users’ security. A remote attacker could easily exploit this bug to steal impacted users’ sensitive data. An important HAProxy update has been released to mitigate this severe bug. Given this vulnerability's damaging repercussions on impacted systems, if left unpatched, we urge all affected users to apply the updates issued by Debian , Debian LTS , SUSE , and Ubuntu immediately to protect against data leakage. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on X for real-time updates on advisories for your distro(s) . . Remain informed about the HAProxy vulnerability and protect confidential information by implementing essential updates for improved security.. HAProxy Exploit, Linux Security Updates, Remote Data Theft. . Brittany Day
Eleven severe vulnerabilities have been found in Chromium, including multiple Type Confusion bugs in V8, use-after-frees in Cast, Blink Task Scheduling and WebRTC, a heap buffer overflow in Visuals, out-of-bounds read and write in WebGL, out-of-bounds memory access in ANGLE, and insufficient data validation and inappropriate implementation in Extensions. These bugs have received a National Vulnerability Database severity rating of “High” due to their ease of exploitation and the significant threat they pose to impacted systems' confidentiality, integrity, and availability. . These issues have allowed a remote attacker to potentially exploit heap corruption and perform arbitrary read/write via a crafted HTML page. They also enabled an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. Important updates have been released for Chromium that fix these dangerous flaws. We urge all impacted users to apply the updates issued by Debian , Fedora and openSUSE to protect against potential security threats. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical vulnerabilities in Chromium jeopardize platforms to distant attacks and memory corruption. Ensure updates are applied to safeguard against risks.. Chromium Flaws, High Severity Advisory, Remote Exploits, Security Update. . Brittany Day
Three important vulnerabilities were discovered in Chromium, including a type confusion in V8 (CVE-2023-3420) and use after frees in Media (CVE-2023-3421) and Guest View (CVE-2023-3422). With a low attack complexity and a high confidentiality, integrity and availability impact, these flaws have received a National Vulnerability Database severity rating of 8.8 out of 10 (“High” severity). . These bugs could allow a remote attacker to potentially exploit heap corruption via a crafted HTML page. An update is available for Chromium that fixes these severe issues. We strongly recommend that all impacted users apply the Chromium updates issued by their distro(s) now to protect against attacks leading to potential system downtime and compromise. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Malicious entities may take advantage of critical vulnerabilities in Chromium through specially designed HTML content. Ensure you update without delay.. Chromium Exploit Issues, Remote Exploitation, High Severity Vulnerability. . Brittany Day
Four critical security vulnerabilities have been discovered in Chromium, including use after free bugs in Autofill payments, WebRTC and WebXR, and a type confusion flaw in V8. . These issues could allow a remote attacker to exploit heap corruption via a crafted HTML page. An important update for Chromium that fixes these severe vulnerabilities is now available. We strongly encourage all impacted users to apply the Chromium updates issued by their distro(s) as soon as possible to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Four significant security flaws in Chromium have been patched, which could enable malicious actors to trigger heap corruption through specially designed web pages.. Chromium Updates, Heap Corruption Threat, Type Confusion Issue, Remote Exploit Fixes, Critical Security Patch. . Brittany Day
Fourteen important vulnerabilities have been discovered in Chromium, including multiple use-after-free and type confusion bugs. With a low attack complexity and a high confidentiality, integrity and availability impact, these issues have received a National Vulnerability Database severity rating of “High”. . These vulnerabilities could allow a remote attacker to potentially exploit heap corruption via a crafted PDF file or a crafted HTML page. An update for Chromium that fixes these severe vulnerabilities has been released. We strongly recommend that all impacted users apply the Chromium updates issued by their distro(s) now to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical vulnerabilities in chromium could enable attackers to execute remote heap corruption through specially designed files. Update is advised.. Chromium Bugs, Security Enhancements, High-Severity Issues, Open Source Security. . Brittany Day
It was discovered that Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1 incorrectly handled uploading multiple files using one form field (CVE-2023-31047). With a low attack complexity, no privileges required to exploit, and a high confidentiality, integrity and availability impact, this vulnerability has been rated as “Critical” by the National Vulnerability Database (NVD). . A remote attacker could possibly use this issue to bypass certain validations, potentially leading to the compromise of confidential information and loss of access to critical systems. An important update for Django that fixes this bug has been released. We strongly recommend that all impacted users apply the Django updates issued by their distro(s) as soon as possible to protect the confidentiality, integrity and availability of their systems. To stay on top of important updates released by the open-source programs and applications you use, be sure to register as a LinuxSecurity user , then subscribe to our Linux Advisory Watch newsletter and customize your advisories for the distro(s) you use. This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . A severe Django security issue exposed file upload weaknesses, risking remote attacks. Upgrade immediately to secure your environments!. Django Security, Remotely Exploitable Flaw, Security Update. . Brittany Day
In December network security vendor Fortinet disclosed that a critical vulnerability in its FortiOS operating system was being exploited by attackers in the wild. This week, after additional analysis, the company released more details about a sophisticated malware implant that those attackers deployed through the flaw. . Based on currently available information, the original zero-day attack was highly targeted to government-related entities. However, since the vulnerability has been known for over a month, all customers should patch it as soon as possible as more attackers could start using it. The vulnerability, tracked as CVE-2022-42475 , is in the SSL-VPN functionality of FortiOS and can be exploited by remote attackers without authentication. Successful exploitation can result in the execution of arbitrary code and commands. . A newly discovered vulnerability exploited a major weakness in Palo Alto's operating systems, jeopardizing vital network infrastructure relied upon by public sector entities.. Fortinet Security, FortiOS Vulnerability, Network Exploit, Linux Malware. . Brittany Day
Are you a RHEL user? Severe bugs in the ubiquitous SQLite engine – used in thousands of software applications – continue to pose a major security threat, security researchers say, with Red Hat admitting that its flagship Red Hat Enterprise Linux (RHEL) 8 remains vulnerable, despite patching other products this week. . Red Hat said in a security update it had now inoculated RHEL 7 and its “RHEL 8.0 Update Services for SAP Solutions”, but RHEL 8 itself remains affected by one of the vulnerabilities, first disclosed to the Chromium team by China’s Tencent Blade – which dubbed them “Magellan 2.0” – in October 2019. The vulnerability in question, CVE-2019-13734 , was reported by Tencent Blade in early December as one of a series of exploitable holes in the SQLite engine. It is described as “out of bounds write in SQLite… [that] allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.” The link for this article located at CBR Online is no longer available. . RHEL 8 continues to face vulnerabilities linked to severe SQLite issues, even after patches were applied to other software that impact its overall security.. RHEL 8 Security Threat, SQLite Bugs, Remote Exploit Risks. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.