-
Stay Vigilant with Timely Linux Security Advisories
Apr 9, 2026 | 20:34 pm
Jeremy Brown discovered a flaw in the GSSAPI Key Exchange patch applied in Debian to OpenSSH, an implementation of the SSH protocol suite, affecting non-default configurations with the GSSAPIKeyExchange setting enabled. A remote attacker can take advantage of this flaw[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 8, 2026 | 18:35 pm
Quang Luong discovered a heap overflow in the libtiff library, which may result in denial of service or the execution of arbitrary code if malformed image files are processed. For the oldstable distribution (bookworm), this problem has been fixed in[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 8, 2026 | 18:34 pm
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code. For the oldstable distribution (bookworm), these problems have been fixed in version 140.9.1esr-1~deb12u1.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 7, 2026 | 21:17 pm
Multiple vulnerabilities have been discovered in OpenSSL, a Secure Sockets Layer toolkit, which may result in denial of service, information leaks, or potentially remote code execution. Additional details can be found in the upstream advisory: https://openssl-library.org/news/secadv/20260407.txt
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 6, 2026 | 21:19 pm
The Bookworm backport of the security fix for CVE-2025-59032 introduced a regression in authenticating against managesieved. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u3. We recommend that you upgrade your dovecot packages.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 5, 2026 | 20:58 pm
Two security vulnerabilities (TROVE-2026-004 and TROVE-2025-015) were discovered in Tor, a connection-based low-latency anonymous communication system, which could result in denial of service. For the oldstable distribution (bookworm), this problem has been fixed in version 0.4.9.6-0+deb12u1.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 5, 2026 | 20:47 pm
Two vulnerabilities were discovered in Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service or HTTP request smuggling. For the oldstable distribution (bookworm), these problems have been fixed in version 9.2.5+ds-0+deb12u4.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 5, 2026 | 16:39 pm
Two security vulnerabilities were discovered in Valkey, a persistent key-value database with network interface, which could result in denial of service or data manipulation. For the stable distribution (trixie), these problems have been fixed in version 8.1.1+dfsg1-3+deb13u2.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 5, 2026 | 15:22 pm
Multiple vulnerabilities have been discovered in the Dovecot IMAP server which way result in denial of service, SQL injection, path traversal, replay attacks or timing side channel attacks. For the oldstable distribution (bookworm), these problems have been fixed in version[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 4, 2026 | 19:53 pm
Multiple vulnerabilities were discovered in roundcube, a skinnable AJAX based webmail solution for IMAP servers, which could result in information disclosure, IMAP injection, CSRF bypass, bypass of remote image blocking, cross-site scripting, access control bypass, or privilege escalation.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 3, 2026 | 21:38 pm
Multiple security vulnerabilities were discovered in the Tornado Python web framework, which could result in denial of service, header injection or cross-site scripting. For the oldstable distribution (bookworm), this problem has been fixed in version 6.2.0-3+deb12u4.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 3, 2026 | 13:15 pm
It was discovered that pyasn1, a generic ASN.1 library for Python, is prone to a denial of service vulnerability when decoding ASN.1 data with deeply nested structures. For the oldstable distribution (bookworm), this problem has been fixed in version 0.4.8-3+deb12u2.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 3, 2026 | 12:49 pm
Several vulnerabilities were discovered in the inetutils implementation of telnetd and telnet, which may result in privilege escalation or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 2:2.4-2+deb12u3.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 3, 2026 | 00:39 am
Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure. For the oldstable distribution (bookworm), these problems have been fixed in version 146.0.7680.177-1~deb12u1.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 1, 2026 | 20:21 pm
Multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the oldstable[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Apr 1, 2026 | 20:19 pm
Multiple multiple vulnerabilities were discovered in plugins for the GStreamer media framework and its codecs and demuxers, which may result in denial of service or potentially the execution of arbitrary code if a malformed media file is opened. For the[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Mar 31, 2026 | 21:15 pm
Two security vulnerabilities were discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (bookworm),[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Mar 31, 2026 | 20:52 pm
Multiple security issues were discovered in LXD, a system container and virtual machine manager, which could result in privilege escalation or the execution of arbitrary commands. For the oldstable distribution (bookworm), these problems have been fixed in version 5.0.2-5+deb12u4.
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Mar 29, 2026 | 19:07 pm
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 3.0.19-1+deb12u4. This update also fixes CVE-2023-52892. For[…]
Read more...
-
Stay Vigilant with Timely Linux Security Advisories
Mar 29, 2026 | 19:02 pm
It was discovered that the AES-CBC implementation in the PHP Secure Communications Library was susceptible to a padding oracle timing attack. For the oldstable distribution (bookworm), these problems have been fixed in version 2.0.42-1+deb12u3. This update also fixes CVE-2023-52892. For[…]
Read more...