Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The package chromium before version 96.0.4664.45-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing, information disclosure, same-origin policy bypass, sandbox escape and denial of service. . Arch Linux Security Advisory ASA-202111-9 ======================================== Severity: High Date : 2021-11-18 CVE-ID : CVE-2021-38005 CVE-2021-38006 CVE-2021-38007 CVE-2021-38008 CVE-2021-38009 CVE-2021-38010 CVE-2021-38011 CVE-2021-38012 CVE-2021-38013 CVE-2021-38014 CVE-2021-38015 CVE-2021-38016 CVE-2021-38017 CVE-2021-38018 CVE-2021-38019 CVE-2021-38020 CVE-2021-38021 CVE-2021-38022 Package : chromium Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2560 Summary ====== The package chromium before version 96.0.4664.45-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, content spoofing, information disclosure, same-origin policy bypass, sandbox escape and denial of service. Resolution ========= Upgrade to 96.0.4664.45-1. # pacman -Syu "chromium> =96.0.4664.45-1" The problems have been fixed upstream in version 96.0.4664.45. Workaround ========= None. Description ========== - CVE-2021-38005 (arbitrary code execution) A use after free security issue has been found in the loader component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38006 (arbitrary code execution) A use after free security issue has been found in the storage foundation component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38007 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38008 (arbitrary code execution) A use after free security issue has been found in the media component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38009 (arbitrary code execution) Aninappropriate implementation security issue has been found in the cache component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38010 (arbitrary code execution) An inappropriate implementation security issue has been found in the service workers component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38011 (arbitrary code execution) A use after free security issue has been found in the storage foundation component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38012 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38013 (arbitrary code execution) A heap buffer overflow security issue has been found in the fingerprint recognition component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38014 (arbitrary code execution) An out of bounds write security issue has been found in the Swiftshader component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38015 (arbitrary code execution) An inappropriate implementation security issue has been found in the input component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38016 (access restriction bypass) An insufficient policy enforcement security issue has been found in the background fetch component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38017 (sandbox escape) An insufficient policy enforcement security issue has been found in the iframe sandbox component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38018 (content spoofing) An inappropriate implementation security issue has been found in the navigation component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38019 (same-origin policy bypass) An insufficient policy enforcement security issue has been found in the CORS component of the Chromium browser engine beforeversion 96.0.4664.45. - CVE-2021-38020 (information disclosure) An insufficient policy enforcement security issue has been found in the contacts picker component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38021 (information disclosure) An inappropriate implementation security issue has been found in the referrer component of the Chromium browser engine before version 96.0.4664.45. - CVE-2021-38022 (denial of service) An inappropriate implementation security issue has been found in the WebAuthentication component of the Chromium browser engine before version 96.0.4664.45. Impact ===== A remote attacker could execute arbitrary code, spoof content, bypass security restrictions or crash the browser through crafted web content. References ========= https://chromereleases.googleblog.com/2021/11/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2021-38005 https://security.archlinux.org/CVE-2021-38006 https://security.archlinux.org/CVE-2021-38007 https://security.archlinux.org/CVE-2021-38008 https://security.archlinux.org/CVE-2021-38009 https://security.archlinux.org/CVE-2021-38010 https://security.archlinux.org/CVE-2021-38011 https://security.archlinux.org/CVE-2021-38012 https://security.archlinux.org/CVE-2021-38013 https://security.archlinux.org/CVE-2021-38014 https://security.archlinux.org/CVE-2021-38015 https://security.archlinux.org/CVE-2021-38016 https://security.archlinux.org/CVE-2021-38017 https://security.archlinux.org/CVE-2021-38018 https://security.archlinux.org/CVE-2021-38019 https://security.archlinux.org/CVE-2021-38020 https://security.archlinux.org/CVE-2021-38021 https://security.archlinux.org/CVE-2021-38022 . Critical vulnerabilities identified in Chromium prior to version 96.0.4664.45-1 on Arch Linux necessitate immediate updates to safeguard users.. Arch Linux Security Advisory, Chromium Update Issues, High Severity Vulnerabilities. . LinuxSecurity.com Team
The package opera before version 78.0.4093.112-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, incorrect calculation, information disclosure and insufficient validation. . Arch Linux Security Advisory ASA-202108-5 ======================================== Severity: High Date : 2021-08-10 CVE-ID : CVE-2021-30565 CVE-2021-30566 CVE-2021-30567 CVE-2021-30568 CVE-2021-30569 CVE-2021-30571 CVE-2021-30572 CVE-2021-30573 CVE-2021-30574 CVE-2021-30575 CVE-2021-30576 CVE-2021-30578 CVE-2021-30579 CVE-2021-30581 CVE-2021-30582 CVE-2021-30584 CVE-2021-30585 CVE-2021-30588 CVE-2021-30589 Package : opera Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2203 Summary ====== The package opera before version 78.0.4093.112-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution, content spoofing, incorrect calculation, information disclosure and insufficient validation. Resolution ========= Upgrade to 78.0.4093.112-1. # pacman -Syu "opera> =78.0.4093.112-1" The problems have been fixed upstream in version 78.0.4093.112. Workaround ========= None. Description ========== - CVE-2021-30565 (arbitrary code execution) An out of bounds write security issue has been found in the Tab Groups component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30566 (arbitrary code execution) A stack buffer overflow security issue has been found in the Printing component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30567 (arbitrary code execution) A use after free security issue has been found in the DevTools component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30568 (arbitrary code execution) A heap buffer overflow security issue has been found in the WebGL component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30569 (arbitrary codeexecution) A use after free security issue has been found in the sqlite component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30571 (access restriction bypass) An insufficient policy enforcement security issue has been found in the DevTools component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30572 (arbitrary code execution) A use after free security issue has been found in the Autofill component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30573 (arbitrary code execution) A use after free security issue has been found in the GPU component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30574 (arbitrary code execution) A use after free security issue has been found in the protocol handling component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30575 (information disclosure) An out of bounds read security issue has been found in the Autofill component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30576 (arbitrary code execution) A use after free security issue has been found in the DevTools component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30578 (arbitrary code execution) An uninitialized use security issue has been found in the Media component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30579 (arbitrary code execution) A use after free security issue has been found in the UI framework component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30581 (arbitrary code execution) A use after free security issue has been found in the DevTools component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30582 (incorrect calculation) An inappropriate implementation security issue has been found in the Animation component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30584 (content spoofing) An incorrect securityUI security issue has been found in the Downloads component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30585 (arbitrary code execution) A use after free security issue has been found in the sensor handling component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30588 (incorrect calculation) A type confusion security issue has been found in the V8 component of the Chromium browser engine before version 92.0.4515.107. - CVE-2021-30589 (insufficient validation) An insufficient validation of untrusted input security issue has been found in the Sharing component of the Chromium browser engine before version 92.0.4515.107. Impact ===== A remote attacker could execute arbitrary code or spoof content through a crafted web page. References ========= https://blogs.opera.com/desktop/changelog-for-77/ https://blogs.opera.com/desktop/changelog-for-78/ https://chromereleases.googleblog.com/2021/07/stable-channel-update-for-desktop_20.html https://security.archlinux.org/CVE-2021-30565 https://security.archlinux.org/CVE-2021-30566 https://security.archlinux.org/CVE-2021-30567 https://security.archlinux.org/CVE-2021-30568 https://security.archlinux.org/CVE-2021-30569 https://security.archlinux.org/CVE-2021-30571 https://security.archlinux.org/CVE-2021-30572 https://security.archlinux.org/CVE-2021-30573 https://security.archlinux.org/CVE-2021-30574 https://security.archlinux.org/CVE-2021-30575 https://security.archlinux.org/CVE-2021-30576 https://security.archlinux.org/CVE-2021-30578 https://security.archlinux.org/CVE-2021-30579 https://security.archlinux.org/CVE-2021-30581 https://security.archlinux.org/CVE-2021-30582 https://security.archlinux.org/CVE-2021-30584 https://security.archlinux.org/CVE-2021-30585 https://security.archlinux.org/CVE-2021-30588 https://security.archlinux.org/CVE-2021-30589 . Enhance Firefox to the latest edition 110.0.1-1 on Arch Linux to address critical vulnerabilities.. Arch Linux Security Advisory, Opera Multiple Issues, Upgrade Opera.. LinuxSecurity.com Team
The package wpewebkit before version 2.32.3-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site scripting and information disclosure. . Arch Linux Security Advisory ASA-202107-68 ========================================= Severity: High Date : 2021-07-27 CVE-ID : CVE-2021-21775 CVE-2021-21779 CVE-2021-30663 CVE-2021-30665 CVE-2021-30689 CVE-2021-30720 CVE-2021-30734 CVE-2021-30744 CVE-2021-30749 CVE-2021-30795 CVE-2021-30797 CVE-2021-30799 Package : wpewebkit Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2221 Summary ====== The package wpewebkit before version 2.32.3-1 is vulnerable to multiple issues including arbitrary code execution, access restriction bypass, cross-site scripting and information disclosure. Resolution ========= Upgrade to 2.32.3-1. # pacman -Syu "wpewebkit> =2.32.3-1" The problems have been fixed upstream in version 2.32.3. Workaround ========= None. Description ========== - CVE-2021-21775 (information disclosure) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of WebKit. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim must be tricked into visiting a malicious webpage. - CVE-2021-21779 (information disclosure) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. A use-after-free vulnerability exists in the way that WebKit GraphicsContext handles certain events. A specially crafted web page can lead to a potential information leak and further memory corruption. A victim must be tricked into visiting a malicious web page to trigger this vulnerability. - CVE-2021-30663 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content maylead to arbitrary code execution. - CVE-2021-30665 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. - CVE-2021-30689 (cross-site scripting) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to universal cross site scripting. - CVE-2021-30720 (access restriction bypass) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. A malicious website may be able to access restricted ports on arbitrary servers. - CVE-2021-30734 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to arbitrary code execution. - CVE-2021-30744 (cross-site scripting) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to universal cross site scripting. - CVE-2021-30749 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to arbitrary code execution. - CVE-2021-30795 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to arbitrary code execution. - CVE-2021-30797 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to code execution. - CVE-2021-30799 (arbitrary code execution) A security issue has been found in WebKitGTK and WPE WebKit before 2.32.3. Processing maliciously crafted web content may lead to arbitrary code execution. Impact ===== A remote attacker could execute arbitrary code or disclose sensitive information through crafted web content.Apple is aware of a report that one of the arbitrary code execution issues may have been actively exploited. References ========= https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-21775 https://talosintelligence.com/vulnerability_reports/TALOS-2021-1229 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-21779 https://talosintelligence.com/vulnerability_reports/TALOS-2021-1238 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30663 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30665 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30689 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30720 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30734 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30744 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30749 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30795 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30797 https://webkitgtk.org/security/WSA-2021-0004.html#CVE-2021-30799 https://security.archlinux.org/CVE-2021-21775 https://security.archlinux.org/CVE-2021-21779 https://security.archlinux.org/CVE-2021-30663 https://security.archlinux.org/CVE-2021-30665 https://security.archlinux.org/CVE-2021-30689 https://security.archlinux.org/CVE-2021-30720 https://security.archlinux.org/CVE-2021-30734 https://security.archlinux.org/CVE-2021-30744 https://security.archlinux.org/CVE-2021-30749 https://security.archlinux.org/CVE-2021-30795 https://security.archlinux.org/CVE-2021-30797 https://security.archlinux.org/CVE-2021-30799 . Debian Security Notice DSN-2023-45 highlights critical flaws in libxml2, mandating immediate attention for system integrity.. wpewebkit Issues, Code Execution Risk, Arch Linux Security, Security Advisory, Cross-Site Scripting. . LinuxSecurity.com Team
The package nextcloud before version 21.0.3-1 is vulnerable to multiple issues including authentication bypass, privilege escalation, access restriction bypass, content spoofing, cross-site scripting, incorrect calculation, information disclosure and insufficient validation. . Arch Linux Security Advisory ASA-202107-22 ========================================= Severity: High Date : 2021-07-14 CVE-ID : CVE-2021-32678 CVE-2021-32679 CVE-2021-32680 CVE-2021-32688 CVE-2021-32703 CVE-2021-32705 CVE-2021-32725 CVE-2021-32726 CVE-2021-32733 CVE-2021-32734 CVE-2021-32741 Package : nextcloud Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2144 Summary ====== The package nextcloud before version 21.0.3-1 is vulnerable to multiple issues including authentication bypass, privilege escalation, access restriction bypass, content spoofing, cross-site scripting, incorrect calculation, information disclosure and insufficient validation. Resolution ========= Upgrade to 21.0.3-1. # pacman -Syu "nextcloud> =21.0.3-1" The problems have been fixed upstream in version 21.0.3. Workaround ========= None. Description ========== - CVE-2021-32678 (insufficient validation) In Nextcloud Server versions prior to 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. - CVE-2021-32679 (content spoofing) In Nextcloud Server versions prior to 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a benign file extension. This would show in UI behaviours where Nextcloud applications would display a benign file extension (e.g. JPEG), butthe file will actually be downloaded with an executable file extension. Administrators of Nextcloud instances do not have a workaround available, but developers of Nextcloud apps may manually escape the file name before passing it into `DownloadResponse`. - CVE-2021-32680 (incorrect calculation) In Nextcloud Server versions prior to 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. - CVE-2021-32688 (privilege escalation) Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. - CVE-2021-32703 (information disclosure) In Nextcloud Server versions prior to 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. - CVE-2021-32705 (information disclosure) In Nextcloud Server versions prior to 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. - CVE-2021-32725 (access restriction bypass) In Nextcloud Server versions prior to 21.0.3, default share permissions were not being respected for federated reshares of files and folders. - CVE-2021-32726 (authentication bypass) In Nextcloud Server versions prior to 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. - CVE-2021-32733 (cross-site scripting) A cross-site scripting vulnerability is present in Nextcloud Text in versions prior to21.0.3. The Nextcloud Text application shipped with Nextcloud Server used a `text/html` Content-Type when serving files to users. Due the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content- Security-Policy. - CVE-2021-32734 (information disclosure) In Nextcloud Server versions prior to 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. As a workaround, one may disable the Nextcloud Text application in Nextcloud Server app settings. - CVE-2021-32741 (information disclosure) In Nextcloud Server versions prior to 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. Impact ===== A remote attacker could bypass authentication, escalate privileges, disclose sensitive information or spoofcontent. References ========= https://github.com/nextcloud/security-advisories/security/advisories/GHSA-48rx-3gmf-g74j https://hackerone.com/reports/1214158 https://github.com/nextcloud/server/pull/27329 https://github.com/nextcloud/server/commit/6a6bcdc558ae691b634ca23480562a0b0e45dc78 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-3hjp-26x8-mhf6 https://hackerone.com/reports/1215263 https://github.com/nextcloud/server/pull/27354 https://github.com/nextcloud/server/commit/d838108deaa90a2f2d78af4e608452fb105fcd15 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fxpq-wq7c-vppf https://hackerone.com/reports/1200810 https://github.com/nextcloud/server/pull/27024 https://github.com/nextcloud/server/commit/6300a1b84605b4674c2cee3860eaae17bdfeace7 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-48m7-7r2r-838r https://hackerone.com/reports/1193321 https://github.com/nextcloud/server/pull/27000 https://github.com/nextcloud/server/commit/e3090136b832498042778f81593c6b95fa79305c https://github.com/nextcloud/security-advisories/security/advisories/GHSA-375p-cxxq-gc9p https://hackerone.com/reports/1173684 https://github.com/nextcloud/server/pull/26945 https://github.com/nextcloud/server/commit/6bc2d6d68e19212ed83a2f3ce51ddbfcefa248ae https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fjv7-283f-5m54 https://hackerone.com/reports/1192159 https://github.com/nextcloud/server/pull/27610 https://github.com/nextcloud/server/commit/117e466e2051095bb6e9d863faf5f42a347e60a0 https://github.com/nextcloud/server/commit/ddcb70bd81e99f8bd469019f923bd335b59b04c1 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6f6v-h9x9-jj4v https://github.com/nextcloud/server/pull/26946 https://github.com/nextcloud/server/commit/7ca8fd43a6fdbebd1c931ae09a94ab072ef6773e https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6qr9-c846-j8mg https://hackerone.com/reports/1202590 https://github.com/nextcloud/server/pull/27532 https://github.com/nextcloud/server/commit/e757a5ecfdcddbddc29edf0e61ba60de1181315b https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x4w3-jhcr-57pq https://hackerone.com/reports/1241460 https://github.com/nextcloud/text/pull/1689 https://github.com/nextcloud/text/commit/e7dcbee067afe95bf13cbe49a9394b540d362e00 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6hf5-c2c4-2526 https://hackerone.com/reports/1246721 https://github.com/nextcloud/text/pull/1695 https://github.com/nextcloud/text/commit/6ea959f10039b5b1a79ca5e68eb0a5926f7ae257 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-crvj-vmf7-xrvr https://hackerone.com/reports/1192144 https://github.com/nextcloud/server/pull/26958 https://github.com/nextcloud/server/commit/1ed66f2ac17a2b4effba46a13ed735b67a1e94ba https://security.archlinux.org/CVE-2021-32678 https://security.archlinux.org/CVE-2021-32679 https://security.archlinux.org/CVE-2021-32680 https://security.archlinux.org/CVE-2021-32688 https://security.archlinux.org/CVE-2021-32703 https://security.archlinux.org/CVE-2021-32705 https://security.archlinux.org/CVE-2021-32725 https://security.archlinux.org/CVE-2021-32726 https://security.archlinux.org/CVE-2021-32733 https://security.archlinux.org/CVE-2021-32734 https://security.archlinux.org/CVE-2021-32741 . Nextcloud versions earlier than 21.0.3 on Arch Linux present various critical vulnerabilities that necessitate immediate upgrading.. Nextcloud Security, Arch Linux Advisory, Access Restriction, Authentication Bypass, Security Update. . LinuxSecurity.com Team
The package redmine before version 4.2.1-1 is vulnerable to multiple issues including arbitrary filesystem access, access restriction bypass, cross-site scripting, arbitrary file upload and information disclosure. . Arch Linux Security Advisory ASA-202105-1 ======================================== Severity: Critical Date : 2021-05-19 CVE-ID : CVE-2021-29274 CVE-2021-30163 CVE-2021-30164 CVE-2021-31863 CVE-2021-31864 CVE-2021-31865 CVE-2021-31866 Package : redmine Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1743 Summary ====== The package redmine before version 4.2.1-1 is vulnerable to multiple issues including arbitrary filesystem access, access restriction bypass, cross-site scripting, arbitrary file upload and information disclosure. Resolution ========= Upgrade to 4.2.1-1. # pacman -Syu "redmine> =4.2.1-1" The problems have been fixed upstream in version 4.2.1. Workaround ========= None. Description ========== - CVE-2021-29274 (cross-site scripting) Redmine 4.1.x before 4.1.2 allows cross-site scripting (XSS) because an issues subject is mishandled in the auto complete tip. - CVE-2021-30163 (information disclosure) Redmine before 4.1.2 allows attackers to discover the names of private projects if issue-journal details exist that have changes to project_id values. - CVE-2021-30164 (access restriction bypass) Redmine before 4.1.2 allows attackers to bypass the add_issue_notes permission requirement by leveraging the Issues API. - CVE-2021-31863 (arbitrary filesystem access) Insufficient input validation in the Git repository integration of Redmine before 4.2.1 allows Redmine users to read arbitrary local files accessible by the application server process. - CVE-2021-31864 (access restriction bypass) Redmine before 4.2.1 allows attackers to bypass the add_issue_notes permission requirement by leveraging the incoming mail handler. - CVE-2021-31865 (arbitrary file upload) Redminebefore 4.2.1 allows users to circumvent the allowed filename extensions of uploaded attachments. - CVE-2021-31866 (information disclosure) Redmine before 4.1.3 allows an attacker to learn the values of internal authentication keys by observing timing differences in string comparison operations within SysController and MailHandlerController. Impact ===== A remote attacker could disclose private information, perform actions without having the required permissions, or execute arbitrary JavaScript code by leveraging cross-site scripting. References ========= https://bugs.archlinux.org/task/70203 https://github.com/redmine/redmine/commit/bbfade972865e78e4d865af2cdb93e6cb57d5a45 https://github.com/redmine/redmine/commit/0d96c4ebdb1cceeb6cac8f940a11b5407a0a5211 https://github.com/redmine/redmine/commit/a7b9fa99966e8d59bd88548248ab11400ea48e5e https://github.com/redmine/redmine/commit/45461bfe51e9492d607f7204120f49ce3396a0cf https://github.com/redmine/redmine/commit/d03a718e6efca0493d8b42bd4ba356d736a77f49 https://github.com/redmine/redmine/commit/56979912c9bb041aac3fc5b88bf8275b743b0e28 https://github.com/redmine/redmine/commit/23e09ef64e26d6f63dcdcd624827440d9ad05f93 https://security.archlinux.org/CVE-2021-29274 https://security.archlinux.org/CVE-2021-30163 https://security.archlinux.org/CVE-2021-30164 https://security.archlinux.org/CVE-2021-31863 https://security.archlinux.org/CVE-2021-31864 https://security.archlinux.org/CVE-2021-31865 https://security.archlinux.org/CVE-2021-31866 . Debian Security Bulletin DSA-2021-02 discusses critical flaws found in mediawiki prior to version 1.35.0-1.. Redmine Security Issues, Arch Linux Advisory, Critical Redmine Threats. . Severity: Critical. LinuxSecurity.com Team
The package vivaldi before version 3.7.2218.45-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation, access restriction bypass, content spoofing, incorrect calculation and information disclosure. . Arch Linux Security Advisory ASA-202103-19 ========================================= Severity: High Date : 2021-03-25 CVE-ID : CVE-2020-27844 CVE-2021-21159 CVE-2021-21160 CVE-2021-21161 CVE-2021-21162 CVE-2021-21163 CVE-2021-21165 CVE-2021-21166 CVE-2021-21167 CVE-2021-21168 CVE-2021-21169 CVE-2021-21170 CVE-2021-21171 CVE-2021-21172 CVE-2021-21173 CVE-2021-21174 CVE-2021-21175 CVE-2021-21176 CVE-2021-21177 CVE-2021-21178 CVE-2021-21179 CVE-2021-21180 CVE-2021-21181 CVE-2021-21182 CVE-2021-21183 CVE-2021-21184 CVE-2021-21185 CVE-2021-21186 CVE-2021-21187 CVE-2021-21188 CVE-2021-21189 CVE-2021-21190 CVE-2021-21191 CVE-2021-21192 CVE-2021-21193 Package : vivaldi Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1633 Summary ====== The package vivaldi before version 3.7.2218.45-1 is vulnerable to multiple issues including arbitrary code execution, insufficient validation, access restriction bypass, content spoofing, incorrect calculation and information disclosure. Resolution ========= Upgrade to 3.7.2218.45-1. # pacman -Syu "vivaldi> =3.7.2218.45-1" The problems have been fixed upstream in version 3.7.2218.45. Workaround ========= None. Description ========== - CVE-2020-27844 (arbitrary code execution) A heap-based buffer overflow was discovered in lib/openjp2/t2.c:973 in the current master (commit 18b1138fbe3bb0ae4aa2bf1369f9430a8ec6fa00) of OpenJPEG. - CVE-2021-21159 (arbitrary code execution) A heap buffer overflow security issue was found in the TabStrip component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21160 (arbitrary code execution) A heap buffer overflow security issue was found in the WebAudio component of theChromium browser before version 89.0.4389.72. - CVE-2021-21161 (arbitrary code execution) A heap buffer overflow security issue was found in the TabStrip component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21162 (arbitrary code execution) A use after free security issue was found in the WebRTC component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21163 (insufficient validation) An insufficient data validation security issue was found in the Reader Mode component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21165 (arbitrary code execution) An object lifecycle security issue was found in the audio component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21166 (arbitrary code execution) An object lifecycle security issue was found in the audio component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21167 (arbitrary code execution) A use after free security issue was found in the bookmarks component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21168 (access restriction bypass) An insufficient policy enforcement security issue was found in the appcache component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21169 (information disclosure) An out of bounds memory access security issue was found in the V8 component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21170 (content spoofing) An incorrect security UI security issue was found in the Loader component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21171 (content spoofing) An incorrect security UI security issue was found in the TabStrip and Navigation components of the Chromium browser before version 89.0.4389.72. - CVE-2021-21172 (access restriction bypass) An insufficient policy enforcement security issue was found in the File System API component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21173 (information disclosure) A side-channel informationleakage security issue was found in the Network Internals component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21174 (incorrect calculation) An inappropriate implementation security issue was found in the Referrer component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21175 (incorrect calculation) An inappropriate implementation security issue was found in the Site isolation component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21176 (incorrect calculation) An inappropriate implementation security issue was found in the full screen mode component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21177 (access restriction bypass) An insufficient policy enforcement security issue was found in the Autofill component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21178 (incorrect calculation) An inappropriate implementation security issue was found in the Compositing component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21179 (arbitrary code execution) A use after free security issue was found in the Network Internals component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21180 (arbitrary code execution) A use after free security issue was found in the tab search component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21181 (information disclosure) A side-channel information leakage security issue was found in the autofill component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21182 (access restriction bypass) An insufficient policy enforcement security issue was found in the navigations component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21183 (incorrect calculation) An inappropriate implementation security issue was found in the performance APIs component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21184 (incorrect calculation) An inappropriate implementation security issue was found inthe performance APIs component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21185 (access restriction bypass) An insufficient policy enforcement security issue was found in the extensions component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21186 (access restriction bypass) An insufficient policy enforcement security issue was found in the QR scanning component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21187 (insufficient validation) An insufficient data validation security issue was found in the URL formatting component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21188 (arbitrary code execution) A use after free security issue was found in the Blink component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21189 (access restriction bypass) An insufficient policy enforcement security issue was found in the payments component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21190 (arbitrary code execution) An uninitialized use security issue was found in the PDFium component of the Chromium browser before version 89.0.4389.72. - CVE-2021-21191 (arbitrary code execution) A use after free security issue was found in the WebRTC component of the Chromium browser before version 89.0.4389.90. - CVE-2021-21192 (arbitrary code execution) A heap buffer overflow security issue was found in the tab groups component of the Chromium browser before version 89.0.4389.90. - CVE-2021-21193 (arbitrary code execution) A use after free security issue was found in the Blink component of the Chromium browser before version 89.0.4389.90. Google is aware of reports that an exploit for this issue exists in the wild. Impact ===== A remote attacker might be able to bypass security measures, trick the user into performing unwanted actions or execute arbitrarycode. References ========= https://vivaldi.com/blog/desktop/minor-update-2-for-vivaldi-desktop-3-6/ https://vivaldi.com/blog/vivaldi-fires-up-performance-2/ https://github.com/uclouvain/openjpeg/issues/1299 https://github.com/uclouvain/openjpeg/pull/1301 https://github.com/uclouvain/openjpeg/commit/73fdf28342e4594019af26eb6a347a34eceb6296 https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2021/03/stable-channel-update-for-desktop_12.html https://security.archlinux.org/CVE-2020-27844 https://security.archlinux.org/CVE-2021-21159 https://security.archlinux.org/CVE-2021-21160 https://security.archlinux.org/CVE-2021-21161 https://security.archlinux.org/CVE-2021-21162 https://security.archlinux.org/CVE-2021-21163 https://security.archlinux.org/CVE-2021-21165 https://security.archlinux.org/CVE-2021-21166 https://security.archlinux.org/CVE-2021-21167 https://security.archlinux.org/CVE-2021-21168 https://security.archlinux.org/CVE-2021-21169 https://security.archlinux.org/CVE-2021-21170 https://security.archlinux.org/CVE-2021-21171 https://security.archlinux.org/CVE-2021-21172 https://security.archlinux.org/CVE-2021-21173 https://security.archlinux.org/CVE-2021-21174 https://security.archlinux.org/CVE-2021-21175 https://security.archlinux.org/CVE-2021-21176 https://security.archlinux.org/CVE-2021-21177 https://security.archlinux.org/CVE-2021-21178 https://security.archlinux.org/CVE-2021-21179 https://security.archlinux.org/CVE-2021-21180 https://security.archlinux.org/CVE-2021-21181 https://security.archlinux.org/CVE-2021-21182 https://security.archlinux.org/CVE-2021-21183 https://security.archlinux.org/CVE-2021-21184 https://security.archlinux.org/CVE-2021-21185 https://security.archlinux.org/CVE-2021-21186 https://security.archlinux.org/CVE-2021-21187 https://security.archlinux.org/CVE-2021-21188 https://security.archlinux.org/CVE-2021-21189 https://security.archlinux.org/CVE-2021-21190 https://security.archlinux.org/CVE-2021-21191 https://security.archlinux.org/CVE-2021-21192 https://security.archlinux.org/CVE-2021-21193 . Critical security flaws in the Vivaldi software on Arch Linux have been identified. Update without delay to thwart potential attacks.. ArchLinux Vivaldi Remote Exploitation Security HighSeverity. . LinuxSecurity.com Team
The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation. . Arch Linux Security Advisory ASA-202004-9 ======================================== Severity: High Date : 2020-04-08 CVE-ID : CVE-2020-6423 CVE-2020-6430 CVE-2020-6431 CVE-2020-6432 CVE-2020-6433 CVE-2020-6434 CVE-2020-6435 CVE-2020-6436 CVE-2020-6437 CVE-2020-6438 CVE-2020-6439 CVE-2020-6440 CVE-2020-6441 CVE-2020-6442 CVE-2020-6443 CVE-2020-6444 CVE-2020-6445 CVE-2020-6446 CVE-2020-6447 CVE-2020-6448 CVE-2020-6454 CVE-2020-6455 CVE-2020-6456 Package : chromium Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1128 Summary ====== The package chromium before version 81.0.4044.92-1 is vulnerable to multiple issues including arbitrary code execution, information disclosure, access restriction bypass and insufficient validation. Resolution ========= Upgrade to 81.0.4044.92-1. # pacman -Syu "chromium> =81.0.4044.92-1" The problems have been fixed upstream in version 81.0.4044.92. Workaround ========= None. Description ========== - CVE-2020-6423 (arbitrary code execution) A use after free security issue has been found in the audio component of the chromium browser before 81.0.4044.92. - CVE-2020-6430 (arbitrary code execution) A type confusion security issue has been found in the V8 component of the chromium browser before 81.0.4044.92. - CVE-2020-6431 (access restriction bypass) An insufficient policy enforcement security issue has been found in the full screen component of the chromium browser before 81.0.4044.92. - CVE-2020-6432 (access restriction bypass) An insufficient policy enforcement security issue has been found in the navigations component of the chromium browser before 81.0.4044.92. - CVE-2020-6433 (access restriction bypass) An insufficient policyenforcement security issue has been found in the extensions component of the chromium browser before 81.0.4044.92. - CVE-2020-6434 (arbitrary code execution) A use-after-free security issue has been found in the devtools component of the chromium browser before 81.0.4044.92. - CVE-2020-6435 (access restriction bypass) An insufficient policy enforcement security issue has been found in the extensions component of the chromium browser before 81.0.4044.92. - CVE-2020-6436 (arbitrary code execution) A use-after-free security issue has been found in the window management component of the chromium browser before 81.0.4044.92. - CVE-2020-6437 (access restriction bypass) An inappropriate implementation security issue has been found in the WebView component of the chromium browser before 81.0.4044.92. - CVE-2020-6438 (access restriction bypass) An insufficient policy enforcement security issue has been found in the extensions component of the chromium browser before 81.0.4044.92. - CVE-2020-6439 (access restriction bypass) An insufficient policy enforcement security issue has been found in the navigations component of the chromium browser before 81.0.4044.92. - CVE-2020-6440 (access restriction bypass) An inappropriate implementation security issue has been found in the extensions component of the chromium browser before 81.0.4044.92. - CVE-2020-6441 (access restriction bypass) An insufficient policy enforcement security issue has been found in the omnibox component of the chromium browser before 81.0.4044.92. - CVE-2020-6442 (access restriction bypass) An inappropriate implementation security issue has been found in the cache component of the chromium browser before 81.0.4044.92. - CVE-2020-6443 (insufficient validation) An insufficient data validation security issue has been found in the developer tools component of the chromium browser before 81.0.4044.92. - CVE-2020-6444 (information disclosure) An uninitialized memory use issue has beenfound in the WebRTC component of the chromium browser before 81.0.4044.92. - CVE-2020-6445 (access restriction bypass) An insufficient policy enforcement security issue has been found in the trusted types component of the chromium browser before 81.0.4044.92. - CVE-2020-6446 (access restriction bypass) An insufficient policy enforcement security issue has been found in the trusted types component of the chromium browser before 81.0.4044.92. - CVE-2020-6447 (access restriction bypass) An inappropriate implementation security issue has been found in the developer tools component of the chromium browser before 81.0.4044.92. - CVE-2020-6448 (arbitrary code execution) A use-after-free security issue has been found in the V8 component of the chromium browser before 81.0.4044.92. - CVE-2020-6454 (arbitrary code execution) A use after free security issue has been found in the extensions component of the chromium browser before 81.0.4044.92. - CVE-2020-6455 (information disclosure) A out of bounds read security issue has been found in the WebSQL component of the chromium browser before 81.0.4044.92. - CVE-2020-6456 (insufficient validation) An insufficient validation of untrusted input security issue has been found in the clipboard component of the chromium browser before 81.0.4044.92. Impact ===== A remote attacker might be able to access sensitive information, bypass security measures or execute arbitrarycode. References ========= https://chromereleases.googleblog.com/2020/04/stable-channel-update-for-desktop_7.html https://security.archlinux.org/CVE-2020-6423 https://security.archlinux.org/CVE-2020-6430 https://security.archlinux.org/CVE-2020-6431 https://security.archlinux.org/CVE-2020-6432 https://security.archlinux.org/CVE-2020-6433 https://security.archlinux.org/CVE-2020-6434 https://security.archlinux.org/CVE-2020-6435 https://security.archlinux.org/CVE-2020-6436 https://security.archlinux.org/CVE-2020-6437 https://security.archlinux.org/CVE-2020-6438 https://security.archlinux.org/CVE-2020-6439 https://security.archlinux.org/CVE-2020-6440 https://security.archlinux.org/CVE-2020-6441 https://security.archlinux.org/CVE-2020-6442 https://security.archlinux.org/CVE-2020-6443 https://security.archlinux.org/CVE-2020-6444 https://security.archlinux.org/CVE-2020-6445 https://security.archlinux.org/CVE-2020-6446 https://security.archlinux.org/CVE-2020-6447 https://security.archlinux.org/CVE-2020-6448 https://security.archlinux.org/CVE-2020-6454 https://security.archlinux.org/CVE-2020-6455 https://security.archlinux.org/CVE-2020-6456 . Arch Linux Security Advisory ASA-202004-9 ======================================== Severity: High Da. package, chromium, version, vulnerable, arbitr. . LinuxSecurity.com Team
The package chromium before version 80.0.3987.149-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and information disclosure. . Arch Linux Security Advisory ASA-202003-12 ========================================= Severity: High Date : 2020-03-19 CVE-ID : CVE-2019-20503 CVE-2020-6422 CVE-2020-6424 CVE-2020-6425 CVE-2020-6426 CVE-2020-6427 CVE-2020-6428 CVE-2020-6429 CVE-2020-6449 Package : chromium Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1118 Summary ====== The package chromium before version 80.0.3987.149-1 is vulnerable to multiple issues including access restriction bypass, arbitrary code execution and information disclosure. Resolution ========= Upgrade to 80.0.3987.149-1. # pacman -Syu "chromium> =80.0.3987.149-1" The problems have been fixed upstream in version 80.0.3987.149. Workaround ========= None. Description ========== - CVE-2019-20503 (information disclosure) An out-of-bounds read has been found in Firefox before 74, Thunderbird before 68.6 and chromium before 80.0.3987.149. The inputs to sctp_load_addresses_from_init are verified by sctp_arethere_unrecognized_parameters; however, the two functions handled parameter bounds differently, resulting in out of bounds reads when parameters are partially outside a chunk. - CVE-2020-6422 (arbitrary code execution) A use-after-free security issue has been found in the WebGL component of the chromium browser before 80.0.3987.149. - CVE-2020-6424 (arbitrary code execution) A use-after-free security issue has been found in the media component of the chromium browser before 80.0.3987.149. - CVE-2020-6425 (access restriction bypass) An insufficient policy enforcement security issue has been found in the extensions component of the chromium browser before 80.0.3987.149. - CVE-2020-6426 (access restriction bypass) An inappropriate implementation security issue has been foundin the V8 component of the chromium browser before 80.0.3987.149. - CVE-2020-6427 (arbitrary code execution) A use after free security issue has been found in the audio component of the chromium browser before 80.0.3987.149. - CVE-2020-6428 (arbitrary code execution) A use-after-free security issue has been found in the audio component of the chromium browser before 80.0.3987.149. - CVE-2020-6429 (arbitrary code execution) A use-after-free security issue has been found in the audio component of the chromium browser before 80.0.3987.149. - CVE-2020-6449 (arbitrary code execution) A use-after-free security issue has been found in the audio component of the chromium browser before 80.0.3987.149. Impact ===== A remote attacker can access sensitive information, bypass security measures and possibly execute arbitrary code on the affected host. References ========= https://chromereleases.googleblog.com/2020/03/stable-channel-update-for-desktop_18.html https://www.mozilla.org/en-US/security/advisories/mfsa2020-08/#CVE-2019-20503 https://www.mozilla.org/en-US/security/advisories/mfsa2020-10/#CVE-2019-20503 https://bugzilla.mozilla.org/show_bug.cgi?id=1613765 https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html https://security.archlinux.org/CVE-2019-20503 https://security.archlinux.org/CVE-2020-6422 https://security.archlinux.org/CVE-2020-6424 https://security.archlinux.org/CVE-2020-6425 https://security.archlinux.org/CVE-2020-6426 https://security.archlinux.org/CVE-2020-6427 https://security.archlinux.org/CVE-2020-6428 https://security.archlinux.org/CVE-2020-6429 https://security.archlinux.org/CVE-2020-6449 . Update the chromium package on Arch Linux to address critical security vulnerabilities, including potential code execution risks and access control bypasses.. ArchLinux Security Advisory, Chromium Issues, Upgrade Instructions, High Severity Security. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.