Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
browserify-sign could allow unintended access if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6800-1 May 30, 2024 node-browserify-sign vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: browserify-sign could allow unintended access if it opened a specially crafted file. Software Description: - node-browserify-sign: createSign and createVerify in your browser Details: It was discovered that browserify-sign incorrectly handled an upper bound check in signature verification. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to perform a signature forgery attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10 node-browserify-sign 4.2.1-3ubuntu0.1 Ubuntu 22.04 LTS node-browserify-sign 4.2.1-2ubuntu0.1 Ubuntu 20.04 LTS node-browserify-sign 4.0.4-2ubuntu0.20.04.1 Ubuntu 18.04 LTS node-browserify-sign 4.0.4-2ubuntu0.18.04.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6800-1 CVE-2023-46234 Package Information: https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-3ubuntu0.1 https://launchpad.net/ubuntu/+source/node-browserify-sign/4.2.1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/node-browserify-sign/4.0.4-2ubuntu0.20.04.1 . A critical vulnerability in the browserify-sign package affects Ubuntu 20.04, 21.10, and 22.04, needing immediate updates to ensure system security.browserify-sign, Node-Browserify-Sign, access control, signature forgery. . LinuxSecurity.com Team
The updated packages fix a security vulnerability: GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. . MGASA-2023-0311 - Updated gnome-shell packages fix a security vulnerability Publication date: 09 Nov 2023 URL: https://advisories.mageia.org/MGASA-2023-0311.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-43090 The updated packages fix a security vulnerability: GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool. (CVE-2023-43090) References: - https://bugs.mageia.org/show_bug.cgi?id=32320 - https://ubuntu.com/security/notices/USN-6395-1 - https://www.cve.org/CVERecord?id=CVE-2023-43090 SRPMS: - 9/core/gnome-shell-44.2-1.1.mga9 . Revised gnome-shell installations address a vulnerability affecting local session entry. Important specifics outlined.. Gnome Shell Security Update, Mageia Security Advisory, Local User Access Risk. . Severity: Critical. LinuxSecurity.com Team
Multiple security fixes.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7e7ce7df2e 2022-07-27 02:34:21.694815 --------------------------------------------------------------------------------Name : moodle Product : Fedora 35 Version : 3.11.8 Release : 1.fc35 URL : https://moodle.org/ Summary : A Course Management System Description : Moodle is a course management system (CMS) - a free, Open Source software package designed using sound pedagogical principles, to help educators create effective online learning communities. --------------------------------------------------------------------------------Update Information: Multiple security fixes. --------------------------------------------------------------------------------ChangeLog: * Mon Jul 18 2022 Gwyn Ciesla - 3.11.8-1 - 3.11.8 --------------------------------------------------------------------------------References: [ 1 ] Bug #2108037 - CVE-2022-35649 moodle: PostScript Code Injection / Remote code execution risk [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108037 [ 2 ] Bug #2108039 - CVE-2022-35650 moodle: Arbitrary file read when importing lesson questions [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108039 [ 3 ] Bug #2108041 - CVE-2022-35651 moodle: Stored XSS and blind SSRF possible via SCORM track details [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108041 [ 4 ] Bug #2108043 - CVE-2022-35652 moodle: Open redirect risk in mobile auto-login feature [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108043 [ 5 ] Bug #2108045 - CVE-2022-35653 moodle: LTI module reflected XSS risk - affecting unauthenticated users only [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2108045 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2022-7e7ce7df2e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
A Flatpak application could access files that it would not normally be permitted to access.. =========================================================================Ubuntu Security Notice USN-4951-1 May 12, 2021 flatpak vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: A Flatpak application could access files that it would not normally be permitted to access. Software Description: - flatpak: Application deployment framework for desktop apps Details: Anton Lydike discovered that Flatpak did not properly handle special tokens in desktop files. An attacker could use this to specially craft a Flatpak application that could escape sandbox confinement. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: flatpak 1.8.2-1ubuntu0.2 libflatpak0 1.8.2-1ubuntu0.2 Ubuntu 20.04 LTS: flatpak 1.6.5-0ubuntu0.3 libflatpak0 1.6.5-0ubuntu0.3 Ubuntu 18.04 LTS: flatpak 1.0.9-0ubuntu0.3 libflatpak0 1.0.9-0ubuntu0.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4951-1 CVE-2021-21381 Package Information: https://launchpad.net/ubuntu/+source/flatpak/1.8.2-1ubuntu0.2 https://launchpad.net/ubuntu/+source/flatpak/1.6.5-0ubuntu0.3 https://launchpad.net/ubuntu/+source/flatpak/1.0.9-0ubuntu0.3 . Security Alert USN-5002-2 addresses a Snap vulnerability permitting unauthorized data exposure on Linux distributions.. Flatpak Issue, Ubuntu Security, Application Access Risk, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: glusterfs security update Advisory ID: RHSA-2018:1269-01 Product: Red Hat Gluster Storage Advisory URL: https://access.redhat.com/errata/RHSA-2018:1269 Issue date: 2018-04-30 CVE Names: CVE-2018-1112 ==================================================================== 1. Summary: An update for glusterfs is now available for Native Client for Red Hat Enterprise Linux 7 for Red Hat Storage and Red Hat Gluster Storage 3.3 for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Gluster Storage Server 3.3 on RHEL-7 - noarch, x86_64 Red Hat Storage Native Client for Red Hat Enterprise Linux 7 - noarch, x86_64 3. Description: GlusterFS is a key building block of Red Hat Gluster Storage. It is based on a stackable user-space design and can deliver exceptional performance for diverse workloads. GlusterFS aggregates various storage servers over network interconnections into one large, parallel network file system. Security Fix(es): * It was found that fix for CVE-2018-1088 introduced a new vulnerability in the way 'auth.allow' is implemented in glusterfs server. An unauthenticated gluster client could mount gluster storage volumes. (CVE-2018-1112) 4. Solution: For details on how to apply this update, which includes the changes described in this advisory,refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1570891 - CVE-2018-1112 glusterfs: auth.allow allows unauthenticated clients to mount gluster volumes (CVE-2018-1088 regression) 6. Package List: Red Hat Gluster Storage Server 3.3 on RHEL-7: Source: glusterfs-3.8.4-54.8.el7rhgs.src.rpm noarch: glusterfs-resource-agents-3.8.4-54.8.el7rhgs.noarch.rpm python-gluster-3.8.4-54.8.el7rhgs.noarch.rpm x86_64: glusterfs-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-api-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-api-devel-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-cli-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-client-xlators-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-debuginfo-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-devel-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-events-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-fuse-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-ganesha-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-geo-replication-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-libs-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-rdma-3.8.4-54.8.el7rhgs.x86_64.rpm glusterfs-server-3.8.4-54.8.el7rhgs.x86_64.rpm Red Hat Storage Native Client for Red Hat Enterprise Linux 7: Source: glusterfs-3.8.4-54.8.el7.src.rpm noarch: python-gluster-3.8.4-54.8.el7.noarch.rpm x86_64: glusterfs-3.8.4-54.8.el7.x86_64.rpm glusterfs-api-3.8.4-54.8.el7.x86_64.rpm glusterfs-api-devel-3.8.4-54.8.el7.x86_64.rpm glusterfs-cli-3.8.4-54.8.el7.x86_64.rpm glusterfs-client-xlators-3.8.4-54.8.el7.x86_64.rpm glusterfs-debuginfo-3.8.4-54.8.el7.x86_64.rpm glusterfs-devel-3.8.4-54.8.el7.x86_64.rpm glusterfs-fuse-3.8.4-54.8.el7.x86_64.rpm glusterfs-libs-3.8.4-54.8.el7.x86_64.rpm glusterfs-rdma-3.8.4-54.8.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7.References: https://access.redhat.com/security/cve/CVE-2018-1112 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/articles/3422521 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFa5xE6XlSAg2UNWIIRAqdbAJ9Oxi9vblI58F2ybMtlEOJdfsoyJwCfVCCU pRdFLhHdtQaMhzEXT/SXXG8=V28B -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Depend on https://bodhi.fedoraproject.org/updates/FEDORA-2018-92de33f3b9. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-b7e606d011 2018-01-10 20:51:05.568143 --------------------------------------------------------------------------------Name : electrum Product : Fedora 26 Version : 3.0.5 Release : 1.fc26 URL : https://electrum.org/ Summary : A lightweight Bitcoin Client Description : Electrum is an easy to use Bitcoin client. It protects you from losing coins in a backup mistake or computer failure, because your wallet can be recovered from a secret phrase that you can write on paper or learn by heart. There is no waiting time when you start the client, because it does not download the Bitcoin block chain. --------------------------------------------------------------------------------Update Information: Depend on https://bodhi.fedoraproject.org/updates/FEDORA-2018-92de33f3b9 --------------------------------------------------------------------------------References: [ 1 ] Bug #1532554 - electrum: Unprotected JSON-RPC interface https://bugzilla.redhat.com/show_bug.cgi?id=1532554 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade electrum' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] samba (SSA:2017-082-02) New samba packages are available for Slackware 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/samba-4.4.12-i586-1_slack14.2.txz: Upgraded. This update fixes a security issue: All versions of Samba prior to 4.6.1, 4.5.7, 4.4.12 are vulnerable to a malicious client using a symlink race to allow access to areas of the server file system not exported under the share definition. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-2619 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.0 package: c17714e61d60e8e643bdd9bc51edafe1 samba-4.4.12-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 54bfdadaf8b7abc1242c5a71ea0a407f samba-4.4.12-x86_64-1_slack14.0.txz Slackware 14.1 package: 500af32e09c75b7a234b4a9e05c62f5a samba-4.4.12-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 9f86969a772e06f991e9452dda584b81 samba-4.4.12-x86_64-1_slack14.1.txz Slackware 14.2 package: e48f91e5a15555caec1d6c4b8b3b88f7 samba-4.4.12-i586-1_slack14.2.txz Slackware x86_64 14.2package: 4dd6e6936de5236eef7f7b0254390b05 samba-4.4.12-x86_64-1_slack14.2.txz Slackware -current package: 4b0c75d2b3fecc64c6ad50c3d847e839 n/samba-4.6.1-i586-1.txz Slackware x86_64 -current package: ff9eca50dedd7452a9f3a6f6fed43c84 n/samba-4.6.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg samba-4.4.12-i586-1_slack14.2.txz Then, if Samba is running restart it: # /etc/rc.d/rc.samba restart +-----+ . An important Samba patch for Slackware resolves a vulnerability enabling unauthorized entry through a symlink competition. Update immediately!. Samba Update, Slackware Security, Access Risk Fix. . Severity: Critical. LinuxSecurity.com Team
Nicolas Gregoire and Kevin Schaller discovered that Batik, a toolkit for processing SVG images, would load XML external entities by default. If a user or automated system were tricked into opening a specially crafted SVG file, an attacker could possibly obtain access . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3205-1
Get the latest Linux and open source security news straight to your inbox.