Explore top 10 tips to secure your open-source projects now. Read More
×
CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-e41ba62ff1 2025-10-03 00:52:22.552541+00:00 -------------------------------------------------------------------------------- Name : freeipa Product : Fedora 42 Version : 4.12.5 Release : 2.fc42 URL : http://www.freeipa.org/ Summary : The Identity, Policy and Audit system Description : IPA is an integrated solution to provide centrally managed Identity (users, hosts, services), Authentication (SSO, 2FA), and Authorization (host access control, SELinux user roles, services). The solution provides features for further integration with Linux based clients (SUDO, automount) and integration with Active Directory based infrastructures (Trusts). -------------------------------------------------------------------------------- Update Information: CVE-2025-7493: host to admin escalation prevention: https://www.freeipa.org/release-notes/4-12-5.html Update FreeIPA to latest fixes from ipa-4-12 branch -------------------------------------------------------------------------------- ChangeLog: * Tue Sep 30 2025 Alexander Bokovoy - 4.12.5-2 - Update minor version metadata to alow IPA data upgrade * Tue Sep 30 2025 Alexander Bokovoy - 4.12.5-1 - CVE-2025-7493: host to admin escalation prevention * Tue Sep 23 2025 Alexander Bokovoy - 4.12.2-15 - Update fixes from ipa-4-12 branch -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-e41ba62ff1' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
nano could be made to give users administrator privileges.. ========================================================================== Ubuntu Security Notice USN-7064-2 October 29, 2024 nano vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: nano could be made to give users administrator privileges. Software Description: - nano: small, friendly text editor inspired by Pico Details: USN-7064-1 fixed a vulnerability in nano. This update provides the corresponding update for Ubuntu 14.04 LTS. Original advisory details: It was discovered that nano allowed a possible privilege escalation through an insecure temporary file. If nano was killed while editing, the permissions granted to the emergency save file could be used by an attacker to escalate privileges using a malicious symlink. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS nano 2.2.6-1ubuntu1+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7064-2 https://ubuntu.com/security/notices/USN-7064-1 CVE-2024-5742 . The Ubuntu Security Notice USN-7064-2 addresses a security flaw in nano that could allow for privilege escalation. For further information, click here.. Ubuntu Security, nano Update, Privilege Escalation, Security Notice, System Update. . LinuxSecurity.com Team
The system could be made to crash or run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-6089-1 May 18, 2023 linux-oem-6.0 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS Summary: The system could be made to crash or run programs as an administrator. Software Description: - linux-oem-6.0: Linux kernel for OEM systems Details: It was discovered that the Intel i915 graphics driver in the Linux kernel did not perform a GPU TLB flush in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: linux-image-6.0.0-1016-oem 6.0.0-1016.16 linux-image-oem-22.04b 6.0.0.1016.16 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6089-1 CVE-2022-4139 Package Information: https://launchpad.net/ubuntu/+source/linux-oem-6.0/6.0.0-1016.16 . Ubuntu 22.04 LTS patch necessary for linux-oem-6.0 flaw impacting system integrity and permission levels.. Linux Kernel Vulnerability, Ubuntu Security Update, Admin Access Exploit. . LinuxSecurity.com Team
The system could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-6052-1 May 01, 2023 linux-ibm-5.4, linux-snapdragon vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: The system could be made to run programs as an administrator. Software Description: - linux-ibm-5.4: Linux kernel for IBM cloud systems - linux-snapdragon: Linux kernel for Qualcomm Snapdragon processors Details: It was discovered that the Traffic-Control Index (TCINDEX) implementation in the Linux kernel did not properly perform filter deactivation in some situations. A local attacker could possibly use this to gain elevated privileges. Please note that with the fix for this CVE, kernel support for the TCINDEX classifier has been removed. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: linux-image-4.15.0-1149-snapdragon 4.15.0-1149.159 linux-image-5.4.0-1048-ibm 5.4.0-1048.53~18.04.1 linux-image-ibm 5.4.0.1048.59 linux-image-snapdragon 4.15.0.1149.148 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-6052-1 CVE-2023-1829 Package Information: https://launchpad.net/ubuntu/+source/linux-ibm-5.4/5.4.0-1048.53~18.04.1 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.15.0-1149.159 . The latest security update from Ubuntu addresses a critical kernel flaw that could allow unauthorized execution of administrative programs. Users are urged to upgrade.. Kernel Privilege Escalation, Ubuntu 18.04 LTS, Administrative Privileges. . Severity: Important. LinuxSecurity.com Team
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. (CVE-2022-24706) . MGASA-2022-0466 - Updated couchdb packages fix security vulnerability Publication date: 17 Dec 2022 URL: https://advisories.mageia.org/MGASA-2022-0466.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-24706 In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default installation without authenticating and gain admin privileges. The CouchDB documentation has always made recommendations for properly securing an installation, including recommending using a firewall in front of all CouchDB installations. (CVE-2022-24706) References: - https://bugs.mageia.org/show_bug.cgi?id=30342 - https://www.openwall.com/lists/oss-security/2022/04/26/1 - https://www.cve.org/CVERecord?id=CVE-2022-24706 SRPMS: - 8/core/couchdb-3.2.2-1.mga8 . A patch has been issued for CouchDB to fix a significant vulnerability that permitted unauthorized administrative entry prior to version 3.2.2.. CouchDB Security Update, Mageia 2022-0466, Apache CouchDB Issues, Admin Access Vulnerability. . Severity: Critical. LinuxSecurity.com Team
NTFS-3G could be made to crash or run programs as an administrator if it mounted a specially crafted disk. (CVE-2022-40284) References: - https://bugs.mageia.org/show_bug.cgi?id=31056 . MGASA-2022-0408 - Updated ntfs-3g packages fix security vulnerability Publication date: 04 Nov 2022 URL: https://advisories.mageia.org/MGASA-2022-0408.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-40284 NTFS-3G could be made to crash or run programs as an administrator if it mounted a specially crafted disk. (CVE-2022-40284) References: - https://bugs.mageia.org/show_bug.cgi?id=31056 - https://www.openwall.com/lists/oss-security/2022/10/31/2 - https://github.com/tuxera/ntfs-3g/releases/tag/2022.10.3 - https://ubuntu.com/security/notices/USN-5711-1 - https://www.cve.org/CVERecord?id=CVE-2022-40284 SRPMS: - 8/core/ntfs-3g-2021.8.22-1.2.mga8 . The ntfs-3g filesystem driver received important updates on 04 Nov 2022 to address vulnerabilities that could lead to crashes or unauthorized access, improving system security. ntfs-3g security update, mageia advisory, crash risk, admin access risk. . LinuxSecurity.com Team
An update that solves two vulnerabilities and has one errata is now available. . openSUSE Security Update: Security update for mailman ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1452-1 Rating: important References: #1047218 #1191959 #1191960 Cross-References: CVE-2021-42096 CVE-2021-42097 CVSS scores: CVE-2021-42096 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N CVE-2021-42097 (SUSE): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Backports SLE-15-SP2 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for mailman fixes the following issues: Update to 2.1.35 to fix 2 security issues: - A potential for for a list member to carry out an off-line brute force attack to obtain the list admin password has been reported by Andre Protas, Richard Cloke and Andy Nuttall of Apple. This is fixed. CVE-2021-42096 (boo#1191959, LP:#1947639) - A CSRF attack via the user options page could allow takeover of a users account. This is fixed. CVE-2021-42097 (boo#1191960, LP:#1947640) - make package build reproducible (boo#1047218) This update was imported from the openSUSE:Leap:15.2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2021-1452=1 Package List: - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390x x86_64): mailman-2.1.35-bp152.7.6.1 References: https://www.suse.com/security/cve/CVE-2021-42096.html https://www.suse.com/security/cve/CVE-2021-42097.html https://bugzilla.suse.com/1047218 https://bugzilla.suse.com/1191959 https://bugzilla.suse.com/1191960 . A crucial openSUSE security patch addresses two flaws in Mailman that impact user accounts and administrative permissions.. Mailman Security Fixes, openSUSE Updates, CSRF Vulnerability Solutions. . Severity: Important. LinuxSecurity.com Team
It was discovered that the LDAP authentication modules for the Prosody Jabber/XMPP server incorrectly validated the XMPP address when checking whether a user has admin access. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4612-1
Get the latest Linux and open source security news straight to your inbox.