Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
172

Ubuntu 14.04 ESM: USN-4667-2 High Severity APT Denial Of Service

APT could be made to crash or stop responding if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4667-2 January 11, 2021 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM Summary: APT could be made to crash or stop responding if it opened a specially crafted file. Software Description: - apt: Advanced front-end for dpkg Details: USN-4667-1 fixed a vulnerability in APT. This update provides the corresponding update for Ubuntu 14.04 ESM. Original advisory details: Kevin Backhouse discovered that APT incorrectly handled certain packages. A local attacker could possibly use this issue to cause APT to crash or stop responding, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: apt 1.0.1ubuntu2.24+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4667-2 https://ubuntu.com/security/notices/USN-4667-1 CVE-2020-27350 . A flaw in APT on Ubuntu might lead to system instability or failure when processing specially designed files.. APT Denial of Service, Ubuntu Security Notice, ESM Update. . LinuxSecurity.com Team

Calendar%202 Jan 11, 2021 Ubuntu
197

Debian LTS DLA-2487-1: CVE-2020-27350 Critical Denial Of Service in APT

It was discovered that missing input validation in the ar/tar implementations of APT, the high level package manager, could cause out-of-bounds reads or infinite loops, resulting in denial of service when processing malformed deb files. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2487-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta December 10, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : apt Version : 1.4.11 CVE ID : CVE-2020-27350 It was discovered that missing input validation in the ar/tar implementations of APT, the high level package manager, could cause out-of-bounds reads or infinite loops, resulting in denial of service when processing malformed deb files. For Debian 9 stretch, this problem has been fixed in version 1.4.11. We recommend that you upgrade your apt packages. For the detailed security status of apt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/apt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance apt components to address vulnerabilities resulting in service interruptions cited in Debian LTS Notice DLA-2487-1.. Debian LTS, APT Security, Denial Of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 09, 2020 Critical Debian LTS
172

Ubuntu 20.10: 4683-2 Moderate: APT Resource Exhaustion Vulnerability

APT could be made to crash or stop responding if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4667-1 December 09, 2020 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: APT could be made to crash or stop responding if it opened a specially crafted file. Software Description: - apt: Advanced front-end for dpkg Details: Kevin Backhouse discovered that APT incorrectly handled certain packages. A local attacker could possibly use this issue to cause APT to crash or stop responding, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: apt 2.1.10ubuntu0.1 Ubuntu 20.04 LTS: apt 2.0.2ubuntu0.2 Ubuntu 18.04 LTS: apt 1.6.12ubuntu0.2 Ubuntu 16.04 LTS: apt 1.2.32ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4667-1 CVE-2020-27350 Package Information: https://launchpad.net/ubuntu/+source/apt/2.1.10ubuntu0.1 https://launchpad.net/ubuntu/+source/apt/2.0.2ubuntu0.2 https://launchpad.net/ubuntu/+source/apt/1.6.12ubuntu0.2 https://launchpad.net/ubuntu/+source/apt/1.2.32ubuntu0.2 . A critical flaw in Ubuntu's APT could lead to system freezes or disruptions. Announcement for a security patch related to advisory USN-4670-1.. APT Vulnerability, Ubuntu Notice, Denial of Service. . LinuxSecurity.com Team

Calendar%202 Dec 09, 2020 Ubuntu
87

Debian DSA-4808-1 Critical: APT DoS Input Validation Issue

It was discovered that missing input validation in the ar/tar implementations of APT, the high level package manager, could cause out-of-bounds reads or infinite loops, resulting in denial of service when processing malformed deb files. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4808-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso December 09, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : apt CVE ID : CVE-2020-27350 It was discovered that missing input validation in the ar/tar implementations of APT, the high level package manager, could cause out-of-bounds reads or infinite loops, resulting in denial of service when processing malformed deb files. For the stable distribution (buster), this problem has been fixed in version 1.8.2.2. We recommend that you upgrade your apt packages. For the detailed security status of apt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/apt Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-4810-2 informs about a vulnerability in dpkg's handling of package metadata that could lead to system crashes with improperly constructed .deb packages.. APT Security Update, DoS Issue, Debian Advisory, Input Validation Failure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 09, 2020 Critical Debian
172

Ubuntu 14.04 ESM, 12.04 ESM: USN-4359-2 Moderate APT Crash

APT could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4359-2 May 28, 2020 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 ESM - Ubuntu 12.04 ESM Summary: APT could be made to crash if it opened a specially crafted file. Software Description: - apt: Advanced front-end for dpkg Details: USN-4359-1 fixed a vulnerability in APT. This update provides the corresponding update for Ubuntu 12.04 ESM and 14.04 ESM. Original advisory details: It was discovered that APT incorrectly handled certain filenames during package installation. If an attacker could provide a specially crafted package to be installed by the system administrator, this could cause APT to crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 ESM: apt 1.0.1ubuntu2.24+esm1 Ubuntu 12.04 ESM: apt 0.8.16~exp12ubuntu10.29 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4359-2 https://ubuntu.com/security/notices/USN-4359-1 CVE-2020-3810 . A vulnerability in Ubuntu's APT has been discovered, potentially causing crashes with specially crafted files in ESM versions. Update your system promptly to mitigate this issue. APT Update, Ubuntu Security Notice, Package Management Issue. . LinuxSecurity.com Team

Calendar%202 May 28, 2020 Ubuntu
197

Debian Jessie: DLA-2210-1 Critical: Apt Out-Of-Bounds Read

When normalizing ar member names by removing trailing whitespace and slashes, an out-out-bound read can be caused if the ar member name consists only of such characters, because the code did not . Package : apt Version : 1.0.9.8.6 CVE ID : CVE-2020-3810 When normalizing ar member names by removing trailing whitespace and slashes, an out-out-bound read can be caused if the ar member name consists only of such characters, because the code did not stop at 0, but would wrap around and continue reading from the stack, without any limit. For Debian 8 "Jessie", this problem has been fixed in version 1.0.9.8.6. We recommend that you upgrade your apt packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Best, Utkarsh . Enhance apt iteration 1.0.9.8.6 on Debian to address out-of-bounds read flaw stemming from inadequate management of member names.. apt Security Update, Debian LTS, Out-of-Bounds Read, Stack Overflow Fix, CVE-2020-3810. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 14, 2020 Critical Debian LTS
172

Ubuntu 20.04 LTS: USN-4359-1 Moderate: APT Crash Vulnerability Fix

APT could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4359-1 May 14, 2020 apt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 19.10 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: APT could be made to crash if it opened a specially crafted file. Software Description: - apt: Advanced front-end for dpkg Details: It was discovered that APT incorrectly handled certain filenames during package installation. If an attacker could provide a specially crafted package to be installed by the system administrator, this could cause APT to crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: apt 2.0.2ubuntu0.1 Ubuntu 19.10: apt 1.9.4ubuntu0.1 Ubuntu 18.04 LTS: apt 1.6.12ubuntu0.1 Ubuntu 16.04 LTS: apt 1.2.32ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4359-1 CVE-2020-3810 Package Information: https://launchpad.net/ubuntu/+source/apt/2.0.2ubuntu0.1 https://launchpad.net/ubuntu/+source/apt/1.9.4ubuntu0.1 https://launchpad.net/ubuntu/+source/apt/1.6.12ubuntu0.1 https://launchpad.net/ubuntu/+source/apt/1.2.32ubuntu0.1 . Recent flaw in APT on Ubuntu could permit intruders to destabilize system performance. It is advisable to apply updates for vulnerable installations.. APT Crash, Ubuntu Security Advisory, Package Management Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 14, 2020 Important Ubuntu
197

Debian: DLA-1637-1 Critical: APT HTTP Transport Code Execution Risk

(amended to refer to jessie in the sources.list entry below, instead of stable) Max Justicz discovered a vulnerability in APT, the high level package manager. . Package : apt Version : 1.0.9.8.5 CVE ID : CVE-2019-3462 Debian Bug : (amended to refer to jessie in the sources.list entry below, instead of stable) Max Justicz discovered a vulnerability in APT, the high level package manager. The code handling HTTP redirects in the HTTP transport method doesn't properly sanitize fields transmitted over the wire. This vulnerability could be used by an attacker located as a man-in-the-middle between APT and a mirror to inject malicous content in the HTTP connection. This content could then be recognized as a valid package by APT and used later for code execution with root privileges on the target machine. Since the vulnerability is present in the package manager itself, it is recommended to disable redirects in order to prevent exploitation during this upgrade only, using: apt -o Acquire::http::AllowRedirect=false update apt -o Acquire::http::AllowRedirect=false upgrade This is known to break some proxies when used against security.debian.org. If that happens, people can switch their security APT source to use: deb jessie/updates main For Debian 8 "Jessie", this problem has been fixed in version 1.0.9.8.5. We recommend that you upgrade your apt packages. Specific upgrade instructions: If upgrading using APT without redirect is not possible in your situation, you can manually download the files (using wget/curl) for your architecture using the URL provided below, verifying that the hashes match. Then you can install them using dpkg -i. Architecture independent files: Size/SHA256 checksum: 301106 47df9567e45fadcd2a56c0fd3d514d8136f2f206aa7baa47405c6fcb94824ab6 Size/SHA256 checksum: 750506 ce79b2ef272716b8da11f3fd0497ce0b7ee69c9c66d01669e8abbbfdde5e6256 amd64 architecture: Size/SHA256 checksum: 792126295d9c69854a4cfbcb46001b09b853f5a098a04c986fc5ae01a0124c1c27e6bd Size/SHA256 checksum: 168896 f9615532b1577b3d1455fa51839ce91765f2860eb3a6810fb5e0de0c87253030 Size/SHA256 checksum: 1109308 4078748632abc19836d045f80f9d6933326065ca1d47367909a0cf7f29e7dfe8 Size/SHA256 checksum: 192950 09ef86d178977163b8cf0081d638d74e0a90c805dd77750c1d91354b6840b032 Size/SHA256 checksum: 368396 87c55d9ccadcabd59674873c221357c774020c116afd978fb9df6d2d0303abf2 Size/SHA256 checksum: 137230 f5a17422fd319ff5f6e3ea9a9e87d2508861830120125484130da8c1fd479df2 armel architecture: Size/SHA256 checksum: 717002 80fe021d87f2444abdd7c5491e7a4bf9ab9cb2b8e6fa72d308905f4e0aad60d4 Size/SHA256 checksum: 166784 046fb962fa214c5d6acfb7344e7719f8c4898d87bf29ed3cd2115e3f6cdd14e9 Size/SHA256 checksum: 1067404 f9a257d6aace1f222633e0432abf1d6946bad9dbd0ca18dccb288d50f17b895f Size/SHA256 checksum: 193768 4cb226f55132a68a2f5db925ada6147aaf052adb02301fb45fb0c2d1cfce36f0 Size/SHA256 checksum: 353178 38042838d8bc79642e5389be7d2d2d967cbf316805d4c8c2d6afbe1bc164aacc Size/SHA256 checksum: 134932 755b6d22f5914f3153a1c15427e5221507b174c0a4c6b860ebd16234c9e9a146 armhf architecture: Size/SHA256 checksum: 734302 0f48f6d0406afdf0bd4d39e90e56460fab3d9b5fa4c91e2dca78ec22caf2fe2a Size/SHA256 checksum: 166556 284a1ffd529e1daab3c300be17a20f11450555be9c0af166d9796c18147a03ba Size/SHA256 checksum: 1078212 08d85c30c8e4a6df0dced8e232a6c7639caa231acef4af8fdee2c1e07f0178ba Size/SHA256 checksum: 193796 3a26bd79677b46ce0a992e2ac808c4bbd2d5b3fc37b57fc93c8efa114de1adaa Size/SHA256 checksum: 357074 19dec9ffc0fe4a86d6e61b5213e75c55ae6aaade6f3804f90e2e4034bbdc44d8 Size/SHA256 checksum: 135072 06ba556c5218e58fd14119e3b08a08f685209a0cbe09f2328bd572cabc580bca i386 architecture: Size/SHA256 checksum: 800840 201b6cf4625ed175e6a024ac1f7ca6c526ca79d859753c125b02cd69e26c349d Size/SHA256checksum: 170484 5791661dd4ade72b61086fefdc209bd1f76ac7b7c812d6d4ba951b1a6232f0b9 Size/SHA256 checksum: 1110418 13c230e9c544b1e67a8da413046bf1728526372170533b1a23e70cc99c40a228 Size/SHA256 checksum: 193780 c5b1bfa913ea2e2e332c228f5c5fe4dbc11ab334d0551a68ba6e87e94a51ffee Size/SHA256 checksum: 371218 1a74b12c8bb6b3968a721f3aa96739073e4fe2ced9302792c533e21535bc9cf4 Size/SHA256 checksum: 139036 32148d92914a97df8bbb9f223e788dcbc7c39e570cf48e6759cb483a65b68666 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- debian developer - deb.li/jak | jak-linux.org - free software dev ubuntu core developer i speak de, en . The latest APT package revision resolves a critical vulnerability, preventing potential man-in-the-middle attacks. Updating is advised to safeguard against possible threats.. APT Security Update, Debian Jessie, Man-In-The-Middle Attack, HTTP Transport Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 22, 2019 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200