Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9 Stretch DLA-2488-1 Moderate: Python-Apt Denial of Service Risk

Various memory and file descriptor leaks were discovered in the Python interface to the APT package management runtime library, which could result in denial of service. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2488-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta December 10, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : python-apt Version : 1.4.2 CVE ID : CVE-2020-27351 Various memory and file descriptor leaks were discovered in the Python interface to the APT package management runtime library, which could result in denial of service. For Debian 9 stretch, this problem has been fixed in version 1.4.2. We recommend that you upgrade your python-apt packages. For the detailed security status of python-apt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-apt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A fix for memory leakage issues in the python-apt library for Debian 9 Stretch is now available. Updating to this version is recommended for better security and stability. debian security advisory, python-apt security, memory leak fix, debian stretch security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 09, 2020 Important Debian LTS
87

Debian: DSA-4809-1 python-apt Moderate: Denial Of Service Risk

Various memory and file descriptor leaks were discovered in the Python interface to the APT package management runtime library, which could result in denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4809-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso December 09, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-apt CVE ID : CVE-2020-27351 Various memory and file descriptor leaks were discovered in the Python interface to the APT package management runtime library, which could result in denial of service. For the stable distribution (buster), this problem has been fixed in version 1.8.4.2. We recommend that you upgrade your python-apt packages. For the detailed security status of python-apt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-apt Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance python-apt to mitigate memory and file descriptor leaks that could lead systems to potential denial-of-service vulnerabilities.. Python Apt Update, Debian Security Advisory, Memory Leak Fix, Package Management Security. . LinuxSecurity.com Team

Calendar%202 Dec 09, 2020 Debian
87

Debian: DSA-3048-1 Critical: Apt File Overwrite Risk Vulnerability

Guillem Jover discovered that the changelog retrieval functionality in apt-get used temporary files in an insecure way, allowing a local user to cause arbitrary files to be overwritten. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3048-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst October 08, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : apt CVE ID : CVE-2014-7206 Debian Bug : 763780 Guillem Jover discovered that the changelog retrieval functionality in apt-get used temporary files in an insecure way, allowing a local user to cause arbitrary files to be overwritten. This vulnerability is neutralized by the fs.protected_symlinks setting in the Linux kernel, which is enabled by default in Debian 7 Wheezy and up. For the stable distribution (wheezy), this problem has been fixed in version 0.9.7.9+deb7u6. For the unstable distribution (sid), this problem has been fixed in version 1.0.9.2. We recommend that you upgrade your apt packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-5048-1 tackles apt's manifest problem that stops file replacements. Update is advised.. Debian Security,Apt Security,File Overwrite Mitigation,Update Recommendation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 08, 2014 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200