Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
197

Debian Buster: DLA-3741-1 Critical Engrama Directory Bypass Vulnerability

It was discovered that engrampa, an archive manager for the MATE desktop environment was susceptible to path traversal when handling CPIO archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3741-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz February 26, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : engrampa Version : 1.20.2-1+deb10u1 CVE ID : CVE-2023-52138 It was discovered that engrampa, an archive manager for the MATE desktop environment was susceptible to path traversal when handling CPIO archives. For Debian 10 buster, this problem has been fixed in version 1.20.2-1+deb10u1. We recommend that you upgrade your engrampa packages. For the detailed security status of engrampa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/engrampa Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Engrama susceptible to directory traversal in CPIO files. Upgrade to 1.20.2-1+deb10u1 for patching.. Engrama Update, Security Patch, Debian Buster, CPIO Archive Exploit, Archive Manager Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 26, 2024 Critical Debian LTS
172

Ubuntu 20.10 USN-4927-1 Minor: File Roller Information Exposure

File Roller could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4927-1 April 26, 2021 file-roller vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: File Roller could be made to expose sensitive information. Software Description: - file-roller: archive manager for GNOME Details: It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: file-roller 3.38.0-1ubuntu0.1 Ubuntu 20.04 LTS: file-roller 3.36.3-0ubuntu1.1 Ubuntu 18.04 LTS: file-roller 3.28.0-1ubuntu1.3 Ubuntu 16.04 LTS: file-roller 3.16.5-0ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4927-1 CVE-2020-36314 Package Information: https://launchpad.net/ubuntu/+source/file-roller/3.38.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/file-roller/3.36.3-0ubuntu1.1 https://launchpad.net/ubuntu/+source/file-roller/3.28.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/file-roller/3.16.5-0ubuntu1.5 . This document discusses Ubuntu Security Notice USN-4927-1 regarding a critical vulnerability in File Roller, allowing unauthorized access to sensitive data and urging users to update their installations to enhance system security against potential risks. File Roller, Information Exposure, Ubuntu Security Notice. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 26, 2021 Important Ubuntu
89

Fedora 33 FEDORA-2020-f04f41bcc9 Critical Ark Security Fix

security fix for CVE-2020-24654. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f04f41bcc9 2020-09-25 16:31:57.890800 --------------------------------------------------------------------------------Name : ark Product : Fedora 33 Version : 20.04.3 Release : 5.fc33 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: security fix for CVE-2020-24654 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2020 Than Ngo - 20.04.3-5 - backport security fix for CVE-2020-24654 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f04f41bcc9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The recent patch for Ark on Fedora 33 tackles an urgent concern, enhancing the protection of file handling against potential threats.. Fedora 33, Ark Security, Archive Management, Security Update, Patch Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 25, 2020 Critical Fedora
89

Fedora 32 Ark Security Fix: CVE-2020-24654 Moderate Risk

security fix for CVE-2020-24654. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c2f8a1e8a5 2020-09-07 17:12:41.698719 --------------------------------------------------------------------------------Name : ark Product : Fedora 32 Version : 20.04.3 Release : 5.fc32 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: security fix for CVE-2020-24654 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2020 Than Ngo - 20.04.3-5 - backport security fix for CVE-2020-24654 * Sat Aug 1 2020 Fedora Release Engineering - 20.04.3-4 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c2f8a1e8a5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 32 has issued a vital security update for CVE-2020-24654, affecting Ark, a file archiving tool that can allow command execution by attackers. Fedora Update, Ark Security Fix, Archive Management, CVE-2020-24654. . LinuxSecurity.com Team

Calendar 2 Sep 07, 2020 Fedora
89

Fedora 32: FEDORA-2020-e2fe8f0165 Critical: Ark File Installation Risk

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e2fe8f0165 2020-08-13 01:38:09.348906 --------------------------------------------------------------------------------Name : ark Product : Fedora 32 Version : 20.04.3 Release : 3.fc32 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt --------------------------------------------------------------------------------ChangeLog: * Fri Jul 31 2020 Rex Dieter - 20.04.3-3 - backport security fix for CVE-2020-16116 * Mon Jul 27 2020 Fedora Release Engineering - 20.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Rex Dieter - 20.04.3-1 - 20.04.3 * Fri Jun 12 2020 Rex Dieter - 20.04.2-1 - 20.04.2 * Wed May 27 2020 Rex Dieter - 20.04.1-1 - 20.04.1 * Sat Mar 7 2020 Rex Dieter - 19.12.3-1 - 19.12.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1862464 - CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory https://bugzilla.redhat.com/show_bug.cgi?id=1862464 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e2fe8f0165' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A patch has been released for ark in Fedora 32 to remedy CVE-2020-16116. Discover the nuances of archive handling and strategies for risk reduction.. Fedora Update, Ark Application, Security Fix, Archive Management, CVE-2020-16116. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 12, 2020 Critical Fedora
89

Fedora 31 Ark Security Advisory FEDORA-2020-cac5ae9b6e: Moderate DoS Risk

Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cac5ae9b6e 2020-08-09 03:12:26.543960 --------------------------------------------------------------------------------Name : ark Product : Fedora 31 Version : 20.04.3 Release : 3.fc31 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt --------------------------------------------------------------------------------ChangeLog: * Fri Jul 31 2020 Rex Dieter - 20.04.3-3 - backport security fix for CVE-2020-16116 * Mon Jul 27 2020 Fedora Release Engineering - 20.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Rex Dieter - 20.04.3-1 - 20.04.3 * Fri Jun 12 2020 Rex Dieter - 20.04.2-1 - 20.04.2 * Wed May 27 2020 Rex Dieter - 20.04.1-1 - 20.04.1 * Sat Mar 7 2020 Rex Dieter - 19.12.3-1 - 19.12.3 * Tue Feb 4 2020 Rex Dieter - 19.12.2-1 - 19.12.2 * Fri Jan 31 2020 Rex Dieter - 19.12.1-1 - 19.12.1 * Tue Jan 28 2020 Fedora Release Engineering - 19.08.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Tue Nov 12 2019 Rex Dieter - 19.08.3-1 - 19.08.3 * Thu Oct 17 2019 Rex Dieter - 19.08.2-1 - 19.08.2 * Fri Oct 4 2019 Rex Dieter - 19.08.1-1 - 19.08.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1862464 -CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory https://bugzilla.redhat.com/show_bug.cgi?id=1862464 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cac5ae9b6e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A crucial patch for ark rectifies vulnerabilities that permitted harmful archives to compromise Fedora 31 systems. Discover further details about the remedy.. Fedora Security Update, ark Archive Manager, CVE-2020-16116, Fedora 31 Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 08, 2020 Important Fedora
87

Debian: DSA-4738-1 Moderate: Ark Archive Manager Path Issue

Dominik Penner discovered that the Ark archive manager did not sanitise extraction paths, which could result in maliciously crafted archives writing outside the extraction directory. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4738-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff July 31, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ark CVE ID : CVE-2020-16116 Dominik Penner discovered that the Ark archive manager did not sanitise extraction paths, which could result in maliciously crafted archives writing outside the extraction directory. For the stable distribution (buster), this problem has been fixed in version 4:18.08.3-1+deb10u1. We recommend that you upgrade your ark packages. For the detailed security status of ark please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ark Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Vulnerability discovered in Ark archive tool enables path traversal attacks; Debian users should apply updates immediately. Protect your devices today!. Ark Archive Manager, Debian Security Update, Path Exploitation. . LinuxSecurity.com Team

Calendar 2 Jul 31, 2020 Debian
172

Ubuntu 20.04 LTS: USN-4332-2 Medium: File Roller Information Exposure

File Roller could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4332-2 April 27, 2020 file-roller vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: File Roller could be made to expose sensitive information. Software Description: - file-roller: archive manager for GNOME Details: USN-4332-1 fixed vulnerabilities in File Roller. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: file-roller 3.36.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4332-2 https://ubuntu.com/security/notices/USN-4332-1 CVE-2020-11736 Package Information: https://launchpad.net/ubuntu/+source/file-roller/3.36.1-1ubuntu0.1 . Ubuntu Security Alert USN-4332-2 outlines a critical vulnerability in file-roller that may reveal confidential data. Discover measures to enhance your security today.. File Roller Vulnerability, Ubuntu Security Advisory, Information Exposure Issue. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Apr 27, 2020 Medium Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here