Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
87

Debian: pgpool-II Major Authentication Flaw & Data Leak DSA-5980-2

Two security issues were found in pgpool-II, the connection pool server and replication proxy for PostgreSQL, which could result in authentication bypass and exposure of sensitive information. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5974-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu August 13, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : pgpool2 CVE ID : CVE-2024-45624 CVE-2025-46801 Debian Bug : 1081659 1106119 Two security issues were found in pgpool-II, the connection pool server and replication proxy for PostgreSQL, which could result in authentication bypass and exposure of sensitive information. For the oldstable distribution (bookworm), these problems have been fixed in version 4.3.5-1+deb12u1. We recommend that you upgrade your pgpool2 packages. For the detailed security status of pgpool2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pgpool2 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent vulnerabilities identified in pgpool2 may lead to unauthorized access and potential data leakage. Immediate upgrade is advised.. pgpool2 Debian security authentication bypass sensitive data. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 13, 2025 Critical Debian
197

Debian 9: DLA-2506-1 Critical: Awstats Path Traversal Attack Fix

It was discovered that Awstats, a web server log analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2506-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ December 23, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : awstats Version : 7.6+dfsg-1+deb9u2 CVE ID : CVE-2020-29600 CVE-2020-35176 Debian Bug : 891469 977190 It was discovered that Awstats, a web server log analyzer, was vulnerable to path traversal attacks. A remote unauthenticated attacker could leverage that to perform arbitrary code execution. The previous fix did not fully address the issue when the default /etc/awstats/awstats.conf is not present. For Debian 9 stretch, this problem has been fixed in version 7.6+dfsg-1+deb9u2. We recommend that you upgrade your awstats packages. For the detailed security status of awstats please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/awstats Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2510-1 details a severe vulnerability in Awstats, allowing for potential code execution through path traversal techniques.. Awstats Security, Path Traversal, Debian LTS, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 23, 2020 Critical Debian LTS
200

SciLinux SL7: SLSA-2017-2790-1 Moderate: Samba Man-In-The-Middle Threats

It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man- in-the-middle attack and retrieve information in plain-text. (CVE-2017-12150) * A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS re [More...]. Synopsis: Moderate: samba security update Advisory ID: SLSA-2017:2790-1 Issue Date: 2017-09-21 CVE Numbers: CVE-2017-12150 CVE-2017-12163 CVE-2017-12151 -- Security Fix(es): * It was found that samba did not enforce "SMB signing" when certain configuration options were enabled. A remote attacker could launch a man- in-the-middle attack and retrieve information in plain-text. (CVE-2017-12150) * A flaw was found in the way samba client used encryption with the max protocol set as SMB3. The connection could lose the requirement for signing and encrypting to any DFS redirects, allowing an attacker to read or alter the contents of the connection via a man-in-the-middle attack. (CVE-2017-12151) * An information leak flaw was found in the way SMB1 protocol was implemented by Samba. A malicious client could use this flaw to dump server memory contents to a file on the samba share or to a shared printer, though the exact area of server memory cannot be controlled by the attacker. (CVE-2017-12163) -- SL7 x86_64 libsmbclient-4.6.2-11.el7_4.i686.rpm libsmbclient-4.6.2-11.el7_4.x86_64.rpm libwbclient-4.6.2-11.el7_4.i686.rpm libwbclient-4.6.2-11.el7_4.x86_64.rpm samba-client-4.6.2-11.el7_4.x86_64.rpm samba-client-libs-4.6.2-11.el7_4.i686.rpm samba-client-libs-4.6.2-11.el7_4.x86_64.rpm samba-common-libs-4.6.2-11.el7_4.x86_64.rpm samba-common-tools-4.6.2-11.el7_4.x86_64.rpm samba-debuginfo-4.6.2-11.el7_4.i686.rpm samba-debuginfo-4.6.2-11.el7_4.x86_64.rpm samba-krb5-printing-4.6.2-11.el7_4.x86_64.rpm samba-libs-4.6.2-11.el7_4.i686.rpm samba-libs-4.6.2-11.el7_4.x86_64.rpm samba-winbind-4.6.2-11.el7_4.x86_64.rpm samba-winbind-clients-4.6.2-11.el7_4.x86_64.rpm samba-winbind-modules-4.6.2-11.el7_4.i686.rpm samba-winbind-modules-4.6.2-11.el7_4.x86_64.rpm libsmbclient-devel-4.6.2-11.el7_4.i686.rpm libsmbclient-devel-4.6.2-11.el7_4.x86_64.rpm libwbclient-devel-4.6.2-11.el7_4.i686.rpm libwbclient-devel-4.6.2-11.el7_4.x86_64.rpm samba-4.6.2-11.el7_4.x86_64.rpm samba-dc-4.6.2-11.el7_4.x86_64.rpm samba-dc-libs-4.6.2-11.el7_4.x86_64.rpm samba-devel-4.6.2-11.el7_4.i686.rpm samba-devel-4.6.2-11.el7_4.x86_64.rpm samba-python-4.6.2-11.el7_4.x86_64.rpm samba-test-4.6.2-11.el7_4.x86_64.rpm samba-test-libs-4.6.2-11.el7_4.i686.rpm samba-test-libs-4.6.2-11.el7_4.x86_64.rpm samba-vfs-glusterfs-4.6.2-11.el7_4.x86_64.rpm samba-winbind-krb5-locator-4.6.2-11.el7_4.x86_64.rpm noarch samba-common-4.6.2-11.el7_4.noarch.rpm samba-pidl-4.6.2-11.el7_4.noarch.rpm - Scientific Linux Development Team . Samba security patch notification concerns intermediate risks in SL7.x related to SMB authentication and ciphering weaknesses.. Samba Security, SL7 Network, SA Update, Moderate Threats, SMB Protocol. . LinuxSecurity.com Team

Calendar%202 Sep 21, 2017 Scientific Linux
87

Debian Wheezy: DSA-3034-1 Moderate: Iceweasel Signature Forgery Attack

Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the Mozilla Network Security Service library, embedded in Wheezy's Iceweasel package), was parsing ASN.1 data used in signatures, making it vulnerable to a signature forgery attack. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3034-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Yves-Alexis Perez September 25, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : iceweasel CVE ID : CVE-2014-1568 Antoine Delignat-Lavaud from Inria discovered an issue in the way NSS (the Mozilla Network Security Service library, embedded in Wheezy's Iceweasel package), was parsing ASN.1 data used in signatures, making it vulnerable to a signature forgery attack. An attacker could craft ASN.1 data to forge RSA certificates with a valid certification chain to a trusted CA. For the stable distribution (wheezy), this problem has been fixed in version 24.8.1esr-1~deb7u1. For the testing distribution (jessie) and unstable distribution (sid), Iceweasel uses the system NSS library, handled in DSA 3033-1. We recommend that you upgrade your iceweasel packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade Iceweasel to address the signature forgery vulnerability in the NSS package on Debian to ensure improved security.. Iceweasel Security, Debian Vulnerability, NSS Signature Forgery. . LinuxSecurity.com Team

Calendar%202 Sep 25, 2014 Debian
87

Debian: DSA-2234-2 Critical: OpenSSH Vulnerability Mitigation

Several vulnerabilities were discovered in Postfix, a mail transfer agent. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2233-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer May 10, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postfix Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2009-2939 CVE-2011-0411 CVE-2011-1720 Several vulnerabilities were discovered in Postfix, a mail transfer agent. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-2939 The postinst script grants the postfix user write access to /var/spool/postfix/pid, which might allow local users to conduct symlink attacks that overwrite arbitrary files. CVE-2011-0411 The STARTTLS implementation does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is processed after TLS is in place. CVE-2011-1720 A heap-based read-only buffer overflow allows malicious clients to crash the smtpd server process using a crafted SASL authentication request. For the oldstable distribution (lenny), this problem has been fixed in version 2.5.5-1.1+lenny1. For the stable distribution (squeeze), this problem has been fixed in version 2.7.1-1+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 2.8.0-1. We recommend that you upgrade your postfix packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be foundat: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-2234-2 tackles multiple sendmail vulnerabilities. Update advised for email relay application safety.. Postfix Update, Remote Attacks, Debian Security Advisory, Mail Transfer Agent, Common Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 10, 2011 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200