Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 20.04 LTS USN-7211-1 critical: audacity information exposure

Audacity could expose sensitive information.. ========================================================================== Ubuntu Security Notice USN-7211-1 January 16, 2025 audacity vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Audacity could expose sensitive information. Software Description: - audacity: fast, cross-platform audio editor Details: Mike Salvatore discovered that Audacity incorrectly handled default permissions of temporary files created by the application. An attacker could possibly use this issue to obtain sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS audacity 2.3.3-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 18.04 LTS audacity 2.2.1-1ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 16.04 LTS audacity 2.1.2-1ubuntu0.1~esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7211-1 CVE-2020-11867 . Important security vulnerability found in Audacity on Ubuntu versions 20.04, 18.04, and 16.04. Ensure you upgrade to the latest package releases to resolve this concern.. audacity security, Ubuntu updates, information exposure, Ubuntu Pro, software vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 16, 2025 Critical Ubuntu
89

Fedora 34: 2021-06-22 Audacity Information Disclosure Fix Moderate

- Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Fix CVE-2020-1867 (fixes rhbz #1904016). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-1a043ee3d2 2021-06-22 01:01:06.903238 --------------------------------------------------------------------------------Name : audacity Product : Fedora 34 Version : 3.0.2 Release : 3.fc34 URL : https://www.audacityteam.org/ Summary : Multitrack audio editor Description : Audacity is a cross-platform multitrack audio editor. It allows you to record sounds directly or to import files in various formats. It features a few simple effects, all of the editing features you should need, and unlimited undo. The GUI was built with wxWidgets and the audio I/O supports PulseAudio, OSS and ALSA under Linux. --------------------------------------------------------------------------------Update Information: - Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Fix CVE-2020-1867 (fixes rhbz #1904016) --------------------------------------------------------------------------------ChangeLog: * Thu Jun 17 2021 Ian McInerney - 3.0.2-3 - Fix detection of Jack development package (fixes rhbz #1972963) - Add packages needed for the LV2 interface to use the system libraries - Temporarily disable the rpath checks until upstream fixes it - Fix CVE-2020-1867 (fixes rhbz #1904016) --------------------------------------------------------------------------------References: [ 1 ] Bug #1904016 - CVE-2020-11867 audacity: insecure use of temporary directory leads to information disclosure [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1904016 [ 2 ] Bug #1972963 - audacity: no jack host listed via pipewire https://bugzilla.redhat.com/show_bug.cgi?id=1972963 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-1a043ee3d2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Arch's Studio update introduces vital improvements and boosts system efficiency alongside essential packages.. Fedora Audacity Update, Audacity Security Patch, Audio Editor Fixes. . LinuxSecurity.com Team

Calendar%202 Jun 21, 2021 Fedora
203

Mageia: 2021-0001 Moderate: Audacity File Access Concern

Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867). . MGASA-2021-0001 - Updated audacity package fixes security vulnerability Publication date: 02 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0001.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-11867 Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there (CVE-2020-11867). References: - https://bugs.mageia.org/show_bug.cgi?id=27850 - - https://www.cve.org/CVERecord?id=CVE-2020-11867 SRPMS: - 7/core/audacity-2.3.1-1.2.mga7 . Mageia has unveiled an Audacity update addressing a critical security flaw involving temporary files, potentially allowing unauthorized user access. More details are available here. Mageia Security, Audacity Update, File Permissions. . LinuxSecurity.com Team

Calendar%202 Jan 02, 2021 Mageia
202

openSUSE Leap 15.x: 2020:2262-1 Moderate Audacity Security Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for audacity ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:2261-1 Rating: moderate References: #1179449 Cross-References: CVE-2020-11867 Affected Products: openSUSE Leap 15.2 openSUSE Leap 15.1 openSUSE Backports SLE-15-SP2 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for audacity fixes the following issues: - CVE-2020-11867: Avoid saving temporary files to /var/tmp/audacity-$USER by default, which permissions are set to 755. (bsc#1179449) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Backports SLE-15-SP2: zypper in -t patch openSUSE-2020-2261=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-2261=1 Package List: - openSUSE Leap 15.2 (noarch): audacity-lang-2.2.2-lp152.4.3.1 - openSUSE Leap 15.2 (x86_64): audacity-2.2.2-lp152.4.3.1 audacity-debuginfo-2.2.2-lp152.4.3.1 audacity-debugsource-2.2.2-lp152.4.3.1 - openSUSE Leap 15.1 (noarch): audacity-lang-2.2.2-lp151.3.3.1 - openSUSE Leap 15.1 (x86_64): audacity-2.2.2-lp151.3.3.1 audacity-debuginfo-2.2.2-lp151.3.3.1 audacity-debugsource-2.2.2-lp151.3.3.1 - openSUSE Backports SLE-15-SP2 (aarch64 ppc64le s390xx86_64): audacity-2.2.2-bp152.4.3.1 audacity-debuginfo-2.2.2-bp152.4.3.1 audacity-debugsource-2.2.2-bp152.4.3.1 - openSUSE Backports SLE-15-SP2 (noarch): audacity-lang-2.2.2-bp152.4.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): audacity-2.2.2-bp151.4.3.1 - openSUSE Backports SLE-15-SP1 (noarch): audacity-lang-2.2.2-bp151.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-11867.html https://bugzilla.suse.com/1179449 _______________________________________________ openSUSE Security Announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe, email This email address is being protected from spambots. You need JavaScript enabled to view it. List Netiquette: List Archives: . Delve into the latest openSUSE security patch for Audacity, designed to rectify file access vulnerabilities while enhancing overall system protection.. openSUSE, Audacity Update, Security Patch. . LinuxSecurity.com Team

Calendar%202 Dec 15, 2020 OpenSUSE
91

Gentoo: GLSA-202310-05 Normal: VLC Media Player Vulnerability Expose

A boundary error in Audacity allows for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Audacity: User-assisted execution of arbitrary code Date: March 06, 2009 Bugs: #253493 ID: 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A boundary error in Audacity allows for the execution of arbitrary code. Background ========= Audacity is a free cross-platform audio editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/audacity < 1.3.6 > = 1.3.6 Description ========== Houssamix discovered a boundary error in the String_parse::get_nonspace_quoted() function in lib-src/allegro/strparse.cpp. Impact ===== A remote attacker could entice a user into importing a specially crafted *.gro file, resulting in the execution of arbitrary code or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Audacity users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/audacity-1.3.6" References ========= [ 1 ] CVE-2009-0490 https://www.cve.org/CVERecord?id=CVE-2009-0490 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A buffer overflow vulnerability in Audacity enables threat actors to run unauthorized commands, creating a security concern within Debian Linux distributions.. Audacity Security,Gentoo Advisory,Code Execution Risk,Boundary Error,User-Assisted Threats. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200