Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
87

Debian Bookworm DSA-5777-1 moderate: booth authentication flaw

It was discovered that the Booth cluster ticket manager failed to correctly validate some authentication hashes. For the stable distribution (bookworm), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5777-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 27, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : booth CVE ID : CVE-2024-3049 It was discovered that the Booth cluster ticket manager failed to correctly validate some authentication hashes. For the stable distribution (bookworm), this problem has been fixed in version 1.0-283-g9d4029a-2+deb12u1. We recommend that you upgrade your booth packages. For the detailed security status of booth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/booth Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the new Ubuntu Security Notice USN-1234-1 tackling vulnerabilities in the curl package. Update immediately!. booth security advisory, authentication hashes, Debian updates. . LinuxSecurity.com Team

Calendar%202 Sep 27, 2024 Debian
197

Debian 11: DLA-3894-1 moderate: booth invalid HMAC acceptance

Invalid HMAC could have been accepted in the Booth Cluster Ticket Manager. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3894-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 24, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : booth Version : 1.0-237-gdd88847-2+deb11u2 CVE ID : CVE-2024-3049 Debian Bug : 1073249 Invalid HMAC could have been accepted in the Booth Cluster Ticket Manager. For Debian 11 bullseye, this problem has been fixed in version 1.0-237-gdd88847-2+deb11u2. We recommend that you upgrade your booth packages. For the detailed security status of booth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/booth Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5021-1 addresses severe flaw in Libgcrypt's cryptographic functions.. Debian LTS, booth, security updates, cluster ticket manager, HMAC. . LinuxSecurity.com Team

Calendar%202 Sep 24, 2024 Debian LTS
100

SUSE: 2024:2251-1 Important: booth Security Threat - HMAC Issue

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2251-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Availability GEO Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability GEO Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-GEO-12-SP5-2024-2251=1 ## Package List: * SUSE Linux Enterprise High Availability GEO Extension 12 SP5 (s390x x86_64) * booth-debugsource-1.0-42.6.1 * booth-debuginfo-1.0-42.6.1 * booth-1.0-42.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3049.html * https://bugzilla.suse.com/show_bug.cgi?id=1226032 . Important security patch for booth rectifying CVE-2024-3050 vulnerabilities in Red Hat. Apply updates to enhance your protection.. SUSE Enterprise Security, CVE-2024-3049, booth security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 01, 2024 Important SuSE
100

SUSE: 2024:2062-1 Critical: CVE-2024-3049 HMAC Vulnerability Alert

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2062-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Availability Extension 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 Business Critical Linux 15-SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Manager Proxy 4.2 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Server 4.2 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2024-2062=1 * SUSE Linux Enterprise High Availability Extension 15 SP3 zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2024-2062=1 ## Package List: * openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64 i586) * booth-debugsource-1.0-150300.18.6.1 * booth-debuginfo-1.0-150300.18.6.1 * booth-1.0-150300.18.6.1 * booth-test-1.0-150300.18.6.1 * SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le s390x x86_64) * booth-debugsource-1.0-150300.18.6.1 * booth-debuginfo-1.0-150300.18.6.1 * booth-1.0-150300.18.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3049.html *https://bugzilla.suse.com/show_bug.cgi?id=1226032 . Crucial SUSE patch release targeting booth mitigates CVE-2024-3049, bearing severe consequences for impacted systems.. SUSE Security Advisory, booth Update, HMAC Vulnerability, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2024 Critical SuSE
100

SUSE: 2024:2063-1 Important: HMAC Security Update for Booth

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2063-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2024-2063=1 openSUSE-SLE-15.5-2024-2063=1 * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2024-2063=1 ## Package List: * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * booth-debuginfo-1.0+20220815.f40c2d5-150500.3.3.1 * booth-debugsource-1.0+20220815.f40c2d5-150500.3.3.1 * booth-1.0+20220815.f40c2d5-150500.3.3.1 * booth-test-1.0+20220815.f40c2d5-150500.3.3.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * booth-debuginfo-1.0+20220815.f40c2d5-150500.3.3.1 * booth-debugsource-1.0+20220815.f40c2d5-150500.3.3.1 * booth-1.0+20220815.f40c2d5-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3049.html * https://bugzilla.suse.com/show_bug.cgi?id=1226032 .Critical security update for booth IPs CVE-2024-3050 impacting several SUSE versions. Apply the update immediately!. booth security,SUSE update,HMAC patch,security advisory,update notification. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 18, 2024 Important SuSE
100

SUSE: 2024:2040-1 Important: Booth CVE-2024-3049 Security Issue

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2040-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2024-2040=1 openSUSE-SLE-15.6-2024-2040=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2024-2040=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * booth-debugsource-1.1+git0.09b0074-150600.3.3.1 * booth-debuginfo-1.1+git0.09b0074-150600.3.3.1 * booth-1.1+git0.09b0074-150600.3.3.1 * booth-test-1.1+git0.09b0074-150600.3.3.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * booth-debugsource-1.1+git0.09b0074-150600.3.3.1 * booth-debuginfo-1.1+git0.09b0074-150600.3.3.1 * booth-1.1+git0.09b0074-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3049.html * https://bugzilla.suse.com/show_bug.cgi?id=1226032 . Essential SUSE patch released for booth, addressing CVE-2024-3049 in multiple SUSEofferings, complete with detailed update information.. SUSE Linux Security, Booth Patch, CVE-2024-3049, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2024 Important SuSE
100

SUSE: 2024:2041-1 Important: CVE-2024-3049 Booth Security Issue

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2041-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 Business Critical Linux 15-SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Manager Proxy 4.1 * SUSE Manager Retail Branch Server 4.1 * SUSE Manager Server 4.1 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP2 zypper in -t patch SUSE-SLE-Product-HA-15-SP2-2024-2041=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP2 (aarch64 ppc64le s390x x86_64) * booth-debugsource-1.0-150100.11.6.1 * booth-debuginfo-1.0-150100.11.6.1 * booth-1.0-150100.11.6.1 ## References: * https://www.suse.com/security/cve/CVE-2024-3049.html * https://bugzilla.suse.com/show_bug.cgi?id=1226032 . A security advisory under ID: SUSE-SU-2024:2041-1 has been issued for booth, addressing CVE-2024-3049. It highlights the importance of the update and includes installation details.. booth security advisory,SUSE updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 17, 2024 Important SuSE
100

SUSE: 2024:2042-1 Critical: Booth Security Issue CVE-2024-3049

* bsc#1226032 Cross-References: * CVE-2024-3049 . # Security update for booth Announcement ID: SUSE-SU-2024:2042-1 Rating: important References: * bsc#1226032 Cross-References: * CVE-2024-3049 CVSS scores: * CVE-2024-3049 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2024-3049 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for booth fixes the following issues: * CVE-2024-3049: Fixed a vulnerability where a specially crafted hash can lead to invalid HMAC being accepted by Booth server. (bsc#1226032) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2024-2042=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2024-2042=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * booth-1.0+20210519.bfb2f92-150400.3.6.1 * booth-debuginfo-1.0+20210519.bfb2f92-150400.3.6.1 * booth-debugsource-1.0+20210519.bfb2f92-150400.3.6.1 * booth-test-1.0+20210519.bfb2f92-150400.3.6.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * booth-1.0+20210519.bfb2f92-150400.3.6.1 * booth-debuginfo-1.0+20210519.bfb2f92-150400.3.6.1 * booth-debugsource-1.0+20210519.bfb2f92-150400.3.6.1 ## References: *https://www.suse.com/security/cve/CVE-2024-3049.html * https://bugzilla.suse.com/show_bug.cgi?id=1226032 . Significant announcements regarding the SUSE Enterprise display; this notice outlines essential guidelines for enhancing security measures.. SUSE Linux, Security Update, Booth Vulnerability, Linux Enterprise, Important Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2024 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200