Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
91

Gentoo: GLSA-202402-32 Normal: btrbk Remote Code Execution

A vulnerability has been discovered in btrbk which can lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202402-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: btrbk: Remote Code Execution Date: February 26, 2024 Bugs: #806962 ID: 202402-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in btrbk which can lead to remote code execution. Background ========== btrbk is a backup tool for btrfs subvolumes, taking advantage of btrfs specific capabilities to create atomic snapshots and transfer them incrementally to your backup locations. Affected packages ================= Package Vulnerable Unaffected ---------------- ------------ ------------ app-backup/btrbk < 0.31.2 > = 0.31.2 Description =========== A vulnerability has been discovered in btrbk. Please review the CVE identifier referenced below for details. Impact ====== Specialy crafted commands may be executed without being propely checked. Applies to remote hosts filtering ssh commands using ssh_filter_btrbk.sh in authorized_keys. Workaround ========== There is no known workaround at this time. Resolution ========== All btrbk users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-backup/btrbk-0.31.2" References ========== [ 1 ] CVE-2021-38173 https://nvd.nist.gov/vuln/detail/CVE-2021-38173 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202402-32 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and securityof our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2024 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . An exploit in ztrbk may allow for remote control. Update now to resolve. Fix has been released. Immediate action required.. remote Code Execution,Gentoo Linux,btrbk security,system exploit. . LinuxSecurity.com Team

Calendar 2 Feb 26, 2024 Gentoo
89

Fedora 35: FEDORA-2022-a66734e7a2 Moderate: Btrbk Script Permission Fix

Remove executable permissions from scripts in /usr/shar. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-a66734e7a2 2022-01-19 02:10:14.239473 --------------------------------------------------------------------------------Name : btrbk Product : Fedora 35 Version : 0.31.3 Release : 1.fc35 URL : https://digint.ch/btrbk/ Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes Description : Backup tool for btrfs sub-volumes, using a configuration file, allows creation of backups from multiple sources to multiple destinations, with ssh and flexible retention policy support (hourly, daily, weekly, monthly) --------------------------------------------------------------------------------Update Information: Remove executable permissions from scripts in /usr/shar --------------------------------------------------------------------------------ChangeLog: * Mon Jan 10 2022 Juan Orti Alcaine - 0.31.3-1 - Version 0.31.3 (#1765928) - Remove executable permissions from scripts in /usr/share (#1994989) --------------------------------------------------------------------------------References: [ 1 ] Bug #1994989 - CVE-2021-38173 btrbk: remote execution in ssh_filter_btrbk.sh [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1994989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-a66734e7a2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . The release FEDORA-2022-b77c82f6b3 implements updates to the access controls of btrbk utilities to fortify defenses against unauthorized remote commands.. Btrbk Tool, Fedora Update, Snapshot Backups, Script Security. . LinuxSecurity.com Team

Calendar 2 Jan 18, 2022 Fedora
89

Fedora 34: FEDORA-2022-dc62389784 Critical: btrbk Remote Execution Risk

Remove executable permissions from scripts in /usr/share. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-dc62389784 2022-01-19 01:53:29.295579 --------------------------------------------------------------------------------Name : btrbk Product : Fedora 34 Version : 0.31.3 Release : 1.fc34 URL : https://digint.ch/btrbk/ Summary : Tool for creating snapshots and remote backups of btrfs sub-volumes Description : Backup tool for btrfs sub-volumes, using a configuration file, allows creation of backups from multiple sources to multiple destinations, with ssh and flexible retention policy support (hourly, daily, weekly, monthly) --------------------------------------------------------------------------------Update Information: Remove executable permissions from scripts in /usr/share --------------------------------------------------------------------------------ChangeLog: * Mon Jan 10 2022 Juan Orti Alcaine - 0.31.3-1 - Version 0.31.3 (#1765928) - Remove executable permissions from scripts in /usr/share (#1994989) * Wed Jul 21 2021 Fedora Release Engineering - 0.28.3-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1994989 - CVE-2021-38173 btrbk: remote execution in ssh_filter_btrbk.sh [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1994989 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-dc62389784' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Update notice for btrbk on Fedora 34; mitigates elevated execution vulnerability by modifying script permissions in /usr/share.. btrbk updates,Fedora 34 advisories,remote exec risks,script permissions,btrfs backup tool. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 18, 2022 Critical Fedora
197

Debian 9: DLA-2755-1 Critical: Btrbk Arbitrary Code Execution Fix

An issue has been found in btrbk, a backup tool for btrfs subvolumes. Due to mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys an arbitrary code execution would . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2755-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz September 05, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : btrbk Version : 0.24.0-1+deb9u1 CVE ID : CVE-2021-38173 An issue has been found in btrbk, a backup tool for btrfs subvolumes. Due to mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys an arbitrary code execution would have been allowed. For Debian 9 stretch, this problem has been fixed in version 0.24.0-1+deb9u1. We recommend that you upgrade your btrbk packages. For the detailed security status of btrbk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/btrbk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance btrbk to mitigate arbitrary code execution vulnerability as per Debian LTS Advisory DLA-2755-1.. btrbk update, Debian security, backup tool vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 05, 2021 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here