Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
202

openSUSE Leap 15.3 Important: Cryptctl Password Client Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for cryptctl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2136-1 Rating: important References: #1186226 Cross-References: CVE-2019-18906 Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptctl fixes the following issues: Update to version 2.4: - CVE-2019-18906: Client side password hashing was equivalent to clear text password storage (bsc#1186226) - First step to use plain text password instead of hashed password. - Move repository into the SUSE github organization - in RPC server, if client comes from localhost, remember its ipv4 localhost address instead of ipv6 address - tell a record to clear expired pending commands upon saving a command result; introduce pending commands RPC test case - avoid hard coding 127.0.0.1 in host ID of alive message test; let system administrator mount and unmount disks by issuing these two commands on key server. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2136=1 Package List: - openSUSE Leap 15.3 (ppc64le x86_64): cryptctl-2.4-4.5.1 cryptctl-debuginfo-2.4-4.5.1 References: https://www.suse.com/security/cve/CVE-2019-18906.html https://bugzilla.suse.com/1186226 . Critical patch released for cryptctl taking care of a severe client password encryption flaw in openSUSE Leap 15.3.. openSUSE Security Update,Crypto Security,Password Management. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jul 10, 2021 Important OpenSUSE
203

Mageia 7: 2020-0042 Moderate: Tigervnc Client And Server Issues

Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the . MGASA-2020-0042 - Updated tigervnc packages fix security vulnerabilities Publication date: 19 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0042.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695 Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the software on the other side. No working exploit is known at this time, and the issues require the peer to first be authenticated (CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695). References: - https://bugs.mageia.org/show_bug.cgi?id=25917 - https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1 - https://www.openwall.com/lists/oss-security/2019/12/20/2 - https://www.cve.org/CVERecord?id=CVE-2019-15691 - https://www.cve.org/CVERecord?id=CVE-2019-15692 - https://www.cve.org/CVERecord?id=CVE-2019-15693 - https://www.cve.org/CVERecord?id=CVE-2019-15694 - https://www.cve.org/CVERecord?id=CVE-2019-15695 SRPMS: - 7/core/tigervnc-1.10.1-1.mga7 . Recent updates to tigervnc packages tackle security vulnerabilities that could enable unauthorized control by malicious actors. Learn more about the specifics of these fixes.. tigervnc update, mageia security, package vulnerabilities, software patching. . LinuxSecurity.com Team

Calendar%202 Jan 19, 2020 Mageia
200

SciLinux: SLSA-2018-2439-1 Moderate: MariaDB Security Update for SL7

mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 20 [More...]. Synopsis: Moderate: mariadb security and bug fix update Advisory ID: SLSA-2018:2439-1 Issue Date: 2018-08-16 CVE Numbers: CVE-2017-3636 CVE-2017-3641 CVE-2017-3653 CVE-2017-10268 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 CVE-2018-2562 CVE-2018-2622 CVE-2018-2640 CVE-2018-2665 CVE-2018-2668 CVE-2018-2755 CVE-2018-2761 CVE-2018-2771 CVE-2018-2781 CVE-2018-2813 CVE-2018-2817 CVE-2018-2819 CVE-2017-3651 CVE-2018-2767 -- The following packages have been upgraded to a later upstream version: mariadb (5.5.60). Security Fix(es): * mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) (CVE-2017-10378) * mysql: Client programs unspecified vulnerability (CPU Oct 2017) (CVE-2017-10379) * mysql: Server: DDL unspecified vulnerability (CPU Oct 2017) (CVE-2017-10384) * mysql: Server: Partition unspecified vulnerability (CPU Jan 2018) (CVE-2018-2562) * mysql: Server: DDLunspecified vulnerability (CPU Jan 2018) (CVE-2018-2622) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2640) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2665) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2668) * mysql: Server: Replication unspecified vulnerability (CPU Apr 2018) (CVE-2018-2755) * mysql: Client programs unspecified vulnerability (CPU Apr 2018) (CVE-2018-2761) * mysql: Server: Locking unspecified vulnerability (CPU Apr 2018) (CVE-2018-2771) * mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2018) (CVE-2018-2781) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2813) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2817) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2819) * mysql: Server: DDL unspecified vulnerability (CPU Jul 2017) (CVE-2017-3653) * mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM) (CVE-2018-2767) Bug Fix(es): * Previously, the mysqladmin tool waited for an inadequate length of time if the socket it listened on did not respond in a specific way. Consequently, when the socket was used while the MariaDB server was starting, the mariadb service became unresponsive for a long time. With this update, the mysqladmin timeout has been shortened to 2 seconds. As a result, the mariadb service either starts or fails but no longer hangs in the described situation. -- SL7 x86_64 mariadb-5.5.60-1.el7_5.x86_64.rpm mariadb-debuginfo-5.5.60-1.el7_5.i686.rpm mariadb-debuginfo-5.5.60-1.el7_5.x86_64.rpm mariadb-libs-5.5.60-1.el7_5.i686.rpm mariadb-libs-5.5.60-1.el7_5.x86_64.rpm mariadb-server-5.5.60-1.el7_5.x86_64.rpm mariadb-bench-5.5.60-1.el7_5.x86_64.rpm mariadb-devel-5.5.60-1.el7_5.i686.rpm mariadb-devel-5.5.60-1.el7_5.x86_64.rpm mariadb-embedded-5.5.60-1.el7_5.i686.rpm mariadb-embedded-5.5.60-1.el7_5.x86_64.rpm mariadb-embedded-devel-5.5.60-1.el7_5.i686.rpm mariadb-embedded-devel-5.5.60-1.el7_5.x86_64.rpm mariadb-test-5.5.60-1.el7_5.x86_64.rpm mariadb-5.5.60-1.el7_5.src.rpm - Scientific Linux Development Team . The recent mariadb update for SL7 has introduced a significant security patch that tackles various vulnerabilities affecting both client and server functionalities.. scientific linux,mariadb,security advisory,client issues,server issues. . LinuxSecurity.com Team

Calendar%202 Aug 16, 2018 Scientific Linux
91

Gentoo: GLSA-202301-07 High: MyApp External Data Exposure Threat

Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201705-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Teeworlds: Remote execution of arbitrary code on client Date: May 26, 2017 Bugs: #600178 ID: 201705-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Teeworlds client vulnerability in snap handling could result in execution of arbitrary code. Background ========= Teeworlds is an online multi-player platform 2D shooter. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 games-action/teeworlds < 0.6.4 > = 0.6.4 Description ========== Teeworlds client contains a vulnerability allowing a malicious server to execute arbitrary code, or write to arbitrary physical memory via the CClient::ProcessServerPacket method. Impact ===== A remote malicious server can write to arbitrary physical memory locations and possibly execute arbitrary if a vulnerable client joins the server. Workaround ========= There is no known workaround at this time. Resolution ========= All Teeworlds users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-action/teeworlds-0.6.4:0" References ========= [ 1 ] CVE-2016-9400 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9400 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201705-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . Recent Teeworlds client security advisory highlights potential threats of unauthorized code execution. Suggested update to mitigate vulnerabilities.. Teeworlds, Remote Code Execution, Gentoo Advisory. . LinuxSecurity.com Team

Calendar%202 May 26, 2017 Gentoo
98

Red Hat 9 RHSA-2004:154-01 Critical: CVS Client Exploitation

Updated cvs packages that fix a client vulnerability that could be exploited by a malicious server are now available.. Red Hat Security Advisory Synopsis: Updated CVS packages fix security issue Advisory ID: RHSA-2004:154-01 Issue date: 2004-04-14 Updated on: 2004-04-14 Product: Red Hat Linux Keywords: Cross references: Obsoletes: RHSA-2004:003 CVE Names: CAN-2004-0180 - --------------------------------------------------------------------- 1. Topic: Updated cvs packages that fix a client vulnerability that could be exploited by a malicious server are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: CVS is a version control system frequently used to manage source code repositories. Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can create files with absolute pathnames. An attacker could create a fake malicious CVS server that would cause arbitrary files to be created or overwritten when a victim connects to it. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0180 to this issue. Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the followingcommand: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- 44ad2349b6b00275273280eac1a52e20 9/en/os/SRPMS/cvs-1.11.2-17.src.rpm 586d676137b75f940baa90ee28fd33ce 9/en/os/i386/cvs-1.11.2-17.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2004-0180 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Updated CVS packages from Red Hat fix critical client exploitation risk posed by malicious servers for Linux.. Red Hat Security,cvs update,client issue,escape threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 14, 2004 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200