Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for cryptctl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:2136-1 Rating: important References: #1186226 Cross-References: CVE-2019-18906 Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cryptctl fixes the following issues: Update to version 2.4: - CVE-2019-18906: Client side password hashing was equivalent to clear text password storage (bsc#1186226) - First step to use plain text password instead of hashed password. - Move repository into the SUSE github organization - in RPC server, if client comes from localhost, remember its ipv4 localhost address instead of ipv6 address - tell a record to clear expired pending commands upon saving a command result; introduce pending commands RPC test case - avoid hard coding 127.0.0.1 in host ID of alive message test; let system administrator mount and unmount disks by issuing these two commands on key server. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2021-2136=1 Package List: - openSUSE Leap 15.3 (ppc64le x86_64): cryptctl-2.4-4.5.1 cryptctl-debuginfo-2.4-4.5.1 References: https://www.suse.com/security/cve/CVE-2019-18906.html https://bugzilla.suse.com/1186226 . Critical patch released for cryptctl taking care of a severe client password encryption flaw in openSUSE Leap 15.3.. openSUSE Security Update,Crypto Security,Password Management. . Severity: Important.LinuxSecurity.com Team
Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the . MGASA-2020-0042 - Updated tigervnc packages fix security vulnerabilities Publication date: 19 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0042.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695 Updated tigervnc packages fix security vulnerabilities: The tigervnc package has been updated to version 1.10.1 to fix multiple unspecified security issues. These issues affect both the client and server and could theoretically allow an malicious peer to take control over the software on the other side. No working exploit is known at this time, and the issues require the peer to first be authenticated (CVE-2019-15691, CVE-2019-15692, CVE-2019-15693, CVE-2019-15694, CVE-2019-15695). References: - https://bugs.mageia.org/show_bug.cgi?id=25917 - https://github.com/TigerVNC/tigervnc/releases/tag/v1.10.1 - https://www.openwall.com/lists/oss-security/2019/12/20/2 - https://www.cve.org/CVERecord?id=CVE-2019-15691 - https://www.cve.org/CVERecord?id=CVE-2019-15692 - https://www.cve.org/CVERecord?id=CVE-2019-15693 - https://www.cve.org/CVERecord?id=CVE-2019-15694 - https://www.cve.org/CVERecord?id=CVE-2019-15695 SRPMS: - 7/core/tigervnc-1.10.1-1.mga7 . Recent updates to tigervnc packages tackle security vulnerabilities that could enable unauthorized control by malicious actors. Learn more about the specifics of these fixes.. tigervnc update, mageia security, package vulnerabilities, software patching. . LinuxSecurity.com Team
mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 20 [More...]. Synopsis: Moderate: mariadb security and bug fix update Advisory ID: SLSA-2018:2439-1 Issue Date: 2018-08-16 CVE Numbers: CVE-2017-3636 CVE-2017-3641 CVE-2017-3653 CVE-2017-10268 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 CVE-2018-2562 CVE-2018-2622 CVE-2018-2640 CVE-2018-2665 CVE-2018-2668 CVE-2018-2755 CVE-2018-2761 CVE-2018-2771 CVE-2018-2781 CVE-2018-2813 CVE-2018-2817 CVE-2018-2819 CVE-2017-3651 CVE-2018-2767 -- The following packages have been upgraded to a later upstream version: mariadb (5.5.60). Security Fix(es): * mysql: Client programs unspecified vulnerability (CPU Jul 2017) (CVE-2017-3636) * mysql: Server: DML unspecified vulnerability (CPU Jul 2017) (CVE-2017-3641) * mysql: Client mysqldump unspecified vulnerability (CPU Jul 2017) (CVE-2017-3651) * mysql: Server: Replication unspecified vulnerability (CPU Oct 2017) (CVE-2017-10268) * mysql: Server: Optimizer unspecified vulnerability (CPU Oct 2017) (CVE-2017-10378) * mysql: Client programs unspecified vulnerability (CPU Oct 2017) (CVE-2017-10379) * mysql: Server: DDL unspecified vulnerability (CPU Oct 2017) (CVE-2017-10384) * mysql: Server: Partition unspecified vulnerability (CPU Jan 2018) (CVE-2018-2562) * mysql: Server: DDLunspecified vulnerability (CPU Jan 2018) (CVE-2018-2622) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2640) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2665) * mysql: Server: Optimizer unspecified vulnerability (CPU Jan 2018) (CVE-2018-2668) * mysql: Server: Replication unspecified vulnerability (CPU Apr 2018) (CVE-2018-2755) * mysql: Client programs unspecified vulnerability (CPU Apr 2018) (CVE-2018-2761) * mysql: Server: Locking unspecified vulnerability (CPU Apr 2018) (CVE-2018-2771) * mysql: Server: Optimizer unspecified vulnerability (CPU Apr 2018) (CVE-2018-2781) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2813) * mysql: Server: DDL unspecified vulnerability (CPU Apr 2018) (CVE-2018-2817) * mysql: InnoDB unspecified vulnerability (CPU Apr 2018) (CVE-2018-2819) * mysql: Server: DDL unspecified vulnerability (CPU Jul 2017) (CVE-2017-3653) * mysql: use of SSL/TLS not enforced in libmysqld (Return of BACKRONYM) (CVE-2018-2767) Bug Fix(es): * Previously, the mysqladmin tool waited for an inadequate length of time if the socket it listened on did not respond in a specific way. Consequently, when the socket was used while the MariaDB server was starting, the mariadb service became unresponsive for a long time. With this update, the mysqladmin timeout has been shortened to 2 seconds. As a result, the mariadb service either starts or fails but no longer hangs in the described situation. -- SL7 x86_64 mariadb-5.5.60-1.el7_5.x86_64.rpm mariadb-debuginfo-5.5.60-1.el7_5.i686.rpm mariadb-debuginfo-5.5.60-1.el7_5.x86_64.rpm mariadb-libs-5.5.60-1.el7_5.i686.rpm mariadb-libs-5.5.60-1.el7_5.x86_64.rpm mariadb-server-5.5.60-1.el7_5.x86_64.rpm mariadb-bench-5.5.60-1.el7_5.x86_64.rpm mariadb-devel-5.5.60-1.el7_5.i686.rpm mariadb-devel-5.5.60-1.el7_5.x86_64.rpm mariadb-embedded-5.5.60-1.el7_5.i686.rpm mariadb-embedded-5.5.60-1.el7_5.x86_64.rpm mariadb-embedded-devel-5.5.60-1.el7_5.i686.rpm mariadb-embedded-devel-5.5.60-1.el7_5.x86_64.rpm mariadb-test-5.5.60-1.el7_5.x86_64.rpm mariadb-5.5.60-1.el7_5.src.rpm - Scientific Linux Development Team . The recent mariadb update for SL7 has introduced a significant security patch that tackles various vulnerabilities affecting both client and server functionalities.. scientific linux,mariadb,security advisory,client issues,server issues. . LinuxSecurity.com Team
Teeworlds client vulnerability in snap handling could result in execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201705-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Teeworlds: Remote execution of arbitrary code on client Date: May 26, 2017 Bugs: #600178 ID: 201705-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Teeworlds client vulnerability in snap handling could result in execution of arbitrary code. Background ========= Teeworlds is an online multi-player platform 2D shooter. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 games-action/teeworlds < 0.6.4 > = 0.6.4 Description ========== Teeworlds client contains a vulnerability allowing a malicious server to execute arbitrary code, or write to arbitrary physical memory via the CClient::ProcessServerPacket method. Impact ===== A remote malicious server can write to arbitrary physical memory locations and possibly execute arbitrary if a vulnerable client joins the server. Workaround ========= There is no known workaround at this time. Resolution ========= All Teeworlds users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-action/teeworlds-0.6.4:0" References ========= [ 1 ] CVE-2016-9400 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-9400 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201705-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Updated cvs packages that fix a client vulnerability that could be exploited by a malicious server are now available.. Red Hat Security Advisory Synopsis: Updated CVS packages fix security issue Advisory ID: RHSA-2004:154-01 Issue date: 2004-04-14 Updated on: 2004-04-14 Product: Red Hat Linux Keywords: Cross references: Obsoletes: RHSA-2004:003 CVE Names: CAN-2004-0180 - --------------------------------------------------------------------- 1. Topic: Updated cvs packages that fix a client vulnerability that could be exploited by a malicious server are now available. 2. Relevant releases/architectures: Red Hat Linux 9 - i386 3. Problem description: CVS is a version control system frequently used to manage source code repositories. Sebastian Krahmer discovered a flaw in CVS clients where rcs diff files can create files with absolute pathnames. An attacker could create a fake malicious CVS server that would cause arbitrary files to be created or overwritten when a victim connects to it. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2004-0180 to this issue. Users of CVS are advised to upgrade to these erratum packages, which contain a patch correcting this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the followingcommand: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 9: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- 44ad2349b6b00275273280eac1a52e20 9/en/os/SRPMS/cvs-1.11.2-17.src.rpm 586d676137b75f940baa90ee28fd33ce 9/en/os/i386/cvs-1.11.2-17.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: CVE -CVE-2004-0180 8. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . Updated CVS packages from Red Hat fix critical client exploitation risk posed by malicious servers for Linux.. Red Hat Security,cvs update,client issue,escape threat. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.