Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4069-1
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments. . MGASA-2024-0288 - Updated orc packages fix security vulnerability Publication date: 10 Sep 2024 URL: https://advisories.mageia.org/MGASA-2024-0288.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-40897 Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39. If a developer is tricked to process a specially crafted file with the affected ORC compiler, an arbitrary code may be executed on the developer's build environment. This may lead to compromise of developer machines or CI build environments. (CVE-2024-40897) References: - https://bugs.mageia.org/show_bug.cgi?id=33529 - https://ubuntu.com/security/notices/USN-6964-1 - https://www.cve.org/CVERecord?id=CVE-2024-40897 SRPMS: - 9/core/orc-0.4.33-1.1.mga9 . A stack-related buffer overflow issue in ORC poses a risk of unauthorized code execution that may compromise system integrity. Urgent patches are advised.. orc packages,Mageia security,buffer overflow fix,software vulnerability,developer security. . Severity: Critical. LinuxSecurity.com Team
A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3653-1
Jupyter Core could be made to run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-6153-1 June 12, 2023 jupyter-core vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.10 - Ubuntu 22.04 LTS (Available with Ubuntu Pro) - Ubuntu 20.04 LTS (Available with Ubuntu Pro) - Ubuntu 18.04 LTS (Available with Ubuntu Pro) Summary: Jupyter Core could be made to run programs as your login if it opened a specially crafted file. Software Description: - jupyter-core: Core common functionality of Jupyter projects (tools) Details: It was discovered that Jupyter Core executed untrusted files in the current working directory. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.10: python3-jupyter-core 4.11.1-1ubuntu0.22.10.1 Ubuntu 22.04 LTS (Available with Ubuntu Pro): python3-jupyter-core 4.9.1-1ubuntu0.1~esm1 Ubuntu 20.04 LTS (Available with Ubuntu Pro): python3-jupyter-core 4.6.3-3ubuntu0.1~esm1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): python-jupyter-core 4.4.0-2ubuntu0.1~esm1 python3-jupyter-core 4.4.0-2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6153-1 CVE-2022-39286 Package Information: https://launchpad.net/ubuntu/+source/jupyter-core/4.11.1-1ubuntu0.22.10.1 . Investigate the Jupyter Core vulnerability in Ubuntu that affects multiple releases. Ensure to apply the latest patches immediately to protect against potential unauthorized code execution.. Jupyter Core Vulnerability, Ubuntu Software Security, PythonKernel Flaw. . Severity: Critical. LinuxSecurity.com Team
Several security issues were fixed in Nanopb.. =========================================================================Ubuntu Security Notice USN-6121-1 May 30, 2023 nanopb vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Nanopb. Software Description: - nanopb: Protocol Buffers with small code size Details: It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this cause a denial of service or expose sensitive information. (CVE-2020-26243) It was discovered that Nanopb incorrectly handled certain decode messages. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2021-21401) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS (Available with Ubuntu Pro): nanopb 0.4.1-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6121-1 CVE-2020-26243, CVE-2021-21401 . Multiple vulnerabilities in Nanopb resolved via Ubuntu Security Notice USN-6121-1 mitigating code execution and denial-of-service threats.. Nanopb Security, Ubuntu Updates, DoS Protection. . LinuxSecurity.com Team
It was discovered that SPIP, a website engine for publishing, would allow a malicious user to execute arbitrary code. For the stable distribution (bullseye), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5367-1
Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-1
An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: libksba security update Advisory ID: RHSA-2023:0594-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:0594 Issue date: 2023-02-06 CVE Names: CVE-2022-47629 ==================================================================== 1. Summary: An update for libksba is now available for Red Hat Enterprise Linux 8.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat CodeReady Linux Builder EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux BaseOS EUS (v.8.6) - aarch64, ppc64le, s390x, x86_64 3. Description: KSBA (pronounced Kasbah) is a library to make X.509 certificates as well as the CMS easily accessible by other applications. Both specifications are building blocks of S/MIME and TLS. Security Fix(es): * libksba: integer overflow to code executiona (CVE-2022-47629) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2161571 - CVE-2022-47629 libksba:integer overflow to code execution 6. Package List: Red Hat Enterprise Linux BaseOS EUS (v.8.6): Source: libksba-1.3.5-9.el8_6.src.rpm aarch64: libksba-1.3.5-9.el8_6.aarch64.rpm libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-1.3.5-9.el8_6.ppc64le.rpm libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-1.3.5-9.el8_6.s390x.rpm libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-1.3.5-9.el8_6.i686.rpm libksba-1.3.5-9.el8_6.x86_64.rpm libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm Red Hat CodeReady Linux Builder EUS (v.8.6): aarch64: libksba-debuginfo-1.3.5-9.el8_6.aarch64.rpm libksba-debugsource-1.3.5-9.el8_6.aarch64.rpm libksba-devel-1.3.5-9.el8_6.aarch64.rpm ppc64le: libksba-debuginfo-1.3.5-9.el8_6.ppc64le.rpm libksba-debugsource-1.3.5-9.el8_6.ppc64le.rpm libksba-devel-1.3.5-9.el8_6.ppc64le.rpm s390x: libksba-debuginfo-1.3.5-9.el8_6.s390x.rpm libksba-debugsource-1.3.5-9.el8_6.s390x.rpm libksba-devel-1.3.5-9.el8_6.s390x.rpm x86_64: libksba-debuginfo-1.3.5-9.el8_6.i686.rpm libksba-debuginfo-1.3.5-9.el8_6.x86_64.rpm libksba-debugsource-1.3.5-9.el8_6.i686.rpm libksba-debugsource-1.3.5-9.el8_6.x86_64.rpm libksba-devel-1.3.5-9.el8_6.i686.rpm libksba-devel-1.3.5-9.el8_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-47629 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY+FwatzjgjWX9erEAQjkEQ/+MjgHxmWjyizq0RATTn3EmEFo4zRkuT7/ xMuwNFp0nM/oG0s+PSGHosHEb9qIHvEOVSABWIAV5YsrPDtulL5j2YpdsFcYq9Xf 19X5gY7TUt1yaIDykxxnyWs1fP/8551J8WtwSOPk5hGAcULBd9QmllCjIjernWnj PfKvqvPl3us4fBHwiwO2FFPT8/ddUcKuDXMyHMWwRVyolfLI71lScF/J4/bCNZOh gCE1ujmEnsCDenyWr2Zk6Q+rq+xMVIxlNGI4wXKqAi1izaA1rMjsCdaIBabcMhBL EQxJ04oFlGUvB4obCWPzTdnInBanH64WiNbZWzI8/zMCxRh83Qx2rmMV0+ie455q nTTu2HNFRRMto8MKZSInKkbA3EfBo1S0dNSNnCAtsYm+3pCQry9kzbLssdcbqdSq WRELA5Em8RQqwxg+6+HRvk4D6jKl8rAd37qcDBSbL1XKvhIKk3O3/bgLzgKdopTB L0rFPLv8VAELGyRbnZ9nTZHjHZYOmk07ula+sMsAMualm2hMiKSXFreYNQF8bxwB LStcWvZkO8MAAeoL+SiRHfxV2wuyB50vEchDfdTVUsyPE8ny2nTGya8igVmtN7/h +aYebE+QbI450/eMtvOSUhdblMrO4A9JPYgQD3heMPmIZvkqWmDzFvP2F0VmLPz9 fdY5Xv3Pk5I=xQ5I -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Get the latest Linux and open source security news straight to your inbox.