Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 32: FEDORA-2020-73bd8167a0 Critical: CouchDB Access Issues

CouchDB 3.0.0. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-73bd8167a0 2020-03-16 20:26:14.978062 --------------------------------------------------------------------------------Name : couchdb Product : Fedora 32 Version : 3.0.0 Release : 1.fc32 URL : https://couchdb.apache.org/ Summary : A document database server, accessible via a RESTful JSON API Description : Apache CouchDB is a distributed, fault-tolerant and schema-free document-oriented database accessible via a RESTful HTTP/JSON API. Among other features, it provides robust, incremental replication with bi-directional conflict detection and resolution, and is queryable and indexable using a table-oriented view engine with JavaScript acting as the default view definition language. --------------------------------------------------------------------------------Update Information: CouchDB 3.0.0 --------------------------------------------------------------------------------ChangeLog: * Thu Mar 28 2019 Peter Lemenkov - 2.3.1-1 - Ver. 2.3.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1803197 - Install of CouchDB on Fedora 31 fails because nothing provides libmozjs185.so.1.0 https://bugzilla.redhat.com/show_bug.cgi?id=1803197 [ 2 ] Bug #1660481 - CVE-2018-17188 couchdb: Remote Privilege Escalations [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660481 [ 3 ] Bug #1660403 - CVE-2018-11769 couchdb: Possible privilege escalation by couchdb administrator to system couchdb user [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1660403 [ 4 ] Bug #1601003 - CVE-2018-8007 couchdb: Administrative Privilege Escalation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1601003 [ 5 ] Bug #1799258 - couchdb: FTBFS in Fedora rawhide/f32 https://bugzilla.redhat.com/show_bug.cgi?id=1799258 [ 6 ]Bug #1377306 - couchdb-3.0.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1377306 [ 7 ] Bug #1767037 - couchdb broken dependancies https://bugzilla.redhat.com/show_bug.cgi?id=1767037 [ 8 ] Bug #1735052 - couchdb: FTBFS in Fedora rawhide/f31 https://bugzilla.redhat.com/show_bug.cgi?id=1735052 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-73bd8167a0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The release of CouchDB 3.0.0 for Fedora 32 brings significant improvements, focusing on enhancing both security and performance metrics.. CouchDB Update, Fedora 32 Security, Document Database Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 16, 2020 Critical Fedora
100

SUSE: 2021:0456-2 Critical Security Update for MongoDB Released

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for couchdb ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0392-1 Rating: important References: #1104204 Cross-References: CVE-2018-11769 Affected Products: SUSE OpenStack Cloud Crowbar 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for couchdb fixes the following issues: Security issue fixed: - CVE-2018-11769: Fixed a remote code execution vulnerability by removing the _config route from default.ini (bsc#1104204) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2019-392=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): couchdb-1.7.2-3.6.1 couchdb-debuginfo-1.7.2-3.6.1 couchdb-debugsource-1.7.2-3.6.1 References: https://www.suse.com/security/cve/CVE-2018-11769.html https://bugzilla.suse.com/1104204 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update: Security update for couchdb __________________________________________________. update, security, fixes, vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 14, 2019 Important SuSE
100

SUSE: 2018:2578-1 Important: CouchDB Configuration Flaws Detected

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for couchdb ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:2578-1 Rating: important References: #1068386 #1100973 Cross-References: CVE-2017-12636 CVE-2018-8007 Affected Products: SUSE OpenStack Cloud 7 SUSE Enterprise Storage 4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for couchdb to 1.7.2 fixes the following security issues: - CVE-2018-8007: Apache CouchDB administrative users can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it was possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user that CouchDB runs under, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API (bsc#1100973). - CVE-2017-12636: CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allowed an admin user in Apache CouchDB to execute arbitrary shell commands as the CouchDB user (bsc#1068386). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2018-1807=1 - SUSE Enterprise Storage 4: zypper in -t patch SUSE-Storage-4-2018-1807=1 Package List: - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64): couchdb-1.7.2-2.8.2 couchdb-debuginfo-1.7.2-2.8.2 couchdb-debugsource-1.7.2-2.8.2 - SUSE Enterprise Storage 4 (aarch64 x86_64): couchdb-1.7.2-2.8.2 couchdb-debuginfo-1.7.2-2.8.2 couchdb-debugsource-1.7.2-2.8.2 References: https://www.suse.com/security/cve/CVE-2017-12636.html https://www.suse.com/security/cve/CVE-2018-8007.html https://bugzilla.suse.com/1068386 https://bugzilla.suse.com/1100973 . A recent update for CouchDB addresses critical security vulnerabilities impacting both SUSE OpenStack Cloud and SUSE Enterprise Storage platforms.. SUSE OpenStack Cloud,CouchDB Security Update,SUSE Enterprise Storage,Configuration Issues,Apache CouchDB. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 31, 2018 Important SuSE
89

Fedora 26: 2017-12-09 Moderate: Command Injection in Erlang-Jiffy

* CouchDB ver. 1.7.1 * Fixed CVE-2017-12635 * Fixed CVE-2017-12636 * Switched to eunit for testing * Erlang 20 compatible. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d0a336a2a3 2017-12-09 21:09:01.031086 --------------------------------------------------------------------------------Name : erlang-jiffy Product : Fedora 26 Version : 0.14.13 Release : 1.fc26 URL : https://github.com/davisp/jiffy Summary : Erlang JSON parser Description : A JSON parser for Erlang implemented as a NIF. --------------------------------------------------------------------------------Update Information: * CouchDB ver. 1.7.1 * Fixed CVE-2017-12635 * Fixed CVE-2017-12636 * Switched to eunit for testing * Erlang 20 compatible --------------------------------------------------------------------------------References: [ 1 ] Bug #1516980 - CVE-2017-12636 couchdb: OS Command injection as couchdb user via remote configuration options https://bugzilla.redhat.com/show_bug.cgi?id=1516980 [ 2 ] Bug #1516979 - CVE-2017-12635 couchdb: Privilege escalation via _users documents with duplicate keys for 'roles' https://bugzilla.redhat.com/show_bug.cgi?id=1516979 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade erlang-jiffy' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent patch for erlang-jiffy on Fedora 26 addresses severe security flaws, including remote code execution and unauthorized access escalation.. Erlang Jiffy Fix, Fedora 26 Update, CouchDB Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 09, 2017 Important Fedora
172

Ubuntu 11.10: USN-1381-1 Medium: CouchDB Server Certificate Risk

Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet.. =========================================================================Ubuntu Security Notice USN-1381-1 March 01, 2012 ubuntuone-couch vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 Summary: Fraudulent security certificates could allow sensitive information to be exposed when accessing the Internet. Software Description: - ubuntuone-couch: Ubuntu One CouchDB Details: It was discovered that Ubuntu One Couch did not perform any server certificate validation when using HTTPS connections. If a remote attacker were able to perform a man-in-the-middle attack, this flaw could be exploited to alter or compromise confidential information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: ubuntuone-couch 0.3.0-0ubuntu2.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1381-1 https://bugs.launchpad.net/ubuntu/+source/ubuntuone-couch/+bug/882049 Package Information: https://launchpad.net/ubuntu/+source/ubuntuone-couch/0.3.0-0ubuntu2.1 . Ubuntu Security Notice USN-1390-2 highlights a flaw in the NetworkManager, which may lead to unauthorized access to data.. ubuntu one couch, information exposure, security advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Mar 01, 2012 Medium Ubuntu
87

Debian 5.0: DSA-2107-1 Moderate: CouchDB Local Code Execution Risk

Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------ Debian Security Advisory DSA-2107-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Sébastien Delafond Sep 9, 2010 http://www.debian.org/security/faq - - ------------------------------------------------------------------------ Package : couchdb Vulnerability : untrusted search path Problem type : local Debian-specific: no CVE Id : CVE-2010-2953 Debian Bug : 594412 Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some directory, and then having an administrator run couchdb from this same directory. For the stable distribution (lenny), this problem has been fixed in version 0.8.0-2+lenny1. We recommend that you upgrade your couchdb package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Sourcearchives: Size/MD5 checksum: 1309 2a4a53978b085f1222e75f6106f4ee4d Size/MD5 checksum: 4941 dca93014f06c7521660ebe5e2c2309da Size/MD5 checksum: 560637 0837bce26ed2ab2ce2efd65e86c85bfc alpha architecture (DEC Alpha) Size/MD5 checksum: 277348 1a038436ac64f66a2d9cc23775589b6f amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 277324 cb838abfb1b2a623a9e3457922bf1925 arm architecture (ARM) Size/MD5 checksum: 274602 2e75d6e81dbb7194d1a8f6001d37598b armel architecture (ARM EABI) Size/MD5 checksum: 275548 d5a7b1f7407269243e6c79bdf4ce50ea hppa architecture (HP PA RISC) Size/MD5 checksum: 278728 3bb4c5a7d223fae6b96437ed89575c3f i386 architecture (Intel ia32) Size/MD5 checksum: 275686 f0135ec654b502ecbcbdaa26f65542c4 ia64 architecture (Intel ia64) Size/MD5 checksum: 279586 4725662dc6d62d1d193e58eaa0c00d2f mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 276820 d2dd578ac579d20c719bfcd225265eb8 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 278256 680e03ba3bc11f30c2aa4748b3e76f31 powerpc architecture (PowerPC) Size/MD5 checksum: 281584 40fa5e635d4c0c956cee908f7cf66096 s390 architecture (IBM S/390) Size/MD5 checksum: 276302 cd6162c5068d9f2e25e0f7952d7f5df0 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 275786 5f6d4d4208838527a16cf7ce95d848c7 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu Security Notice regarding PostgreSQL highlights vulnerable modules allowing unauthorized access; users urged to upgrade.. CouchDB Risk, Debian Update, Arbitrary CodeExecution. . LinuxSecurity.com Team

Calendar 2 Sep 09, 2010 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here