Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
98

RedHat: RHSA-2020-4134-01 Moderate: CloudForms API Security Fix

An update is now available for CloudForms Management Engine 5.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: CloudForms 5.0.8 security, bug fix and enhancement update Advisory ID: RHSA-2020:4134-01 Product: Red Hat CloudForms Advisory URL: https://access.redhat.com/errata/RHSA-2020:4134 Issue date: 2020-09-30 Cross references: RHSA-2020:3358 CVE Names: CVE-2020-14369 ==================================================================== 1. Summary: An update is now available for CloudForms Management Engine 5.11. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: CloudForms Management Engine 5.11 - x86_64 3. Description: Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components. Security Fix(es): * cfme-gemset: CloudForms: Cross Site Request Forgery in API notifications (CVE-2020-14369) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: This update fixes various bugs and adds enhancements. Documentation for thesechanges is available from the Release Notes document linked to in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 If the postgresql service is running, it will be automatically restarted after installing this update. After installing the updated packages, the httpd daemon will be restarted automatically. 5. Bugs fixed (https://bugzilla.redhat.com/): 1672358 - [RFE] Unable to create Service Template via the API 1686077 - [RFE] : Feature request to be able to add a default date/time to Timepicker in dialog 1706848 - Not able to set specific dates and time in for timepicker in service dialog 1713205 - Dialog Dropdown value is not getting selected in first attempt 1723864 - Openstack Director nodes does not show OpenStack Service Status section - OSPD 15 1741633 - Invalid dynamic field causes service dialog to not be save-able 1772762 - [RFE] Size of disks added is not shown when VM_Reconfigure 1794551 - Security group/rule create/delete triggers targeted refresh but doesn't update in UI 1804263 - Mapping fail when selecting public network not directly belongs to the selected project. 1825961 - SmartState sometimes fails to find /var/lib/rpm/Packages file, so software collection reports no packages installed 1846273 - Cloudforms no longer sees vms in resource pools after some targetted refreshes are ran 1846623 - [RFE] "CPU Affinity" not updated for VMs on RHV providers1846624 - [RFE] "Platform Tools" Status is set to "N/A" for all VMs on RHV providers1851087 - [RFE] Scheduled Retirement - Check for Existing "active" Requests before creating new Request. 1856470 - repmgr10.service is failing to start on cfme db appliance reboot 1858079 - using escalate privilage with a nil become_password causes playbooks to get stuck waiting for a password 1858107 - SSA not possible on any RHV datastore depending on navigation to it. 1859388 - Availability zones not showing in dropdown menuwhen adding volume through storage 1859542 - Tag Control dropdown field listing extra value -> 'Nothing Selected' in service order page 1860033 - "Add a provider" button for Ansible Tower disappears after using accordion 1861252 - Dropdown dialog field listing extra value -> 'Nothing Selected' in service order page 1862202 - RHOS 16.1: geneve" Provider Network Type is missing when creating cloud network 1870737 - passwordless sudo command reports error when querying podman/docker containers for OSP16.1 1871921 - CVE-2020-14369 CloudForms: Cross Site Request Forgery in API notifications 1874921 - [RFE] Service Retirement Logging improvement to show Service id 1876974 - Enhance error handle for failing playbook clone 6. Package List: CloudForms Management Engine 5.11: Source: ansible-tower-3.6.5-1.el8at.src.rpm cfme-5.11.8.1-1.el8cf.src.rpm cfme-amazon-smartstate-5.11.8.1-1.el8cf.src.rpm cfme-appliance-5.11.8.1-1.el8cf.src.rpm cfme-gemset-5.11.8.1-1.el8cf.src.rpm repmgr10-4.0.6-4.el8cf.src.rpm x86_64: ansible-tower-venv-ansible-3.6.5-1.el8at.x86_64.rpm cfme-5.11.8.1-1.el8cf.x86_64.rpm cfme-amazon-smartstate-5.11.8.1-1.el8cf.x86_64.rpm cfme-appliance-5.11.8.1-1.el8cf.x86_64.rpm cfme-appliance-common-5.11.8.1-1.el8cf.x86_64.rpm cfme-appliance-tools-5.11.8.1-1.el8cf.x86_64.rpm cfme-gemset-5.11.8.1-1.el8cf.x86_64.rpm repmgr10-4.0.6-4.el8cf.x86_64.rpm repmgr10-debuginfo-4.0.6-4.el8cf.x86_64.rpm repmgr10-debugsource-4.0.6-4.el8cf.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-14369 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3SOv9zjgjWX9erEAQiOMg//SHKm/wMCHkcsqZPcWjd6l7yetqOo2tHL EpVdaTqWau0KKPMrdfuh9yqIgnTxDzWizD6xAeSgHPKqzMYw+VL2z/rr8MdzlYKK 7FHCsQ5U3lvjRYpnL1/2XI6j95ne6NB5HRQQR3UcsyvDIKYK3b+dE2SDYlJSPJO8 iSt7Uq6BmhjGNtnNOUyAQbGq3wiB1EMwBX49pfAHkXFQYIF18FaaTYZwRNW8RgYc wIxahDgn5/JOh+8TgrLQ+2YsHMIiqqHgfYKKa8a9uSYPiR/uraqtcuAf9ARCG15O YNKAIy4TD3nhKibpqGAgHaZb7t/HtwTubMI2xh0G993ib54W9YqgtcfspF9i32aK x7lvayOp5ufv8PpmXNR8vVmfQU+qvdSdzMB6ldhqU9NauCpe5WpvA0xFEn5JeW/4 zJNGsSb88nffERhZkIo48kG1aG7tk5YvphumL1uR7fpDhYkTOFUnCeXE3PC5YeWY RtHo9tnlGPX9l9aW+hJ3FevMiwg4KxVCqmU8a89v+CYZkbe2IdqCnwjMiWfRmOrb V47dw8a9AMWDJK3CVK3qJ1BF3O2jJkumMh1mMQtEsyFloBlprpJ5TXJeL9RvwW+I owJGB3gh/z2HBCQFhZBxJY+0q6itdqAr1LwpPNReKfZbSRHLSXvI+ey00eiwnqns ly7uPdQyl9s=UcYj -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat has issued an update for CloudForms 5.11 to address security vulnerabilities and fix bugs, enhancing overall system security and stability. CloudForms Management, Red Hat Security, Bug Fixes, API Security, Software Update. . LinuxSecurity.com Team

Calendar%202 Sep 30, 2020 Red Hat
89

Fedora 32: 2020-09-13 Critical Drupal 7.72 CSRF Security Advisory

- https://www.drupal.org/project/drupal/releases/7.72 - [Drupal core - Critical - Cross Site Request Forgery - SA-CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 - https://www.drupal.org/project/drupal/releases/7.71 - https://www.drupal.org/project/drupal/releases/7.70 - [Drupal core -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0b32a59b54 2020-09-13 14:27:05.374728 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 32 Version : 7.72 Release : 1.fc32 URL : https://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - https://www.drupal.org/project/drupal/releases/7.72 - [Drupal core -Critical - Cross Site Request Forgery - SA-CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 -https://www.drupal.org/project/drupal/releases/7.71 -https://www.drupal.org/project/drupal/releases/7.70 - [Drupal core -Moderately critical - Cross Site Scripting - SA-CORE-2020-002](https://www.drupal.org/sa-core-2020-002) / CVE-2020-11022 / CVE-2020-11023 - [Drupal core - Moderately critical - Open Redirect - SA-CORE-2020-003](https://www.drupal.org/sa-core-2020-003) / CVE-2020-13662 --------------------------------------------------------------------------------ChangeLog: * Fri Sep 4 2020 Shawn Iwinski - 7.72-1 - Update to 7.72 - SA-CORE-2020-004/CVE-2020-13663 (RHBZ #1860912, #1860913) * Mon Jul 27 2020 Fedora Release Engineering - 7.70-3 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1828417 - CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1828417 [ 2 ] Bug #1850013 - CVE-2020-11023 drupal7: jQuery: passing HTML containing elements to manipulation methods could result in untrusted code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1850013 [ 3 ] Bug #1850023 - CVE-2020-11023 drupal7: jQuery: passing HTML containing elements to manipulation methods could result in untrusted code execution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1850023 [ 4 ] Bug #1860912 - CVE-2020-13663 drupal7: Form API does not properly handle certain form input from cross-site requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1860912 [ 5 ] Bug #1860913 - CVE-2020-13663 drupal7: Form API does not properly handle certain form input from cross-site requests [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1860913 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-0b32a59b54' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines:https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora System Alert for Drupal 7.72 focusing on urgent cross-site request forgery vulnerabilities and patches.. Drupal 7.72 update, Fedora security advisory, Cross Site Forgery fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 13, 2020 Critical Fedora
89

Fedora 31: FEDORA-2020-fbb94073a1 Urgent: Drupal7 CSRF Vulnerability Patch

- https://www.drupal.org/project/drupal/releases/7.72 - [Drupal core - Critical - Cross Site Request Forgery - SA-CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 - https://www.drupal.org/project/drupal/releases/7.71 - https://www.drupal.org/project/drupal/releases/7.70 - [Drupal core -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-fbb94073a1 2020-09-13 14:17:24.303433 --------------------------------------------------------------------------------Name : drupal7 Product : Fedora 31 Version : 7.72 Release : 1.fc31 URL : https://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. --------------------------------------------------------------------------------Update Information: - https://www.drupal.org/project/drupal/releases/7.72 - [Drupal core -Critical - Cross Site Request Forgery - SA-CORE-2020-004](https://www.drupal.org/sa-core-2020-004) / CVE-2020-13663 -https://www.drupal.org/project/drupal/releases/7.71 -https://www.drupal.org/project/drupal/releases/7.70 - [Drupal core -Moderately critical - Cross Site Scripting - SA-CORE-2020-002](https://www.drupal.org/sa-core-2020-002) / CVE-2020-11022 / CVE-2020-11023 - [Drupal core - Moderately critical - Open Redirect - SA-CORE-2020-003](https://www.drupal.org/sa-core-2020-003) / CVE-2020-13662 --------------------------------------------------------------------------------ChangeLog: * Fri Sep 4 2020 Shawn Iwinski - 7.72-1 - Update to 7.72 - SA-CORE-2020-004/CVE-2020-13663 (RHBZ #1860912, #1860913) * Mon Jul 27 2020 Fedora Release Engineering - 7.70-3 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Sun May 31 2020 Shawn Iwinski - 7.70-2 - rpmbuild sub-pkg: Fix auto-provides for F32+ * Fri May 22 2020 Peter Borsa - 7.70-1 - Update to 7.70 - RHBZ #1837516 / SA-CORE-2020-003 - RHBZ #1828416 / SA-CORE-2020-002 * Fri May 22 2020 Peter Borsa - 7.69-3 - Remove php-recode as dependency * Tue Jan 28 2020 Fedora Release Engineering - 7.69-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1828417 - CVE-2020-11022 drupal7: jquery: Cross-site scripting due to improper injQuery.htmlPrefilter method [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1828417 [ 2 ] Bug #1850013 - CVE-2020-11023 drupal7: jQuery: passing HTML containing elements to manipulation methods could result in untrusted code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1850013 [ 3 ] Bug #1850023 - CVE-2020-11023 drupal7: jQuery: passing HTML containing elements to manipulation methods could result in untrusted code execution [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1850023 [ 4 ] Bug #1860912 - CVE-2020-13663 drupal7: Form API does not properly handle certain form input from cross-site requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1860912 [ 5 ] Bug #1860913 - CVE-2020-13663 drupal7: Form API does not properly handle certain form input from cross-site requests [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1860913 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-fbb94073a1' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important patch for Drupal 7 on Fedora 31 resolves cross-site scripting vulnerabilities and strengthens overall protection protocols.. Drupal Security, Fedora Update, Cross Site Threats, Open Source Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 13, 2020 Critical Fedora
87

Debian: DSA-4706-1 Critical: Drupal7 Cross Site Request Forgery

It was discovered that Drupal, a fully-featured content management framework, was suspectible to cross site request forgery. For additional information, please refer to the upstream advisory at . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4706-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 18, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : drupal7 CVE ID : CVE-2020-13663 It was discovered that Drupal, a fully-featured content management framework, was suspectible to cross site request forgery. For additional information, please refer to the upstream advisory at https:// For the oldstable distribution (stretch), this problem has been fixed in version 7.52-2+deb9u11. We recommend that you upgrade your drupal7 packages. For the detailed security status of drupal7 please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-4707-1 deals with a vulnerability in Drupal 8 related to SQL injection. Users are urged to perform updates for protection.. Drupal Update, Security Patch, Debian Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 18, 2020 Critical Debian
89

Fedora 10 Drupal 6.14 Critical Threat: OpenID Issues Advisory

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9751 2009-09-18 23:22:41 -------------------------------------------------------------------------------- Name : drupal Product : Fedora 10 Version : 6.14 Release : 1.fc10 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: Fixes SA-CORE-2009-008 https:// Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to to run the upgrade script. Multiple vulnerabilities and weaknesses were discovered in Drupal. OpenID association cross site request forgeries The OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities. The core OpenID module does not correctly implement Form API for the form that allows one to link user accounts with OpenID identifiers. A malicious user is therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities can then be used to gain access to the affected accounts. This issue affects Drupal 6.x only. OpenID impersonation The OpenID module is not a compliant implementation of the OpenID Authentication 2.0 specification. An implementation error allows a user to access the account of another user when they share the same OpenID 2.0 provider. This issue affects Drupal 6.x only. File upload File uploads with certain extensions are not correctly processed by the File API. This may lead to the creation of files that areexecutable by Apache. The .htaccess that is saved into the files directory by Drupal should normally prevent execution. The files are only executable when the server is configured to ignore the directives in the .htaccess file. This issue affects Drupal 6.x only. Session fixation Drupal doesn't regenerate the session ID when an anonymous user follows the one time login link used to confirm email addresses and reset forgotten passwords. This enables a malicious user to fix and reuse the session id of a victim under certain circumstances. This issue affects Drupal 5.x only. Versions affected * Drupal 6.x before version 6.14. * Drupal 5.x before version 5.20. Solution Install the latest version: * If you are running Drupal 6.x then upgrade to Drupal 6.14. * If you are running Drupal 5.x then upgrade to Drupal 5.20. If you are unable to upgrade immediately, you can apply a patch to secure your installation until you are able to do a proper upgrade. Theses patches fix the security vulnerabilities, but do not contain other fixes which were released in Drupal 6.14 or Drupal 5.20. * To patch Drupal 6.13 use SA- CORE-2009-008-6.13.patch. * To patch Drupal 5.19 use SA- CORE-2009-008-5.19.patch. Important note: Some users using OpenID might not be able to use the existing OpenID associations to login after the upgrade. These users should use the one time login via password recovery to get access to their user account and re-add desired associations. These users likely had issues with OpenID logins prior to the upgrade. Reported by The session fixation issue was reported by Noel Sharpe. OpenID impersonation was reported by Robert Metcalf. OpenID association CSRF was reported by Heine Deelstra (*). The file upload issue was reported by Heine Deelstra (*). (*) Member of the Drupal security team Fixed by The session fixation issue was fixed by Jakub Suchy. The OpenID and file upload issues were fixed by Heine Deelstra. Contact The security team for Drupal canbe reached at security at drupal.org or via the form at https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 16 2009 Jon Ciesla - 6.14-1 - Update to 6.14, SA-CORE-2009-008. * Fri Jul 24 2009 Fedora Release Engineering - 6.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Thu Jul 2 2009 Jon Ciesla - 6.13-1 - Update to 6.11, SA-CORE-2009-007. - Added clarifying text on module installation to readme, BZ 500707. * Thu May 14 2009 Jon Ciesla - 6.12-1 - Update to 6.11, SA-CORE-2009-006. * Thu Apr 30 2009 Jon Ciesla - 6.11-1 - Update to 6.11, SA-CORE-2009-005. * Mon Apr 27 2009 Jon Ciesla - 6.10-2 - Added SELinux/sendmail note to README, BZ 497642. * Thu Feb 26 2009 Jon Ciesla - 6.10-1 - Update to 6.10, SA-CORE-2009-003. * Tue Feb 17 2009 Jon Ciesla - 6.9-2 - Drop pre script for files move, 472642. - Updated drupal-README.fedora. - Mark cron job noreplace, BZ 485567. * Thu Jan 15 2009 Jon Ciesla - 6.9-1 - Upgrade to 6.9, SA-CORE-2009-001. * Fri Jan 2 2009 Jon Ciesla - 6.8-1 - Upgrade to 6.8. - Move files directories from sites to /var/lib/drupal/files/N for selinux reasons, 472642. - Included script to move files outside of default, use at your own risk, patches welcome. * Thu Dec 11 2008 Jon Ciesla - 6.7-1 - Upgrade to 6.7, SA-2008-073. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Fixes SA-CORE-2009-008 https:// Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to to run the upgrade script. Multiple vulnerabilities and weaknesses were discovered in Drupal. OpenID association cross site request forgeries The OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities. The core OpenID module does not correctly implement Form API for the form that allows one to link user accounts with OpenID identifiers. A malicious user is therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities can then be used to gain access to the affected accounts. This issue affects Drupal 6.x only. OpenID impersonation The OpenID module is not a compliant implementation of the OpenID Authentication 2.0 specification. An implementation error allows a user to access the account of another user when they share the same OpenID 2.0 provider. This issue affects Drupal 6.x only. File upload File uploads with certain extensions are not correctly processed by the File API. This may lead to the creation of files that are executable by Apache. The .htaccess that is saved into the files directory by Drupal should normally prevent execution. The files are only executable when the server is configured to ignore the directives in the .htaccess file. This issue affects Drupal 6.x only. Session fixation Drupal doesn't regenerate the session ID when an anonymous user follows the one time login link used to confirm email addresses and reset forgotten passwords. This enables a malicious user to fix and reuse the session id of a victim under certain circumstances. This issue affects Drupal 5.x only. Versions affected * Drupal 6.x before version 6.14. * Drupal 5.x before version 5.20. Solution Install the latest version: * If you are running Drupal 6.x then upgrade to Drupal 6.14. * If you arerunning Drupal 5.x then upgrade to Drupal 5.20. If you are unable to upgrade immediately, you can apply a patch to secure your installation until you are able to do a proper upgrade. Theses patches fix the security vulnerabilities, but do not contain other fixes which were released in Drupal 6.14 or Drupal 5.20. * To patch Drupal 6.13 use SA- CORE-2009-008-6.13.patch. * To patch Drupal 5.19 use SA- CORE-2009-008-5.19.patch. Important note: Some users using OpenID might not be able to use the existing OpenID associations to login after the upgrade. These users should use the one time login via password recovery to get access to their user account and re-add desired associations. These users likely had issues with OpenID logins prior to the upgrade. Reported by The session fixation issue was reported by Noel Sharpe. OpenID impersonation was reported by Robert Metcalf. OpenID association CSRF was reported by Heine Deelstra (*). The file upload issue was reported by Heine Deelstra (*). (*) Member of the Drupal security team Fixed by The session fixation issue was fixed by Jakub Suchy. The OpenID and file upload issues were fixed by Heine Deelstra. Contact The security team for Drupal can be reached at security at drupal.org or via the form at https://. A significant Drupal update for Fedora 10 has been released, fixing critical security vulnerabilities. Promptly apply the update to maintain site integrity and security. Drupal Update,Fedora Security,OpenID Issues,Software Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 18, 2009 Critical Fedora
89

Fedora 11: Update Drupal 6.14 Critical OpenID Issues and Fixes

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9721 2009-09-18 23:21:42 -------------------------------------------------------------------------------- Name : drupal Product : Fedora 11 Version : 6.14 Release : 1.fc11 URL : http://www.drupal.org Summary : An open-source content-management platform Description : Equipped with a powerful blend of features, Drupal is a Content Management System written in PHP that can support a variety of websites ranging from personal weblogs to large community-driven websites. Drupal is highly configurable, skinnable, and secure. -------------------------------------------------------------------------------- Update Information: Fixes SA-CORE-2009-008 https:// Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to to run the upgrade script. Multiple vulnerabilities and weaknesses were discovered in Drupal. OpenID association cross site request forgeries The OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities. The core OpenID module does not correctly implement Form API for the form that allows one to link user accounts with OpenID identifiers. A malicious user is therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities can then be used to gain access to the affected accounts. This issue affects Drupal 6.x only. OpenID impersonation The OpenID module is not a compliant implementation of the OpenID Authentication 2.0 specification. An implementation error allows a user to access the account of another user when they share the same OpenID 2.0 provider. This issue affects Drupal 6.x only. File upload File uploads with certain extensions are not correctly processed by the File API. This may lead to the creation of files that areexecutable by Apache. The .htaccess that is saved into the files directory by Drupal should normally prevent execution. The files are only executable when the server is configured to ignore the directives in the .htaccess file. This issue affects Drupal 6.x only. Session fixation Drupal doesn't regenerate the session ID when an anonymous user follows the one time login link used to confirm email addresses and reset forgotten passwords. This enables a malicious user to fix and reuse the session id of a victim under certain circumstances. This issue affects Drupal 5.x only. Versions affected * Drupal 6.x before version 6.14. * Drupal 5.x before version 5.20. Solution Install the latest version: * If you are running Drupal 6.x then upgrade to Drupal 6.14. * If you are running Drupal 5.x then upgrade to Drupal 5.20. If you are unable to upgrade immediately, you can apply a patch to secure your installation until you are able to do a proper upgrade. Theses patches fix the security vulnerabilities, but do not contain other fixes which were released in Drupal 6.14 or Drupal 5.20. * To patch Drupal 6.13 use SA- CORE-2009-008-6.13.patch. * To patch Drupal 5.19 use SA- CORE-2009-008-5.19.patch. Important note: Some users using OpenID might not be able to use the existing OpenID associations to login after the upgrade. These users should use the one time login via password recovery to get access to their user account and re-add desired associations. These users likely had issues with OpenID logins prior to the upgrade. Reported by The session fixation issue was reported by Noel Sharpe. OpenID impersonation was reported by Robert Metcalf. OpenID association CSRF was reported by Heine Deelstra (*). The file upload issue was reported by Heine Deelstra (*). (*) Member of the Drupal security team Fixed by The session fixation issue was fixed by Jakub Suchy. The OpenID and file upload issues were fixed by Heine Deelstra. Contact The security team for Drupal canbe reached at security at drupal.org or via the form at https:// -------------------------------------------------------------------------------- ChangeLog: * Wed Sep 16 2009 Jon Ciesla - 6.14-1 - Update to 6.14, SA-CORE-2009-008. * Fri Jul 24 2009 Fedora Release Engineering - 6.13-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild * Thu Jul 2 2009 Jon Ciesla - 6.13-1 - Update to 6.11, SA-CORE-2009-007. - Added clarifying text on module installation to readme, BZ 500707. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update drupal' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Fixes SA-CORE-2009-008 https:// Remember to log in to your site as the admin user before upgrading this package. After upgrading the package, browse to to run the upgrade script. Multiple vulnerabilities and weaknesses were discovered in Drupal. OpenID association cross site request forgeries The OpenID module in Drupal 6 allows users to create an account or log into a Drupal site using one or more OpenID identities. The core OpenID module does not correctly implement Form API for the form that allows one to link user accounts with OpenID identifiers. A malicious user is therefore able to use cross site request forgeries to add attacker controlled OpenID identities to existing accounts. These OpenID identities can then be used to gain access to the affected accounts. This issue affects Drupal 6.x only. OpenID impersonation The OpenID module is not a compliantimplementation of the OpenID Authentication 2.0 specification. An implementation error allows a user to access the account of another user when they share the same OpenID 2.0 provider. This issue affects Drupal 6.x only. File upload File uploads with certain extensions are not correctly processed by the File API. This may lead to the creation of files that are executable by Apache. The .htaccess that is saved into the files directory by Drupal should normally prevent execution. The files are only executable when the server is configured to ignore the directives in the .htaccess file. This issue affects Drupal 6.x only. Session fixation Drupal doesn't regenerate the session ID when an anonymous user follows the one time login link used to confirm email addresses and reset forgotten passwords. This enables a malicious user to fix and reuse the session id of a victim under certain circumstances. This issue affects Drupal 5.x only. Versions affected * Drupal 6.x before version 6.14. * Drupal 5.x before version 5.20. Solution Install the latest version: * If you are running Drupal 6.x then upgrade to Drupal 6.14. * If you are running Drupal 5.x then upgrade to Drupal 5.20. If you are unable to upgrade immediately, you can apply a patch to secure your installation until you are able to do a proper upgrade. Theses patches fix the security vulnerabilities, but do not contain other fixes which were released in Drupal 6.14 or Drupal 5.20. * To patch Drupal 6.13 use SA- CORE-2009-008-6.13.patch. * To patch Drupal 5.19 use SA- CORE-2009-008-5.19.patch. Important note: Some users using OpenID might not be able to use the existing OpenID associations to login after the upgrade. These users should use the one time login via password recovery to get access to their user account and re-add desired associations. These users likely had issues with OpenID logins prior to the upgrade. Reported by The session fixation issue was reported by Noel Sharpe. OpenIDimpersonation was reported by Robert Metcalf. OpenID association CSRF was reported by Heine Deelstra (*). The file upload issue was reported by Heine Deelstra (*). (*) Member of the Drupal security team Fixed by The session fixation issue was fixed by Jakub Suchy. The OpenID and file upload issues were fixed by Heine Deelstra. Contact The security team for Drupal can be reached at security at drupal.org or via the form at https://. Numerous security flaws discovered in WordPress highlighted with guidance for Ubuntu 20.04 users to fortify their setups adequately.. Drupal Update, Fedora Security, OpenID Issues, Content Management, Web App Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 18, 2009 Critical Fedora
87

Debian: DSA-1488-1 Moderate: Remote Access Attack on phpBB2

Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board.Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1488-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst February 09, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : phpbb2 Vulnerability : several Problem type : remote Debian-specific: no CVE Id(s) : CVE-2006-4758 CVE-2006-6839 CVE-2006-6840 CVE-2006-6508 CVE-2006-6841 CVE-2008-0471 Debian Bug : 388120 405980 463589 Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0471 Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page. CVE-2006-6841 / CVE-2006-6508 Cross site request forgery enabled an attacker to perform various actions on behalf of a logged in user. (Applies to sarge only) CVE-2006-6840 A negative start parameter could allow an attacker to create invalid output. (Applies to sarge only) CVE-2006-6839 Redirection targets were not fully checked, leaving room for unauthorised external redirections via a phpBB forum. (Applies to sarge only) CVE-2006-4758 An authenticated forum administrator may upload files of any type by using specially crafted filenames. (Applies to sarge only) For the stable distribution (etch), these problems have been fixed in version 2.0.21-7. For the old stable distribution (sarge), these problems have been fixed in version 2.0.13+1-6sarge4. For the unstabledistribution (sid) these problems have been fixed in version 2.0.22-3. We recommend that you upgrade your phpbb2 package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - --------------------------------Source archives: Size/MD5 checksum: 67912 c403597d08f4c5af0f62b84c5ee72a7e Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78 Size/MD5 checksum: 1011 d5ca94a7a4c2b3468428a993a1dbc5cc Architecture independent packages: Size/MD5 checksum: 37766 f0df2114bd60d9b84fbda1d241294fdd Size/MD5 checksum: 526154 944e55e056fc34d970e95b78201589fe Size/MD5 checksum: 2868920 f10c4962035ede6e02417b8098efeda0 Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 1051 88ad3a4f2ee714cce779873b53ebd323 Size/MD5 checksum: 3203456 30383a9bf6c5d21736e4bdf9ec7852d5 Size/MD5 checksum: 90580 896f80500e90867741c516e57fc8bfcc Architecture independent packages: Size/MD5 checksum: 2791410 afd8a0fe8138c8a5cf00a3e4ac10ac59 Size/MD5 checksum: 554842 e8825ef3431bfe7ccf72f9f59f13a119 Size/MD5 checksum: 53706 49baf96bcc1c273a93e8bb5169dca722 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -------------------------------------------------------------------------Debian Security Advisory D. remote, vulnerabilities, phpbb, based, bulletin, board, private. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2008 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200