Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for cups ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0638-1 Rating: important References: #1184161 Cross-References: CVE-2021-25317 CVSS scores: CVE-2021-25317 (SUSE): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for cups fixes the following issues: - CVE-2021-25317: ownership of /var/log/cups could allow privilege escalation from lp user to root via symlink attacks (bsc#1184161) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-638=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): cups-2.2.7-lp152.9.9.1 cups-client-2.2.7-lp152.9.9.1 cups-client-debuginfo-2.2.7-lp152.9.9.1 cups-config-2.2.7-lp152.9.9.1 cups-ddk-2.2.7-lp152.9.9.1 cups-ddk-debuginfo-2.2.7-lp152.9.9.1 cups-debuginfo-2.2.7-lp152.9.9.1 cups-debugsource-2.2.7-lp152.9.9.1 cups-devel-2.2.7-lp152.9.9.1 libcups2-2.2.7-lp152.9.9.1 libcups2-debuginfo-2.2.7-lp152.9.9.1 libcupscgi1-2.2.7-lp152.9.9.1 libcupscgi1-debuginfo-2.2.7-lp152.9.9.1 libcupsimage2-2.2.7-lp152.9.9.1 libcupsimage2-debuginfo-2.2.7-lp152.9.9.1 libcupsmime1-2.2.7-lp152.9.9.1 libcupsmime1-debuginfo-2.2.7-lp152.9.9.1 libcupsppdc1-2.2.7-lp152.9.9.1 libcupsppdc1-debuginfo-2.2.7-lp152.9.9.1 - openSUSE Leap15.2 (x86_64): cups-devel-32bit-2.2.7-lp152.9.9.1 libcups2-32bit-2.2.7-lp152.9.9.1 libcups2-32bit-debuginfo-2.2.7-lp152.9.9.1 libcupscgi1-32bit-2.2.7-lp152.9.9.1 libcupscgi1-32bit-debuginfo-2.2.7-lp152.9.9.1 libcupsimage2-32bit-2.2.7-lp152.9.9.1 libcupsimage2-32bit-debuginfo-2.2.7-lp152.9.9.1 libcupsmime1-32bit-2.2.7-lp152.9.9.1 libcupsmime1-32bit-debuginfo-2.2.7-lp152.9.9.1 libcupsppdc1-32bit-2.2.7-lp152.9.9.1 libcupsppdc1-32bit-debuginfo-2.2.7-lp152.9.9.1 References: https://www.suse.com/security/cve/CVE-2021-25317.html https://bugzilla.suse.com/1184161 . An important openSUSE patch addressing a vulnerability in cups has been released, which stops the lp user from obtaining root privileges.. openSUSE Update, cups Fix, Privilege Escalation, Security Patch. . Severity: Important. LinuxSecurity.com Team
The container sles-15-sp2-chost-byos-v20210304 was updated. The following patches have been included in this update:. SUSE Image Update Advisory: sles-15-sp2-chost-byos-v20210304 ----------------------------------------------------------------- Image Advisory ID : SUSE-IU-2021:414-1 Image Tags : sles-15-sp2-chost-byos-v20210304:20210304 Image Release : Severity : important Type : security References : 1170671 1177460 1179691 1180520 1180603 1181319 CVE-2019-8842 CVE-2020-10001 ----------------------------------------------------------------- The container sles-15-sp2-chost-byos-v20210304 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:278-1 Released: Tue Feb 2 09:43:08 2021 Summary: Recommended update for lvm2 Type: recommended Severity: moderate References: 1181319 This update for lvm2 fixes the following issues: - Backport 'lvmlockd' to adopt orphan locks feature. (bsc#1181319) ----------------------------------------------------------------- Advisory ID: SUSE-SU-2021:285-1 Released: Tue Feb 2 13:08:54 2021 Summary: Security update for cups Type: security Severity: moderate References: 1170671,1180520,CVE-2019-8842,CVE-2020-10001 This update for cups fixes the following issues: - CVE-2020-10001: Fixed an out-of-bounds read in the ippReadIO function (bsc#1180520). - CVE-2019-8842: Fixed an out-of-bounds read in an extension field (bsc#1170671). ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:293-1 Released: Wed Feb 3 12:52:34 2021 Summary: Recommended update for gmp Type: recommended Severity: moderate References: 1180603 This update for gmp fixes the following issues: - correct license statements of packages (library itself is no GPL-3.0)(bsc#1180603) ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:301-1 Released: Thu Feb 4 08:46:27 2021 Summary: Recommended update for timezone Type: recommended Severity: moderate References: 1177460 This update for timezone fixes the following issues: - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. - timezone update 2021a (bsc#1177460) * South Sudan changes from +03 to +02 on 2021-02-01 at 00:00. ----------------------------------------------------------------- Advisory ID: SUSE-RU-2021:302-1 Released: Thu Feb 4 13:18:35 2021 Summary: Recommended update for lvm2 Type: recommended Severity: important References: 1179691 This update for lvm2 fixes the following issues: - lvm2 will no longer use external_device_info_source='udev' as default because it introduced a regression (bsc#1179691). If this behavior is still wanted, please change this manually in the lvm.conf ----------------------------------------------------------------- Advisory ID: SUSE-OU-2021:339-1 Released: Mon Feb 8 13:16:07 2021 Summary: Optional update for pam Type: optional Severity: low References: This update for pam fixes the following issues: - Added rpm macros for this package, so that other packages can make use of it This patch is optional to be installed - it doesn't fix any bugs. . The advisory for SUSE container sles-15-sp3-chost-byos-v20210405 presents crucial security enhancements and updates.. SUSE Update, Security Patches, Container Security, Image Advisory, CUPS Security Fix. . Severity: Important. LinuxSecurity.com Team
Moderate: xpdf security update. Date: Tue, 9 Aug 2005 18:01:31 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: ERRATA for SL 40 x86_64 now available Comments: To:
Get the latest Linux and open source security news straight to your inbox.