Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
100

SUSE: 2023:4099-1 Moderate: Buildah Data Disclosure Risk

* bsc#1202812 * bsc#1216005 Cross-References: * CVE-2022-2990 . # Security update for buildah Announcement ID: SUSE-SU-2023:4099-1 Rating: moderate References: * bsc#1202812 * bsc#1216005 Cross-References: * CVE-2022-2990 CVSS scores: * CVE-2022-2990 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2022-2990 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE CaaS Platform 4.0 * SUSE Enterprise Storage 7 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for buildah fixes the following issues: * CVE-2022-2990: Fixed a flaw which might allow sensitive information disclosure or possible data modification. (bsc#1202812) * buildah is also rebuilt against go1.21. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2023-4099=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4099=1 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2023-4099=1 * SUSE LinuxEnterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4099=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2023-4099=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4099=1 * SUSE Enterprise Storage 7 zypper in -t patch SUSE-Storage-7-2023-4099=1 * SUSE CaaS Platform 4.0 To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS 15-SP1 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server 15 SP1 LTSS 15-SP1 (aarch64 ppc64le s390x x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 (ppc64le x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE Enterprise Storage 7 (aarch64 x86_64) * buildah-1.25.1-150100.3.20.15 * SUSE CaaS Platform 4.0 (x86_64) * buildah-1.25.1-150100.3.20.15 ## References: * https://www.suse.com/security/cve/CVE-2022-2990.html * https://bugzilla.suse.com/show_bug.cgi?id=1202812 * https://bugzilla.suse.com/show_bug.cgi?id=1216005 . A recent SUSE buildah update addresses a moderate severity vulnerability, enhancing security for applications using buildah in container image management. SUSE Update, Buildah Security, Data Protection, Security Patch. . LinuxSecurity.com Team

Calendar%202 Oct 17, 2023 SuSE
87

Debian DSA-5372-1 Urgent Security Advisory: Rails XSS and Data Threats

Multiple vunerabilities were discovered in rails, the Ruby based server-side MVC web application framework, which could result in XSS, data disclosure and open redirect. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5372-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu March 13, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : rails CVE ID : CVE-2021-22942 CVE-2021-44528 CVE-2022-21831 CVE-2022-22577 CVE-2022-23633 CVE-2022-27777 CVE-2023-22792 CVE-2023-22794 CVE-2023-22795 CVE-2023-22796 Debian Bug : 992586 1001817 1011940 1011941 1005389 1016982 1030050 Multiple vunerabilities were discovered in rails, the Ruby based server-side MVC web application framework, which could result in XSS, data disclosure and open redirect. For the stable distribution (bullseye), these problems have been fixed in version 2:6.0.3.7+dfsg-2+deb11u1. We recommend that you upgrade your rails packages. For the detailed security status of rails please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rails Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Advisory DSA-5372-1 highlights various security flaws within rails that could compromise both integrity and performance.. Debian Rails Update, Web Application Security, Ruby Framework Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 13, 2023 Critical Debian
87

Debian: DSA-5159-1 Critical: Python-Bottle Data Disclosure

Elton Nokaj discovered that incorrect error handling in Bottle, a WSGI framework for Python, could result in the disclosure of sensitive information. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5159-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 09, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : python-bottle CVE ID : CVE-2022-31799 Elton Nokaj discovered that incorrect error handling in Bottle, a WSGI framework for Python, could result in the disclosure of sensitive information. For the oldstable distribution (buster), this problem has been fixed in version 0.12.15-2+deb10u2. For the stable distribution (bullseye), this problem has been fixed in version 0.12.19-1+deb11u1. We recommend that you upgrade your python-bottle packages. For the detailed security status of python-bottle please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/python-bottle Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent patch released for Debian's python-bottle to address vulnerability that risks leaking confidential information. Users should upgrade immediately!. Python Bottle Security, Debian DSA-5159-1, Data Disclosure Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2022 Critical Debian
197

Debian LTS: DLA-3028-1 atftp Buffer Overrun Risk Advisory

An issue has been found in package atftp, an advanced TFTP client/server. Due to missing bound checks, data could be read behind a buffer so that . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3028-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz May 27, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : atftp Version : 0.7.git20120829-3.1~deb9u3 CVE ID : CVE-2021-46671 An issue has been found in package atftp, an advanced TFTP client/server. Due to missing bound checks, data could be read behind a buffer so that sensible information might be disclosed to a remote client. For Debian 9 stretch, this problem has been fixed in version 0.7.git20120829-3.1~deb9u3. We recommend that you upgrade your atftp packages. For the detailed security status of atftp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/atftp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This advisory highlights a vulnerability in the atftp package on Debian LTS, risking remote disclosure of sensitive information under specific conditions. Debian LTS, atftp Security, Remote Data Disclosure, Security Patch, Buffer Overflow. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 26, 2022 Important Debian LTS
91

Gentoo: GLSA-202307-22 Alert: rclone Lacks Entropy in Random Generation

rclone uses weak random number generation such that generated passwords can be easily cracked.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202107-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: rclone: Weak random number generation Date: July 08, 2021 Bugs: #755638 ID: 202107-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= rclone uses weak random number generation such that generated passwords can be easily cracked. Background ========= rclone is a problem to sync files to and from various cloud storage providers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/rclone < 1.53.3 > = 1.53.3 Description ========== Passwords generated with rclone were insecurely generated and are vulnerable to brute force attacks. Impact ===== Data kept secret with a password generated by rclone may be disclosed to a local attacker. Workaround ========= There is no known workaround at this time. Resolution ========= All rclone users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/rclone-1.53.3" References ========= [ 1 ] CVE-2020-28924 https://nvd.nist.gov/vuln/detail/CVE-2020-28924 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202107-14 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machinesis of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2021 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Enhance rclone to mitigate unpredictable randomness that jeopardizes password integrity and data privacy on Gentoo.. rclone password security, random number generation, cloud sync security. . LinuxSecurity.com Team

Calendar%202 Jul 07, 2021 Gentoo
203

Mageia: 2021-0243 Critical: Curl Telnet Data Disclosure

TELNET stack contents disclosure (CVE-2021-22898). References: - https://bugs.mageia.org/show_bug.cgi?id=28971 - https://curl.se/docs/CVE-2021-22898.html . MGASA-2021-0243 - Updated curl packages fix a security vulnerability Publication date: 08 Jun 2021 URL: https://advisories.mageia.org/MGASA-2021-0243.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-22898 TELNET stack contents disclosure (CVE-2021-22898). References: - https://bugs.mageia.org/show_bug.cgi?id=28971 - https://curl.se/docs/CVE-2021-22898.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/BQBFQI6AGHALKDLOL5S4ST4RMK2YG5SG/ - https://www.cve.org/CVERecord?id=CVE-2021-22898 SRPMS: - 8/core/curl-7.74.0-1.2.mga8 - 7/core/curl-7.71.0-1.3.mga7 . Recent adjustments to curl packages for Mageia address a significant telnet data exposure flaw disclosed on June 8, 2021.. Mageia Security,Curl Update,Tailored Patch,Telnet Vulnerability,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2021 Critical Mageia
203

Mageia: MGASA-2021-0221 Critical: PostgreSQL Memory Flaws

Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027). Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE. (CVE-2021-32028). Memory disclosure in partitioned-table UPDATE ... RETURNING. (CVE-2021-32029). . MGASA-2021-0221 - Updated postgresql packages fix security vulnerabilities Publication date: 23 May 2021 URL: https://advisories.mageia.org/MGASA-2021-0221.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-32027, CVE-2021-32029, CVE-2021-32029 Buffer overrun from integer overflow in array subscripting calculations (CVE-2021-32027). Memory disclosure in INSERT ... ON CONFLICT ... DO UPDATE. (CVE-2021-32028). Memory disclosure in partitioned-table UPDATE ... RETURNING. (CVE-2021-32029). References: - https://bugs.mageia.org/show_bug.cgi?id=28929 - https://www.postgresql.org/about/news/postgresql-133-127-1112-1017-and-9622-released-2210/ - https://www.cve.org/CVERecord?id=CVE-2021-32027 - https://www.cve.org/CVERecord?id=CVE-2021-32029 - https://www.cve.org/CVERecord?id=CVE-2021-32029 SRPMS: - 8/core/postgresql11-11.12-1.mga8 - 8/core/postgresql13-13.3-1.mga8 - 7/core/postgresql9.6-9.6.22-1.mga7 - 7/core/postgresql11-11.12-1.mga7 . Recent updates to PostgreSQL packages as indicated by Mageia's security advisory have successfully resolved issues related to buffer overflow and memory leak vulnerabilities.. PostgreSQL Security, Mageia Updates, Memory Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 23, 2021 Critical Mageia
203

Mageia: 2020-0163 Moderate: Firefox Security Risks and Fixes

Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, . MGASA-2020-0163 - Updated firefox packages fix security vulnerabilities Publication date: 08 Apr 2020 URL: https://advisories.mageia.org/MGASA-2020-0163.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-XXXX Updated firefox packages fix security vulnerabilities: When reading from areas partially or fully outside the source resource with WebGL's copyTexSubImage method, the specification requires the returned values be zero. Previously, this memory was uninitialized, leading to potentially sensitive data disclosure (CVE-2020-6821). On 32-bit builds, an out of bounds write could have occurred when processing an image larger than 4 GB in GMPDecodeData. It is possible that with enough effort this could have been exploited to run arbitrary code (CVE-2020-6822). Mozilla developers Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code (CVE-2020-6825). References: - https://bugs.mageia.org/show_bug.cgi?id=26442 - https://www.mozilla.org/en-US/security/advisories/mfsa2020-13/ - https://www.cve.org/CVERecord?id=CVE-2019-XXXX SRPMS: - 7/core/firefox-68.7.0-1.mga7 - 7/core/firefox-l10n-68.7.0-1.mga7 . Mageia 2020-0174: Enhanced Chrome resolves security vulnerabilities and prospective threats. Discover the full report now!. Firefox Update, Mageia Security, Memory Safety, CVE-2020-6821, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 08, 2020 Important Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200