Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
87

Debian: DSA-5553-1 Critical PostgreSQL Memory Leak and Buffer Overflows

Several vulnerabilities have been discovered in the PostgreSQL database system. CVE-2023-5868 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5553-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 13, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : postgresql-15 CVE ID : CVE-2023-5868 CVE-2023-5869 CVE-2023-5870 CVE-2023-39417 CVE-2023-39418 Several vulnerabilities have been discovered in the PostgreSQL database system. CVE-2023-5868 Jingzhou Fu discovered a memory disclosure flaw in aggregate function calls. CVE-2023-5869 Pedro Gallegos reported integer overflow flaws resulting in buffer overflows in the array modification functions. CVE-2023-5870 Hemanth Sandrana and Mahendrakar Srinivasarao reported that the pg_cancel_backend role can signal certain superuser processes, potentially resulting in denial of service. CVE-2023-39417 Micah Gate, Valerie Woolard, Tim Carey-Smith, and Christoph Berg reported that an extension script using @substitutions@ within quoting may allow to perform an SQL injection for an attacker having database-level CREATE privileges. CVE-2023-39418 Dean Rasheed reported that the MERGE command to enforce UPDATE or SELECT row security policies. For the stable distribution (bookworm), these problems have been fixed in version 15.5-0+deb12u1. We recommend that you upgrade your postgresql-15 packages. For the detailed security status of postgresql-15 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/postgresql-15 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list:This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian security announcement DSA-5554-1 highlights critical vulnerabilities in the Apache HTTP Server, necessitating immediate patches. Comprehensive information provided.. Debian Security, PostgreSQL Update, Database Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 13, 2023 Critical Debian
91

Gentoo: 202211-04 High Severity: PostgreSQL Multiple Threats Detected

Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202211-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: PostgreSQL: Multiple Vulnerabilities Date: November 19, 2022 Bugs: #793734, #808984, #823125, #865255 ID: 202211-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in PostgreSQL, the worst of which could result in remote code execution. Background ========= PostgreSQL is an open source object-relational database management system. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- dev-db/postgresql < 10.22 > = 10.22:10 < 11.17:11 > = 11.17:11 < 12.12:12 > = 12.12:12 < 13.8:13 > = 13.8:13 < 14.5:14 > = 14.5 Description ========== Multiple vulnerabilities have been discovered in PostgreSQL. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All PostgreSQL 10.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-10.22:10" All PostgreSQL 11.x users should upgrade to the latest version: # emerge --sync # emerge--ask --oneshot --verbose "> =dev-db/postgresql-11.17:11" All PostgreSQL 12.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-12.12:12" All PostgreSQL 13.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-13.8:13" All PostgreSQL 14.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-db/postgresql-14.5:14" References ========= [ 1 ] CVE-2021-3677 https://nvd.nist.gov/vuln/detail/CVE-2021-3677 [ 2 ] CVE-2021-23214 https://nvd.nist.gov/vuln/detail/CVE-2021-23214 [ 3 ] CVE-2021-23222 https://nvd.nist.gov/vuln/detail/CVE-2021-23222 [ 4 ] CVE-2021-32027 https://nvd.nist.gov/vuln/detail/CVE-2021-32027 [ 5 ] CVE-2021-32028 https://nvd.nist.gov/vuln/detail/CVE-2021-32028 [ 6 ] CVE-2022-1552 https://nvd.nist.gov/vuln/detail/CVE-2022-1552 [ 7 ] CVE-2022-2625 https://nvd.nist.gov/vuln/detail/CVE-2022-2625 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202211-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Risks linked to PostgreSQL vulnerabilities can be significant. It is essential for users to update systems promptly to protect their data from potential threats.. PostgreSQL Security,Gentoo Advisory,High Severity Threats,Security Issues. . LinuxSecurity.com Team

Calendar%202 Nov 18, 2022 Gentoo
172

Ubuntu 16.04 ESM USN-5022-3 MySQL Security Issues Resolved

Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-5022-3 October 07, 2021 mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database Details: USN-5022-1 fixed several vulnerabilities in MySQL. This update provides the corresponding update for Ubuntu 16.04 ESM. Original advisory details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to MySQL 5.7.35 on Ubuntu 16.04 ESM. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-35.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-26.html https://www.oracle.com/security-alerts/cpujul2021.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: mysql-server 5.7.35-0ubuntu0.16.04.1+esm1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5022-3 https://ubuntu.com/security/notices/USN-5022-1 CVE-2021-2146, CVE-2021-2154, CVE-2021-2162, CVE-2021-2166, CVE-2021-2169, CVE-2021-2171, CVE-2021-2179, CVE-2021-2180, CVE-2021-2194, CVE-2021-2226, CVE-2021-2307, CVE-2021-2342, CVE-2021-2372, CVE-2021-2385, CVE-2021-2389, CVE-2021-2390 . Multiple vulnerabilities addressed in MySQL patch for Ubuntu 16.04 ESM on Oct 07, 2021, as outlined in advisory USN-5022-3.. MySQL Update, Ubuntu Security,Database Issues, Software Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 07, 2021 Important Ubuntu
172

Ubuntu 21.04: USN-4952-1 Critical: MySQL Database Issues

Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-4952-1 May 12, 2021 mysql-5.7, mysql-8.0 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.04 - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-8.0: MySQL database - mysql-5.7: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 8.0.25 in Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. Ubuntu 18.04 LTS has been updated to MySQL 5.7.34. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-34.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-24.html https://dev.mysql.com/doc/relnotes/mysql/8.0/en/news-8-0-25.html https://www.oracle.com/security-alerts/cpuapr2021.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.04: mysql-server-8.0 8.0.25-0ubuntu0.21.04.1 Ubuntu 20.10: mysql-server-8.0 8.0.25-0ubuntu0.20.10.1 Ubuntu 20.04 LTS: mysql-server-8.0 8.0.25-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: mysql-server-5.7 5.7.34-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4952-1 CVE-2021-2146, CVE-2021-2154, CVE-2021-2162, CVE-2021-2164, CVE-2021-2166, CVE-2021-2169, CVE-2021-2170,CVE-2021-2171, CVE-2021-2172, CVE-2021-2179, CVE-2021-2180, CVE-2021-2193, CVE-2021-2194, CVE-2021-2196, CVE-2021-2201, CVE-2021-2203, CVE-2021-2208, CVE-2021-2212, CVE-2021-2215, CVE-2021-2217, CVE-2021-2226, CVE-2021-2230, CVE-2021-2232, CVE-2021-2278, CVE-2021-2293, CVE-2021-2298, CVE-2021-2299, CVE-2021-2300, CVE-2021-2301, CVE-2021-2304, CVE-2021-2305, CVE-2021-2307, CVE-2021-2308 Package Information: https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.20.10.1 https://launchpad.net/ubuntu/+source/mysql-8.0/8.0.25-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.34-0ubuntu0.18.04.1 . Regularly applying security patches for PostgreSQL in Debian systems is crucial for ensuring system stability and database efficiency.. MySQL Update, Database Security, Linux Bug Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 12, 2021 Critical Ubuntu
172

Ubuntu 16.10: MySQL Critical Security Updates Addressed in USN-3174-1

Several security issues were fixed in MySQL.. =========================================================================Ubuntu Security Notice USN-3174-1 January 19, 2017 mysql-5.5, mysql-5.7 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in MySQL. Software Description: - mysql-5.7: MySQL database - mysql-5.5: MySQL database Details: Multiple security issues were discovered in MySQL and this update includes new upstream MySQL versions to fix these issues. MySQL has been updated to 5.5.54 in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS. Ubuntu 16.04 LTS and Ubuntu 16.10 have been updated to MySQL 5.7.17. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Please see the following for more information: http://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-17.html https://www.oracle.com/security-alerts/cpujan2017.html Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: mysql-server-5.7 5.7.17-0ubuntu0.16.10.1 Ubuntu 16.04 LTS: mysql-server-5.7 5.7.17-0ubuntu0.16.04.1 Ubuntu 14.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: mysql-server-5.5 5.5.54-0ubuntu0.12.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2016-8318, CVE-2016-8327, CVE-2017-3238, CVE-2017-3243, CVE-2017-3244, CVE-2017-3251, CVE-2017-3256, CVE-2017-3258, CVE-2017-3265, CVE-2017-3273, CVE-2017-3291, CVE-2017-3312, CVE-2017-3313, CVE-2017-3317, CVE-2017-3318, CVE-2017-3319, CVE-2017-3320 Package Information: https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/mysql-5.7/5.7.17-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/mysql-5.5/5.5.54-0ubuntu0.12.04.1 . Several problems addressed in MySQL for Ubuntu versions 16.10, 16.04, 14.04, and 12.04, with crucial patches detailed for every iteration.. MySQL Security Issues, Ubuntu Updates, Database Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 19, 2017 Critical Ubuntu
89

Fedora 24: 2016-badd014afe Moderate: Tarantool Multiple DoS Issues

Security fix for CVE-2016-9036, CVE-2016-9037. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-badd014afe 2016-12-22 02:23:18.167589 -------------------------------------------------------------------------------- Name : tarantool Product : Fedora 24 Version : 1.6.9.52 Release : 1.fc24 URL : https://www.tarantool.io/en/developers/ Summary : In-memory database and Lua application server Description : Tarantool is a high performance in-memory NoSQL database and Lua application server. Tarantool supports replication, online backup and stored procedures in Lua. This package provides the server daemon and admin tools. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-9036, CVE-2016-9037 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1406682 - CVE-2016-9036 CVE-2016-9037 tarantool: Multiple DoS vulnerabilities [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1406682 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tarantool' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . A security patch has been issued addressing various Denial of Service (DoS) vulnerabilities in Tarantool on Fedora 24. Users are advised tofollow the outlined steps for a secure update.. Fedora Tarantool Security Update, DoS Fix, In-Memory Database, Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 22, 2016 Important Fedora
87

Debian: DSA-3135-1 Critical: Upgrade MySQL 5.5 to Fix Issues

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.41. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3135-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso January 23, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mysql-5.5 CVE ID : CVE-2014-6568 CVE-2015-0374 CVE-2015-0381 CVE-2015-0382 CVE-2015-0411 CVE-2015-0432 Debian Bug : 775881 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.41. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: https://www.oracle.com/security-alerts/cpujan2015.html For the stable distribution (wheezy), these problems have been fixed in version 5.5.41-0+wheezy1. For the unstable distribution (sid), these problems will be fixed soon. We recommend that you upgrade your mysql-5.5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Advisory DSA-3135-1 highlights vulnerabilities in the MySQL server. It is advisable to perform an immediate upgrade to bolster security measures.. MySQL Security Update, Database Protection, Debian Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 23, 2015 Critical Debian
87

Debian: DSA-3054-1 Critical: MySQL Database Server Exploit Risks

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.40. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3054-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso October 20, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mysql-5.5 CVE ID : CVE-2012-5615 CVE-2014-4274 CVE-2014-4287 CVE-2014-6463 CVE-2014-6464 CVE-2014-6469 CVE-2014-6478 CVE-2014-6484 CVE-2014-6491 CVE-2014-6494 CVE-2014-6495 CVE-2014-6496 CVE-2014-6500 CVE-2014-6505 CVE-2014-6507 CVE-2014-6520 CVE-2014-6530 CVE-2014-6551 CVE-2014-6555 CVE-2014-6559 Debian Bug : 765663 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.40. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: https://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-40.html https://www.oracle.com/security-alerts/cpuoct2014.html For the stable distribution (wheezy), these problems have been fixed in version 5.5.40-0+wheezy1. For the unstable distribution (sid), these problems will be fixed soon. We recommend that you upgrade your mysql-5.5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The security update for MySQL 5.5, cataloged under DSA-3054-1, addresses severe vulnerabilities impacting the database system. It isadvisable to perform an upgrade.. MySQL Security Update, Database Threats, Debian DSA. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 20, 2014 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200