Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
172

Ubuntu 18.04 LTS USN-7730-1 PIM Messagelib Critical Email Issue

Several security issues were fixed in PIM Messagelib.. ========================================================================== Ubuntu Security Notice USN-7730-1 September 02, 2025 kf5-messagelib vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Several security issues were fixed in PIM Messagelib. Software Description: - kf5-messagelib: KDE PIM messaging library Details: Damian Poddebniak, Christian Dresen, Jens Müller, Fabian Ising, Sebastian Schinzel, Simon Friedberger, Juraj Somorovsky, and Jörg Schwenk discovered that PIM Messagelib could be made to leak the plaintext of S/MIME encrypted emails when retrieving external content in emails. Under certain configurations, if a user were tricked into opening a specially crafted email using an application linked against PIM Messagelib, an attacker could possibly use this issue to obtain the plaintext of an encrypted email. This update mitigates the issue by preventing automatic loading of external content. (CVE-2017-17689) Jens Müller, Marcus Brinkmann, Damian Poddebniak, Sebastian Schinzel, and Jörg Schwenk discovered that PIM Messagelib could be made to leak the plaintext of S/MIME or PGP encrypted emails. If a user were tricked into replying to a specially crafted email using an application linked against PIM Messagelib, an attacker could possibly use this issue to obtain the plaintext of an encrypted email. (CVE-2019-10732) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS libkf5messageviewer5abi4 4:17.12.3-0ubuntu3+esm1 Available with Ubuntu Pro libkf5mimetreeparser5abi2 4:17.12.3-0ubuntu3+esm1 Available with Ubuntu Pro libkf5templateparser5abi2 4:17.12.3-0ubuntu3+esm1 Available with Ubuntu Pro After astandard system update you need to restart any applications which use PIM Messagelib, such as KMail, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7730-1 CVE-2017-17689, CVE-2019-10732 . Serious security flaws have been identified in PIM Messagelib on Ubuntu 18.04 LTS that urgently need to be addressed to avert potential data breaches.. PIM Messagelib, Ubuntu vulnerabilities, email leak, data exposure, critical issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 03, 2025 Critical Ubuntu
197

Debian DLA-3642-1 Moderate: Request Tracker Email Leak Advisory

Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3642-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Salvatore Bonaccorso October 31, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : request-tracker4 Version : 4.4.3-2+deb10u3 CVE ID : CVE-2023-41259 CVE-2023-41260 Debian Bug : 1054516 Multiple vulnerabilities have been discovered in Request Tracker, an extensible trouble-ticket tracking system. CVE-2023-41259 Tom Wolters reported that Request Tracker is vulnerable to accepting unvalidated RT email headers in incoming email and the mail-gateway REST interface. CVE-2023-41260 Tom Wolters reported that Request Tracker is vulnerable to information leakage via response messages returned from requests sent via the mail-gateway REST interface. For Debian 10 buster, these problems have been fixed in version 4.4.3-2+deb10u3. We recommend that you upgrade your request-tracker4 packages. For the detailed security status of request-tracker4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/request-tracker4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian Long Term Support team has issued an advisory addressing multiple vulnerabilities in Request Tracker, focusing on email processing and data security.. Debian Security, Request Tracker, Email Vulnerability. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Debian LTS
202

openSUSE Leap 15.2: SUSE-SU-2021:0646-1 Moderate Email Issue Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for postsrsd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0646-1 Rating: moderate References: #1180251 Cross-References: CVE-2020-35573 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for postsrsd fixes the following issues: Update to release 1.11 [boo#1180251] * Drop group privileges as well as user privileges * Fixed: The subprocess that talks to Postfix could be caused to hang with a very long email address. [CVE-2020-35573] Update to release 1.6 * Fix endianness issue with SHA-1 implementation * Add dual stack support * Make SRS separator configurable Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-646=1 Package List: - openSUSE Leap 15.2 (x86_64): postsrsd-1.11-lp152.4.3.1 postsrsd-debuginfo-1.11-lp152.4.3.1 postsrsd-debugsource-1.11-lp152.4.3.1 References: https://www.suse.com/security/cve/CVE-2020-35573.html https://bugzilla.suse.com/1180251 . A security update addressing one vulnerability in openSUSE's postsrsd has been issued. For further information, please consult the announcement ID.. openSUSE Security, postsrsd Update, Email Security Patch. . LinuxSecurity.com Team

Calendar%202 May 01, 2021 OpenSUSE
172

Ubuntu 20.10: USN-4703-1 Moderate: Mutt Denial Of Service Issue

Mutt could be made to denial of service if it received a specially crafted email message.. =========================================================================Ubuntu Security Notice USN-4703-1 January 25, 2021 mutt vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Mutt could be made to denial of service if it received a specially crafted email message. Software Description: - mutt: text-based mailreader supporting MIME, GPG, PGP and threading Details: It was discovered that Mutt incorrectly handled certain email messages. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: mutt 1.14.6-1ubuntu0.2 Ubuntu 20.04 LTS: mutt 1.13.2-1ubuntu0.4 Ubuntu 18.04 LTS: mutt 1.9.4-3ubuntu0.5 Ubuntu 16.04 LTS: mutt 1.5.24-1ubuntu0.6 In general, a standard system update will make all the necessary changes. References: CVE-2021-3181 Package Information: https://launchpad.net/ubuntu/+source/mutt/1.14.6-1ubuntu0.2 https://launchpad.net/ubuntu/+source/mutt/1.13.2-1ubuntu0.4 https://launchpad.net/ubuntu/+source/mutt/1.9.4-3ubuntu0.5 https://launchpad.net/ubuntu/+source/mutt/1.5.24-1ubuntu0.6 . Explore how to mitigate the Denial of Service risk in Mutt on Ubuntu 20.10 caused by specifically crafted email messages to ensure your security. Mutt Denial of Service, Ubuntu Security Update, Mutt Vulnerability Fix. . LinuxSecurity.com Team

Calendar%202 Jan 25, 2021 Ubuntu
197

Debian 9 DLA-2529-1: Critical Security Update for Mutt DoS Vulnerability

rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2529-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta January 21, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : mutt Version : 1.7.2-1+deb9u5 CVE ID : CVE-2021-3181 Debian Bug : 980326 rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of empty groups). A small email message from the attacker can cause large memory consumption, and the victim may then be unable to see email messages from other persons. For Debian 9 stretch, this problem has been fixed in version 1.7.2-1+deb9u5. We recommend that you upgrade your mutt packages. For the detailed security status of mutt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mutt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security vulnerability concerning Denial of Service has been addressed in Mutt within Debian LTS Advisory DLA-2529-1. It is recommended to update your packages to ensure protection.. Mutt Attack, Debian Security, Email Vulnerability, LTS Update, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 20, 2021 Critical Debian LTS
203

Mageia: 2021-0008 Critical: Dovecot Remote Access and DoS Issues

It was discovered that Dovecot incorrectly handled certain imap hibernation commands. A remote authenticated attacker could possibly use this issue to access other users’ email (CVE-2020-24386). Innokentii Sennovskiy discovered that Dovecot incorrectly handled MIME . MGASA-2021-0008 - Updated dovecot packages fix security vulnerabilities Publication date: 08 Jan 2021 URL: https://advisories.mageia.org/MGASA-2021-0008.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24386, CVE-2020-25275 It was discovered that Dovecot incorrectly handled certain imap hibernation commands. A remote authenticated attacker could possibly use this issue to access other users’ email (CVE-2020-24386). Innokentii Sennovskiy discovered that Dovecot incorrectly handled MIME parsing. A remote attacker could possibly use this issue to cause Dovecot to crash, resulting in a denial of service (CVE-2020-25275). The dovecot package has been updated to version 2.3.13, fixing these issues and other bugs. See the upstream release announcement for details. References: - https://bugs.mageia.org/show_bug.cgi?id=28012 - https://dovecot.org/pipermail/dovecot-news/2021-January/000450.html - https://dovecot.org/pipermail/dovecot-news/2021-January/000451.html - https://dovecot.org/pipermail/dovecot-news/2021-January/000448.html - https://ubuntu.com/security/notices/USN-4674-1 - https://www.cve.org/CVERecord?id=CVE-2020-24386 - https://www.cve.org/CVERecord?id=CVE-2020-25275 SRPMS: - 7/core/dovecot-2.3.13-1.mga7 . New Dovecot updates in Mageia address severe security vulnerabilities, including possible remote exploitation and Denial of Service threats.. Dovecot Security, Mageia Update, Remote Access Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 08, 2021 Critical Mageia
200

SciLinux: SLSA-2020-0574-1 Important: Thunderbird Crash Fixes and Issues

Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect p [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2020:0574-1 Issue Date: 2020-02-24 CVE Numbers: None -- Security Fix(es): Mozilla: Memory safety bugs fixed in Firefox 73 and Firefox ESR 68.5 (CVE-2020-6800) Mozilla: Out-of-bounds read when processing certain email messages (CVE-2020-6793) Mozilla: Setting a master password post-Thunderbird 52 does not delete unencrypted previously stored passwords (CVE-2020-6794) Mozilla: Crash processing S/MIME messages with multiple signatures (CVE-2020-6795) Mozilla: Incorrect parsing of template tag could result in JavaScript injection (CVE-2020-6798) Mozilla: Message ID calculation was based on uninitialized data (CVE-2020-6792) -- SL6 x86_64 thunderbird-68.5.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.5.0-1.el6_10.x86_64.rpm i386 thunderbird-68.5.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.5.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Scientists must immediately apply the security update for Thunderbird to fix critical email processing bugs on SL6.. Mozilla, Thunderbird, Memory Safety, Email Security, SL6. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 25, 2020 Important Scientific Linux
172

Ubuntu 18.04 & 16.04: USN-3998-1 Critical Evolution Email Display Issue

Evolution Data Server would sometimes display email content as encrypted when it was not.. =========================================================================Ubuntu Security Notice USN-3998-1 May 30, 2019 evolution-data-server vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Evolution Data Server would sometimes display email content as encrypted when it was not. Software Description: - evolution-data-server: Evolution suite data server Details: Marcus Brinkmann discovered that Evolution Data Server did not correctly interpret the output from GPG when decrypting encrypted messages. Under certain circumstances, this could result in displaying clear-text portions of encrypted messages as though they were encrypted. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: evolution-data-server 3.28.5-0ubuntu0.18.04.2 evolution-data-server-common 3.28.5-0ubuntu0.18.04.2 libcamel-1.2-61 3.28.5-0ubuntu0.18.04.2 libebackend-1.2-10 3.28.5-0ubuntu0.18.04.2 libedataserver-1.2-23 3.28.5-0ubuntu0.18.04.2 Ubuntu 16.04 LTS: evolution-data-server 3.18.5-1ubuntu1.2 evolution-data-server-common 3.18.5-1ubuntu1.2 libcamel-1.2-54 3.18.5-1ubuntu1.2 libebackend-1.2-10 3.18.5-1ubuntu1.2 libedataserver-1.2-21 3.18.5-1ubuntu1.2 After a standard system update you need to restart Evolution to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3998-1 CVE-2018-15587 Package Information: https://launchpad.net/ubuntu/+source/evolution-data-server/3.28.5-0ubuntu0.18.04.2 https://launchpad.net/ubuntu/+source/evolution-data-server/3.18.5-1ubuntu1.2 . Ubuntu Security Notice USN-3999-1 addresses a vulnerability within the NetworkManagerservice that may expose sensitive information.. email decryption, Evolution Data Server, Ubuntu updates, data security, encryption errors. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 30, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200