Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian LTS: DLA-2284-1 Moderate: ksh Remote Command Execution Threat

A flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2284-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Brian May July 21, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ksh Version : 93u+20120801-3.1+deb9u1 CVE ID : CVE-2019-14868 A flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow remote unauthenticated attackers to provide one of those environment variables could allow them to exploit this issue remotely. For Debian 9 stretch, this problem has been fixed in version 93u+20120801-3.1+deb9u1. We recommend that you upgrade your ksh packages. For the detailed security status of ksh please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ksh Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS: DLA-2285-2 upgrades vim to address a security vulnerability that could lead to arbitrary code execution.. Debian Security, ksh Update, Remote Exploit, Shell Command Bypass. . LinuxSecurity.com Team

Calendar%202 Jul 21, 2020 Debian LTS
172

Ubuntu 14.04 LTS USN-2363-1: Bash Environment Bypass Threat

Bash allowed bypassing environment restrictions in certain environments.. =========================================================================Ubuntu Security Notice USN-2363-1 September 25, 2014 bash vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Bash allowed bypassing environment restrictions in certain environments. Software Description: - bash: GNU Bourne Again SHell Details: Tavis Ormandy discovered that the security fix for Bash included in USN-2362-1 was incomplete. An attacker could use this issue to bypass certain environment restrictions. (CVE-2014-7169) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: bash 4.3-7ubuntu1.2 Ubuntu 12.04 LTS: bash 4.2-2ubuntu2.3 Ubuntu 10.04 LTS: bash 4.1-2ubuntu3.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2363-1 CVE-2014-7169 Package Information: https://launchpad.net/ubuntu/+source/bash/4.3-7ubuntu1.2 https://launchpad.net/ubuntu/+source/bash/4.2-2ubuntu2.3 https://launchpad.net/ubuntu/+source/bash/4.1-2ubuntu3.2 . Alert regarding security vulnerability in Ubuntu Bash impacting versions 10.04, 12.04, and 14.04. Users are urged to implement protective measures and install available patches.. Ubuntu Security,Bash Update,USN-2363-1,Environment Bypass,Linux Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2014 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200