Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes four vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 20 for SLE 15) ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:3178-1 Rating: important References: #1173942 #1176012 #1176382 #1176896 Cross-References: CVE-2020-0431 CVE-2020-11668 CVE-2020-14381 CVE-2020-25212 Affected Products: SUSE Linux Enterprise Module for Live Patching 15 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for the Linux Kernel 4.12.14-150_58 fixes several issues. The following security issues were fixed: - CVE-2020-14381: Fixed a use-after-free in the fast user mutex (futex) wait operation, which could have lead to memory corruption and possibly privilege escalation (bsc#1176011). - CVE-2020-0431: In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. (bsc#1176722) - CVE-2020-25212: A TOCTOU mismatch in the NFS client code could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c (bsc#1176381). - CVE-2020-11668: Fixed an out of bounds write to the heap in drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) caused by mishandling invalid descriptors (bsc#1168952). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for LivePatching 15: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-2020-3178=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15 (ppc64le x86_64): kernel-livepatch-4_12_14-150_58-default-2-2.1 kernel-livepatch-4_12_14-150_58-default-debuginfo-2-2.1 References: https://www.suse.com/security/cve/CVE-2020-0431.html https://www.suse.com/security/cve/CVE-2020-11668.html https://www.suse.com/security/cve/CVE-2020-14381.html https://www.suse.com/security/cve/CVE-2020-25212.html https://bugzilla.suse.com/1173942 https://bugzilla.suse.com/1176012 https://bugzilla.suse.com/1176382 https://bugzilla.suse.com/1176896 . Important security patch released for SUSE Linux Kernel addressing various vulnerabilities related to privilege abuses and memory corruption.. SUSE Linux Kernel Patch, Live Patching, Security Update. . Severity: Important. LinuxSecurity.com Team
A vulnerability in Apache might allow an attacker to escalate privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201904-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Apache: Privilege escalation Date: April 22, 2019 Bugs: #682306 ID: 201904-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in Apache might allow an attacker to escalate privileges. Background ========= The Apache HTTP server is one of the most popular web servers on the Internet. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/apache < 2.4.39 > = 2.4.39 Description ========== A vulnerability was discovered in Apache with MPM event, worker, or prefork. Impact ===== An attacker could escalate privileges. Workaround ========= There is no known workaround at this time. Resolution ========= All Apache users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-servers/apache-2.4.39" References ========= [ 1 ] CVE-2019-0211 https://nvd.nist.gov/vuln/detail/CVE-2019-0211 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201904-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180 . Package : cups Version : 1.7.5-11+deb8u4 CVE ID : CVE-2018-4180 CVE-2018-4181 CVE-2018-6553 Several vulnerabilities were discovered in CUPS, the Common UNIX Printing System. These issues have been identified with the following CVE ids: CVE-2018-4180 Dan Bastone of Gotham Digital Science discovered that a local attacker with access to cupsctl could escalate privileges by setting an environment variable. CVE-2018-4181 Eric Rafaloff and John Dunlap of Gotham Digital Science discovered that a local attacker can perform limited reads of arbitrary files as root by manipulating cupsd.conf. CVE-2018-6553 Dan Bastone of Gotham Digital Science discovered that an attacker can bypass the AppArmor cupsd sandbox by invoking the dnssd backend using an alternate name that has been hard linked to dnssd. For Debian 8 "Jessie", these problems have been fixed in version 1.7.5-11+deb8u4. We recommend that you upgrade your cups packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : cups Version : 1.7.5-11+deb8u4 CVE ID : CVE-2018-4180 CVE-2018-4181 CVE-2018-6553 Several . vulnerabilities, common, printing, system, these. . Severity: Important. LinuxSecurity.com Team
A vulnerability in PNP4Nagios which may allow local attackers to gain root privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201806-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PNP4Nagios: Root privilege escalation Date: June 24, 2018 Bugs: #637640 ID: 201806-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in PNP4Nagios which may allow local attackers to gain root privileges. Background ========= PNP4Nagios is an addon for the Nagios Network Monitoring System. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/pnp4nagios < 0.6.26-r9 > = 0.6.26-r9 Description ========== It was found that PHP4Nagios creates files owned by an unprivileged user that are used by root. Impact ===== A local attacker could escalate privileges to root. Workaround ========= There is no known workaround at this time. Resolution ========= All PNP4Nagios users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-analyzer/pnp4nagios-0.6.26-r9" References ========= [ 1 ] CVE-2017-16834 https://nvd.nist.gov/vuln/detail/CVE-2017-16834 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201806-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should beaddressed to
Gnu C library could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-3323-1 June 19, 2017 eglibc, glibc vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Gnu C library could be made to run programs as an administrator. Software Description: - glibc: GNU C Library - eglibc: GNU C Library Details: It was discovered that the GNU C library did not properly handle memory when processing environment variables for setuid programs. A local attacker could use this in combination with another vulnerability to gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libc6 2.24-9ubuntu2.2 Ubuntu 16.10: libc6 2.24-3ubuntu2.2 Ubuntu 16.04 LTS: libc6 2.23-0ubuntu9 Ubuntu 14.04 LTS: libc6 2.19-0ubuntu6.13 After a standard system update you need to reboot your computer to make all the necessary changes. References: CVE-2017-1000366 Package Information: https://launchpad.net/ubuntu/+source/glibc/2.24-9ubuntu2.2 https://launchpad.net/ubuntu/+source/glibc/2.24-3ubuntu2.2 https://launchpad.net/ubuntu/+source/glibc/2.23-0ubuntu9 https://launchpad.net/ubuntu/+source/eglibc/2.19-0ubuntu6.13 . The GNU C Library on Ubuntu may enable local exploitation leading to elevated permissions. Immediate updates are essential for enhanced security.. glibc, escalation threat, ubuntu update, security advisory, local exploit. . Severity: Critical. LinuxSecurity.com Team
An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2017:0366-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2017:0366.html Issue date: 2017-03-01 CVE Names: CVE-2017-6074 ==================================================================== 1. Summary: An update for kernel is now available for Red Hat Enterprise Linux 6.5 Advanced Update Support and Red Hat Enterprise Linux 6.5 Telco Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 6.5) - noarch, x86_64 Red Hat Enterprise Linux Server Optional AUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server Optional TUS (v. 6.5) - x86_64 Red Hat Enterprise Linux Server TUS (v. 6.5) - noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * A use-after-free flaw was found in the way the Linux kernel's Datagram Congestion Control Protocol (DCCP) implementation freed SKB (socket buffer) resources for a DCCP_PKT_REQUEST packet when the IPV6_RECVPKTINFO option is set on the socket. A local, unprivileged user could use this flaw to alter the kernel memory, allowing them to escalate their privileges on the system. (CVE-2017-6074, Important) Red Hat would like to thank Andrey Konovalov(Google) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1423071 - CVE-2017-6074 kernel: use after free in dccp protocol 6. Package List: Red Hat Enterprise Linux Server AUS (v. 6.5): Source: kernel-2.6.32-431.78.1.el6.src.rpm noarch: kernel-abi-whitelists-2.6.32-431.78.1.el6.noarch.rpm kernel-doc-2.6.32-431.78.1.el6.noarch.rpm kernel-firmware-2.6.32-431.78.1.el6.noarch.rpm x86_64: kernel-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-431.78.1.el6.x86_64.rpm kernel-devel-2.6.32-431.78.1.el6.x86_64.rpm kernel-headers-2.6.32-431.78.1.el6.x86_64.rpm perf-2.6.32-431.78.1.el6.x86_64.rpm perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 6.5): Source: kernel-2.6.32-431.78.1.el6.src.rpm noarch: kernel-abi-whitelists-2.6.32-431.78.1.el6.noarch.rpm kernel-doc-2.6.32-431.78.1.el6.noarch.rpm kernel-firmware-2.6.32-431.78.1.el6.noarch.rpm x86_64: kernel-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debug-devel-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-431.78.1.el6.x86_64.rpm kernel-devel-2.6.32-431.78.1.el6.x86_64.rpm kernel-headers-2.6.32-431.78.1.el6.x86_64.rpm perf-2.6.32-431.78.1.el6.x86_64.rpm perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional AUS (v.6.5): Source: kernel-2.6.32-431.78.1.el6.src.rpm x86_64: kernel-debug-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-431.78.1.el6.x86_64.rpm perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm python-perf-2.6.32-431.78.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm Red Hat Enterprise Linux Server Optional TUS (v. 6.5): Source: kernel-2.6.32-431.78.1.el6.src.rpm x86_64: kernel-debug-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-431.78.1.el6.x86_64.rpm perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm python-perf-2.6.32-431.78.1.el6.x86_64.rpm python-perf-debuginfo-2.6.32-431.78.1.el6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-6074 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2017 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFYtwatXlSAg2UNWIIRAqOuAJ4lbOtfqj3ExIVAfnvsCRcfEt8OjgCfbR8W s7bi+3r1VgNMrL9uEP2nBCs=e3U0 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list
A vulnerability in xinetd could lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201611-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xinetd: Privilege escalation Date: November 15, 2016 Bugs: #488158 ID: 201611-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in xinetd could lead to privilege escalation. Background ========= xinetd is a secure replacement for inetd. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/xinetd < 2.3.15-r2 > = 2.3.15-r2 Description ========== Xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root. Impact ===== Attackers could escalate privileges outside of the running process. Workaround ========= There is no known workaround at this time. Resolution ========= All xinetd users should upgrade to the latest version: # emerge --sync # emerge --ask --verbose --oneshot "> =sys-apps/xinetd-2.3.15-r2" References ========= [ 1 ] CVE-2013-4342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4342 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201611-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
Get the latest Linux and open source security news straight to your inbox.