Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure, denial of service or privilege escalation. For Debian 11 bullseye, these problems have been fixed in version. Debian LTS Advisory DLA-4510-1
Several security issues were fixed in the Linux kernel.. =========================================================================Ubuntu Security Notice USN-4116-1 September 02, 2019 linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: - linux: Linux kernel - linux-aws: Linux kernel for Amazon Web Services (AWS) systems - linux-kvm: Linux kernel for cloud environments - linux-raspi2: Linux kernel for Raspberry Pi 2 - linux-snapdragon: Linux kernel for Snapdragon processors Details: It was discovered that a use-after-free error existed in the block layer subsystem of the Linux kernel when certain failure conditions occurred. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2018-20856) Amit Klein and Benny Pinkas discovered that the Linux kernel did not sufficiently randomize IP ID values generated for connectionless networking protocols. A remote attacker could use this to track particular Linux devices. (CVE-2019-10638) Praveen Pandey discovered that the Linux kernel did not properly validate sent signals in some situations on PowerPC systems with transactional memory disabled. A local attacker could use this to cause a denial of service. (CVE-2019-13648) It was discovered that the floppy driver in the Linux kernel did not properly validate meta data, leading to a buffer overread. A local attacker could use this to cause a denial of service (system crash). (CVE-2019-14283) It was discovered that the floppy driver in the Linux kernel did not properly validate ioctl() calls, leading to a division-by-zero. A local attacker could use this to cause a denial of service (system crash). (CVE-2019-14284) Jason Wang discovered that an infinite loop vulnerabilityexisted in the virtio net driver in the Linux kernel. A local attacker in a guest VM could possibly use this to cause a denial of service in the host system. (CVE-2019-3900) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: linux-image-4.4.0-1056-kvm 4.4.0-1056.63 linux-image-4.4.0-1092-aws 4.4.0-1092.103 linux-image-4.4.0-1120-raspi2 4.4.0-1120.129 linux-image-4.4.0-1124-snapdragon 4.4.0-1124.130 linux-image-4.4.0-161-generic 4.4.0-161.189 linux-image-4.4.0-161-generic-lpae 4.4.0-161.189 linux-image-4.4.0-161-lowlatency 4.4.0-161.189 linux-image-4.4.0-161-powerpc-e500mc 4.4.0-161.189 linux-image-4.4.0-161-powerpc-smp 4.4.0-161.189 linux-image-4.4.0-161-powerpc64-emb 4.4.0-161.189 linux-image-4.4.0-161-powerpc64-smp 4.4.0-161.189 linux-image-aws 4.4.0.1092.96 linux-image-generic 4.4.0.161.169 linux-image-generic-lpae 4.4.0.161.169 linux-image-kvm 4.4.0.1056.56 linux-image-lowlatency 4.4.0.161.169 linux-image-powerpc-e500mc 4.4.0.161.169 linux-image-powerpc-smp 4.4.0.161.169 linux-image-powerpc64-emb 4.4.0.161.169 linux-image-powerpc64-smp 4.4.0.161.169 linux-image-raspi2 4.4.0.1120.120 linux-image-snapdragon 4.4.0.1124.116 linux-image-virtual 4.4.0.161.169 After a standard system update you need to reboot your computer to make all the necessary changes. ATTENTION: Due to an unavoidable ABI change the kernel updates have been given a new version number, which requires you to recompile and reinstall all third party kernel modules you might have installed. Unless you manually uninstalled the standard kernel metapackages (e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual, linux-powerpc), a standard system upgrade will automatically perform this as well. References: https://ubuntu.com/security/notices/USN-4116-1 CVE-2018-20856,CVE-2019-10638, CVE-2019-13648, CVE-2019-14283, CVE-2019-14284, CVE-2019-3900 Package Information: https://launchpad.net/ubuntu/+source/linux/4.4.0-161.189 https://launchpad.net/ubuntu/+source/linux-aws/4.4.0-1092.103 https://launchpad.net/ubuntu/+source/linux-kvm/4.4.0-1056.63 https://launchpad.net/ubuntu/+source/linux-raspi2/4.4.0-1120.129 https://launchpad.net/ubuntu/+source/linux-snapdragon/4.4.0-1124.130 . In September 2019, Ubuntu released a vital security advisory addressing key vulnerabilities in its kernel, crucial for system integrity and data security. Ubuntu Kernel Security, Linux Kernel Issues, Denial Of Service, Buffer Overread. . Severity: Critical. LinuxSecurity.com Team
It was discovered that wireshark, a network protocol analyzer, contained several vulnerabilities in the dissectors for DCERPC, AllJoyn, DTN, and OpenFlow, that could lead to various crashes, denial-of-service, or execution of arbitrary code. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3719-1
Critical: firefox security update. Date: Mon, 3 Nov 2014 17:53:33 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Synopsis: Critical: firefox security update Advisory ID: SLSA-2014:1635-1 Issue Date: 2014-10-15 CVE Numbers: CVE-2014-1574 CVE-2014-1576 CVE-2014-1577 CVE-2014-1578 CVE-2014-1581 CVE-2014-1583 -- Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2014-1574, CVE-2014-1578, CVE-2014-1581, CVE-2014-1576, CVE-2014-1577) A flaw was found in the Alarm API, which allows applications to schedule actions to be run in the future. A malicious web application could use this flaw to bypass cross-origin restrictions. (CVE-2014-1583) After installing the update, Firefox must be restarted for the changes to take effect. -- SL5 x86_64 firefox-31.2.0-3.el5_11.i386.rpm firefox-31.2.0-3.el5_11.x86_64.rpm firefox-debuginfo-31.2.0-3.el5_11.i386.rpm firefox-debuginfo-31.2.0-3.el5_11.x86_64.rpm i386 firefox-31.2.0-3.el5_11.i386.rpm firefox-debuginfo-31.2.0-3.el5_11.i386.rpm SL6 x86_64 firefox-31.2.0-3.el6_6.x86_64.rpm firefox-debuginfo-31.2.0-3.el6_6.x86_64.rpm firefox-31.2.0-3.el6_6.i686.rpm firefox-debuginfo-31.2.0-3.el6_6.i686.rpm i386 firefox-31.2.0-3.el6_6.i686.rpm firefox-debuginfo-31.2.0-3.el6_6.i686.rpm SL7 x86_64 firefox-31.2.0-3.el7_0.x86_64.rpm firefox-debuginfo-31.2.0-3.el7_0.x86_64.rpm xulrunner-31.2.0-1.el7_0.i686.rpm xulrunner-31.2.0-1.el7_0.x86_64.rpm xulrunner-debuginfo-31.2.0-1.el7_0.i686.rpm xulrunner-debuginfo-31.2.0-1.el7_0.x86_64.rpm firefox-31.2.0-3.el7_0.i686.rpm firefox-debuginfo-31.2.0-3.el7_0.i686.rpm xulrunner-devel-31.2.0-1.el7_0.i686.rpm xulrunner-devel-31.2.0-1.el7_0.x86_64.rpm - Scientific Linux Development Team .Important Firefox patch resolves several vulnerabilities to bolster protection for Scientific Linux variants.. firefox Update, Linux Security, Cross-Origin Issue, Scientific Linux Advisory, Code Execution Threat. . Severity: Critical. LinuxSecurity.com Team
Important: openoffice.org security update. Date: Thu, 6 Nov 2008 13:20:24 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for openoffice.org on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "
Get the latest Linux and open source security news straight to your inbox.