Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 7 LTS: DLA-1063-1 Critical Command Injection in Extplorer

CVE-2017-12756 Fix command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the . Hash: SHA512 Package : extplorer Version : 2.1.0b6+dfsg.3-4+deb7u5 CVE ID : CVE-2017-12756 CVE-2017-12756 Fix command inject in transfer from another server in extplorer 2.1.9 and prior allows attacker to inject command via the userfile[0] parameter. For Debian 7 "Wheezy", these problems have been fixed in version 2.1.0b6+dfsg.3-4+deb7u5. We recommend that you upgrade your extplorer packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Critical security patch released for Debian 7 targeting remote code execution vulnerability, users advised to upgrade software immediately.. Extplorer Security Update, Debian LTS Update, Command Injection Resolution, Extplorer Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 21, 2017 Critical Debian LTS
87

Debian: DSA-2882-1 Urgent: Extplorer XSS Vulnerability Resolution

Multiple cross-site scripting (XSS) vulnerabilities have been discovered in extplorer, a web file explorer and manager using Ext JS. A remote attackers can inject arbitrary web script or HTML code via a crafted string in the URL to application.js.php, admin.php, copy_move.php, . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2882-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano March 20, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : extplorer CVE ID : CVE-2013-5951 Debian Bug : 741908 Multiple cross-site scripting (XSS) vulnerabilities have been discovered in extplorer, a web file explorer and manager using Ext JS. A remote attackers can inject arbitrary web script or HTML code via a crafted string in the URL to application.js.php, admin.php, copy_move.php, functions.php, header.php and upload.php. For the oldstable distribution (squeeze), this problem has been fixed in version 2.1.0b6+dfsg.2-1+squeeze2. For the stable distribution (wheezy), this problem has been fixed in version 2.1.0b6+dfsg.3-4+deb7u1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your extplorer packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-2893-1: Mitigating various CSRF vulnerabilities in filemanager for improved protection protocols.. XSS Exploit, Extplorer Fix, Debian Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 20, 2014 Critical Debian
87

Debian DSA-2510-1 Critical: eXtplorer Cross-Site Request Forgery Issue

John Leitch has discovered a vulnerability in eXtplorer, a very feature rich web server file manager, which can be exploited by malicious people to conduct cross-site request forgery attacks. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2510-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Luciano Bello July 12, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : extplorer Vulnerability : Cross-site request forgery Problem type : remote Debian-specific: no CVE ID : CVE-2012-3362 Debian Bug : 678737 John Leitch has discovered a vulnerability in eXtplorer, a very feature rich web server file manager, which can be exploited by malicious people to conduct cross-site request forgery attacks. The vulnerability allows users to perform certain actions via HTTP requests without performing any validity checks to verify the request. This can be exploited for example, to create an administrative user account by tricking an logged administrator to visiting an attacker-defined web link. For the stable distribution (squeeze), this problem has been fixed in version 2.1.0b6+dfsg.2-1+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 2.1.0b6+dfsg.3-3. For the unstable distribution (sid), this problem has been fixed in version 2.1.0b6+dfsg.3-3. We recommend that you upgrade your extplorer packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Important Debian Notification DSA-2510-1 addresses a cross-site request forgery vulnerability found in eXtplorer; an update is advised.. extplorer vulnerability,debian security update,cross-site request forgery. . Severity:Critical. LinuxSecurity.com Team

Calendar%202 Jul 12, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200