Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian 3.0: DSA 661-2 Critical: f2c Insecure Temporary Files Advisory

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 661-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze April 20th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : f2c Vulnerability : insecure temporary files Problem-Type : local Debian-specific: no CVE ID : CAN-2005-0017 Dan McMahill noticed that our our advisory DSA 661-1 did not correct the multiple insecure files problem, hence, this update. For completeness below is the original advisory text: Javier Fernández-Sanguino Peña from the Debian Security Audit project discovered that f2c and fc, which are both part of the f2c package, a fortran 77 to C/C++ translator, open temporary files insecurely and are hence vulnerable to a symlink attack. The Common Vulnerabilities and Exposures project identifies the following vulnerabilities: CAN-2005-0017 Multiple insecure temporary files in the f2c translator. For the stable distribution (woody) and all others including testing this problem has been fixed in version 20010821-3.2. We recommend that you upgrade your f2c package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 519 9b2bb4378799e59604236b0b3ac9d071 Size/MD5 checksum: 288462d49723d6a8e1ea4f67737dd031d34c0 Size/MD5 checksum: 416017 f2527aed84c8db35c883615c3b9b8511 Alpha architecture: Size/MD5 checksum: 524226 0f5c34632212482cf65bb34353e8a22d ARM architecture: Size/MD5 checksum: 470606 c6dd76b690a83e375f8c921d2b871b6e Intel IA-32 architecture: Size/MD5 checksum: 423136 d1d1523248bc0da3216c9361e3674b6c Intel IA-64 architecture: Size/MD5 checksum: 678896 8f1fff444a7c3f19d0928b932c170b53 HP Precision architecture: Size/MD5 checksum: 493478 add18234ac7c933ab0200fb31a085048 Motorola 680x0 architecture: Size/MD5 checksum: 407490 4767c71a54b67e19d6039afa3e272f7b Big endian MIPS architecture: Size/MD5 checksum: 482944 8efcba5fae72fac7afdaa21985a24201 Little endian MIPS architecture: Size/MD5 checksum: 481100 0f45588cacac79ee241319f4a83fcb42 PowerPC architecture: Size/MD5 checksum: 455566 1b8f4f055268a71e99bd39ecc952cbef IBM S/390 architecture: Size/MD5 checksum: 446284 333d26b19a55a4b564ba927cd5e689db Sun Sparc architecture: Size/MD5 checksum: 467270 743a0e4974deed21925aba2900942338 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolution for vulnerable temporary files identified in Debian's f2c package. Update to maintain system safety and enhance security measures.. Debian Advisory, f2c Package Fix, Security Patch, System Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 20, 2005 Critical Debian
91

Gentoo: GLSA-200501-43 Normal: Insecure f2c File Creation Issue

f2c is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-43 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: f2c: Insecure temporary file creation Date: January 30, 2005 Bugs: #79725 ID: 200501-43 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= f2c is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= f2c is a Fortran to C translator. Portage uses this package in some ebuilds to build Fortran sources. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/f2c = 20030320-r1 Description ========== Javier Fernandez-Sanguino Pena from the Debian Security Audit Team discovered that f2c creates temporary files in world-writeable directories with predictable names. Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When f2c is executed, this would result in the file being overwritten with the rights of the user running the software, which could be the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All f2c users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/f2c-20030320-r1" References ========= [ 1 ] CAN-2005-0017 https://www.cve.org/CVERecord?id=CVE-CAN-2005-0017 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-43 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Uncover the vulnerabilities associated with f2c's insecure handling of temporary files on Gentoo. Implement measures to avert possible symlink exploits.. Gentoo F2C Advisory, Temporary File Risks, Symlink Exploitation. . LinuxSecurity.com Team

Calendar%202 Jan 30, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200