Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 22 mod_nss Security Advisory: CVE-2015-5244 Critical Cipher Issue

Fix for CVE-2015-5244. An OpenSSL cipher string wasn't disabled when prefixed with !.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-6aa4dd4f3a 2016-01-24 18:32:28.486161 -------------------------------------------------------------------------------- Name : mod_nss Product : Fedora 22 Version : 1.0.11 Release : 6.fc22 URL : https://fedoraproject.org/wiki/Infrastructure/Fedorahosted-retirement/ Summary : SSL/TLS module for the Apache HTTP server Description : The mod_nss module provides strong cryptography for the Apache Web server via the Secure Sockets Layer (SSL) and Transport Layer Security (TLS) protocols using the Network Security Services (NSS) security library. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2015-5244. An OpenSSL cipher string wasn't disabled when prefixed with !. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1263070 - CVE-2015-5244 mod_nss: incorrect ciphersuite parsing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1263070 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mod_nss' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Mitigate the mod_nss vulnerability CVE-2015-5244 on Fedora 22 by updating Apache HTTP server packagesfor secure cipher management and reducing risks. Fedora Updates, mod_nss Security, OpenSSL Issues, SSL Module Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 24, 2016 Critical Fedora
89

Fedora 22: 2015-8dd01b09a9 Moderate: Arts IPC Hijacking Issue

Security fix for CVE-2015-7543 in arts (the legacy aRts sound server): A temporary directory was being created insecurely using mktemp and mkdir, allowing an attacker to hijack the temporary directory and thus the inter- process communication (IPC). This update fixes the temporary directory creation to use the safe mkdtemp function instead.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-8dd01b09a9 2015-12-30 17:33:17.150916 -------------------------------------------------------------------------------- Name : arts Product : Fedora 22 Version : 1.5.10 Release : 30.fc22 URL : https://kde.org/ Summary : aRts (analog realtime synthesizer) - the KDE sound system Description : arts (analog real-time synthesizer) is the sound system of KDE 3. The principle of arts is to create/process sound using small modules which do certain tasks. These may be create a waveform (oscillators), play samples, filter data, add signals, perform effects like delay/flanger/chorus, or output the data to the soundcard. By connecting all those small modules together, you can perform complex tasks like simulating a mixer, generating an instrument or things like playing a wave file with some effects. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-7543 in arts (the legacy aRts sound server): A temporary directory was being created insecurely using mktemp and mkdir, allowing an attacker to hijack the temporary directory and thus the inter- process communication (IPC). This update fixes the temporary directory creation to use the safe mkdtemp function instead. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1280543 - CVE-2015-7543 arts,kdelibs3: Use of mktemp(3) allows attacker to hijack the IPC https://bugzilla.redhat.com/show_bug.cgi?id=1280543 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update arts' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Patch addresses vulnerable temp directory configurations in the audio service, preventing IPC exploitation. Critical security notification!. Fedora Update, Arts Security, IPC Hijacking Fix, Temporary Directory Issues. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2015 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200