Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves five vulnerabilities can now be installed.. # Security update for grub2 Announcement ID: SUSE-SU-2025:4152-1 Release Date: 2025-11-21T09:10:40Z Rating: moderate References: * bsc#1252931 * bsc#1252932 * bsc#1252933 * bsc#1252934 * bsc#1252935 Cross-References: * CVE-2025-54771 * CVE-2025-61661 * CVE-2025-61662 * CVE-2025-61663 * CVE-2025-61664 CVSS scores: * CVE-2025-54771 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-54771 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-54771 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61661 ( SUSE ): 4.3 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-61661 ( SUSE ): 4.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-61661 ( NVD ): 4.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-61662 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-61662 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61662 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61663 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-61663 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61663 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61664 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-61664 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-61664 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves five vulnerabilities can now be installed. ## Description: This update for grub2 fixes the following issues: * CVE-2025-54771: Fixed rub_file_close() does not properly controls the fs refcount (bsc#1252931) * CVE-2025-61662: Fixed missing unregister call for gettext command may lead to use-after-free (bsc#1252933) * CVE-2025-61663: Fixed missing unregister call for normal commands may lead to use-after-free (bsc#1252934) * CVE-2025-61664: Fixed missing unregister call for normal_exit command may lead to use-after-free (bsc#1252935) * CVE-2025-61661: Fixed out-of-bounds write in grub_usb_get_string() function (bsc#1252932) Other fixes: * Bump upstream SBAT generation to 6 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2025-4152=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2025-4152=1 ## Package List: * openSUSE Leap 15.5 (aarch64 s390x x86_64 i586) * grub2-debugsource-2.06-150500.29.59.1 * openSUSE Leap 15.5 (noarch) * grub2-i386-pc-2.06-150500.29.59.1 * grub2-i386-xen-debug-2.06-150500.29.59.1 * grub2-powerpc-ieee1275-2.06-150500.29.59.1 * grub2-arm64-efi-debug-2.06-150500.29.59.1 * grub2-x86_64-efi-2.06-150500.29.59.1 * grub2-i386-efi-2.06-150500.29.59.1 * grub2-i386-efi-extras-2.06-150500.29.59.1 * grub2-i386-pc-extras-2.06-150500.29.59.1 * grub2-x86_64-efi-extras-2.06-150500.29.59.1 * grub2-i386-xen-extras-2.06-150500.29.59.1 * grub2-powerpc-ieee1275-extras-2.06-150500.29.59.1 * grub2-i386-xen-2.06-150500.29.59.1 * grub2-arm64-efi-2.06-150500.29.59.1 * grub2-i386-pc-debug-2.06-150500.29.59.1 * grub2-s390x-emu-extras-2.06-150500.29.59.1 * grub2-snapper-plugin-2.06-150500.29.59.1 * grub2-powerpc-ieee1275-debug-2.06-150500.29.59.1 * grub2-x86_64-efi-debug-2.06-150500.29.59.1 * grub2-x86_64-xen-extras-2.06-150500.29.59.1 * grub2-x86_64-xen-debug-2.06-150500.29.59.1 * grub2-x86_64-xen-2.06-150500.29.59.1 * grub2-i386-efi-debug-2.06-150500.29.59.1 * grub2-systemd-sleep-plugin-2.06-150500.29.59.1 * grub2-arm64-efi-extras-2.06-150500.29.59.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64 i586) * grub2-branding-upstream-2.06-150500.29.59.1 * grub2-debuginfo-2.06-150500.29.59.1 * grub2-2.06-150500.29.59.1 * openSUSE Leap 15.5 (s390x) * grub2-s390x-emu-debug-2.06-150500.29.59.1 * grub2-s390x-emu-2.06-150500.29.59.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * grub2-debuginfo-2.06-150500.29.59.1 * grub2-2.06-150500.29.59.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * grub2-snapper-plugin-2.06-150500.29.59.1 * grub2-i386-pc-2.06-150500.29.59.1 * grub2-powerpc-ieee1275-2.06-150500.29.59.1 * grub2-x86_64-efi-2.06-150500.29.59.1 * grub2-arm64-efi-2.06-150500.29.59.1 * grub2-x86_64-xen-2.06-150500.29.59.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 s390x x86_64) * grub2-debugsource-2.06-150500.29.59.1 * SUSE Linux Enterprise Micro 5.5 (s390x) * grub2-s390x-emu-2.06-150500.29.59.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54771.html * https://www.suse.com/security/cve/CVE-2025-61661.html * https://www.suse.com/security/cve/CVE-2025-61662.html * https://www.suse.com/security/cve/CVE-2025-61663.html * https://www.suse.com/security/cve/CVE-2025-61664.html * https://bugzilla.suse.com/show_bug.cgi?id=1252931 * https://bugzilla.suse.com/show_bug.cgi?id=1252932 * https://bugzilla.suse.com/show_bug.cgi?id=1252933 * https://bugzilla.suse.com/show_bug.cgi?id=1252934 * https://bugzilla.suse.com/show_bug.cgi?id=1252935 . Five issues fixed in grub2 for openSUSE that includes important updates for system stability.. openSUSE update, grub2 security patch, moderate vulnerability fix, Linux system update. . LinuxSecurity.com Team
* bsc#1216207 * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 . # Security update for slurm_18_08 Announcement ID: SUSE-SU-2024:0313-1 Rating: important References: * bsc#1216207 * bsc#1216869 * bsc#1218046 * bsc#1218050 * bsc#1218051 * bsc#1218053 Cross-References: * CVE-2023-41914 * CVE-2023-49933 * CVE-2023-49936 * CVE-2023-49937 * CVE-2023-49938 CVSS scores: * CVE-2023-41914 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-41914 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49933 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-49936 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49936 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-49937 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2023-49937 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-49938 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2023-49938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N Affected Products: * HPC Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for slurm_18_08 fixes thefollowing issues: Security fixes: * CVE-2023-41914: Prevent filesystem race conditions that could let an attacker take control of an arbitrary file, or remove entire directories' contents. (bsc#1216207) * CVE-2023-49933: Prevent message extension attacks that could bypass the message hash. (bsc#1218046) * CVE-2023-49936: Prevent NULL pointer dereference on `size_valp` overflow. (bsc#1218050) * CVE-2023-49937: Prevent double-xfree() on error in `_unpack_node_reg_resp()`. (bsc#1218051) * CVE-2023-49938: Prevent modified `sbcast` RPCs from opening a file with the wrong group permissions. (bsc#1218053) Other fixes: * Fix slurm upgrading to incompatible versions (bsc#1216869). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 12 zypper in -t patch SUSE-SLE-Module-HPC-12-2024-313=1 ## Package List: * HPC Module 12 (aarch64 x86_64) * slurm_18_08-lua-debuginfo-18.08.9-3.23.1 * slurm_18_08-torque-18.08.9-3.23.1 * slurm_18_08-lua-18.08.9-3.23.1 * slurm_18_08-plugins-18.08.9-3.23.1 * slurm_18_08-auth-none-debuginfo-18.08.9-3.23.1 * slurm_18_08-node-debuginfo-18.08.9-3.23.1 * slurm_18_08-sql-18.08.9-3.23.1 * slurm_18_08-pam_slurm-18.08.9-3.23.1 * slurm_18_08-slurmdbd-debuginfo-18.08.9-3.23.1 * slurm_18_08-sql-debuginfo-18.08.9-3.23.1 * slurm_18_08-doc-18.08.9-3.23.1 * slurm_18_08-config-18.08.9-3.23.1 * libpmi0_18_08-18.08.9-3.23.1 * libslurm33-18.08.9-3.23.1 * slurm_18_08-munge-debuginfo-18.08.9-3.23.1 * slurm_18_08-debugsource-18.08.9-3.23.1 * slurm_18_08-devel-18.08.9-3.23.1 * perl-slurm_18_08-debuginfo-18.08.9-3.23.1 * slurm_18_08-torque-debuginfo-18.08.9-3.23.1 * perl-slurm_18_08-18.08.9-3.23.1 * slurm_18_08-auth-none-18.08.9-3.23.1 * slurm_18_08-node-18.08.9-3.23.1 * slurm_18_08-slurmdbd-18.08.9-3.23.1 *slurm_18_08-18.08.9-3.23.1 * slurm_18_08-plugins-debuginfo-18.08.9-3.23.1 * slurm_18_08-munge-18.08.9-3.23.1 * libslurm33-debuginfo-18.08.9-3.23.1 * slurm_18_08-debuginfo-18.08.9-3.23.1 * slurm_18_08-pam_slurm-debuginfo-18.08.9-3.23.1 * libpmi0_18_08-debuginfo-18.08.9-3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2023-41914.html * https://www.suse.com/security/cve/CVE-2023-49933.html * https://www.suse.com/security/cve/CVE-2023-49936.html * https://www.suse.com/security/cve/CVE-2023-49937.html * https://www.suse.com/security/cve/CVE-2023-49938.html * https://bugzilla.suse.com/show_bug.cgi?id=1216207 * https://bugzilla.suse.com/show_bug.cgi?id=1216869 * https://bugzilla.suse.com/show_bug.cgi?id=1218046 * https://bugzilla.suse.com/show_bug.cgi?id=1218050 * https://bugzilla.suse.com/show_bug.cgi?id=1218051 * https://bugzilla.suse.com/show_bug.cgi?id=1218053 . Crucial Ubuntu security patch for apache_20_04 tackling urgent vulnerabilities and fortifying defenses against potential threats.. SUSE Security Update, Slurm 18.08 Patch, SUSE Advisory, Critical Security Update. . Severity: Critical. LinuxSecurity.com Team
private-cwd leaks access to the entire filesystem References: - https://bugs.mageia.org/show_bug.cgi?id=30007 - https://github.com/netblue30/firejail/issues/4780 . MGASA-2022-0055 - Updated firejail packages fix security vulnerability Publication date: 09 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0055.html Type: security Affected Mageia releases: 8 private-cwd leaks access to the entire filesystem References: - https://bugs.mageia.org/show_bug.cgi?id=30007 - https://github.com/netblue30/firejail/issues/4780 SRPMS: - 8/core/firejail-0.9.64-1.2.mga8 . Enhanced firejail components in Mageia address private-cwd filesystem vulnerabilities, bolstering system security.. Mageia Firejail Security Update, Private-CWD Access Issue, Firejail Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team
The package jenkins before version 2.319-1 is vulnerable to multiple issues including arbitrary filesystem access and sandbox escape. . Arch Linux Security Advisory ASA-202111-1 ======================================== Severity: Critical Date : 2021-11-05 CVE-ID : CVE-2021-21685 CVE-2021-21686 CVE-2021-21687 CVE-2021-21688 CVE-2021-21689 CVE-2021-21690 CVE-2021-21691 CVE-2021-21692 CVE-2021-21693 CVE-2021-21694 CVE-2021-21695 CVE-2021-21696 CVE-2021-21697 Package : jenkins Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-2526 Summary ====== The package jenkins before version 2.319-1 is vulnerable to multiple issues including arbitrary filesystem access and sandbox escape. Resolution ========= Upgrade to 2.319-1. # pacman -Syu "jenkins> =2.319-1" The problems have been fixed upstream in version 2.319. Workaround ========= If you are unable to immediately upgrade to Jenkins 2.319 right away, you can install the Remoting Security Workaround Plugin. It will prevent all agent-to-controller file access using FilePath APIs. Because it is more restrictive than Jenkins 2.319, more plugins are incompatible with it. Make sure to read the plugin documentation before installing it. Description ========== - CVE-2021-21685 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#mkdirs does not check permission to create parent directories. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21686 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. File path filters do not canonicalize paths, allowing operations to follow symbolic links to outside allowed directories. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain someinformation about Jenkins controller file systems. - CVE-2021-21687 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#untar does not check permission to create symbolic links when unarchiving a symbolic link. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21688 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#reading(FileVisitor) does not reject any operations, allowing users to have unrestricted read access using certain operations (creating archives, #copyRecursiveTo). This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21689 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#unzip and FilePath#untar were not subject to any access control. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21690 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. Agent processes are able to completely bypass file path filtering by wrapping the file operation in an agent file path. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21691 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. Creating symbolic links is possible without the symlink permission. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. -CVE-2021-21692 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. The operations FilePath#renameTo and FilePath#moveAllChildrenTo only check read permission on the source path. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21693 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. When creating temporary files, permission to create files is only checked after they’ve been created. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21694 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#toURI, FilePath#hasSymlink, FilePath#absolutize, FilePath#isDescendant, and FilePath#get*DiskSpace do not check any permissions. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21695 (arbitrary filesystem access) A security issue has been found in Jenkins before version 2.319. FilePath#listFiles lists files outside directories with agent read access when following symbolic links. This allows agent processes to read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. - CVE-2021-21696 (sandbox escape) Jenkins before version 2.319 does not limit agent read/write access to the libs/ directory inside build directories when using the FilePath APIs. This directory is used by the "Pipeline: Shared Groovy Libraries" Plugin to store copies of shared libraries. This allows attackers in control of agent processes to replace the code of a trusted library with a modified variant, resulting inunsandboxed code execution in the Jenkins controller process. Jenkins 2.319 prohibits agent read/write access to the libs/ directory inside build directories. - CVE-2021-21697 (arbitrary filesystem access) Agents are allowed some limited access to files on the Jenkins controller file system. The directories agents are allowed to access in Jenkins before 2.319 include the directories storing build-related information, intended to allow agents to store build-related metadata during build execution. As a consequence, this allows any agent to read and write the contents of any build directory stored in Jenkins with very few restrictions (build.xml and some Pipeline-related metadata). Jenkins 2.319 prevents agents from accessing contents of build directories unless it’s for builds currently running on the agent attempting to access the directory. Impact ===== Agent processes could read and write arbitrary files on the Jenkins controller file system, and obtain some information about Jenkins controller file systems. References ========= https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2455 https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2423 https://www.jenkins.io/security/advisory/2021-11-04/#SECURITY-2428 https://security.archlinux.org/CVE-2021-21685 https://security.archlinux.org/CVE-2021-21686 https://security.archlinux.org/CVE-2021-21687 https://security.archlinux.org/CVE-2021-21688 https://security.archlinux.org/CVE-2021-21689 https://security.archlinux.org/CVE-2021-21690 https://security.archlinux.org/CVE-2021-21691 https://security.archlinux.org/CVE-2021-21692 https://security.archlinux.org/CVE-2021-21693 https://security.archlinux.org/CVE-2021-21694 https://security.archlinux.org/CVE-2021-21695 https://security.archlinux.org/CVE-2021-21696 https://security.archlinux.org/CVE-2021-21697 . Arch Linux Security Notification regarding Jenkins flaws linked to severe file system exposure and sandbox breaching vulnerabilities.. ArchLinux, Jenkins, Security Advisory, Filesystem Access, Sandbox Escape. . Severity: Critical. LinuxSecurity.com Team
The package ark before version 20.08.0-2 is vulnerable to arbitrary filesystem access. . Arch Linux Security Advisory ASA-202009-2 ======================================== Severity: High Date : 2020-09-03 CVE-ID : CVE-2020-24654 Package : ark Type : arbitrary filesystem access Remote : No Link : https://security.archlinux.org/AVG-1216 Summary ====== The package ark before version 20.08.0-2 is vulnerable to arbitrary filesystem access. Resolution ========= Upgrade to 20.08.0-2. # pacman -Syu "ark> =20.08.0-2" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. Impact ===== An attacker can overwrite local files by tricking a legitimate user into extracting a specially crafted TAR archive. References ========= https://kde.org/info/security/advisory-20200827-1.txt https://security.archlinux.org/CVE-2020-24654 . Ubuntu Security Notice USN-2021-01 reveals an urgent patch for the Gnome display server exploitation risk. ark package, filesystem access, arch linux advisory. . LinuxSecurity.com Team
The package samba before version 4.10.10-1 is vulnerable to multiple issues including arbitrary filesystem access, insufficient validation and denial of service. . Arch Linux Security Advisory ASA-201911-6 ======================================== Severity: Medium Date : 2019-11-03 CVE-ID : CVE-2019-10218 CVE-2019-14833 CVE-2019-14847 Package : samba Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1057 Summary ====== The package samba before version 4.10.10-1 is vulnerable to multiple issues including arbitrary filesystem access, insufficient validation and denial of service. Resolution ========= Upgrade to 4.10.10-1. # pacman -Syu "samba> =4.10.10-1" The problems have been fixed upstream in version 4.10.10. Workaround ========= None. Description ========== - CVE-2019-10218 (arbitrary filesystem access) An issue has been found in Samba before 4.10.10 where a malicious server can craft a pathname containing separators and return this to client code, causing the client to use this access local pathnames for reading or writing instead of SMB network pathnames. - CVE-2019-14833 (insufficient validation) A security issue has been found in Samba before 4.10.10, where the check password script does not receive the full password string when the password contains multi-byte (non-ASCII) characters. Since Samba Version 4.5.0 a Samba AD DC can use a custom command to verify the password complexity. The command can be specified with the "check password script" smb.conf parameter. This command is called when Samba handles a user password change or a new user password is set. The script receives the new cleartext password string in order to run custom password complexity checks like dictionary checks to avoid weak user passwords. If the check password script parameter is not specified, Samba runs the internal password quality checks. The internal check makes sure that a password contains characters from three of five different characters categories. - CVE-2019-14847 (denialof service) A denial of service has been found in Samba before 4.10.10, where userswith the "get changes" extended access right can crash the AD DC LDAP server by requesting an attribute using the range= syntax. By default, the supported versions of Samba impacted by this issue run using the "standard" process model, which is unaffected. This is controlled by the -M or --model parameter to the samba binary. Unsupported Samba versions before Samba 4.7 use a single process for the LDAP server, and so are impacted. Samba 4.8, 4.9 and 4.10 are impacted if -M prefork or -M single is used. To mitigate this issue, select -M standard (the default). Impact ===== An attacker is able to access and write on files via arbitrary paths or crash the application. References ========= https://security.archlinux.org/CVE-2019-10218 https://security.archlinux.org/CVE-2019-14833 https://security.archlinux.org/CVE-2019-14847 . Arch Linux released a Samba advisory detailing security vulnerabilities and recommended package upgrades to improve system security, highlighting urgent updates for users. samba security, Arch Linux advisory, filesystem access issue, denial of service fix. . Severity: Medium. LinuxSecurity.com Team
The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure. . Arch Linux Security Advisory ASA-201807-2 ======================================== Severity: High Date : 2018-07-04 CVE-ID : CVE-2018-10857 CVE-2018-10859 Package : git-annex Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-725 Summary ====== The package git-annex before version 6.20180626-1 is vulnerable to multiple issues including arbitrary filesystem access and information disclosure. Resolution ========= Upgrade to 6.20180626-1. # pacman -Syu "git-annex> =6.20180626-1" The problems have been fixed upstream in version 6.20180626. Workaround ========= None. Description ========== - CVE-2018-10857 (arbitrary filesystem access) Some uses of git-annex were vulnerable to a private data exposure and exfiltration attack. It could expose the content of files located outside the git-annex repository, or content from a private web server on localhost or the LAN. - CVE-2018-10859 (information disclosure) A malicious server for a special remote could trick git-annex into decrypting a file that was encrypted to the user's gpg key. This attack could be used to expose encrypted data that was never stored in git- annex Impact ===== A remote attacker is able to read arbitrary files on the filesystem or decrypt encrypted files by modifying the git-annex repository. References ========= https://git-annex.branchable.com/security/CVE-2018-10857_and_CVE-2018-10859/ https://git.joeyh.name/index.cgi/git-annex.git/commit/?id=b54b2cdc0ef1373fc200c0d28fded3c04fd57212 https://security.archlinux.org/CVE-2018-10857 https://security.archlinux.org/CVE-2018-10859 . Enhance git-annex on Arch Linux to address critical vulnerabilities concerning file system permissions and data safety.. git-annex issues, Arch Linux advisory, git-annex vulnerability. . LinuxSecurity.com Team
The package cacti before version 1.1.28-1 is vulnerable to multiple issues including arbitrary code execution, arbitrary command execution, cross-site scripting and arbitrary filesystem access. . Arch Linux Security Advisory ASA-201712-2 ======================================== Severity: High Date : 2017-12-02 CVE-ID : CVE-2017-16641 CVE-2017-16660 CVE-2017-16661 CVE-2017-16785 Package : cacti Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-537 Summary ====== The package cacti before version 1.1.28-1 is vulnerable to multiple issues including arbitrary code execution, arbitrary command execution, cross-site scripting and arbitrary filesystem access. Resolution ========= Upgrade to 1.1.28-1. # pacman -Syu "cacti> =1.1.28-1" The problems have been fixed upstream in version 1.1.28. Workaround ========= None. Description ========== - CVE-2017-16641 (arbitrary command execution) lib/rrd.php in Cacti 1.1.27 allows remote authenticated administratorsto execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php. - CVE-2017-16660 (arbitrary code execution) Cacti 1.1.27 allows remote authenticated administrators to conduct Remote Code Execution attacks by placing the Log Path under the web root, and then making a remote_agent.php request containing PHP code in a Client-ip header. - CVE-2017-16661 (arbitrary filesystem access) Cacti 1.1.27 allows remote authenticated administrators to read arbitrary files by placing the Log Path into a private directory, and then making a clog.php?filename= request, as demonstrated by filename=passwd (with a Log Path under /etc) to read /etc/passwd. - CVE-2017-16785 (cross-site scripting) Cacti 1.1.27 has reflected XSS via the PATH_INFO to host.php. Impact ===== A remote authenticated admin user is able to read arbitrary files, execute arbitrary code and commands on the affected host. An unauthenticated user is able to perform cross-site scriptingattacks. References ========= https://github.com/Cacti/cacti/commit/e8088bb6593e6a49d000c342d17402f01db8740e https://github.com/Cacti/cacti/issues/1066 https://github.com/Cacti/cacti/commit/4e74f46fe24bed533fcfc8c8a43121ed59ce2002 https://github.com/Cacti/cacti/commit/a179e8092dbff7406e39ca16c2823f4fe530f5e0 https://github.com/Cacti/cacti/commit/c0f0ce27f0c281d7e1e57f91891c5ca9a92df013 https://github.com/Cacti/cacti/commit/96d793f33ebf16c0b12e1ec779d7debb87990cdd https://github.com/Cacti/cacti/issues/1071 https://security.archlinux.org/CVE-2017-16641 https://security.archlinux.org/CVE-2017-16660 https://security.archlinux.org/CVE-2017-16661 https://security.archlinux.org/CVE-2017-16785 . Fedora Linux reveals vulnerabilities in Nagios, presenting critical threats such as code execution and SQL injection risks.. Cacti Security Issues, Arch Linux Advisory, High Severity Flaws. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.