Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 494
Alerts This Week
Warning Icon 1 494

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
91

Gentoo: GLSA-202007-44 Advisory: Multiple Vulnerabilities in FreeXL

Multiple vulnerabilities have been found in FreeXL, the worst of which could result in a Denial of Service condition.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: FreeXL: Multiple vulnerabilities Date: July 27, 2020 Bugs: #648700 ID: 202007-44 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in FreeXL, the worst of which could result in a Denial of Service condition. Background ========= FreeXL is an open source library to extract valid data from within an Excel (.xls) spreadsheet. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/freexl < 1.0.5 > = 1.0.5 Description ========== Multiple vulnerabilities have been discovered in FreeXL. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All FreeXL users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/freexl-1.0.5" References ========= [ 1 ] CVE-2018-7435 https://nvd.nist.gov/vuln/detail/CVE-2018-7435 [ 2 ] CVE-2018-7436 https://nvd.nist.gov/vuln/detail/CVE-2018-7436 [ 3 ] CVE-2018-7437 https://nvd.nist.gov/vuln/detail/CVE-2018-7437 [ 4 ] CVE-2018-7438 https://nvd.nist.gov/vuln/detail/CVE-2018-7438 [ 5 ] CVE-2018-7439 https://nvd.nist.gov/vuln/detail/CVE-2018-7439 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-44 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . FreeXL has unveiled a series of vulnerabilities, potentially causing Denial of Service in Gentoo installations. Users are advised to upgrade promptly.. FreeXL, Gentoo, Denial of Service, Security Advisory, Multiple Issues. . LinuxSecurity.com Team

Calendar%202 Jul 26, 2020 Gentoo
89

Fedora 27 FEDORA-2018-2eb691e7d7 Moderate: Freexl Heap Overflow Issue

Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2eb691e7d7 2018-03-06 17:17:51.856240 --------------------------------------------------------------------------------Name : freexl Product : Fedora 27 Version : 1.0.5 Release : 1.fc27 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora has unveiled a critical security patch for freexl, resolving issues related to heap-buffer-overflows. For installation steps, refer to the details!. fedora update, freexl security, buffer overflow fix. . LinuxSecurity.com Team

Calendar%202 Mar 06, 2018 Fedora
89

Fedora 28: 2019-3cf892a8d1 High: FreeXL Heap Corruption Vulnerability

Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2eb691e7d7 2018-03-06 17:17:51.856240 --------------------------------------------------------------------------------Name : freexl Product : Fedora 27 Version : 1.0.5 Release : 1.fc27 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . To mitigate heap-buffer-overflows in freexl, users must stay updated on security patches and implement proactive measures, ensuring a secure environment. FreeXL Security Update, Fedora Security Advisory, Heap Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 06, 2018 Important Fedora
89

Fedora 26 FEDORA-2018-5573046c3b Critical: freexl Heap Overflow

Fixes several heap-buffer-overflows, see related Bugzilla tickets!. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5573046c3b 2018-03-06 17:26:39.511112 --------------------------------------------------------------------------------Name : freexl Product : Fedora 26 Version : 1.0.5 Release : 1.fc26 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: Fixes several heap-buffer-overflows, see related Bugzilla tickets! --------------------------------------------------------------------------------References: [ 1 ] Bug #1547892 - heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547892 [ 2 ] Bug #1547889 - heap-buffer-overflow in freexl.c:383 parse_unicode_string of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547889 [ 3 ] Bug #1547885 - heap-buffer-overflow in freexl.c:1866 parse_SST of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547885 [ 4 ] Bug #1547883 - heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST https://bugzilla.redhat.com/show_bug.cgi?id=1547883 [ 5 ] Bug #1547879 - heap-buffer-overflow in freexl::destroy_cell of FreeXL 1.0.4 https://bugzilla.redhat.com/show_bug.cgi?id=1547879 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent security patch for libfreexl in Fedora 26 tackling several heap-buffer-overruns.. Fedora Security, freexl Update, Heap Buffer Overflow, Fedora 26, FreeXL Library. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 06, 2018 Critical Fedora
87

Debian: DSA-4130-1 High: libxml2 XML Parsing Integer Overflow Vulnerability

Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4129-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 02, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : freexl CVE ID : CVE-2018-7435 CVE-2018-7436 CVE-2018-7437 CVE-2018-7438 CVE-2018-7439 Multiple heap buffer over reads were discovered in freexl, a library to read Microsoft Excel spreadsheets, which could result in denial of service. For the oldstable distribution (jessie), these problems have been fixed in version 1.0.0g-1+deb8u5. For the stable distribution (stretch), these problems have been fixed in version 1.0.2-2+deb9u2. We recommend that you upgrade your freexl packages. For the detailed security status of freexl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freexl Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Buffer overflow issues in freexl can lead to service interruptions. Users of Debian are urged to perform upgrades to bolster their system's security.. freexl, buffer overflow, denial of service, Debian Security, security update. . LinuxSecurity.com Team

Calendar%202 Mar 02, 2018 Debian
202

openSUSE 42.3: 2018:0570-1 Important: freexl Heap Overflow Issue

An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for freexl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0570-1 Rating: important References: #1082774 #1082775 #1082776 #1082777 #1082778 Cross-References: CVE-2018-7435 CVE-2018-7436 CVE-2018-7437 CVE-2018-7438 CVE-2018-7439 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for freexl fixes the following issues: freexl was updated to version 1.0.5: * No changelog provided by upstream * Various heapoverflows in 1.0.4 have been fixed: * CVE-2018-7439: heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record (boo#1082774) * CVE-2018-7438: heap-buffer-overflow in freexl.c:383 parse_unicode_string (boo#1082775) * CVE-2018-7437: heap-buffer-overflow in freexl.c:1866 parse_SST(boo#1082776) * CVE-2018-7436: heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST (boo#1082777) * CVE-2018-7435: heap-buffer-overflow in freexl::destroy_cell (boo#1082778) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-217=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (i586 x86_64): freexl-debugsource-1.0.5-8.1 freexl-devel-1.0.5-8.1 libfreexl1-1.0.5-8.1 libfreexl1-debuginfo-1.0.5-8.1 References: https://www.suse.com/security/cve/CVE-2018-7435.html https://www.suse.com/security/cve/CVE-2018-7436.html https://www.suse.com/security/cve/CVE-2018-7437.html https://www.suse.com/security/cve/CVE-2018-7438.html https://www.suse.com/security/cve/CVE-2018-7439.html https://bugzilla.suse.com/1082774 https://bugzilla.suse.com/1082775 https://bugzilla.suse.com/1082776 https://bugzilla.suse.com/1082777 https://bugzilla.suse.com/1082778 -- . A crucial security patch for openSUSE freexl addresses 5 severe vulnerabilities. Find patch specifics and upgrade guidelines here.. openSUSE Security Update, freexl Critical Issues, Heap Overflow Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 01, 2018 Important OpenSUSE
202

openSUSE: 2018:0569-1 Important: freexl Heap Overflow Fixes

An update that fixes 5 vulnerabilities is now available.. openSUSE Security Update: Security update for freexl ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0569-1 Rating: important References: #1082774 #1082775 #1082776 #1082777 #1082778 Cross-References: CVE-2018-7435 CVE-2018-7436 CVE-2018-7437 CVE-2018-7438 CVE-2018-7439 Affected Products: SUSE Package Hub for SUSE Linux Enterprise 12 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: This update for freexl fixes the following issues: freexl was updated to version 1.0.5: * No changelog provided by upstream * Various heapoverflows in 1.0.4 have been fixed: * CVE-2018-7439: heap-buffer-overflow in freexl.c:3912 read_mini_biff_next_record (boo#1082774) * CVE-2018-7438: heap-buffer-overflow in freexl.c:383 parse_unicode_string (boo#1082775) * CVE-2018-7437: heap-buffer-overflow in freexl.c:1866 parse_SST(boo#1082776) * CVE-2018-7436: heap-buffer-overflow in freexl.c:1805 parse_SST parse_SST (boo#1082777) * CVE-2018-7435: heap-buffer-overflow in freexl::destroy_cell (boo#1082778) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Package Hub for SUSE Linux Enterprise 12: zypper in -t patch openSUSE-2018-217=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64): freexl-debugsource-1.0.5-8.1 freexl-devel-1.0.5-8.1 libfreexl1-1.0.5-8.1 libfreexl1-debuginfo-1.0.5-8.1 References: https://www.suse.com/security/cve/CVE-2018-7435.html https://www.suse.com/security/cve/CVE-2018-7436.html https://www.suse.com/security/cve/CVE-2018-7437.html https://www.suse.com/security/cve/CVE-2018-7438.html https://www.suse.com/security/cve/CVE-2018-7439.html https://bugzilla.suse.com/1082774 https://bugzilla.suse.com/1082775 https://bugzilla.suse.com/1082776 https://bugzilla.suse.com/1082777 https://bugzilla.suse.com/1082778 -- . Important openSUSE security patch addresses heap overflow vulnerabilities in freexl. Complete information and installation guidelines provided.. openSUSE Security, freexl Update, Heap Overflow Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 01, 2018 Important OpenSUSE
89

Fedora 27: 2017-ea4ed9e540 Critical: freexl Remote Code Execution

This update fixes a Cisco Talos CVE: "A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability.". --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-ea4ed9e540 2017-09-30 05:57:53.231526 --------------------------------------------------------------------------------Name : freexl Product : Fedora 27 Version : 1.0.4 Release : 1.fc27 URL : Summary : Library to extract data from within an Excel spreadsheet Description : FreeXL is a library to extract valid data from within an Excel spreadsheet (.xls) Design goals: * simple and lightweight * stable, robust and efficient * easily and universally portable * completely ignore any GUI-related oddity --------------------------------------------------------------------------------Update Information: This update fixes a Cisco Talos CVE: "A specially crafted XLS file can cause a memory corruption resulting in remote code execution. An attacker can send malicious XLS file to trigger this vulnerability." --------------------------------------------------------------------------------References: [ 1 ] Bug #1489621 - freexl-1.0.4 is available https://bugzilla.redhat.com/show_bug.cgi?id=1489621 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade freexl' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announcemailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch for Fedora 27 addresses remote code execution vulnerability in freexl library stemming from malicious XLS documents.. freexl Update, Fedora Security, Remote Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 30, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200