Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 22: FEDORA-2015-9324 Critical: FusionForge Command Execution

Security fix for CVE-2015-0850 CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9324 2015-06-02 09:31:42 -------------------------------------------------------------------------------- Name : fusionforge Product : Fedora 22 Version : 5.3.2 Release : 4.fc22 URL : Summary : Collaborative development tool Description : FusionForge provides many tools to aid collaboration in a development project, such as bug-tracking, task management, mailing-lists, SCM repository, forums, support request helper, web/FTP hosting, release management, etc. All these services are integrated into one web site and managed through a web interface. This metapackage installs a stand-alone FusionForge site. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-0850 CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . -------------------------------------------------------------------------------- ChangeLog: * Thu May 28 2015 Sylvain Beucler - 5.3.2-4 - CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . -------------------------------------------------------------------------------- References: [ 1 ] Bug #1226872 - CVE-2015-0850 fusionforge: incorrect input validation in Git plug-in https://bugzilla.redhat.com/show_bug.cgi?id=1226872 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fusionforge' at the command line. For more information, refer to "Managing Software withyum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . The latest security patch for Fedora 22 addresses a significant vulnerability in FusionForge. This flaw, allowing for unauthorized command execution, was identified by expert Ansgar Burchardt.. FusionForge Security Update, Fedora 22 Advisory, Command Execution Fix, Security Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 10, 2015 Critical Fedora
89

Fedora 21 FusionForge Security Update: Critical Command Execution Risk

Security fix for CVE-2015-0850 CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9128 2015-05-30 09:30:09 -------------------------------------------------------------------------------- Name : fusionforge Product : Fedora 21 Version : 5.3.2 Release : 4.fc21 URL : Summary : Collaborative development tool Description : FusionForge provides many tools to aid collaboration in a development project, such as bug-tracking, task management, mailing-lists, SCM repository, forums, support request helper, web/FTP hosting, release management, etc. All these services are integrated into one web site and managed through a web interface. This metapackage installs a stand-alone FusionForge site. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-0850 CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . -------------------------------------------------------------------------------- ChangeLog: * Thu May 28 2015 Sylvain Beucler - 5.3.2-4 - CVE-2015-0850: Prevent arbitrary command execution via clone URL parameter of the method to create secondary Git repositories. Found by Ansgar Burchardt . -------------------------------------------------------------------------------- References: [ 1 ] Bug #1226872 - CVE-2015-0850 fusionforge: incorrect input validation in Git plug-in https://bugzilla.redhat.com/show_bug.cgi?id=1226872 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update fusionforge' at the command line. For more information, refer to "Managing Software withyum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Essential FusionForge security patch released in Fedora 21 to safeguard against command execution vulnerabilities via Git clone links.. Fedora Security Update,FusionForge Command Execution Fix,Arbitrary Command Execution,Critical Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 10, 2015 Critical Fedora
87

Debian: DSA-3275-1 Critical: FusionForge Git Plugin Remote Code Execution

Ansgar Burchardt discovered that the Git plugin for FusionForge, a web-based project-management and collaboration software, does not sufficiently validate user provided input as parameter to the method to create secondary Git repositories. A remote attacker can use this flaw . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3275-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso May 30, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : fusionforge CVE ID : CVE-2015-0850 Ansgar Burchardt discovered that the Git plugin for FusionForge, a web-based project-management and collaboration software, does not sufficiently validate user provided input as parameter to the method to create secondary Git repositories. A remote attacker can use this flaw to execute arbitrary code as root via a specially crafted URL. For the stable distribution (jessie), this problem has been fixed in version 5.3.2+20141104-3+deb8u1. For the testing distribution (stretch) and the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your fusionforge packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The security patch DSA-3276-2 for Debian tackles a significant vulnerability in FusionForge's Upcoming plugin, which could permit unauthorized command execution.. Debian Security,FusionForge Update,Remote Execution,Input Validation Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 30, 2015 Critical Debian
87

Debian: DSA-2633-1 Moderate: FusionForge Privilege Escalation

Helmut Grohne discovered multiple privilege escalation flaws in FusionForge, a web-based project-management and collaboration software. Most of the vulnerabilities are related to the bad handling of privileged operations on user-controlled files or directories. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2633-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Yves-Alexis Perez February 26, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : fusionforge Vulnerability : privilege escalation Problem type : remote Debian-specific: no CVE ID : CVE-2013-1423 Debian Bug : Helmut Grohne discovered multiple privilege escalation flaws in FusionForge, a web-based project-management and collaboration software. Most of the vulnerabilities are related to the bad handling of privileged operations on user-controlled files or directories. For the stable distribution (squeeze), this problem has been fixed in version 5.0.2-5+squeeze2. For the testing (wheezy) and unstable (sid) distribution, theses problems will be fixed soon. We recommend that you upgrade your fusionforge packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-1234-1 outlines various vulnerabilities in OpenProject. Users advised to upgrade.. Privilege Escalation, FusionForge, Debian Security. . LinuxSecurity.com Team

Calendar 2 Feb 26, 2013 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here