Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 29 Release: Resolution for Godot 3.0.6 Severe DoS Vulnerability

**Security update: Godot 3.0.6** This update brings the latest upstream release of Godot Engine, with several bug fixes and improvements applied on top of Godot 3.0.4. This release is compatible with previous Godot 3.0.x versions and should load existing projects without issue. Version 3.0.6 also fixes the following security vulnerabilities: Fabio Alessandrelli found and fixed several security. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8d58297dc0 2018-09-21 05:19:39.101712 --------------------------------------------------------------------------------Name : godot Product : Fedora 29 Version : 3.0.6 Release : 1.fc29 URL : https://godotengine.org Summary : Multi-platform 2D and 3D game engine with a feature-rich editor Description : Godot is an advanced, feature-packed, multi-platform 2D and 3D game engine. It provides a huge set of common tools, so you can just focus on making your game without reinventing the wheel. Godot is completely free and open source under the very permissive MIT license. No strings attached, no royalties, nothing. Your game is yours, down to the last line of engine code. --------------------------------------------------------------------------------Update Information: **Security update: Godot 3.0.6** This update brings the latest upstream release of Godot Engine, with several bug fixes and improvements applied on top of Godot 3.0.4. This release is compatible with previous Godot 3.0.x versions and should load existing projects without issue. Version 3.0.6 also fixes the following security vulnerabilities: Fabio Alessandrelli found and fixed several security vulnerabilities in the marshalling code of Godot Engine, which could be used by a remote Godot client to cause a Denial of Service for a Godot server (CVE-2018-1000224). *References:* - Release announcement: https://godotengine.org/article/maintenance-release-godot-3-0-6/ - Changelog:htt ps://downloads.tuxfamily.org/godotengine/3.0.6/Godot_v3.0.6-stable_changelog.txt - Details about CVE-2018-1000224: https://github.com/godotengine/godot/issues/20558 --------------------------------------------------------------------------------References: [ 1 ] Bug #1599287 - godot-3.0.6-stable is available (fixes CVE-2018-1000224) https://bugzilla.redhat.com/show_bug.cgi?id=1599287 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-8d58297dc0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Godot 3.0.6 release addresses vulnerabilities and boosts performance for Fedora 29 users by upgrading the engine.. Godot Engine Update,Fedora Security Fix,Denial Of Service Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2018 Critical Fedora
89

Fedora 27: 2018-7cbf1defa5 High: HEART Game Engine Enhancement

Rebuild for new luajit. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-6bba0bc8d6 2017-06-22 13:34:50.946077 --------------------------------------------------------------------------------Name : love Product : Fedora 26 Version : 0.10.2 Release : 6.fc26 URL : Summary : A free 2D game engine which enables easy game creation in Lua Description : LOVE is an open source, cross platform 2D game engine which uses the Lua scripting language. LOVE can be used to make games of any license allowing it to be used for both free and non-free projects. --------------------------------------------------------------------------------Update Information: Rebuild for new luajit --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade love' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 brings thrilling updates for the LOVE 2D game engine, including a luajit rebuild that dramatically accelerates Lua performance for developers. Fedora Update,LIVE Game Engine,Software Update,LuaJIT Rebuild. . LinuxSecurity.com Team

Calendar%202 Jun 22, 2017 Fedora
87

Debian: DSA-3812-1 Critical: ioquake3 Server Configuration Threat

It was discovered that ioquake3, a modified version of the ioQuake3 game engine performs insufficent restrictions on automatically downloaded content (pk3 files or game code), which allows malicious game servers to modify configuration settings including driver settings. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3812-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 18, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ioquake3 CVE ID : CVE-2017-6903 It was discovered that ioquake3, a modified version of the ioQuake3 game engine performs insufficent restrictions on automatically downloaded content (pk3 files or game code), which allows malicious game servers to modify configuration settings including driver settings. For the stable distribution (jessie), this problem has been fixed in version 1.36+u20140802+gca9eebb-2+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 1.36+u20161101+dfsg1-2. We recommend that you upgrade your ioquake3 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance ioquake3 to resolve urgent security flaw that permits harmful game servers to modify system configuration parameters.. IoQuake3 Update, Debian Security, Game Code Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2017 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200