Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
87

Debian: HSQLDB Moderate Scripting Issue CVE-2023-1183 DSA-5995-1

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5995-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 10, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hsqldb1.8.0 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For the stable distribution (trixie), this problem has been fixed in version 1.8.0.10+dfsg-12.1+deb13u1. We recommend that you upgrade your hsqldb1.8.0 packages. For the detailed security status of hsqldb1.8.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb1.8.0 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest Security Notice DSA-5995-1 from Debian highlights a vulnerability in HSQLDB that could permit the execution of harmful scripts..HSQLDB Security Advisory, Debian Scripting Risk, SQL Database Attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 10, 2025 Important Debian
203

Mageia 8: MGASA-2023-0225 Critical: LibreOffice Arbitrary File Write

Arbitrary File Write in hsqldb 1.8.0. (CVE-2023-1183) References: - https://bugs.mageia.org/show_bug.cgi?id=32042 - https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ . MGASA-2023-0225 - Updated libreoffice packages fix security vulnerability Publication date: 07 Jul 2023 URL: https://advisories.mageia.org/MGASA-2023-0225.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1183 Arbitrary File Write in hsqldb 1.8.0. (CVE-2023-1183) References: - https://bugs.mageia.org/show_bug.cgi?id=32042 - https://www.libreoffice.org/about-us/security/advisories/cve-2023-1183/ - https://www.cve.org/CVERecord?id=CVE-2023-1183 SRPMS: - 8/core/libreoffice-7.4.5.1-1.2.mga8 . The recent updates to LibreOffice packages rectify a critical arbitrary file write vulnerability in Mageia 8. This advisory is listed as MGASA-2023-0225.. Mageia Security Advisory, LibreOffice Update, HSQLDB Issue, Arbitrary Write Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 07, 2023 Critical Mageia
197

Debian 10: DLA-3468-1 Moderate Advisory for HSQLDB Scripting Risks

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3468-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 22, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : hsqldb1.8.0 Version : 1.8.0.10+dfsg-10+deb10u1 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For Debian 10 buster, this problem has been fixed in version 1.8.0.10+dfsg-10+deb10u1. We recommend that you upgrade your hsqldb1.8.0 packages. For the detailed security status of hsqldb1.8.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb1.8.0 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . HSQLDB Notice DLA-3468-2: Security enhancement for the Java SQL database to mitigate the risks associated with script command execution vulnerabilities.. HSQLDB Security, Debian LTS, Java SQL Update, ScriptingCommands, Database Engine. . LinuxSecurity.com Team

Calendar%202 Jun 21, 2023 Debian LTS
197

Debian LTS: DLA-3467-1 Critical: HSQLDB Script Execution Risk

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output . -------------------------------------------------------------------------Debian LTS Advisory DLA-3467-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany June 22, 2023 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : hsqldb Version : 2.4.1-2+deb10u2 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For Debian 10 buster, this problem has been fixed in version 2.4.1-2+deb10u2. We recommend that you upgrade your hsqldb packages. For the detailed security status of hsqldb please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . MySQL security patch released; update your installations to protect against unauthorized SQL injections.. Debian Security,HSQLDB Update,Script Execution Risk,Java Database Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 21, 2023 Critical Debian LTS
87

Debian: DSA-5436-1 Critical Update for HSQLDB Script Injection Risk

Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5436-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany June 21, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hsqldb1.8.0 CVE ID : CVE-2023-1183 Gregor Kopf of Secfault Security GmbH discovered that HSQLDB, a Java SQL database engine, allowed the execution of spurious scripting commands in .script and .log files. Hsqldb supports a "SCRIPT" keyword which is normally used to record the commands input by the database admin to output such a script. In combination with LibreOffice, an attacker could craft an odb containing a "database/script" file which itself contained a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker. For the oldstable distribution (bullseye), this problem has been fixed in version 1.8.0.10+dfsg-10+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 1.8.0.10+dfsg-11+deb12u1. We recommend that you upgrade your hsqldb1.8.0 packages. For the detailed security status of hsqldb1.8.0 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb1.8.0 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A crucial patch addressesHSQLDB weaknesses that allow harmful input execution, impacting Debian platforms.. HSQLDB Update, Debian Security, Script Injection, Database Issue, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 21, 2023 Critical Debian
217

Oracle Linux 6 ELSA-2023-12103 Critical: Hsqldb RCE Threat

The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-12103 https://linux.oracle.com/errata/ELSA-2023-12103.html The following updated rpms for Oracle Linux 6 Extended Lifecycle Support (ELS) have been uploaded to the Unbreakable Linux Network: hsqldb-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-demo-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-javadoc-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-manual-1.8.0.10-12.0.1.el6.noarch.rpm x86_64: hsqldb-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-demo-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-javadoc-1.8.0.10-12.0.1.el6.noarch.rpm hsqldb-manual-1.8.0.10-12.0.1.el6.noarch.rpm Related CVEs: CVE-2022-41853 Description of changes: [1:1.8.0.10-12.0.1] - Fix possible remote code execution vulnerability [CVE-2022-41853][Orabug: 34820687] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux Security Notice ELSA-2023-12103 addresses a significant hsqldb patch related to vulnerabilities that could allow remote code execution.. Oracle Linux, Hsqldb Update, Critical Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 09, 2023 Critical Oracle
87

Debian 11: DSA-5313-1 Critical: Hsqldb Remote Code Execution Risk

It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5313-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany January 11, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hsqldb CVE ID : CVE-2022-41853 Debian Bug : 1023573 It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.5.1-1+deb11u1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names","abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.5.1-1+deb11u1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. For the stable distribution (bullseye), this problem has been fixed in version 2.5.1-1+deb11u1. We recommend that you upgrade your hsqldb packages. For the detailed security status of hsqldb please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailinglist: This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch available for hsqldb addressing vulnerabilities linked to remote code execution due to inadequate management of untrusted inputs. Ensure to update to safeguard your systems.. Debian Security,hsql Update,Remote Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 10, 2023 Critical Debian
197

Debian 10: DLA-3234-1 Critical: Hsqldb Remote Code Execution Risk

It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The . -------------------------------------------------------------------------Debian LTS Advisory DLA-3234-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany December 10, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : hsqldb Version : 2.4.1-2+deb10u1 CVE ID : CVE-2022-41853 Debian Bug : 1023573 It was found that those using java.sql.Statement or java.sql.PreparedStatement in hsqldb, a Java SQL database, to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.4.1-2+deb10u1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names","abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.4.1-2+deb10u1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. For Debian 10 buster, this problem has been fixed in version 2.4.1-2+deb10u1. We recommend that you upgrade your hsqldb packages. For the detailed security status of hsqldb please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hsqldb Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . This alertpertains to a critical vulnerability in hsqldb that allows for potential remote code execution and outlines strategies for securing Debian-based environments.. hsqldb security, remote execution, debian advisory, java database, security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2022 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200