Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 23.10 USN-6483-1 Critical: HTML Tidy Remote Code Execution

tidy-html5 could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6483-1 November 15, 2023 tidy-html5 vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: tidy-html5 could be made to crash or run programs if it opened a specially crafted file. Software Description: - tidy-html5: HTML/XML syntax checker and reformatter Details: Neeraj Pal discovered that HTML Tidy incorrectly handled parsing certain HTML data. If a user or automated system were tricked into parsing specially crafted HTML data, a remote attacker could cause HTML Tidy to consume resources, leading to a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libtidy5deb1 2:5.6.0-11ubuntu0.23.10.1 tidy 2:5.6.0-11ubuntu0.23.10.1 Ubuntu 23.04: libtidy5deb1 2:5.6.0-11ubuntu0.23.04.1 tidy 2:5.6.0-11ubuntu0.23.04.1 Ubuntu 22.04 LTS: libtidy5deb1 2:5.6.0-11ubuntu0.22.04.1 tidy 2:5.6.0-11ubuntu0.22.04.1 Ubuntu 20.04 LTS: libtidy5deb1 2:5.6.0-11ubuntu0.20.04.1 tidy 2:5.6.0-11ubuntu0.20.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2021-33391 Package Information: https://launchpad.net/ubuntu/+source/tidy-html5/2:5.6.0-11ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/tidy-html5/2:5.6.0-11ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/tidy-html5/2:5.6.0-11ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/tidy-html5/2:5.6.0-11ubuntu0.20.04.1 . Secure your Ubuntu system by updating to the latest packages that fix the HTML Tidy vulnerability, which can cause crashes and remote code execution risks. Ubuntu Update, HTML Tidy Issue, Security Notice, Remote Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 15, 2023 Critical Ubuntu
172

Ubuntu 14.04 LTS: USN-2695-1 Moderate: HTML Tidy Denial Of Service

HTML Tidy could be made to crash or run programs if it processed specially crafted data.. =========================================================================Ubuntu Security Notice USN-2695-1 July 29, 2015 tidy vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: HTML Tidy could be made to crash or run programs if it processed specially crafted data. Software Description: - tidy: HTML syntax checker and reformatter Details: Fernando Muñoz discovered that HTML Tidy incorrectly handled memory. If a user or automated system were tricked into processing specially crafted data, applications linked against HTML Tidy could be made to crash, leading to a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: libtidy-0.99-0 20091223cvs-1.4ubuntu0.1 Ubuntu 14.04 LTS: libtidy-0.99-0 20091223cvs-1.2ubuntu1.1 Ubuntu 12.04 LTS: libtidy-0.99-0 20091223cvs-1ubuntu2.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2695-1 CVE-2015-5522, CVE-2015-5523 Package Information: https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.4ubuntu0.1 https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1.2ubuntu1.1 https://launchpad.net/ubuntu/+source/tidy/20091223cvs-1ubuntu2.1 . =========================================================================Ubuntu Security Notice USN-. crash, programs, processed, specially, crafted, ===========. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 29, 2015 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200