Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
202

openSUSE: 2021:1494-1 Moderate: Hylafax+ Buffer Overflow

An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:1494-1 Rating: moderate References: #1191571 Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: hylafax+ was updated to version 7.0.4: * README.SUSE renamed * hylafax.diff added for boo#1191571 (pre-correction) * Dependencies on systemd-services adjusted * retry training twice at the same bitrate unless FTT (26 Aug 2021) * add missing reason messages for session failures (21 Aug 2021) * stop attempts to send or receive signals if the call ended prematurely (16-19 Aug 2021) * add Class1HasRMHookIndication (16 Aug 2021) * don't attempt sending DCN if we're already on hook (15, 17 Aug 2021) * end session sooner if receiver hangs up immediately after TCF or during prologue (14 Aug 2021) * fix some behavior following frame reception timeouts (13 Aug 2021) * improve behavior if procedural interrupt fails (12 Aug 2021) * handle sender repeating RR after we transmit MCF (10 Aug 2021) * add session logging of receipt of CFR/FTT signals (3 Aug 2021) * cope with receipt of PPR following CTC (3 Aug 2021) * attempt to cope with NSF/CSI/DIS after PPS, CTR, ERR, RR and improve coping with the same after MPS/EOP/EOM (2, 12, 14, 18 Aug 2021) * identify DCN after PPS as a receiver abort (2 Aug 2021) * attempt to cope with receipt of CTR after sending PPS (2 Aug 2021) * remove use of deprecated libtiff integer types and "register" storage class specifier (25 Jul 2021) * don't employ senderFumblesECM if V.34-Fax was negotiated (25 Jul 2021) * update configure to accept libtiff v4.2 and v4.3 (24 Jul 2021) * fix pagehandling "botch" if a job's first and previous attempts were on a proxy (20 Jul 2021) * fix data timeout for bitrates less than 14400 bps when non-zero scanline time (15 Jul 2021) * try to cope with T.38 invite stutter at beginning of send (15 Jul 2021) * decouple session logging from direct filesystem I/O (15 Jul 2021) * try to help receivers who may expect initial 1-bits to start high-speed data (8, 9 Jul, 4 Aug 2021) * improve tenacity of "persistent" ECM (26 Jun 2021) * maintain the same SSL Fax passcode during a single session (20 May 2021) * log detection of binary file transfer support in receivers (1 Apr 2021) * add support for SiLabs Si2417/Si2435 (5 Feb 2021) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2021-1494=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): hylafax+-7.0.4-bp153.2.3.1 hylafax+-client-7.0.4-bp153.2.3.1 libfaxutil7_0_4-7.0.4-bp153.2.3.1 References: https://bugzilla.suse.com/1191571 . Apply the most recent openSUSE Security Patch for hylafax+ in order to resolve multiple security vulnerabilities and enhancements.. Hylafax Security Patch, Linux Patch Management, openSUSE Update. . LinuxSecurity.com Team

Calendar%202 Nov 21, 2021 OpenSUSE
202

openSUSE Leap 15.2: 2020:1209-1 Moderate: Hylafax+ Security Update

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1209-1 Rating: moderate References: #1173519 #1173521 Cross-References: CVE-2020-15396 CVE-2020-15397 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for hylafax+ fixes the following issues: Hylafax was updated to upstream version 7.0.3. Security issues fixed: - CVE-2020-15396: Secure temporary directory creation for faxsetup, faxaddmodem, and probemodem (boo#1173521). - CVE-2020-15397: Sourcing of files into binaries from user writeable directories (boo#1173519). Non-security issues fixed: * add UseSSLFax feature in sendfax, sendfax.conf, hyla.conf, and JobControl (31 Jul 2020) * be more resilient in listening for the Phase C carrier (30 Jul 2020) * make sure to return to command mode if HDLC receive times out (29 Jul 2020) * make faxmail ignore boundaries on parts other than multiparts (29 Jul 2020) * don't attempt to write zero bytes of data to a TIFF (29 Jul 2020) * don't ever respond to CRP with CRP (28 Jul 2020) * reset frame counter when a sender retransmits PPS for a previously confirmed ECM block (26 Jul 2020) * scrutinize PPM before concluding that the sender missed our MCF (23 Jul 2020) * fix modem recovery after SSL Fax failure (22, 26 Jul 2020) * ignore echo of PPR, RTN, CRP (10, 13, 21 Jul 2020) * attempt to handle NSF/CSI/DIS in Class 1 sending Phase D (6 Jul 2020) * run scripts directly rather than invoking them via a shell for security hardening (3-5 Jul 2020) * add senderFumblesECM feature (3 Jul 2020) * add support for PIN/PIP/PRI-Q/PPS-PRI-Q signals, addsenderConfusesPIN feature, and utilize PIN for rare conditions where it may be helpful (2, 6, 13-14 Jul 2020) * add senderConfusesRTN feature (25-26 Jun 2020) * add MissedPageHandling feature (24 Jun 2020) * use and handle CFR in Phase D to retransmit Phase C (16, 23 Jun 2020) * cope with hearing echo of RR, CTC during Class 1 sending (15-17 Jun 2020) * fix listening for retransmission of MPS/EOP/EOM if it was received corrupt on the first attempt (15 Jun 2020) * don't use CRP when receiving PPS/PPM as some senders think we are sending MCF (12 Jun 2020) * add BR_SSLFAX to show SSL Fax in notify and faxinfo output (1 Jun 2020) * have faxinfo put units on non-standard page dimensions (28 May 2020) * improve error messages for JobHost connection errors (22 May 2020) * fix perpetual blocking of jobs when a job preparation fails, attempt to fix similar blocking problems for bad jobs in batches, and add "unblock" faxconfig feature (21 May 2020) * ignore TCF if we're receiving an SSL Fax (31 Jan 2020) * fixes for build on FreeBSD 12.1 (31 Jan - 3 Feb 2020) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1209=1 Package List: - openSUSE Leap 15.2 (x86_64): hylafax+-7.0.3-lp152.3.6.1 hylafax+-client-7.0.3-lp152.3.6.1 hylafax+-client-debuginfo-7.0.3-lp152.3.6.1 hylafax+-debuginfo-7.0.3-lp152.3.6.1 hylafax+-debugsource-7.0.3-lp152.3.6.1 libfaxutil7_0_3-7.0.3-lp152.3.6.1 libfaxutil7_0_3-debuginfo-7.0.3-lp152.3.6.1 References: https://www.suse.com/security/cve/CVE-2020-15396.html https://www.suse.com/security/cve/CVE-2020-15397.html https://bugzilla.suse.com/1173519 https://bugzilla.suse.com/1173521 -- . openSUSE Security Update: Security update forhylafax+ _____________________________________________. update, security, fixes, vulnerabilities, opensuse. . LinuxSecurity.com Team

Calendar%202 Aug 14, 2020 OpenSUSE
197

Debian 8: DLA-1515-1 Critical: Hylafax Arbitrary Code Execution

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. . Package : hylafax Version : 3:6.0.6-6+deb8u1 CVE ID : CVE-2018-17141 Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. For Debian 8 "Jessie", this problem has been fixed in version 3:6.0.6-6+deb8u1. We recommend that you upgrade your hylafax packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical security patch for Hylafax addresses a vulnerability in input validation that could allow attackers to execute arbitrary code. Users are urged to upgrade to the latest version.. Hylafax Security Update, Debian LTS, Input Sanitization, Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 22, 2018 Critical Debian LTS
202

openSUSE: 2018:2797-1 Critical: Hylafax+ Remote Execution Vulnerability

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for hylafax+ ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2797-1 Rating: critical References: #1109084 Cross-References: CVE-2018-17141 Affected Products: openSUSE Leap 42.3 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for hylafax+ fixes the following issues: Security issues fixed in 5.6.1: - CVE-2018-17141: multiple vulnerabilities affecting fax page reception in JPEG format Specially crafted input may have allowed remote execution of arbitrary code (boo#1109084) Additionally, this update also contains all upstream corrections and bugfixes in the 5.6.1 version, including: - fix RFC2047 encoding by notify - add jobcontrol PageSize feature - don't wait forever after +FRH:3 - fix faxmail transition between a message and external types - avoid pagehandling from introducing some unnecessary EOM signals - improve proxy connection error handling and logging - add initial ModemGroup limits feature - pass the user's uid onto the session log file for sent faxes - improve job waits to minimize triggers - add ProxyTaglineFormat and ProxyTSI features Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1027=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1027=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): hylafax+-5.6.1-15.1 hylafax+-client-5.6.1-15.1 hylafax+-client-debuginfo-5.6.1-15.1 hylafax+-debuginfo-5.6.1-15.1 hylafax+-debugsource-5.6.1-15.1 libfaxutil5_6_1-5.6.1-15.1 libfaxutil5_6_1-debuginfo-5.6.1-15.1 - openSUSE Leap 15.0 (x86_64): hylafax+-5.6.1-lp150.5.6.1 hylafax+-client-5.6.1-lp150.5.6.1 hylafax+-client-debuginfo-5.6.1-lp150.5.6.1 hylafax+-debuginfo-5.6.1-lp150.5.6.1 hylafax+-debugsource-5.6.1-lp150.5.6.1 libfaxutil5_6_1-5.6.1-lp150.5.6.1 libfaxutil5_6_1-debuginfo-5.6.1-lp150.5.6.1 References: https://www.suse.com/security/cve/CVE-2018-17141.html https://bugzilla.suse.com/1109084 -- . Important openSUSE patch resolves security vulnerabilities in hylafax+. Find installation instructions here!. openSUSE Security, Hylafax Update, Critical Issues, Software Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2018 Critical OpenSUSE
87

Debian: DSA-4301-1 Urgent: Rsyslog Vulnerability Exploit

Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4298-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 20, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : hylafax CVE ID : CVE-2018-17141 Luis Merino, Markus Vervier and Eric Sesterhenn discovered that missing input sanitising in the Hylafax fax software could potentially result in the execution of arbitrary code via a malformed fax message. For the stable distribution (stretch), this problem has been fixed in version 3:6.0.6-7+deb9u1. We recommend that you upgrade your hylafax packages. For the detailed security status of hylafax please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/hylafax Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-4299-1 announces a security patch for Nginx, addressing potential denial-of-service exploits through specially crafted HTTP requests.. Hylafax Security, Debian Security Update, Input Sanitization, Software Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 20, 2018 Important Debian
87

Debian: DSA 933-1 Critical: Hylafax Arbitrary Command Execution

Patrice Fournier found that hylafax passes unsanitized user data in the notify script, allowing users with the ability to submit jobs to run arbitrary commands with the privileges of the hylafax server.. - --------------------------------------------------------------------------Debian Security Advisory DSA 933-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Stone January 9, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : hylafax Vulnerability : arbitrary command execution Problem-Type : local Debian-specific: no CVE ID : CVE-2005-3539 Patrice Fournier found that hylafax passes unsanitized user data in the notify script, allowing users with the ability to submit jobs to run arbitrary commands with the privileges of the hylafax server. For the old stable distribution (woody) this problem has been fixed in version 4.1.1-4woody1. For the stable distribution (sarge) this problem has been fixed in version 4.2.1-5sarge3. For the unstable distribution the problem has been fixed in version 4.2.4-2. We recommend that you upgrade your hylafax package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 800 c9fd457c2782971a41c8328435b00ece Size/MD5 checksum: 116777 a2c212abd4a22134b673b3df345cb779 Size/MD5 checksum: 12876891ed081750be70a800708699b7568e17e Architecture independent components: Size/MD5 checksum: 318384 bf2352b27b55b6a6b66acd8184864ed5 Alpha architecture: Size/MD5 checksum: 556394 4acfe414a92ca39dd08d945927134fde Size/MD5 checksum: 1362704 7c5d2805a86e35f77fbdc320608eae21 ARM architecture: Size/MD5 checksum: 445742 bd7631c263e79ba1fa222616fab0814c Size/MD5 checksum: 1096024 a5bccc072005832e21a63af6cd355d80 Intel IA-32 architecture: Size/MD5 checksum: 462478 a1b1d1ffb63fa002602fa817985c10d4 Size/MD5 checksum: 1132898 f7f7933a5c26c69048628d20c6d8c6e2 Intel IA-64 architecture: Size/MD5 checksum: 615750 9dd3e91618a0b7ff630fc8e73472be90 Size/MD5 checksum: 1491998 fcfa52b30bf30151ce3d9c9c283738b2 HP Precision architecture: Size/MD5 checksum: 501764 532a01a8b1c509fff8640a63743f27b0 Size/MD5 checksum: 1231584 2d3a3a7072c00e4fc71bb48045aac459 Motorola 680x0 architecture: Size/MD5 checksum: 451356 52f1e0515d0dc3f88b25de500aa8916c Size/MD5 checksum: 1100320 294aa660f86c7090eb0092755a788009 PowerPC architecture: Size/MD5 checksum: 450900 349b2498e9ca56c63e219911b79e2953 Size/MD5 checksum: 1104560 48b998cf768a2ff858c948e5892b32c4 IBM S/390 architecture: Size/MD5 checksum: 441344 51762120b318ed4c800a12e28242b5fa Size/MD5 checksum: 1087136 ba81545268b85fa2783814ca8322d3b3 Sun Sparc architecture: Size/MD5 checksum: 433674 4786a267f600ba71c8f9c80a1f371439 Size/MD5 checksum: 1082890 6bdc5a6359c4b953f5127031af69cbe2 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 746 1202e740bcb10a01977c98f6967d2da4 Size/MD5 checksum: 51922 e7d0531c64d48a9907e1a9c73b882bff Size/MD5 checksum: 1412035 05430e41a279d0fff6d6e4b444440829 Architecture independent components: Size/MD5 checksum: 372578 70db2ce1b777e475cbe3335abc31a5a6 Alpha architecture: Size/MD5 checksum: 373996 440dedf0a21a7ea99573ff9a0c8eb675 Size/MD5 checksum: 863606 cff4540597762579538d71e447b09f01 AMD64 architecture: Size/MD5 checksum: 350894 a8040ccfde418e5cdf9f353f8b7471d9 Size/MD5 checksum: 801152 977bdc76fc44339599770227ba93befc ARM architecture: Size/MD5 checksum: 342534 a79825720236fdafac2c6a7841b1fdec Size/MD5 checksum: 808884 10810889ed1c044fb1fec91af88184b2 Intel IA-32 architecture: Size/MD5 checksum: 348172 0b3837a725542ab94fe7525beb54926d Size/MD5 checksum: 805786 05e61ba137faedbaf4a6d4b3faf0cce6 Intel IA-64 architecture: Size/MD5 checksum: 402530 a592a7397d1b75dc541584e3e10cbd23 Size/MD5 checksum: 924558 eb3701170b63c4ca617c93c74aa59f76 HP Precision architecture: Size/MD5 checksum: 402386 7ec015549d9aa57e5a8e037deb6edb32 Size/MD5 checksum: 911520 948195eaaf686a5cffa3237df90d8504 Motorola 680x0 architecture: Size/MD5 checksum: 345380 635f021fb40dbdd09c138608e64c309c Size/MD5 checksum: 784438 3bc0f358363b448d3f8e72f95743a9fe Big endian MIPS architecture: Size/MD5 checksum: 352748 a65a3fcfffc4ec111fe4237a92734254 Size/MD5 checksum: 836146 17146c51624cfc1f7c7eaac74c483f21 Little endian MIPS architecture: Size/MD5 checksum: 350272 d5d512363681880db5e3d587021cab19 Size/MD5 checksum: 831156 b06e0395c7b347093f2f9e1fe9673b91 PowerPC architecture: Size/MD5 checksum: 356672 778a434ea9e2e73d85ee8b7eaec4062c Size/MD5 checksum: 819686 4e82d570b0ffe822945814f90a5c175c IBM S/390 architecture: Size/MD5 checksum: 339480 5afce0e8172e75b1b39d0086f69c5e0a Size/MD5 checksum: 767944bc881199411dce80be644491b031af07 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Remote code execution flaw addressed in hylafax software for Debian; refer to DSA 933-1 for further upgrade instructions. Hylafax Fix, Debian Advisory, Arbitrary Command Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2006 Critical Debian
87

Debian: DSA 865-1 Critical: Hylafax Insecure Temp Files Exploit

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 865-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze October 13th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : hylafax Vulnerability : insecure temporary files Problem type : local Debian-specific: no CVE ID : CAN-2005-3069 CERT advisory : BugTraq ID : Debian Bug : Javier Fernández-Sanguino Peña discovered that several scripts of the hylafax suite, a flexible client/server fax software, create temporary files and directories in an insecure fashion, leaving them vulnerable to symlink exploits. For the old stable distribution (woody) this problem has been fixed in version 4.1.1-3.2. For the stable distribution (sarge) this problem has been fixed in version 4.2.1-5sarge1. For the unstable distribution (sid) this problem has been fixed in version 4.2.2-1. We recommend that you upgrade your hylafax packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 739 a26715f7b967614e4aa3afb4657fb20e Size/MD5 checksum: 116099 ad9d74b7d995655df44c6a257cfb8e1f Size/MD5 checksum: 1287689 1ed081750be70a800708699b7568e17e Architecture independent components: Size/MD5 checksum: 31830249ee14fc07e1ca12ea191ec01209831f Alpha architecture: Size/MD5 checksum: 556336 2ca7177d8d4e45ad08052612d31e3286 Size/MD5 checksum: 1362414 98b7c46d94841981577a46965982daf3 ARM architecture: Size/MD5 checksum: 445654 7fd22812bb3e50f5915a3d5ca56c3412 Size/MD5 checksum: 1095664 3b56df8d25e56adbf657f35f6add331d Intel IA-32 architecture: Size/MD5 checksum: 462410 1b6ef2d2bc9a013abc3ca5c88d9517ef Size/MD5 checksum: 1132566 fe019575d929c90497da4da532dd0e14 Intel IA-64 architecture: Size/MD5 checksum: 615710 80614f594990528f32d72f29a25059aa Size/MD5 checksum: 1491748 1fefde2f9ef1e1f29f2f3e538746e826 HP Precision architecture: Size/MD5 checksum: 501634 a6d82e052b47ec50dcb2074b97bc9118 Size/MD5 checksum: 1231286 21b6141ceb425b35dca9ba8350cea477 Motorola 680x0 architecture: Size/MD5 checksum: 451276 e7bcefc8e040c5dd61993cce93f8463f Size/MD5 checksum: 1099994 35967ff6911e340a8ad03677e314bdb6 PowerPC architecture: Size/MD5 checksum: 450830 a81c00ffe35a3596f2a1cba944e25369 Size/MD5 checksum: 1104318 49a486d5ad824024d1aee622f38bca9b IBM S/390 architecture: Size/MD5 checksum: 441260 40081bae3595b7b5d409129f2658ce6c Size/MD5 checksum: 1086846 a5db5a237b9af20c976adc66ae5186d0 Sun Sparc architecture: Size/MD5 checksum: 433626 5ff8d52490ad2d2a9f77c0371662f757 Size/MD5 checksum: 1082548 78c8ee6392656ad57d66dc03e9619451 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 746 b6ffe5782b520108a41be7da0e65f212 Size/MD5 checksum: 51332 486108ce920ac6adfed78ea503a429d5 Size/MD5 checksum: 1412035 05430e41a279d0fff6d6e4b444440829 Architecture independent components: Size/MD5 checksum: 372500 f5f4b31a5efcfe1c906ee102d03d306c Alphaarchitecture: Size/MD5 checksum: 373904 a8b07000fe5e9fe40c8729411c8c8bdd Size/MD5 checksum: 863548 5ea99f1e2b7770a1f9467081ba076484 AMD64 architecture: Size/MD5 checksum: 350818 0bcd173184e7fa51589b2f54ccfb15c5 Size/MD5 checksum: 801080 9f72610133beab92ca221215e0263b68 ARM architecture: Size/MD5 checksum: 342470 117f8e70e33830ca07f04babd116927d Size/MD5 checksum: 808824 74f5d116878343c02269a2577e06d945 Intel IA-32 architecture: Size/MD5 checksum: 348094 c81c1b6d04a35e3a6d317449b8ec2801 Size/MD5 checksum: 805734 4fcc081ed2e9b0865025cfe2e719d203 Intel IA-64 architecture: Size/MD5 checksum: 402470 6ad9857e7c46d2c51479271a20bb78c7 Size/MD5 checksum: 924518 b98f0ff9f1bae59d39956d5f3fef96bc HP Precision architecture: Size/MD5 checksum: 402304 6f5944f958c4a4fb1297391387547006 Size/MD5 checksum: 911470 a9b443693d95bc152977114b054ebec4 Motorola 680x0 architecture: Size/MD5 checksum: 345324 d0dd8395c48a88e9d080e26fe7beb333 Size/MD5 checksum: 784366 bd761bc6035a6ba2a52e072476d36d47 Big endian MIPS architecture: Size/MD5 checksum: 352702 7227bc9a47689297868b622a0f1328b2 Size/MD5 checksum: 836084 e7a9cf31efe92f03cf8be2f34e6ae4d3 Little endian MIPS architecture: Size/MD5 checksum: 350218 faf1361beefc28c5b3f7feab9703c2a9 Size/MD5 checksum: 831058 44c131e3f464cfd9b6e05ce2cb93658d PowerPC architecture: Size/MD5 checksum: 356594 f25e009fcdbd2cf4e867293f894dab7d Size/MD5 checksum: 819646 3330a4499a03d26f8baf0ad71307a23d IBM S/390 architecture: Size/MD5 checksum: 339420 fb65b63a8de4e4725730b973e4e3ea27 Size/MD5 checksum: 767898 2e7a83d6bd2c026b1b2af53797e63a21 Sun Sparc architecture: Size/MD5 checksum: 328882 502e63cbc6728737c66b39686ff2f1c5 Size/MD5checksum: 759848 2ba892225d8368372a475ecc12acc942 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch addressing the risks associated with insecure temporary file handling in hylafax installations for Debian systems, prioritizing user security and data preservation.. Hylafax Update, Debian Security, Software Exploit, Temporary File Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2005 Critical Debian
91

Gentoo GLSA 200509-21 Normal: Hylafax File Overwrite Risk

Hylafax is vulnerable to linking attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200509-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Hylafax: Insecure temporary file creation in xferfaxstats script Date: September 30, 2005 Bugs: #106882 ID: 200509-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Hylafax is vulnerable to linking attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= Hylafax is a client-server fax package for class 1 and 2 fax modems. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/hylafax < 4.2.2 *> = 4.2.0-r3 *> = 4.2.1-r2 > = 4.2.2 Description ========== Javier Fernandez-Sanguino has discovered that xferfaxstats cron script supplied by Hylafax insecurely creates temporary files with predictable filenames. Impact ===== A local attacker could create symbolic links in the temporary file directory, pointing to a valid file somewhere on the filesystem. When the xferfaxstats script of Hylafax is executed, this would result in the file being overwritten with the rights of the user running the script, which typically is the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All Hylafax users should upgrade to the latestversion: # emerge --sync # emerge --ask --oneshot --verbose net-misc/hylafax References ========= [ 1 ] Original bug report Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200509-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The Hylafax security bulletin points out risks from insecure temporary file creation, exposing Gentoo environments to local exploit chances for attackers.. Hylafax Security Advisory,Gentoo Linking Attack,Temporary File Issue. . LinuxSecurity.com Team

Calendar%202 Sep 30, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200