Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 55 articles for you...
200

SciLinux: SLSA-2020-2966-1 Important Update for Thunderbird on SL6

Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) SL6 x86_64 thunderbird-68.10.0-1.el6_10.x86_64 [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2020:2966-1 Issue Date: 2020-07-16 CVE Numbers: None -- Security Fix(es): * Mozilla: Information disclosure due to manipulated URL object (CVE-2020-12418) * Mozilla: Use-after-free in nsGlobalWindowInner (CVE-2020-12419) * Mozilla: Use-After-Free when trying to connect to a STUN server (CVE-2020-12420) * Mozilla: Add-On updates did not respect the same certificate trust rules as software updates (CVE-2020-12421) -- SL6 x86_64 thunderbird-68.10.0-1.el6_10.x86_64.rpm thunderbird-debuginfo-68.10.0-1.el6_10.x86_64.rpm i386 thunderbird-68.10.0-1.el6_10.i686.rpm thunderbird-debuginfo-68.10.0-1.el6_10.i686.rpm - Scientific Linux Development Team . Important announcement for Thunderbird addressing multiple security issues in SL6. Includes information regarding the identified weaknesses.. Mozilla, SL6, Thunderbird, security update, information disclosure. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 16, 2020 Important Scientific Linux
200

Scientific Linux: SLSA-2019-1774-1 Critical: Vim Command Execution Risk

vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735) SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 [More...]. Synopsis: Important: vim security update Advisory ID: SLSA-2019:1774-1 Issue Date: 2019-07-15 CVE Numbers: CVE-2019-12735 -- Security Fix(es): * vim/neovim: ':source!' command allows arbitrary command execution via modelines (CVE-2019-12735) -- SL6 x86_64 vim-X11-7.4.629-5.el6_10.2.x86_64.rpm vim-common-7.4.629-5.el6_10.2.x86_64.rpm vim-debuginfo-7.4.629-5.el6_10.2.x86_64.rpm vim-enhanced-7.4.629-5.el6_10.2.x86_64.rpm vim-filesystem-7.4.629-5.el6_10.2.x86_64.rpm vim-minimal-7.4.629-5.el6_10.2.x86_64.rpm i386 vim-X11-7.4.629-5.el6_10.2.i686.rpm vim-common-7.4.629-5.el6_10.2.i686.rpm vim-debuginfo-7.4.629-5.el6_10.2.i686.rpm vim-enhanced-7.4.629-5.el6_10.2.i686.rpm vim-filesystem-7.4.629-5.el6_10.2.i686.rpm vim-minimal-7.4.629-5.el6_10.2.i686.rpm - Scientific Linux Development Team . Important vim update for SL6.x addresses the risk of arbitrary command execution vulnerabilities. vim Security Update, Scientific Linux Important, Arbitrary Command Risk, SL6 x86_64 Update. . LinuxSecurity.com Team

Calendar%202 Jul 15, 2019 Scientific Linux
200

SciLinux: SLSA-2019-0680-1 Important: Multiple Mozilla Security Fixes

Mozilla: Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788) * Mozilla: Use-after-free when removing in-use DOM elements (CVE-2019-9790) * Mozilla: Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey (CVE-2019-9791) * Mozilla: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script (CVE-2019-9792) * Mozilla: IonMonkey MArr [More...]. Synopsis: Important: thunderbird security update Advisory ID: SLSA-2019:0680-1 Issue Date: 2019-03-28 CVE Numbers: CVE-2018-18506 CVE-2019-9788 CVE-2019-9790 CVE-2019-9791 CVE-2019-9792 CVE-2019-9793 CVE-2019-9795 CVE-2019-9796 CVE-2019-9810 CVE-2019-9813 -- Security Fix(es): * Mozilla: Memory safety bugs fixed in Firefox 66 and Firefox ESR 60.6 (CVE-2019-9788) * Mozilla: Use-after-free when removing in-use DOM elements (CVE-2019-9790) * Mozilla: Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey (CVE-2019-9791) * Mozilla: IonMonkey leaks JS_OPTIMIZED_OUT magic value to script (CVE-2019-9792) * Mozilla: IonMonkey MArraySlice has incorrect alias information (CVE-2019-9810) * Mozilla: Ionmonkey type confusion with __proto__ mutations (CVE-2019-9813) * Mozilla: Improper bounds checks when Spectre mitigations are disabled (CVE-2019-9793) * Mozilla: Type-confusion in IonMonkey JIT compiler (CVE-2019-9795) * Mozilla: Use-after-free with SMIL animation controller (CVE-2019-9796) * Mozilla: Proxy Auto-Configuration file can define localhost access to be proxied (CVE-2018-18506) -- SL6 x86_64 thunderbird-60.6.1-1.el6_10.x86_64.rpm thunderbird-debuginfo-60.6.1-1.el6_10.x86_64.rpm i386 thunderbird-60.6.1-1.el6_10.i686.rpm thunderbird-debuginfo-60.6.1-1.el6_10.i686.rpm - Scientific Linux Development Team . A recent security patch for Scientific Linuxhas been released to fix several memory safety vulnerabilities in the Thunderbird email client developed by Mozilla.. Mozilla, Thunderbird, Memory Safety Bugs, Security Update, SL6. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 28, 2019 Important Scientific Linux
200

Scientific Linux: 2016:2820-1 Important: Memcached Buffer Overflow

Important: memcached security update. Date: Wed, 23 Nov 2016 14:48:28 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: memcached on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: memcached security update Advisory ID: SLSA-2016:2820-1 Issue Date: 2016-11-23 CVE Numbers: CVE-2016-8704 CVE-2016-8705 -- Security Fix(es): * Two integer overflow flaws, leading to heap-based buffer overflows, were found in the memcached binary protocol. An attacker could create a specially crafted message that would cause the memcached server to crash or, potentially, execute arbitrary code. (CVE-2016-8704, CVE-2016-8705) -- SL6 x86_64 memcached-1.4.4-3.el6_8.1.x86_64.rpm memcached-debuginfo-1.4.4-3.el6_8.1.i686.rpm memcached-debuginfo-1.4.4-3.el6_8.1.x86_64.rpm memcached-devel-1.4.4-3.el6_8.1.i686.rpm memcached-devel-1.4.4-3.el6_8.1.x86_64.rpm i386 memcached-1.4.4-3.el6_8.1.i686.rpm memcached-debuginfo-1.4.4-3.el6_8.1.i686.rpm memcached-devel-1.4.4-3.el6_8.1.i686.rpm - Scientific Linux Development Team . Critical patch released for memcached to fix integer overflow vulnerabilities affecting SL6.x platforms.. memcached security fix, Scientific Linux security advisory, buffer overflow vulnerability, SL6.x memcached update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 23, 2016 Important Scientific Linux
200

Scientific Linux SL5: SLSA-2016:1137-1 Critical: OpenSSL Denial of Service

Important: openssl security update. Date: Tue, 31 May 2016 16:26:36 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: openssl on SL5.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: openssl security update Advisory ID: SLSA-2016:1137-1 Issue Date: 2016-05-31 CVE Numbers: CVE-2016-2108 -- Security Fix(es): * A flaw was found in the way OpenSSL encoded certain ASN.1 data structures. An attacker could use this flaw to create a specially crafted certificate which, when verified or re-encoded by OpenSSL, could cause it to crash, or execute arbitrary code using the permissions of the user running an application compiled against the OpenSSL library. (CVE-2016-2108) -- SL5 x86_64 openssl-0.9.8e-40.el5_11.i686.rpm openssl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.x86_64.rpm openssl-perl-0.9.8e-40.el5_11.x86_64.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.x86_64.rpm i386 openssl-0.9.8e-40.el5_11.i386.rpm openssl-0.9.8e-40.el5_11.i686.rpm openssl-debuginfo-0.9.8e-40.el5_11.i386.rpm openssl-debuginfo-0.9.8e-40.el5_11.i686.rpm openssl-perl-0.9.8e-40.el5_11.i386.rpm openssl-devel-0.9.8e-40.el5_11.i386.rpm - Scientific Linux Development Team lastline . An essential security notice regarding OpenSSL upgrades on Scientific Linux SL5.x targeting major vulnerabilities and their resolutions.. openssl update, security advisory, scientific linux errata, critical security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 31, 2016 Critical Scientific Linux
200

Critical Update: SLSA-2016:0514-1 for Java OpenJDK Sandbox Vulnerability

Important: java-1.8.0-openjdk security update. Date: Fri, 25 Mar 2016 15:59:01 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: java-1.8.0-openjdk on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: java-1.8.0-openjdk security update Advisory ID: SLSA-2016:0514-1 Issue Date: 2016-03-25 CVE Numbers: CVE-2016-0636 -- Security Fix(es): * An improper type safety check was discovered in the Hotspot component. An untrusted Java application or applet could use this flaw to bypass Java Sandbox restrictions. (CVE-2016-0636) -- SL6 x86_64 java-1.8.0-openjdk-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-debug-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-demo-debug-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-devel-debug-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-headless-debug-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.77-0.b03.el6_7.x86_64.rpm java-1.8.0-openjdk-src-debug-1.8.0.77-0.b03.el6_7.x86_64.rpm i386 java-1.8.0-openjdk-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-headless-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-debug-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-demo-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-demo-debug-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-devel-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-devel-debug-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-headless-debug-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-src-1.8.0.77-0.b03.el6_7.i686.rpm java-1.8.0-openjdk-src-debug-1.8.0.77-0.b03.el6_7.i686.rpm noarch java-1.8.0-openjdk-javadoc-1.8.0.77-0.b03.el6_7.noarch.rpm java-1.8.0-openjdk-javadoc-debug-1.8.0.77-0.b03.el6_7.noarch.rpm - Scientific Linux Development Team . The update for Java 1.8.0-openjdk addresses a critical security flaw affecting SL6.x platforms.. java-1.8.0-openjdk updates, Scientific Linux security, SL6.x security, Java sandbox issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 25, 2016 Important Scientific Linux
200

Scientific Linux: Firefox Critical Update SLSA-2015:1586-1 CVE-2015-4473 DoS

Critical: firefox security update. Date: Tue, 11 Aug 2015 23:39:20 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Critical: firefox on SL5.x, SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Critical: firefox security update Advisory ID: SLSA-2015:1586-1 Issue Date: 2015-08-11 CVE Numbers: CVE-2015-4473 CVE-2015-4475 CVE-2015-4478 CVE-2015-4479 CVE-2015-4480 CVE-2015-4493 CVE-2015-4484 CVE-2015-4491 CVE-2015-4485 CVE-2015-4486 CVE-2015-4487 CVE-2015-4488 CVE-2015-4489 CVE-2015-4492 -- Several flaws were found in the processing of malformed web content. A web page containing malicious content could cause Firefox to crash or, potentially, execute arbitrary code with the privileges of the user running Firefox. (CVE-2015-4473, CVE-2015-4475, CVE-2015-4478, CVE-2015-4479, CVE-2015-4480, CVE-2015-4493, CVE-2015-4484, CVE-2015-4491, CVE-2015-4485, CVE-2015-4486, CVE-2015-4487, CVE-2015-4488, CVE-2015-4489, CVE-2015-4492) After installing the update, Firefox must be restarted for the changes to take effect. -- SL5 x86_64 firefox-38.2.0-4.el5_11.i386.rpm firefox-38.2.0-4.el5_11.x86_64.rpm firefox-debuginfo-38.2.0-4.el5_11.i386.rpm firefox-debuginfo-38.2.0-4.el5_11.x86_64.rpm i386 firefox-38.2.0-4.el5_11.i386.rpm firefox-debuginfo-38.2.0-4.el5_11.i386.rpm SL6 x86_64 firefox-38.2.0-4.el6_7.x86_64.rpm firefox-debuginfo-38.2.0-4.el6_7.x86_64.rpm firefox-38.2.0-4.el6_7.i686.rpm firefox-debuginfo-38.2.0-4.el6_7.i686.rpm i386 firefox-38.2.0-4.el6_7.i686.rpm firefox-debuginfo-38.2.0-4.el6_7.i686.rpm SL7 x86_64 firefox-38.2.0-4.el7_1.x86_64.rpm firefox-debuginfo-38.2.0-4.el7_1.x86_64.rpm firefox-38.2.0-4.el7_1.i686.rpm firefox-debuginfo-38.2.0-4.el7_1.i686.rpm - Scientific Linux Development Team . Important security patch issued for Firefox tackling several weaknesses in Scientific Linux configurations. A crucial update necessary for safeguarding user data.. firefox update,scientific linux security, critical patches, firefox vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 11, 2015 Critical Scientific Linux
200

Scientific Linux: 2015:1123-1 Critical CUPS Security Update Available

Important: cups security update. Date: Tue, 16 Jun 2015 08:28:15 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: FASTBUGS for SL 6x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploadedto ccs-0.16.2-75.el6_6.2.i686.rpm chkconfig-1.3.49.3-5.el6.i686.rpm db4-4.7.25-19.el6_6.i686.rpm db4-cxx-4.7.25-19.el6_6.i686.rpm db4-devel-4.7.25-19.el6_6.i686.rpm db4-devel-static-4.7.25-19.el6_6.i686.rpm db4-java-4.7.25-19.el6_6.i686.rpm db4-tcl-4.7.25-19.el6_6.i686.rpm db4-utils-4.7.25-19.el6_6.i686.rpm environment-modules-3.2.10-2.el6.i686.rpm kmod-hpsa-3.4.4_1_RH4-1.el6_5.i686.rpm ntsysv-1.3.49.3-5.el6.i686.rpm poppler-0.12.4-4.el6_6.1.i686.rpm poppler-devel-0.12.4-4.el6_6.1.i686.rpm poppler-glib-0.12.4-4.el6_6.1.i686.rpm poppler-glib-devel-0.12.4-4.el6_6.1.i686.rpm poppler-qt-0.12.4-4.el6_6.1.i686.rpm poppler-qt4-0.12.4-4.el6_6.1.i686.rpm poppler-qt4-devel-0.12.4-4.el6_6.1.i686.rpm poppler-qt-devel-0.12.4-4.el6_6.1.i686.rpm poppler-utils-0.12.4-4.el6_6.1.i686.rpm resource-agents-3.9.5-12.el6_6.6.i686.rpm ricci-0.16.2-75.el6_6.2.i686.rpm x86_64: ccs-0.16.2-75.el6_6.2.x86_64.rpm chkconfig-1.3.49.3-5.el6.x86_64.rpm db4-4.7.25-19.el6_6.i686.rpm db4-4.7.25-19.el6_6.x86_64.rpm db4-cxx-4.7.25-19.el6_6.i686.rpm db4-cxx-4.7.25-19.el6_6.x86_64.rpm db4-devel-4.7.25-19.el6_6.i686.rpm db4-devel-4.7.25-19.el6_6.x86_64.rpm db4-devel-static-4.7.25-19.el6_6.x86_64.rpm db4-java-4.7.25-19.el6_6.x86_64.rpm db4-tcl-4.7.25-19.el6_6.x86_64.rpm db4-utils-4.7.25-19.el6_6.x86_64.rpm environment-modules-3.2.10-2.el6.x86_64.rpm fence-sanlock-2.8-2.el6_5.x86_64.rpm kmod-hpsa-3.4.4_1_RH4-1.el6_5.x86_64.rpm ntsysv-1.3.49.3-5.el6.x86_64.rpm poppler-0.12.4-4.el6_6.1.i686.rpm poppler-0.12.4-4.el6_6.1.x86_64.rpm poppler-devel-0.12.4-4.el6_6.1.i686.rpm poppler-devel-0.12.4-4.el6_6.1.x86_64.rpm poppler-glib-0.12.4-4.el6_6.1.i686.rpm poppler-glib-0.12.4-4.el6_6.1.x86_64.rpm poppler-glib-devel-0.12.4-4.el6_6.1.i686.rpm poppler-glib-devel-0.12.4-4.el6_6.1.x86_64.rpm poppler-qt-0.12.4-4.el6_6.1.i686.rpm poppler-qt-0.12.4-4.el6_6.1.x86_64.rpm poppler-qt4-0.12.4-4.el6_6.1.i686.rpm poppler-qt4-0.12.4-4.el6_6.1.x86_64.rpm poppler-qt4-devel-0.12.4-4.el6_6.1.i686.rpm poppler-qt4-devel-0.12.4-4.el6_6.1.x86_64.rpm poppler-qt-devel-0.12.4-4.el6_6.1.i686.rpm poppler-qt-devel-0.12.4-4.el6_6.1.x86_64.rpm poppler-utils-0.12.4-4.el6_6.1.x86_64.rpm resource-agents-3.9.5-12.el6_6.6.x86_64.rpm ricci-0.16.2-75.el6_6.2.x86_64.rpm sanlock-2.8-2.el6_5.x86_64.rpm sanlock-devel-2.8-2.el6_5.x86_64.rpm sanlock-lib-2.8-2.el6_5.x86_64.rpm sanlock-python-2.8-2.el6_5.x86_64.rpm Date: Tue, 16 Jun 2015 08:45:12 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: FASTBUGS for SL 7x x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to x86_64: ibus-1.5.3-12.el7.i686.rpm ibus-1.5.3-12.el7.x86_64.rpm ibus-devel-1.5.3-12.el7.i686.rpm ibus-devel-1.5.3-12.el7.x86_64.rpm ibus-devel-docs-1.5.3-12.el7.noarch.rpm ibus-gtk2-1.5.3-12.el7.i686.rpm ibus-gtk2-1.5.3-12.el7.x86_64.rpm ibus-gtk3-1.5.3-12.el7.x86_64.rpm ibus-libs-1.5.3-12.el7.i686.rpm ibus-libs-1.5.3-12.el7.x86_64.rpm ibus-pygtk2-1.5.3-12.el7.noarch.rpm ibus-setup-1.5.3-12.el7.noarch.rpm libkkc-0.3.1-8.el7.i686.rpm libkkc-0.3.1-8.el7.x86_64.rpm libkkc-common-0.3.1-8.el7.noarch.rpm libkkc-data-0.3.1-8.el7.x86_64.rpm libkkc-devel-0.3.1-8.el7.i686.rpm libkkc-devel-0.3.1-8.el7.x86_64.rpm libkkc-tools-0.3.1-8.el7.x86_64.rpm Date: Wed, 17 Jun 2015 22:05:51 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: cups on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: cups security update Advisory ID: SLSA-2015:1123-1 Issue Date: 2015-06-17 CVE Numbers: CVE-2014-9679 CVE-2015-1158 CVE-2015-1159 -- A string reference count bug was found in cupsd, causing premature freeing of string objects. An attacker can submit a malicious print job that exploits this flaw to dismantle ACLs protecting privileged operations, allowing a replacement configuration file to be uploaded which in turn allows the attacker to run arbitrary code in the CUPS server (CVE-2015-1158) A cross-site scripting flaw was found in the cups web templating engine. An attacker could usethis flaw to bypass the default configuration settings that bind the CUPS scheduler to the 'localhost' or loopback interface. (CVE-2015-1159) An integer overflow leading to a heap-based buffer overflow was found in the way cups handled compressed raster image files. An attacker could create a specially-crafted image file, which when passed via the cups Raster filter, could cause the cups filter to crash. (CVE-2014-9679) After installing this update, the cupsd daemon will be restarted automatically. -- SL6 x86_64 cups-1.4.2-67.el6_6.1.x86_64.rpm cups-debuginfo-1.4.2-67.el6_6.1.i686.rpm cups-debuginfo-1.4.2-67.el6_6.1.x86_64.rpm cups-libs-1.4.2-67.el6_6.1.i686.rpm cups-libs-1.4.2-67.el6_6.1.x86_64.rpm cups-lpd-1.4.2-67.el6_6.1.x86_64.rpm cups-devel-1.4.2-67.el6_6.1.i686.rpm cups-devel-1.4.2-67.el6_6.1.x86_64.rpm cups-php-1.4.2-67.el6_6.1.x86_64.rpm i386 cups-1.4.2-67.el6_6.1.i686.rpm cups-debuginfo-1.4.2-67.el6_6.1.i686.rpm cups-libs-1.4.2-67.el6_6.1.i686.rpm cups-lpd-1.4.2-67.el6_6.1.i686.rpm cups-devel-1.4.2-67.el6_6.1.i686.rpm cups-php-1.4.2-67.el6_6.1.i686.rpm SL7 x86_64 cups-1.6.3-17.el7_1.1.x86_64.rpm cups-client-1.6.3-17.el7_1.1.x86_64.rpm cups-debuginfo-1.6.3-17.el7_1.1.i686.rpm cups-debuginfo-1.6.3-17.el7_1.1.x86_64.rpm cups-libs-1.6.3-17.el7_1.1.i686.rpm cups-libs-1.6.3-17.el7_1.1.x86_64.rpm cups-lpd-1.6.3-17.el7_1.1.x86_64.rpm cups-devel-1.6.3-17.el7_1.1.i686.rpm cups-devel-1.6.3-17.el7_1.1.x86_64.rpm cups-ipptool-1.6.3-17.el7_1.1.x86_64.rpm noarch cups-filesystem-1.6.3-17.el7_1.1.noarch.rpm - Scientific Linux Development Team . A security patch has been released for Scientific Linux versions SL6.x and SL7.x, fixing various vulnerabilities and enhancing system protection.. CUPS Update, Scientific Linux, Security Patch, Important Notices. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2015 Critical Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200