Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
197

Debian: DLA-1716-1 Critical: ikiwiki Aggregate Plugin Security Issue

The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed: . Package : ikiwiki Version : 3.20141016.4+deb8u1 CVE ID : CVE-2019-9187 The ikiwiki maintainers discovered that the aggregate plugin did not use LWPx::ParanoidAgent. On sites where the aggregate plugin is enabled, authorized wiki editors could tell ikiwiki to fetch potentially undesired URIs even if LWPx::ParanoidAgent was installed: local files via file: URIs other URI schemes that might be misused by attackers, such as gopher: hosts that resolve to loopback IP addresses (127.x.x.x) hosts that resolve to RFC 1918 IP addresses (192.168.x.x etc.) This could be used by an attacker to publish information that should not have been accessible, cause denial of service by requesting "tarpit" URIs that are slow to respond, or cause undesired side-effects if local web servers implement "unsafe" GET requests. (CVE-2019-9187) Additionally, if liblwpx-paranoidagent-perl is not installed, the blogspam, openid and pinger plugins would fall back to LWP, which is susceptible to similar attacks. This is unlikely to be a practical problem for the blogspam plugin because the URL it requests is under the control of the wiki administrator, but the openid plugin can request URLs controlled by unauthenticated remote users, and the pinger plugin can request URLs controlled by authorized wiki editors. This is addressed in ikiwiki 3.20190228 as follows, with the same fixes backported to Debian 9 in version 3.20170111.1: * URI schemes other than http: and https: are not accepted, preventing access to file:, gopher:, etc. * If a proxy is configured in the ikiwiki setup file, it is used for all outgoing http: and https: requests. In this case the proxy is responsible for blocking any requests that are undesired, includingloopback or RFC 1918 addresses. * If a proxy is not configured, and liblwpx-paranoidagent-perl is installed, it will be used. This prevents loopback and RFC 1918 IP addresses, and sets a timeout to avoid denial of service via "tarpit" URIs. * Otherwise, the ordinary LWP user-agent will be used. This allows requests to loopback and RFC 1918 IP addresses, and has less robust timeout behaviour. We are not treating this as a vulnerability: if this behaviour is not acceptable for your site, please make sure to install LWPx::ParanoidAgent or disable the affected plugins. For Debian 8 "Jessie", this problem has been fixed in version 3.20141016.4+deb8u1. We recommend that you upgrade your ikiwiki packages. In addition it is also recommended that you have liblwpx-paranoidagent-perl installed, which listed in the recommends field of ikiwiki. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The ikiwiki software includes a vital security update for the aggregate extension to block unauthorized access to URIs.. ikiwiki, Debian LTS, security update, aggregate plugin, LWPx::ParanoidAgent. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 18, 2019 Critical Debian LTS
203

Mageia: 2019-0113 Moderate: Ikiwiki Security Issues Resolved

Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: - https://bugs.mageia.org/show_bug.cgi?id=24453 . MGASA-2019-0113 - Updated ikiwiki packages fix security vulnerability Publication date: 15 Mar 2019 URL: https://advisories.mageia.org/MGASA-2019-0113.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-9187, CVE-2017-0356, CVE-2016-10026, CVE-2016-9645, CVE-2016-9646, CVE-2016-4561 Several security issues identified in ikiwiki fixed by updating to version 3.20190228. See references for details References: - https://bugs.mageia.org/show_bug.cgi?id=24453 - https://www.openwall.com/lists/oss-security/2019/02/28/1 - https://www.openwall.com/lists/oss-security/2017/01/12/2 - https://www.openwall.com/lists/oss-security/2016/05/06/8 - https://www.openwall.com/lists/oss-security/2016/05/06/9 - https://lists.debian.org/debian-security-announce/2019/msg00042.html - https://www.cve.org/CVERecord?id=CVE-2019-9187 - https://www.cve.org/CVERecord?id=CVE-2017-0356 - https://www.cve.org/CVERecord?id=CVE-2016-10026 - https://www.cve.org/CVERecord?id=CVE-2016-9645 - https://www.cve.org/CVERecord?id=CVE-2016-9646 - https://www.cve.org/CVERecord?id=CVE-2016-4561 SRPMS: - 6/core/ikiwiki-3.20190228-1.1.mga6 . MGASA-2019-0113 - Updated ikiwiki packages fix security vulnerability Publication date: 15 Mar 2019 . security, identified, ikiwiki, updating, version, reference. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2019 Mageia
87

Debian: DSA-4399-1 Critical: Ikiwiki Server-Side Request Forgery

Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4399-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 28, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ikiwiki CVE ID : CVE-2019-9187 Joey Hess discovered that the aggregate plugin of the Ikiwiki wiki compiler was susceptible to server-side request forgery, resulting in information disclosure or denial of service. For the stable distribution (stretch), this problem has been fixed in version 3.20170111.1. We recommend that you upgrade your ikiwiki packages. For the detailed security status of ikiwiki please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ikiwiki Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - --------------------------------------------------. aggregate, plugin, ikiwiki, compiler, susceptible, serve. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2019 Critical Debian
89

Fedora 25 ikiwiki Security Update: Critical Threat Resolved

Update to the latest stable version. See https://ikiwiki.info/news/ for the list of changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-c756d37779 2017-01-27 18:29:55.798167 -------------------------------------------------------------------------------- Name : ikiwiki Product : Fedora 25 Version : 3.20170111 Release : 1.fc25 URL : http://ikiwiki.info/ Summary : A wiki compiler Description : Ikiwiki is a wiki compiler. It converts wiki pages into HTML pages suitable for publishing on a website. Ikiwiki stores pages and history in a revision control system such as Subversion or Git. There are many other features, including support for blogging, as well as a large array of plugins. -------------------------------------------------------------------------------- Update Information: Update to the latest stable version. See https://ikiwiki.info/news/ for the list of changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1409556 - CVE-2016-9646 ikiwiki: Commit metadata forgery https://bugzilla.redhat.com/show_bug.cgi?id=1409556 [ 2 ] Bug #1406693 - CVE-2016-10026 ikiwiki: Authorization bypass when reverting changes https://bugzilla.redhat.com/show_bug.cgi?id=1406693 [ 3 ] Bug #1412698 - CVE-2017-0356 ikiwiki: Authentication bypass via repeated parameters https://bugzilla.redhat.com/show_bug.cgi?id=1412698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ikiwiki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep up to date with the ikiwiki security patch for Fedora 25, tackling urgent vulnerabilities with effective solutions.. ikiwiki Update, Fedora Security, Patch Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2017 Critical Fedora
89

Fedora: ikiwiki Update Notification FEDORA-2017-8873ebdb43 Critical Fix

Update to the latest stable version. See https://ikiwiki.info/news/ for the list of changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-8873ebdb43 2017-01-27 18:29:56.052246 -------------------------------------------------------------------------------- Name : ikiwiki Product : Fedora 24 Version : 3.20170111 Release : 1.fc24 URL : http://ikiwiki.info/ Summary : A wiki compiler Description : Ikiwiki is a wiki compiler. It converts wiki pages into HTML pages suitable for publishing on a website. Ikiwiki stores pages and history in a revision control system such as Subversion or Git. There are many other features, including support for blogging, as well as a large array of plugins. -------------------------------------------------------------------------------- Update Information: Update to the latest stable version. See https://ikiwiki.info/news/ for the list of changes. Security fix for CVE-2016-10026, CVE-2016-9646, CVE-2017-0356. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1409556 - CVE-2016-9646 ikiwiki: Commit metadata forgery https://bugzilla.redhat.com/show_bug.cgi?id=1409556 [ 2 ] Bug #1406693 - CVE-2016-10026 ikiwiki: Authorization bypass when reverting changes https://bugzilla.redhat.com/show_bug.cgi?id=1406693 [ 3 ] Bug #1412698 - CVE-2017-0356 ikiwiki: Authentication bypass via repeated parameters https://bugzilla.redhat.com/show_bug.cgi?id=1412698 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ikiwiki' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPGkeys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 24 has released an update for ikiwiki that tackles security vulnerabilities and introduces improved functionality. Users are encouraged to upgrade.. ikiwiki security update, Fedora 24 update, authentication bypass fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 27, 2017 Critical Fedora
87

Debian: DSA-3760-1 Critical: Ikiwiki Multiple Security Flaws

Multiple vulnerabilities have been found in the Ikiwiki wiki compiler: CVE-2016-9646 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3760-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 12, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ikiwiki CVE ID : CVE-2016-9646 CVE-2016-10026 CVE-2017-0356 Multiple vulnerabilities have been found in the Ikiwiki wiki compiler: CVE-2016-9646 Commit metadata forgery via CGI::FormBuilder context-dependent APIs CVE-2016-10026 Editing restriction bypass for git revert CVE-2017-0356 Authentication bypass via repeated parameters Additional details on these vulnerabilities can be found at https://ikiwiki.info/security/ For the stable distribution (jessie), these problems have been fixed in version 3.20141016.4. For the unstable distribution (sid), these problems have been fixed in version 3.20170111. We recommend that you upgrade your ikiwiki packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several vulnerabilities identified in Ikiwiki wiki generator; users on Debian are advised to update.. ikiwiki Security Update, Debian Security Advisory, Editing Restrictions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 12, 2017 Critical Debian
87

Debian: DSA-3571-1 Important: Ikiwiki XSS Vulnerability Resolution

Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki's use of imagemagick in the img plugin. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3571-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 08, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ikiwiki CVE ID : CVE-2016-4561 Simon McVittie discovered a cross-site scripting vulnerability in the error reporting of Ikiwiki, a wiki compiler. This update also hardens ikiwiki's use of imagemagick in the img plugin. For the stable distribution (jessie), this problem has been fixed in version 3.20141016.3. For the unstable distribution (sid), this problem has been fixed in version 3.20160506. We recommend that you upgrade your ikiwiki packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Important Debian security notice DSA-3572-1 pertains to a CSRF flaw in the Drush utility. Immediate update advised.. Ikiwiki Security, Debian Advisory, Cross-Site Scripting. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 08, 2016 Important Debian
89

Fedora 20: 2015-6815 Cross-Site Scripting Fix for ikiwiki Moderate

Update to the latest stable release of ikiwiki. See for the list of changes.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6815 2015-04-24 17:59:28 -------------------------------------------------------------------------------- Name : ikiwiki Product : Fedora 20 Version : 3.20150329 Release : 1.fc20 URL : http://ikiwiki.info/ Summary : A wiki compiler Description : Ikiwiki is a wiki compiler. It converts wiki pages into HTML pages suitable for publishing on a website. Ikiwiki stores pages and history in a revision control system such as Subversion or Git. There are many other features, including support for blogging, as well as a large array of plugins. -------------------------------------------------------------------------------- Update Information: Update to the latest stable release of ikiwiki. See for the list of changes. -------------------------------------------------------------------------------- ChangeLog: * Mon Apr 20 2015 Thomas Moschny - 3.20150329-1 - Update to 3.20150329. - Minor packaging changes regarding the Python plugin. * Sun Feb 22 2015 Thomas Moschny - 3.20150107-1 - Update to 3.20150107. * Thu Dec 18 2014 Thomas Moschny - 3.20141016-1 - Update to 3.20141016. * Thu Sep 25 2014 Thomas Moschny - 3.20140916-1 - Update to 3.20140916. - Exclude the S3 plugin on on RHEL instead of renaming it. * Tue Sep 9 2014 Jitka Plesnikova - 3.20140831-2 - Perl 5.20 mass * Fri Sep 5 2014 Thomas Moschny - 3.20140831-1 - Update to 3.20140831. * Fri Aug 29 2014 Jitka Plesnikova - 3.20140815-2 - Perl 5.20 rebuild * Fri Aug 22 2014 Thomas Moschny - 3.20140815-1 - Update to 3.20140815. * Fri Aug 1 2014 Thomas Moschny - 3.20140613-2 - Disable the S3 plugin (rhbz#1125850). * Fri Jun 27 2014 Thomas Moschny - 3.20140613-1 - Update to 3.20140613-1. * Sat Jun 7 2014 Fedora Release Engineering - 3.20140227-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild *Sat Mar 8 2014 Thomas Moschny - 3.20140227-1 - Update to 3.20140227. * Sat Jan 25 2014 Thomas Moschny - 3.20140125-1 - Update to 3.20140125. * Sat Jan 25 2014 Thomas Moschny - 3.20140102-1 - Update to 3.20140102. - Modernize spec file. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1207210 - CVE-2015-2793 ikiwiki: cross-site scripting via openid_identifier https://bugzilla.redhat.com/show_bug.cgi?id=1207210 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update ikiwiki' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Critical ikiwiki security patch released for Fedora 20, featuring recent modifications and resolutions for cross-site scripting vulnerabilities. Enhanced safety protocols implemented.. ikiwiki Security Update,Fedora 20 Advisory,cross-site scripting fix,stable ikiwiki release. . LinuxSecurity.com Team

Calendar%202 May 03, 2015 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200