Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 42: Moderate Permissions and Input Sanitization Flaws in Xen

Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-ec271ef07b 2025-11-09 03:17:35.195054+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 42 Version : 4.19.3 Release : 8.fc42 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Michael Young - 4.19.3-8 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.19.3-6 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-ec271ef07b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Identify permissions issues and input sanitisation vulnerabilities in Fedora 42's Xen package with this advisory.. Fedora 42, Xen, PCI device, hypervisor, input sanitisation. . LinuxSecurity.com Team

Calendar%202 Nov 09, 2025 Fedora
89

Fedora 41: xen Critical XSA-476, XSA-475 Input Sanitisation Risks

Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-48dc1c8c79 2025-11-07 02:35:35.301730+00:00 -------------------------------------------------------------------------------- Name : xen Product : Fedora 41 Version : 4.19.3 Release : 7.fc41 URL : https://xenproject.org/ Summary : Xen is a virtual machine monitor Description : This package contains the XenD daemon and xm command line tools, needed to manage virtual machines running under the Xen hypervisor -------------------------------------------------------------------------------- Update Information: Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 24 2025 Michael Young - 4.19.3-7 - Incorrect removal of permissions on PCI device unplug [XSA-476, CVE-2025-58149] * Tue Oct 21 2025 Michael Young - 4.19.3-5 - x86: Incorrect input sanitisation in Viridian hypercalls [XSA-475, CVE-2025-58147, CVE-2025-58148] -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-48dc1c8c79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41's critical xen advisory details input sanitisation issues and permission failures on devices. Immediate actions advised.. Fedora 41,xen,input sanitisation,security advisory,critical issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 07, 2025 Critical Fedora
202

openSUSE: Xen Important Input Sanitisation Issues Advisory 2025:3843-1

An update that solves five vulnerabilities can now be installed.. # Security update for xen Announcement ID: SUSE-SU-2025:3843-1 Release Date: 2025-10-28T16:40:50Z Rating: important References: * bsc#1248807 * bsc#1251271 Cross-References: * CVE-2025-27466 * CVE-2025-58142 * CVE-2025-58143 * CVE-2025-58147 * CVE-2025-58148 CVSS scores: * CVE-2025-27466 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-27466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58142 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-58142 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-58147 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2025-58148 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Proxy 4.3 LTS * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Retail Branch Server 4.3 LTS * SUSE Manager Server 4.3 * SUSE Manager Server 4.3 LTS An update that solves five vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2025-58147, CVE-2025-58148: Fixed incorrect input sanitisation in Viridian hypercalls (bsc#1251271, XSA-475) * CVE-2025-27466,CVE-2025-58142, CVE-2025-58143: Fixed mutiple vulnerabilities in the Viridian interface (bsc#1248807, XSA-472) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3843=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3843=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3843=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3843=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3843=1 * SUSE Manager Proxy 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-LTS-2025-3843=1 * SUSE Manager Retail Branch Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch- Server-4.3-LTS-2025-3843=1 * SUSE Manager Server 4.3 LTS zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-LTS-2025-3843=1 ## Package List: * openSUSE Leap 15.4 (aarch64 x86_64 i586) * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4(x86_64) * xen-libs-32bit-4.16.7_04-150400.4.75.1 * xen-libs-32bit-debuginfo-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64 x86_64) * xen-doc-html-4.16.7_04-150400.4.75.1 * xen-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * openSUSE Leap 15.4 (aarch64_ilp32) * xen-libs-64bit-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-64bit-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 *xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Proxy 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Retail Branch Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (x86_64) * xen-4.16.7_04-150400.4.75.1 * xen-libs-4.16.7_04-150400.4.75.1 * xen-devel-4.16.7_04-150400.4.75.1 * xen-tools-domU-4.16.7_04-150400.4.75.1 * xen-tools-domU-debuginfo-4.16.7_04-150400.4.75.1 * xen-libs-debuginfo-4.16.7_04-150400.4.75.1 * xen-tools-debuginfo-4.16.7_04-150400.4.75.1 * xen-debugsource-4.16.7_04-150400.4.75.1 * xen-tools-4.16.7_04-150400.4.75.1 * SUSE Manager Server 4.3 LTS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_04-150400.4.75.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27466.html * https://www.suse.com/security/cve/CVE-2025-58142.html * https://www.suse.com/security/cve/CVE-2025-58143.html * https://www.suse.com/security/cve/CVE-2025-58147.html * https://www.suse.com/security/cve/CVE-2025-58148.html * https://bugzilla.suse.com/show_bug.cgi?id=1248807 * https://bugzilla.suse.com/show_bug.cgi?id=1251271 . Update for openSUSE addresses five important issues in Xen with significant impact on security features.. openSUSE,Linux vulnerabilities,xen,security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 28, 2025 Important OpenSUSE
87

Debian: DSA-5233-1 e17 Security Update Critical: Local Elevation Risk

Maher Azzouzi discovered that missing input sanitising in the Enlightenment window manager may result in local privilege escalation to root. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5233-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 21, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : e17 CVE ID : CVE-2022-37706 Maher Azzouzi discovered that missing input sanitising in the Enlightenment window manager may result in local privilege escalation to root. For the stable distribution (bullseye), this problem has been fixed in version 0.24.2-8+deb11u1. We recommend that you upgrade your e17 packages. For the detailed security status of e17 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/e17 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest security notice from Debian addresses potential input flaws within the e17 graphical interface, which could lead to unauthorized privilege increases locally.. Debian Security Advisory,e17 Security Update,Input Sanitisation,Local Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2022 Critical Debian
87

Debian DSA-4893-1: Moderate Xorg-Server Privilege Escalation Advisory

Jan-Niklas Sohn discovered that missing input sanitising in the XInput extension of the X.org X server may result in privilege escalation if the X server is running privileged. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4893-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 19, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : xorg-server CVE ID : CVE-2021-3472 Jan-Niklas Sohn discovered that missing input sanitising in the XInput extension of the X.org X server may result in privilege escalation if the X server is running privileged. For the stable distribution (buster), this problem has been fixed in version 2:1.20.4-1+deb10u3. We recommend that you upgrade your xorg-server packages. For the detailed security status of xorg-server please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/xorg-server Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian security patch DSA-4893-1 resolves an elevation of privilege issue in xorg-server caused by inadequate input validation.. Debian Security Update,xorg-server,Privilege Escalation,Input Sanitisation. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 19, 2021 Important Debian
87

Ubuntu: USN-4270-1 Medium: Libjpg Denial Of Service Vulnerability

It was discovered that insufficient input sanitising in libevt, a library to access the Windows Event Log (EVT) format, could result in denial of service or the execution of arbitrary code if a malformed EVT file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4160-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 01, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libevt CVE ID : CVE-2018-8754 It was discovered that insufficient input sanitising in libevt, a library to access the Windows Event Log (EVT) format, could result in denial of service or the execution of arbitrary code if a malformed EVT file is processed. For the stable distribution (stretch), this problem has been fixed in version 20170120-1+deb9u1. We recommend that you upgrade your libevt packages. For the detailed security status of libevt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libevt Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Inadequate input validation in libevt poses risks of potential remote code execution or service interruption. Immediate update advised.. libevt Security Update, Debian Advisory, Denial Of Service Threat. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Apr 01, 2018 Medium Debian
87

Debian: DSA-4040-1 Moderate: Imagemagick Denial Of Service Risk

This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4040-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff November 17, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : imagemagick CVE ID : CVE-2017-11352 CVE-2017-11640 CVE-2017-12431 CVE-2017-12640 CVE-2017-12877 CVE-2017-12983 CVE-2017-13134 CVE-2017-13139 CVE-2017-13144 CVE-2017-13758 CVE-2017-13769 CVE-2017-14224 CVE-2017-14607 CVE-2017-14682 CVE-2017-14989 CVE-2017-15277 CVE-2017-16546 This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed. For the oldstable distribution (jessie), these problems have been fixed in version 8:6.8.9.9-5+deb8u11. We recommend that you upgrade your imagemagick packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . This patch addresses multiple performance concerns and vulnerabilities within imagemagick, significantly improving the security posture of the system.. Imagemagick Update, Debian Security, Denial of Service Fix. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2017 Debian
87

Debian: DSA-3546-1 Critical: Optipng Denial Of Service Risk

Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3546-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 07, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : optipng CVE ID : CVE-2016-2191 Hans Jerry Illikainen discovered that missing input sanitising in the BMP processing code of the optipng PNG optimiser may result in denial of service or the execution of arbitrary code if a malformed file is processed. For the oldstable distribution (wheezy), this problem has been fixed in version 0.6.4-1+deb7u2. This update also fixes CVE-2015-7801, which was originally targeted for a wheezy point update. For the stable distribution (jessie), this problem has been fixed in version 0.7.5-1+deb8u1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your optipng packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch for optipng resolves input validation vulnerabilities posing potential execution threats. Immediate update advised.. Optipng Security Update, Debian DSA-3546, Denial Of Service Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 07, 2016 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200