Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
91

Gentoo 200801-03 Advisory: Claws Mail Vulnerability in Symlink Attack

Claws Mail uses temporary files in an insecure manner, allowing for a symlink attack.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200801-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Claws Mail: Insecure temporary file creation Date: January 09, 2008 Bugs: #201244 ID: 200801-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Claws Mail uses temporary files in an insecure manner, allowing for a symlink attack. Background ========= Claws Mail is a GTK based e-mail client. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-client/claws-mail < 3.0.2-r1 > = 3.0.2-r1 Description ========== Nico Golde from Debian reported that the sylprint.pl script that is part of the Claws Mail tools creates temporary files in an insecure manner. Impact ===== A local attacker could exploit this vulnerability to conduct symlink attacks to overwrite files with the privileges of the user running Claws Mail. Workaround ========= There is no known workaround at this time. Resolution ========= All Claws Mail users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-client/claws-mail-3.0.2-r1" References ========= [ 1 ] CVE-2007-6208 https://www.cve.org/CVERecord?id=CVE-2007-6208 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200801-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFHhUESuhJ+ozIKI5gRAkiaAJsFprbZ/y+eIaDIzjNcbfkTb7AWiwCgoKd3 kpuxtp+N0a8cOR18w92erRk=OSCT -----END PGP SIGNATURE----- . Claws Mail for Gentoo Linux is vulnerable to a symlink attack stemming from improper handling of temporary files. It is advised to apply the latest updates.. Claws Mail Symlink Attack,Gentoo Security Advisory,Insecure Temporary Files. . LinuxSecurity.com Team

Calendar%202 Jan 09, 2008 Gentoo
91

Gentoo: GLSA-200709-04 Normal: po4a Insecure File Creation Risk

A vulnerability has been discovered in po4a, allowing for a symlink attack.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200709-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: po4a: Insecure temporary file creation Date: September 13, 2007 Bugs: #189440 ID: 200709-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in po4a, allowing for a symlink attack. Background ========= po4a is a set of tools for helping with the translation of documentation. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/po4a < 0.32-r1 > = 0.32-r1 Description ========== The po4a development team reported a race condition in the gettextize() function when creating the file "/tmp/gettextization.failed.po". Impact ===== A local attacker could perform a symlink attack, possibly overwriting files with the permissions of the user running po4a. Workaround ========= There is no known workaround at this time. Resolution ========= All po4a users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/po4a-0.32-r1" References ========= [ 1 ] CVE-2007-4462 https://www.cve.org/CVERecord?id=CVE-2007-4462 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200709-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux GLSA 202210-15 alerts about a medium severity vulnerability in libXYZ, enabling potential symlink exploitation necessitating a software patch.. gentoo linux, po4a, symlink attack, software update. . LinuxSecurity.com Team

Calendar%202 Sep 13, 2007 Gentoo
91

Gentoo: GLSA-200703-20 Low-Level Risk from LSAT Symlink Attack

LSAT insecurely creates temporary files which can lead to symlink attacks allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200703-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: LSAT: Insecure temporary file creation Date: March 18, 2007 Bugs: #159542 ID: 200703-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= LSAT insecurely creates temporary files which can lead to symlink attacks allowing a local user to overwrite arbitrary files. Background ========= The Linux Security Auditing Tool (LSAT) is a post install security auditor which checks many system configurations and local network settings on the system for common security or configuration errors and for packages that are not needed. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/lsat

Calendar%202 Mar 18, 2007 Low Gentoo
91

Gentoo: GLSA-202304-07 Normal: Noweb Vulnerable File Handling Exposure

noweb is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200602-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: noweb: Insecure temporary file creation Date: February 26, 2006 Bugs: #122705 ID: 200602-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= noweb is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= noweb is a simple, extensible, and language independent literate programming tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/noweb < 2.9-r5 > = 2.9-r5 Description ========== Javier Fernandez-Sanguino has discovered that the lib/toascii.nw and shell/roff.mm scripts insecurely create temporary files with predictable filenames. Impact ===== A local attacker could create symbolic links in the temporary file directory, pointing to a valid file somewhere on the filesystem. When an affected script is called, this would result in the file being overwritten with the rights of the user running the script. Workaround ========= There is no known workaround at this time. Resolution ========= All noweb users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/noweb-2.9-r5" References ========= [ 1 ] CVE-2005-3342 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200602-14 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Debian alert highlights security concern regarding crontab's improper input validation, leading to privilege escalation vulnerabilities.. noweb symlink attack,Gentoo advisory,file overwrite risk. . LinuxSecurity.com Team

Calendar%202 Feb 26, 2006 Gentoo
91

Gentoo: GLSA 202310-01 Critical: GnuPG Vulnerability Exploit Risk

Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Texinfo: Insecure temporary file creation Date: October 05, 2005 Bugs: #106105 ID: 200510-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Texinfo is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= Texinfo is the official documentation system created by the GNU project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/texinfo < 4.8-r1 > = 4.8-r1 Description ========== Frank Lichtenheld has discovered that the "sort_offline()" function in texindex insecurely creates temporary files with predictable filenames. Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When texindex is executed, this would result in the file being overwritten with the rights of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Texinfo users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/texinfo-4.8-r1" References ========= [ 1 ] CAN-2005-3011 https://www.cve.org/CVERecord?id=CVE-CAN-2005-3011 Availability =========== This GLSA andany updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Gentoo GLSA 200610-05 tackles the vulnerabilities found in LibXML2 that allow remote attackers to execute arbitrary code through crafted XML files.. Texinfo Advisory, Gentoo Security Notice, Symlink Risk, Linux Exploit. . LinuxSecurity.com Team

Calendar%202 Oct 05, 2005 Gentoo
91

Ubuntu USN-2023-4265-1: Critical libcurl Vulnerability in Config Management

gtkdiskfree is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: gtkdiskfree: Insecure temporary file creation Date: October 03, 2005 Bugs: #104565 ID: 200510-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= gtkdiskfree is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= gtkdiskfree is a GTK-based GUI to show free disk space. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/gtkdiskfree < 1.9.3-r1 > = 1.9.3-r1 Description ========== Eric Romang discovered that gtkdiskfree insecurely creates a predictable temporary file to handle command output. Impact ===== A local attacker could create a symbolic link in the temporary files directory, pointing to a valid file somewhere on the filesystem. When gtkdiskfree is executed, this would result in the file being overwritten with the rights of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All gtkdiskfree users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/gtkdiskfree-1.9.3-r1" References ========= [ 1 ] CAN-2005-2918 https://www.cve.org/CVERecord?id=CVE-CAN-2005-2918 [ 2 ] Original Advisory Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The Gentoo Linux Security Advisory GLSA 200510-01 discusses a vulnerability in gtkdiskfree regarding its handling of temporary files, leading to potential filesystem access. gtkdiskfree, file risk, local exploit, gentoo advisory. . LinuxSecurity.com Team

Calendar%202 Oct 03, 2005 Gentoo
91

Gentoo: GLSA-200506-11 High: WebApp Secure Failures in Configuration

LutelWall is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LutelWall: Insecure temporary file creation Date: June 11, 2005 Bugs: #95378 ID: 200506-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= LutelWall is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= LutelWall is a high-level Linux firewall configuration tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-firewall/lutelwall < 0.98 > = 0.98 Description ========== Eric Romang has discovered that the new_version_check() function in LutelWall insecurely creates a temporary file when updating to a new version. Impact ===== A local attacker could create symbolic links in the temporary file directory, pointing to a valid file somewhere on the filesystem. When the update script is executed (usually by the root user), this would result in the file being overwritten with the rights of this user. Workaround ========= There is no known workaround at this time. Resolution ========= All LutelWall users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-firewall/lutelwall-0.98" References ========= [ 1 ] CAN-2005-1879 https://www.cve.org/CVERecord?id=CVE-CAN-2005-1879 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200506-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . FileProtect has a weakness concerning symbolic link vulnerabilities, permitting local users to overwrite files. It is advisable to update. Risk Level: Moderate.. LutelWall, Symlink Attack, File Overwrite, Gentoo Security, Firewall Software. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2005 Gentoo
91

Debian: 202209-23 Warning: Libtool, Python-sql Symlink Vulnerability

GNU shtool and ocaml-mysql are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNU shtool, ocaml-mysql: Insecure temporary file creation Date: June 11, 2005 Bugs: #93782, #93784 ID: 200506-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= GNU shtool and ocaml-mysql are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= GNU shtool is a compilation of small shell scripts into a single shell tool. The ocaml-mysql package includes the GNU shtool code. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/shtool < 2.0.1-r2 > = 2.0.1-r2 2 dev-ml/ocaml-mysql < 1.0.3-r1 > = 1.0.3-r1 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Eric Romang has discovered that GNU shtool insecurely creates temporary files with predictable filenames (CAN-2005-1751). On closer inspection, Gentoo Security discovered that the shtool temporary file, once created, was being reused insecurely (CAN-2005-1759). Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere onthe filesystem. When a GNU shtool script is executed, this would result in the file being overwritten with the rights of the user running the script, which could be the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All GNU shtool users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/shtool-2.0.1-r2" All ocaml-mysql users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-ml/ocaml-mysql-1.0.3-r1" References ========= [ 1 ] CAN-2005-1751 [ 2 ] CAN-2005-1759 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200506-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The GNU shtool and ocaml-mysql packages in Gentoo Linux are susceptible to symlink vulnerabilities, which could lead to potential arbitrary file overwrites.. GNU Shtool,shtool security,ocaml-mysql security. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200