Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
100

SUSE Linux Micro 6.1: SUSE-SU-2025:20452-1 moderate fix for open-vm-tools

* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: . # Security update for open-vm-tools Announcement ID: SUSE-SU-2025:20452-1 Release Date: 2025-06-25T08:23:04Z Rating: moderate References: * bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: * CVE-2025-22247 CVSS scores: * CVE-2025-22247 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22247 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2025-22247 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for open-vm-tools fixes the following issues: * Updated to 12.5.2: * CVE-2025-22247: Fixed Insecure file handling (bsc#1243106) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-159=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * open-vm-tools-debugsource-12.5.2-slfo.1.1_1.1 * libvmtools0-debuginfo-12.5.2-slfo.1.1_1.1 * libvmtools0-12.5.2-slfo.1.1_1.1 * open-vm-tools-debuginfo-12.5.2-slfo.1.1_1.1 * open-vm-tools-12.5.2-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22247.html * https://bugzilla.suse.com/show_bug.cgi?id=1237147 * https://bugzilla.suse.com/show_bug.cgi?id=1241938 * https://bugzilla.suse.com/show_bug.cgi?id=1243106 . A significant recommendation for SUSE Linux Micro 6.1 pertains to the rectification of vulnerable file management through an open-vm-tools upgrade.. SUSE Linux Micro, open-vm-tools, security patch. . LinuxSecurity.com Team

Calendar%202 Jun 30, 2025 SuSE
100

SUSE Linux Micro 6.0: 2025:20379-1 moderate risk: open-vm-tools file issues

* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: . # Security update for open-vm-tools Announcement ID: SUSE-SU-2025:20379-1 Release Date: 2025-06-08T13:23:03Z Rating: moderate References: * bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: * CVE-2025-22247 CVSS scores: * CVE-2025-22247 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22247 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2025-22247 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for open-vm-tools fixes the following issues: * Updated to 12.5.2: * CVE-2025-22247: Fixed insecure file handling (bsc#1243106) * Fixed gcc15 compile time error (bsc#1241938) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-345=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * libvmtools0-debuginfo-12.5.2-1.1 * open-vm-tools-debuginfo-12.5.2-1.1 * open-vm-tools-12.5.2-1.1 * libvmtools0-12.5.2-1.1 * open-vm-tools-debugsource-12.5.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22247.html * https://bugzilla.suse.com/show_bug.cgi?id=1237147 * https://bugzilla.suse.com/show_bug.cgi?id=1241938 * https://bugzilla.suse.com/show_bug.cgi?id=1243106 . Essential patches for open-vm-tools in SUSE rectify vulnerabilities and resolve build issues to enhance system efficiency.. open-vm-tools security, SUSE updates, application security, Linux patching, moderate severity issues. . LinuxSecurity.com Team

Calendar%202 Jun 12, 2025 SuSE
100

UBUNTU: 2025:02942-2 high: packagekit security enhancement

* bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: . # Security update for open-vm-tools Announcement ID: SUSE-SU-2025:01778-1 Release Date: 2025-05-30T13:05:19Z Rating: moderate References: * bsc#1237147 * bsc#1241938 * bsc#1243106 Cross-References: * CVE-2025-22247 CVSS scores: * CVE-2025-22247 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22247 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2025-22247 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for open-vm-tools fixes the following issues: Update to 12.5.2: Security fixes: * CVE-2025-22247: Fixed Insecure file handling (bsc#1243106) Other fixes: * Fixed GCC 15 compile time error (bsc#1241938) * Fixed building with containerd 1.7.25+ (bsc#1237147) Full changelog: https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/ReleaseNotes.md https://github.com/vmware/open-vm-tools/blob/stable-12.5.2/open-vm-tools/ChangeLog ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1778=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * open-vm-tools-sdmp-12.5.2-4.83.1 * open-vm-tools-debugsource-12.5.2-4.83.1 * libvmtools0-debuginfo-12.5.2-4.83.1 * open-vm-tools-desktop-debuginfo-12.5.2-4.83.1 *open-vm-tools-salt-minion-12.5.2-4.83.1 * open-vm-tools-desktop-12.5.2-4.83.1 * open-vm-tools-debuginfo-12.5.2-4.83.1 * open-vm-tools-sdmp-debuginfo-12.5.2-4.83.1 * libvmtools0-12.5.2-4.83.1 * open-vm-tools-12.5.2-4.83.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22247.html * https://bugzilla.suse.com/show_bug.cgi?id=1237147 * https://bugzilla.suse.com/show_bug.cgi?id=1241938 * https://bugzilla.suse.com/show_bug.cgi?id=1243106 . This notification outlines the security enhancement for open-vm-tools on SUSE, tackling a vulnerability related to improper file management.. open-vm-tools update, SUSE security patch, linux advisory, open-vm-tools fix. . LinuxSecurity.com Team

Calendar%202 May 30, 2025 SuSE
87

Debian 4.0 etch DSA-1643-1 Critical: Feta Insecure File Handling

Dmitry E. Oboukhov discovered that the "to-upgrade" plugin of Feta, a simpler interface to APT, dpkg, and other Debian package tools creates temporary files insecurely, which may lead to local denial of service through symlink attacks. . - ------------------------------------------------------------------------Debian Security Advisory DSA-1643-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff October 05, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : feta Vulnerability : insecure temp file handling Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-4440 Debian Bug : 496397 Dmitry E. Oboukhov discovered that the "to-upgrade" plugin of Feta, a simpler interface to APT, dpkg, and other Debian package tools creates temporary files insecurely, which may lead to local denial of service through symlink attacks. For the stable distribution (etch), this problem has been fixed in version 1.4.15+etch1. For the unstable distribution (sid), this problem has been fixed in version 1.4.16+nmu1. We recommend that you upgrade your feta package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 545 87c8cdfc722b149eefc2c4cc1e05c868 Size/MD5 checksum: 5213427b5bc566e7f42a5b79dd8ef67013b8d Architecture independent packages: Size/MD5 checksum: 47708 8133fddc8dc30973c5fcb3368292b1fb These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-1643-2 resolves a security issue in feta related to improper management of temporary files that could lead to a denial of service.. Debian Security, Denial of Service, Package Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 05, 2008 Critical Debian
91

Gentoo: GLSA-202303-05 Normal: Mitigation for R Directory Traversal Issue

R is vulnerable to symlink attacks due to an insecure usage of temporary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: R: Insecure temporary file creation Date: September 22, 2008 Bugs: #235822 ID: 200809-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= R is vulnerable to symlink attacks due to an insecure usage of temporary files. Background ========= R is a GPL licensed implementation of S, a language and environment for statistical computing and graphics. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/R < 2.7.1 > = 2.7.1 Description ========== Dmitry E. Oboukhov reported that the "javareconf" script uses temporary files in an insecure manner. Impact ===== A local attacker could exploit this vulnerability to overwrite arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All R users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/R-2.7.1" References ========= [ 1 ] CVE-2008-3931 https://www.cve.org/CVERecord?id=CVE-2008-3931 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200809-13 Concerns? ======== Security is a primary focus ofGentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202204-02 indicates Python's susceptibility to buffer overflow exploits via improper error handling. Immediate action advised.. Gentoo, R Language, Symlink Exploit, Security Advisory, Insecure Files. . LinuxSecurity.com Team

Calendar%202 Sep 22, 2008 Gentoo
98

Red Hat 3, 4, 5: RHSA-2008:0641-02 Critical: Acroread JavaScript Flaw

Updated acroread packages that fix various security issues are now available for Red Hat Enterprise Linux 3 Extras, 4 Extras, and 5 Supplementary. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: acroread security update Advisory ID: RHSA-2008:0641-02 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2008:0641.html Issue date: 2008-07-21 CVE Names: CVE-2008-0883 CVE-2008-2641 ==================================================================== 1. Summary: Updated acroread packages that fix various security issues are now available for Red Hat Enterprise Linux 3 Extras, 4 Extras, and 5 Supplementary. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 Extras - i386, x86_64 Red Hat Desktop version 3 Extras - i386, x86_64 Red Hat Enterprise Linux ES version 3 Extras - i386, x86_64 Red Hat Enterprise Linux WS version 3 Extras - i386, x86_64 Red Hat Enterprise Linux AS version 4 Extras - i386, x86_64 Red Hat Desktop version 4 Extras - i386, x86_64 Red Hat Enterprise Linux ES version 4 Extras - i386, x86_64 Red Hat Enterprise Linux WS version 4 Extras - i386, x86_64 RHEL Desktop Supplementary (v. 5 client) - i386, x86_64 RHEL Supplementary (v. 5 server) - i386, x86_64 3. Description: Adobe Acrobat Reader allows users to view and print documents in Portable Document Format (PDF). An input validation flaw was discovered in a JavaScript engine used by Acrobat Reader. A malicious PDF file could cause Acrobat Reader to crash or, potentially, execute arbitrary code as the user running Acrobat Reader. (CVE-2008-2641) An insecure temporary file usage issue was discovered in theAcrobat Reader "acroread" startup script. A local attacker could potentially overwrite arbitrary files that were writable by the user running Acrobat Reader, if the victim ran "acroread" with certain command line arguments. (CVE-2008-0883) All acroread users are advised to upgrade to these updated packages, that contain Acrobat Reader version 8.1.2 Security Update 1, and are not vulnerable to these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 436263 - CVE-2008-0883 acroread: insecure handling of temporary files 452632 - CVE-2008-2641 acroread: input validation issue in a JavaScript method 6. Package List: Red Hat Enterprise Linux AS version 3 Extras: i386: acroread-8.1.2.SU1-2.i386.rpm acroread-plugin-8.1.2.SU1-2.i386.rpm x86_64: acroread-8.1.2.SU1-2.i386.rpm Red Hat Desktop version 3 Extras: i386: acroread-8.1.2.SU1-2.i386.rpm acroread-plugin-8.1.2.SU1-2.i386.rpm x86_64: acroread-8.1.2.SU1-2.i386.rpm Red Hat Enterprise Linux ES version 3 Extras: i386: acroread-8.1.2.SU1-2.i386.rpm acroread-plugin-8.1.2.SU1-2.i386.rpm x86_64: acroread-8.1.2.SU1-2.i386.rpm Red Hat Enterprise Linux WS version 3 Extras: i386: acroread-8.1.2.SU1-2.i386.rpm acroread-plugin-8.1.2.SU1-2.i386.rpm x86_64: acroread-8.1.2.SU1-2.i386.rpm Red Hat Enterprise Linux AS version 4 Extras: i386: acroread-8.1.2.SU1-2.el4.i386.rpm acroread-plugin-8.1.2.SU1-2.el4.i386.rpm x86_64: acroread-8.1.2.SU1-2.el4.i386.rpm Red Hat Desktop version 4 Extras: i386: acroread-8.1.2.SU1-2.el4.i386.rpm acroread-plugin-8.1.2.SU1-2.el4.i386.rpm x86_64: acroread-8.1.2.SU1-2.el4.i386.rpm Red Hat Enterprise Linux ES version 4Extras: i386: acroread-8.1.2.SU1-2.el4.i386.rpm acroread-plugin-8.1.2.SU1-2.el4.i386.rpm x86_64: acroread-8.1.2.SU1-2.el4.i386.rpm Red Hat Enterprise Linux WS version 4 Extras: i386: acroread-8.1.2.SU1-2.el4.i386.rpm acroread-plugin-8.1.2.SU1-2.el4.i386.rpm x86_64: acroread-8.1.2.SU1-2.el4.i386.rpm RHEL Desktop Supplementary (v. 5 client): i386: acroread-8.1.2.SU1-2.el5.i386.rpm acroread-plugin-8.1.2.SU1-2.el5.i386.rpm x86_64: acroread-8.1.2.SU1-2.el5.i386.rpm acroread-plugin-8.1.2.SU1-2.el5.i386.rpm RHEL Supplementary (v. 5 server): i386: acroread-8.1.2.SU1-2.el5.i386.rpm acroread-plugin-8.1.2.SU1-2.el5.i386.rpm x86_64: acroread-8.1.2.SU1-2.el5.i386.rpm acroread-plugin-8.1.2.SU1-2.el5.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2008-0883 https://www.cve.org/CVERecord?id=CVE-2008-2641 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2008 Red Hat, Inc. . Important acroread patch for Red Hat resolves security vulnerabilities. Users running impacted editions are encouraged to upgrade.. Red Hat Security Advisory, Acroread Critical Update, Security Impact, Software Upgrade Guidance. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 21, 2008 Critical Red Hat
91

Gentoo: GLSA-202310-04 High Severity: VLC Player Buffer Overflow Issue

Audacity uses temporary files in an insecure manner, allowing for a symlink attack.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200803-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Audacity: Insecure temporary file creation Date: March 02, 2008 Bugs: #199751 ID: 200803-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Audacity uses temporary files in an insecure manner, allowing for a symlink attack. Background ========= Audacity is a free cross-platform audio editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/audacity < 1.3.4-r1 > = 1.3.4-r1 Description ========== Viktor Griph reported that the "AudacityApp::OnInit()" method in file src/AudacityApp.cpp does not handle temporary files properly. Impact ===== A local attacker could exploit this vulnerability to conduct symlink attacks to delete arbitrary files and directories with the privileges of the user running Audacity. Workaround ========= There is no known workaround at this time. Resolution ========= All Audacity users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/audacity-1.3.4-r1" References ========= [ 1 ] CVE-2007-6061 https://www.cve.org/CVERecord?id=CVE-2007-6061 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200803-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.7 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFHy0MZuhJ+ozIKI5gRAqIaAJ4/xcftU28JRF8y4M5j7GDfW3CsQgCfSEn7 TcXpjtDSEWTcIzwmG4rRZ3o=s495 -----END PGP SIGNATURE----- . Vulnerabilities in temporary file management within Audacity facilitate symlink exploitation; users should consider updating their software.. Audacity Security, Symlink Attack, Gentoo Linux Advisory. . LinuxSecurity.com Team

Calendar%202 Mar 03, 2008 Gentoo
91

Gentoo: GLSA 200504-06 Normal: Unshar Symlink Exploit Risk

The unshar utility is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200504-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: sharutils: Insecure temporary file creation Date: April 06, 2005 Bugs: #87939 ID: 200504-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The unshar utility is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files. Background ========= sharutils is a collection of tools to deal with shar archives. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/sharutils < 4.2.1-r11 > = 4.2.1-r11 Description ========== Joey Hess has discovered that the program unshar, which is a part of sharutils, creates temporary files in a world-writable directory with predictable names. Impact ===== A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When unshar is executed, this would result in the file being overwritten with the rights of the user running the utility, which could be the root user. Workaround ========= There is no known workaround at this time. Resolution ========= All sharutils users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/sharutils-4.2.1-r11" References ========= [ 1 ] Ubuntu Advisory Availability =========== ThisGLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200504-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The Gentoo Linux Security Advisory GLSA 200504-06 addresses serious vulnerabilities in the unshar utility's symlink handling, risking file overwriting and system integrity.. sharutils Risks, Gentoo Exploits, File Overwrite Security. . LinuxSecurity.com Team

Calendar%202 Apr 06, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200