Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
89

Fedora 34: 2021-069c0c3950 Critical Fix For x11vnc Permissions Issue

This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-069c0c3950 2021-03-19 19:51:22.363525 --------------------------------------------------------------------------------Name : x11vnc Product : Fedora 34 Version : 0.9.16 Release : 6.fc34 URL : https://github.com/LibVNC/x11vnc Summary : VNC server for the current X11 session Description : What WinVNC is to Windows x11vnc is to X Window System, i.e. a server which serves the current X Window System desktop via RFB (VNC) protocol to the user. Based on the ideas of x0rfbserver and on LibVNCServer it has evolved into a versatile and productive while still easy to use program. --------------------------------------------------------------------------------Update Information: This release fixes an insecure permissins of shared memory semgentes created by an x11vnc server. Previously the segments were readable and writable for any local user. Now they are accessible only to the user who executed the x11vnc server. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 1 2021 Petr Pisar - 0.9.16-6 - Fix CVE-2020-29074 (insecure permissions on a shared memory) (bug #1933603) --------------------------------------------------------------------------------References: [ 1 ] Bug #1933602 - CVE-2020-29074 x11vnc: insecure permissions on shm https://bugzilla.redhat.com/show_bug.cgi?id=1933602 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-069c0c3950' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important patch for Fedora 34 addressing unsafe memory handling in x11vnc. Confirm application safety immediately.. Fedora Update,x11vnc fix,insecure permissions,shared memory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 19, 2021 Critical Fedora
202

openSUSE: 2020:0803-1 Moderate: rubygem-bundler Insecure Permissions Threat

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for rubygem-bundler ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0803-1 Rating: moderate References: #1143436 Cross-References: CVE-2019-3881 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-bundler fixes the following issue: - CVE-2019-3881: Fixed insecure permissions on a directory in /tmp/ that allowed malicious code execution (bsc#1143436). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-803=1 Package List: - openSUSE Leap 15.1 (x86_64): ruby2.5-rubygem-bundler-1.16.1-lp151.3.3.1 ruby2.5-rubygem-bundler-doc-1.16.1-lp151.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-3881.html https://bugzilla.suse.com/1143436 -- . This patch addresses a significant vulnerability in rubygem-bundler for openSUSE, correcting improper permissions that could lead to unauthorized code execution.. openSUSE Security, rubygem-bundler Update, moderate Threat, Code Execution Risk. . LinuxSecurity.com Team

Calendar%202 Jun 13, 2020 OpenSUSE
100

SUSE: 2020:1582-1 Moderate: Rubygem-Bundler Insecure Permissions Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-bundler ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:1582-1 Rating: moderate References: #1143436 Cross-References: CVE-2019-3881 Affected Products: SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-bundler fixes the following issue: - CVE-2019-3881: Fixed insecure permissions on a directory in /tmp/ that allowed malicious code execution (bsc#1143436). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-1582=1 Package List: - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): ruby2.5-rubygem-bundler-1.16.1-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-3881.html https://bugzilla.suse.com/1143436 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Update: Security update for rubygem-bundler fixes insecure permissions issue with CVE-2019-3881.. SUSE Security Update,rubygem-bundler,insecure permissions,patch instructions. . LinuxSecurity.com Team

Calendar%202 Jun 09, 2020 SuSE
200

Scientific Linux SL6: CVE-2013-0254 Moderate: qt Insecure Permissions

Moderate: qt security update. Date: Thu, 21 Mar 2013 15:31:19 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: qt on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: qt security update Issue Date: 2013-03-21 CVE Numbers: CVE-2013-0254 -- It was discovered that the QSharedMemory class implementation of the Qt toolkit created shared memory segments with insecure permissions. A local attacker could use this flaw to read or alter the contents of a particular shared memory segment, possibly leading to their ability to obtain sensitive information or influence the behavior of a process that is using the shared memory segment. (CVE-2013-0254) All running applications linked against Qt libraries must be restarted for this update to take effect. -- SL6 x86_64 phonon-backend-gstreamer-4.6.2-26.el6_4.i686.rpm phonon-backend-gstreamer-4.6.2-26.el6_4.x86_64.rpm qt-4.6.2-26.el6_4.i686.rpm qt-4.6.2-26.el6_4.x86_64.rpm qt-debuginfo-4.6.2-26.el6_4.i686.rpm qt-debuginfo-4.6.2-26.el6_4.x86_64.rpm qt-mysql-4.6.2-26.el6_4.i686.rpm qt-mysql-4.6.2-26.el6_4.x86_64.rpm qt-odbc-4.6.2-26.el6_4.i686.rpm qt-odbc-4.6.2-26.el6_4.x86_64.rpm qt-postgresql-4.6.2-26.el6_4.i686.rpm qt-postgresql-4.6.2-26.el6_4.x86_64.rpm qt-sqlite-4.6.2-26.el6_4.i686.rpm qt-sqlite-4.6.2-26.el6_4.x86_64.rpm qt-x11-4.6.2-26.el6_4.i686.rpm qt-x11-4.6.2-26.el6_4.x86_64.rpm qt-demos-4.6.2-26.el6_4.x86_64.rpm qt-devel-4.6.2-26.el6_4.i686.rpm qt-devel-4.6.2-26.el6_4.x86_64.rpm qt-examples-4.6.2-26.el6_4.x86_64.rpm i386 phonon-backend-gstreamer-4.6.2-26.el6_4.i686.rpm qt-4.6.2-26.el6_4.i686.rpm qt-debuginfo-4.6.2-26.el6_4.i686.rpm qt-mysql-4.6.2-26.el6_4.i686.rpm qt-odbc-4.6.2-26.el6_4.i686.rpm qt-postgresql-4.6.2-26.el6_4.i686.rpm qt-sqlite-4.6.2-26.el6_4.i686.rpm qt-x11-4.6.2-26.el6_4.i686.rpm qt-demos-4.6.2-26.el6_4.i686.rpm qt-devel-4.6.2-26.el6_4.i686.rpm qt-examples-4.6.2-26.el6_4.i686.rpm noarch qt-doc-4.6.2-26.el6_4.noarch.rpm -Scientific Linux Development Team . A minor security patch for qt in Scientific Linux addresses concerns associated with memory sharing vulnerabilities.. qt Security Update, Scientific Linux Update, Shared Memory Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 21, 2013 Important Scientific Linux
87

Debian: DSA-2376-3 Moderate: ipmitool Vulnerable Configuration Management

It was discovered that OpenIPMI, the Intelligent Platform Management Interface library and tools, used too wide permissions PID file, which allows local users to kill arbitrary processes by writing to this file. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2376-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst December 31, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ipmitool Vulnerability : insecure pid file Problem type : local Debian-specific: no CVE ID : CVE-2011-4339 Debian Bug : 651917 It was discovered that OpenIPMI, the Intelligent Platform Management Interface library and tools, used too wide permissions PID file, which allows local users to kill arbitrary processes by writing to this file. The original announcement didn't contain corrections for the Debian 5.0 "lenny" distribution. This update adds packages for lenny. For the oldstable distribution (lenny), this problem has been fixed in version 1.8.9-2+squeeze1. (Although the version number contains the string "squeeze", this is in fact an update for lenny.) For the stable distribution (squeeze), this problem has been fixed in version 1.8.11-2+squeeze2. For the unstable distribution (sid), this problem has been fixed in version 1.8.11-5. We recommend that you upgrade your ipmitool packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the patch DSA-2376-2 for ipmitool tackling internal vulnerability in Debian systems.. OpenIPMI, Local Process Control, Debian Update, PID File Permissions. . LinuxSecurity.com Team

Calendar%202 Dec 31, 2011 Debian
87

Debian: DSA-1768-1 Urgent: OpenSSL Vulnerability Exploit

It was discovered that multipathd of multipath-tools, a tool-chain to manage disk multipath device maps, uses insecure permissions on its unix domain control socket which enables local attackers to issue commands to multipathd . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA-1767-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde April 9th, 2009 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : multipath-tools Vulnerability : insecure file permissions Problem type : local Debian-specific: no CVE ID : CVE-2009-0115 Debian Bug : 522813 It was discovered that multipathd of multipath-tools, a tool-chain to manage disk multipath device maps, uses insecure permissions on its unix domain control socket which enables local attackers to issue commands to multipathd prevent access to storage devices or corrupt file system data. For the oldstable distribution (etch), this problem has been fixed in version 0.4.7-1.1etch2. For the stable distribution (lenny), this problem has been fixed in version 0.4.8-14+lenny1. For the testing distribution (squeeze), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 0.4.8-15. We recommend that you upgrade your multipath-tools packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch -------------------------------- Debian (oldstable) - ------------------ Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 794 96af45800ec71a9fcf8f811416ff90e7 Size/MD5 checksum: 179914 b14f35444f6fee34b6be49a79ebe9439 Size/MD5 checksum: 25941 971e214f6a43d817da8da4dcc3763443 alpha architecture (DEC Alpha) Size/MD5 checksum: 189648 b656f97eb5932ef8a5c7da0f82a84137 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 176688 a51f613920761e339ed609d5894ce7eb hppa architecture (HP PA RISC) Size/MD5 checksum: 173368 2e4e0cd06f1da7b52763595e61ba500d i386 architecture (Intel ia32) Size/MD5 checksum: 150996 48c1d3875c6d379fc0a62e8c1e28666f mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 178114 3fbf325989232f9d696a3bcfbfdf89d1 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 176212 d72b286ae168caa5947cab12db6e8e2b powerpc architecture (PowerPC) Size/MD5 checksum: 161776 923e02c8131bbfd298bd2958637fc90b s390 architecture (IBM S/390) Size/MD5 checksum: 185228 b91cf8601d239237884cd0e03fa67b60 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 154464 a36b4c818a9dbe7b7c8e61722a70dee6 Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1375 04c428b50412dcfe7cefecce779bdd82 Size/MD5 checksum: 22746 ec09a8b773c890812f68c431024b89b2 Size/MD5 checksum: 202446 bf67b278e4b23da0c8ad21a278c04cb3 Architecture independent packages: Size/MD5 checksum: 10886 3d518147b5389246bb18904f9f77bc83 alpha architecture (DEC Alpha) Size/MD5 checksum: 106966 87e769e197696dcd6f0525be77ec0546 Size/MD5 checksum: 20474095063bb64a1bba317baecbb5b1bdccbb Size/MD5 checksum: 27756 470a9055c75c2676795ed1817da24c18 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 99386 501ea5e8fcff7e02fbb77b341ecef38c Size/MD5 checksum: 192420 fb9bc700300370ec53cdf66bf39afcd5 Size/MD5 checksum: 25990 f94b58b8cec5665893ad6fc7e8d747d9 arm architecture (ARM) Size/MD5 checksum: 93068 6a35c0bd3eb8d08fa7613f7eb002297f Size/MD5 checksum: 175800 e25edcbde0e9513b82fb59b19357a417 Size/MD5 checksum: 27610 a62cafb90a1dd13465389a47585362d4 armel architecture (ARM EABI) Size/MD5 checksum: 95358 a0079598fe094908574e9f15dddfb565 Size/MD5 checksum: 27852 80241b8329e8e31767d67ff31690bec9 Size/MD5 checksum: 179324 1af92c3f6959f119aaf56af499a073fb hppa architecture (HP PA RISC) Size/MD5 checksum: 100920 6dd4cfb7b8a1b1957f240b1ee922670e Size/MD5 checksum: 29154 d4de676222f65ef4467e802441253be4 Size/MD5 checksum: 185866 3e7f0749e06a1561c8d9dd21d3cfbc02 i386 architecture (Intel ia32) Size/MD5 checksum: 85600 77e950f2b8ec5f16dd4f61e340073b8e Size/MD5 checksum: 165474 5f23b56e95e99c389f645b1f7ec53165 Size/MD5 checksum: 25336 f9e242279e7c12ea3451f90e8fcf0560 ia64 architecture (Intel ia64) Size/MD5 checksum: 35282 1cc4f5782ed0349da2b1a251ac3a2259 Size/MD5 checksum: 279626 9c86861235fa835825466bc1bed9a93e Size/MD5 checksum: 150898 eb2a2c1d0a85c3390a894667009737dd mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 98504 9d0bae38732fe6e4063a661ac4c852a0 Size/MD5 checksum: 28620 5118f8dda0daf98bdebd3ceae46f1842 Size/MD5 checksum: 185960 b37960b2d780d87b6b9529d4d4f54b13 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 184122 6469d393d9cc31189721350ea83156ea Size/MD5 checksum: 28040 117a10472b5e80e6caf2c21ca33badec Size/MD5 checksum: 96510 8b4e0ce2f511554d4e675119ec949c64 powerpc architecture (PowerPC) Size/MD5checksum: 182596 c06e48ff7f1667d250ba3ebf96139b17 Size/MD5 checksum: 29824 6a02f47ebab83955f5ad7e368bb05a7b Size/MD5 checksum: 98676 cab3a7acabbf1538a4b028cf3f6b3ea4 s390 architecture (IBM S/390) Size/MD5 checksum: 199430 43386b3e236b1a5bc1f776f861777fee Size/MD5 checksum: 106330 deb5ad4134ce0f51d634d7d93114b2df Size/MD5 checksum: 30240 14cc5d88fa49e31d373c94c901c4ccdb sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 90714 c83bb4b5d80c763e17b16da65e6b7d15 Size/MD5 checksum: 26980 2a8721fb9a9c38a6a147bbeade3d8cc1 Size/MD5 checksum: 171574 94ba2d8590bc4775f578d3997e08d9d8 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ----------------------------------------------------. multipathd, multipath-tools, tool-chain, manage, multipath, device. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 09, 2009 Important Debian
89

Fedora 9: 2009-3453 Moderate: Device-Mapper-Multipath Sock Fix

Fix insecure permissions on multipathd.sock (CVE-2009-0115). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3453 2009-04-09 15:25:22 --------------------------------------------------------------------------------Name : device-mapper-multipath Product : Fedora 9 Version : 0.4.7 Release : 17.fc9 URL : http://christophe.varoqui.free.fr/ Summary : Tools to manage multipath devices using device-mapper Description : device-mapper-multipath provides tools to manage multipath devices by instructing the device-mapper multipath kernel module what to do. The tools are : * multipath : Scan the system for multipath devices and assemble them. * multipathd : Detects when paths fail and execs multipath to update things. --------------------------------------------------------------------------------Update Information: Fix insecure permissions on multipathd.sock (CVE-2009-0115) --------------------------------------------------------------------------------ChangeLog: * Tue Apr 7 2009 Milan Broz - 0.4.8-17 - Fix insecure permissions on multipathd.sock (CVE-2009-0115) * Mon Jun 23 2008 Benjamin Marzinski -0.4.7-16 - Fix for bz #451415 - /sbin/multipath.static in no longer a symlink to the non-static version. However, it still dynamically loads all libraries except libsysfs. libsysfs is now statically linked. * Wed May 21 2008 Benjamin Marzinski -0.4.7-15 - Switch multipath to check "subsystem" instead of "bus" - Make static versions of multipath and kpartx symlinks to non-static versions * Fri Feb 29 2008 Tom "spot" Callaway - 0.4.7-14 - fix sparc64 - fix license tag * Tue Feb 19 2008 Fedora Release Engineering - 0.4.7-13 - Autorebuild for GCC 4.3 * Wed Nov 14 2007 Benjamin Marzinski - 0.4.7-12 - Fixed the dist tag so building will work properly. --------------------------------------------------------------------------------References: [ 1 ] Bug #493330 -CVE-2009-0115 device-mapper-multipath: insecure permissions on multipathd.sock https://bugzilla.redhat.com/show_bug.cgi?id=493330 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update device-mapper-multipath' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Correction implemented to address vulnerable access rights concerning multipathd.sock within the device-mapper-multipath package for Fedora environments.. Device Mapper, Multipath Update, Fedora Security Fix. . LinuxSecurity.com Team

Calendar%202 Apr 09, 2009 Fedora
91

Gentoo: GLSA-200510-13 Normal: SPE Insecure File Permissions Overview

SPE files are installed with world-writeable permissions, potentially leading to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200510-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SPE: Insecure file permissions Date: October 15, 2005 Bugs: #108538 ID: 200510-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SPE files are installed with world-writeable permissions, potentially leading to privilege escalation. Background ========= SPE is a cross-platform Python Integrated Development Environment (IDE). Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/spe < 0.7.5c-r1 > = 0.7.5c-r1 *> = 0.5.1f-r1 Description ========== It was reported that due to an oversight all SPE's files are set as world-writeable. Impact ===== A local attacker could modify the executable files, causing arbitrary code to be executed with the permissions of the user running SPE. Workaround ========= There is no known workaround at this time. Resolution ========= All SPE users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose dev-util/spe Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200510-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our usersmachines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Gentoo Linux Security Advisory GLSA 200510-14 addresses issues with GDM's inadequate access controls, rated as a moderate security concern.. SPE Security, Gentoo Advisory, File Permissions, Privilege Escalation. . LinuxSecurity.com Team

Calendar%202 Oct 15, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200