Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
87

Debian: DSA 770-1 Moderate: Insecure Tempfile Risk in Gopher Package

Update package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 770-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze July 29th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : gopher Vulnerability : insecure tmpfile creating Problem-Type : local Debian-specific: no CVE ID : CAN-2005-1853 John Goerzen discovered that gopher, a client for the Gopher Distributed Hypertext protocol, creates temporary files in an insecure fashion. For the old stable distribution (woody) this problem has been fixed in version 3.0.3woody3. For the stable distribution (sarge) this problem has been fixed in version 3.0.7sarge1. For the unstable distribution (sid) this problem has been fixed in version 3.0.9. We recommend that you upgrade your gopher package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 552 c36368a87e599721ce6faf7f6f2b43af Size/MD5 checksum: 508858 9fafa9c495dc402c68e16b1d98578622 Alpha architecture: Size/MD5 checksum: 151672 43a15f4646faee119f5691500e78e8aa Size/MD5 checksum: 120288 cbee60712b9c3bc4ef7df144aa2c16f5 ARM architecture: Size/MD5 checksum: 114782 5d02e52bcdb1e9682e5b338e88d3b1d6 Size/MD5 checksum: 98766adb1f0e3eefea5578fafad6faf305d3e Intel IA-32 architecture: Size/MD5 checksum: 112728 b2b16c3f5cfa2df5aa3a26361adba13f Size/MD5 checksum: 96958 ad5d261eb022846bb9099e27e1c0faea Intel IA-64 architecture: Size/MD5 checksum: 173840 1a9b23617bb59a99de29c77f9438f266 Size/MD5 checksum: 139924 92daf67a685a0a1d7092477037fc6883 HP Precision architecture: Size/MD5 checksum: 129958 662dcf6bc361150a7edab41fd8ace48d Size/MD5 checksum: 109924 e27effcad026aa923fa6cd069abc2353 Motorola 680x0 architecture: Size/MD5 checksum: 105804 9adb09f5a9705f668ef3f6c678beb738 Size/MD5 checksum: 92012 0a99b4b07a6e7f5cdfab672ecaa0c24c Big endian MIPS architecture: Size/MD5 checksum: 131172 321d042012f31e63989901fb0a799905 Size/MD5 checksum: 109634 9f52a094c0c3c4751ba759697b1a8a51 Little endian MIPS architecture: Size/MD5 checksum: 131172 09507006f76bad2f36a7ef1b845f895e Size/MD5 checksum: 109522 0b3ee016c1135a1d7e6d9883d101f52c PowerPC architecture: Size/MD5 checksum: 121388 f1e8c648dfd1a9be38c8c595c1a10d3b Size/MD5 checksum: 102924 6cacbf8097a31dac9d93ccb887294f83 IBM S/390 architecture: Size/MD5 checksum: 116412 4026e77e65aa9029e59191085f37d76e Size/MD5 checksum: 99978 00b9bfc610eb7583b1dc35757b017d87 Sun Sparc architecture: Size/MD5 checksum: 122096 0f85aa93d4e54b4a8ecc658f7e5caa78 Size/MD5 checksum: 102280 f78c3fb64a500acc9a9b3ff714d16b34 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 547 31eead81f6846deabd19e34c620e368f Size/MD5 checksum: 678218 8f159dcfc9ed25335e8bc0b87fb3e3d8 Alpha architecture: Size/MD5 checksum: 148342 adcd570d5fc2baf7ab4bb43d54727444 ARM architecture: Size/MD5 checksum: 116832ef4570961aac6e3f6e3a9b8ef640e43a Intel IA-32 architecture: Size/MD5 checksum: 120802 a9b89709899d3c9380219887d5a89573 Intel IA-64 architecture: Size/MD5 checksum: 168676 3ec0be402bd6057a56a094d7baf5b0cd HP Precision architecture: Size/MD5 checksum: 132718 088fc0a402a26fded33bcc374810a354 Motorola 680x0 architecture: Size/MD5 checksum: 110014 c2155dd93f6d6c0cecf27d026a107766 Big endian MIPS architecture: Size/MD5 checksum: 133724 42237ccac6bd4dd4c3b8a16f6fc60c8d Little endian MIPS architecture: Size/MD5 checksum: 133830 a0e6f0436a1068dd86bdac1dedf51978 PowerPC architecture: Size/MD5 checksum: 129276 5c2d33e24f528e9f55d7537acc960c4e IBM S/390 architecture: Size/MD5 checksum: 129252 462cdf9e475ef667550c419d1d5537ca Sun Sparc architecture: Size/MD5 checksum: 117344 ebcfe7c3898b6015f0b5a893145746ed These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. update, package, --------------------------------------------------------------------------debian. . LinuxSecurity.com Team

Calendar%202 Jul 29, 2005 Debian
87

Debian 2.2 DSA-037-1 Critical: Insecure Tempfile Bug Fix

It has been reported that the AsciiSrc and MultiSrc widget in the Athena widget library handle temporary files insecurely.. ---------------------------------------------------------------------------- Debian Security Advisory DSA-037-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 7, 2001 ---------------------------------------------------------------------------- Package : nextaw, xaw3d, xaw95 Vulnerability : insecure tempfile handling Type : local insecure tempfile bug Debian-specific: no Fixed version : nextaw 0.5.1-34potato1 xaw3d 1.3-6.9potato1 xaw95 1.1-4.6potato1 It has been reported that the AsciiSrc and MultiSrc widget in the Athena widget library handle temporary files insecurely. Joey Hess has ported the bugfix from XFree86 to these Xaw replacements libraries. We recommend you upgrade your nextaw, xaw3d and xaw95 packages. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. This package, though, is only fixed for i386 and m68k. The version for sparc is still vulnerable and isn't maintained anymore. Source archives: MD5 checksum: 39f64281940612d3fcd9caab2e577aec MD5 checksum: 8f4d5420ccb9a10eeba1bbbbf4039618 MD5 checksum: ca6b7f0cd5929c67d31bec1cc85597fd MD5 checksum: a0253eff70f0e295471a57b085475b94 MD5 checksum: d058e2bcf84375b47237c731b2226ed6 MD5 checksum: 9475773be43a669ef347bd5b99f9ff7c MD5 checksum: 8e2814e26829f8618407bddc2a8139a0 MD5 checksum: e1e851e56e8bd55e7aa7ad75d53e1795 MD5 checksum:e0983faf630fa74dfa2c0d5ed10635ea Intel ia32 architecture: MD5 checksum: 8d4c42a419d12058a81a4875c0482683 MD5 checksum: b8d4405cf60e0cdae4a67078c3c5df54 MD5 checksum: c2d82fd02430195fb2e2f63dea884b37 MD5 checksum: da8c800a7e533970914beea1288eac86 MD5 checksum: f44322639de2bcb5049fa3360602fb79 MD5 checksum: ad465ec7dd6b7cdf155da49ed40fd0f1 Motorola 680x0 architecture: MD5 checksum: 0cecbd698a8f2c38d9853b8955375278 MD5 checksum: 80961f0094a9e150354a44c80a2aedcb MD5 checksum: 48e1ab6da9de7decca460c4bcd0ed0db MD5 checksum: bf128f7f8b208e65e40b66e39ad895c8 MD5 checksum: 1a18260226eb093deb72a249b20c8dc4 MD5 checksum: 66bc729de8b5ac24e81679a223aab3c6 Sun Sparc architecture: Not fixed, not maintained. These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian has issued an alert regarding vulnerable tempfile handling found in Nextaw, Xaw3D, and Xaw95, advising users to upgrade to the most recent package releases.. Debian Advisory, Insecure Tempfile, Nextaw Security, Xaw3D Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 07, 2001 Critical Debian
87

Debian DSA-011-2 Critical: mgetty Insecure Tempfile Issues

In Debian Security Advisory DSA 011-1 we have reported insecure creation of temporary files in the mgetty package that have been fixed. For details please read the main advisory.. ---------------------------------------------------------------------------- Debian Security Advisory DSA-011-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 6, 2001 ---------------------------------------------------------------------------- Package : mgetty Vulnerability : insecure tempfile creation Debian-specific: no In Debian Security Advisory DSA 011-1 we have reported insecure creation of temporary files in the mgetty package that have been fixed. For details please read the main advisory. The most recent advisory covering proftpd missed two architectures that were released with Debian GNU/Linux 2.2. Therefore this advisory is only an addition to DSA 011-1 and only adds the relevant package for the Motorola 680x0 and PowerPC architecture. We recommend you upgrade your sudo packages for m68k immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. Motorola 680x0 architecture: MD5 checksum: c175cdd07927e5a6e9f6ebecbd91366b MD5 checksum: 8aa48ed8b00d7873452cac3970c47877 MD5 checksum: 89a9c11cfaa04cac4f2cc752714e1f3f MD5 checksum: 40b004e0dcaad89253a552e823809f7a PowerPC architecture: MD5 checksum: fe951cbfbbd37d26cd7c210ee9eee8a1 MD5 checksum: e9b3c8b63f82333cc8cb22eeecaaa1c9 MD5 checksum: afbed28e1382f53cfdca42c089d56516 MD5 checksum: 244d5c6525382b342117ec2e72ee0f1c These files will be movedinto soon. For not yet released architectures please refer to the appropriate directory . ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Urgent update for Debian addressing insecure tempfile creation in mgetty. Immediate action required for system safety.. Debian Security,mgetty,insecure tempfile,update recommendation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 05, 2001 Critical Debian
87

Debian: DSA-021-1 Critical: Apache Insecure Tempfile And Mod_Rewrite Issue

WireX have found some occurrences of insecure opening of temporaryfiles in htdigest and htpasswd. The Apache group has also fixed a vulnerability in mod_rewrite.. - ---------------------------------------------------------------------------- Debian Security Advisory DSA-021-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze January 26, 2001 - ---------------------------------------------------------------------------- Package : apache Vulnerability : insecure tempfile bug, broken mod_rewrite Debian-specific: no WireX have found some occurrences of insecure opening of temporary files in htdigest and htpasswd. Both programs are not installed setuid or setgid and thus the impact should be minimal. The Apache group has released another security bugfix which fixes a vulnerability in mod_rewrite which may result the remote attacker to access arbitrary files on the web server. We recommend you upgrade your Apache packages. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. Source archives: MD5 checksum: e718ee855e7252197ae22049a607bf19 MD5 checksum: 974bb0bffd1a97ed2a355b4f300aba6e MD5 checksum: 6758fe8b931be0b634b6737d9debf703 Intel ia32 architecture: MD5 checksum: 252886b62b347fe41d492b22a23ef1f8 MD5 checksum: 0b3df81c96378160a86d8c47f2e06424 MD5 checksum: 719bb4743340715230f0ca6d9167dc21 Motorola 680x0 architecture: MD5 checksum: fd903e38c9e5f60d5b022726613013ac MD5 checksum: ca4c076e5855bb655e156cbc201fc002 MD5 checksum: b4f63bc8cf2dd56a1fccc3d01606b769 Sun Sparcarchitecture: MD5 checksum: f1a8e98a14f456fcd954c0c79aa1112b MD5 checksum: 1b81ec639bfff592c104ee8feb7f7bff MD5 checksum: 9d066a85be2660d5412a8da52ef38856 Alpha architecture: MD5 checksum: c3802eee3b924fba4f715c0768b8e2a0 MD5 checksum: b12cd7b68b9eae42e73e990f7a31fe50 MD5 checksum: 43ebd20f2be39c35279cce8d921dfe2a PowerPC architecture: MD5 checksum: 41e381b05a80b8d7c850b05d3790f93e MD5 checksum: 65ab212b4825537384db0f509f90b284 MD5 checksum: f6193cb949543a3030ddbddf119476bf ARM architecture: MD5 checksum: 0b4f9725689593ca276a63c5907acc4e MD5 checksum: 99a7bf367af716bafad48587f8dd1d42 MD5 checksum: 0f76dc4a491fba532460048d4652c387 Architecture independent: MD5 checksum: e8b121ff22f0b8a52d0dac7b8daefc25 These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . - ---------------------------------------------------------------------------- Debian Security Advis. wirex, found, occurrences, insecure, opening, temporaryfiles, htdigest, htpasswd. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 26, 2001 Critical Debian
87

Debian: DSA-020-1 High: Apache HTTP Server Path Traversal Vulnerability

WireX discovered a potential temporary file race condition in the waythat squid sends out email messages notifying the administrator aboutupdating the program.. - ---------------------------------------------------------------------------- Debian Security Advisory DSA-019-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze January 25, 2001 - ---------------------------------------------------------------------------- Package : squid Vulnerability : insecure tempfile hole Debian-specific: no WireX discovered a potential temporary file race condition in the way that squid sends out email messages notifying the administrator about updating the program. This could lead to arbitrary files to get overwritten. However the code would only be executed if running a very bleeding edge release of squid, running a server whose time is set some number of months in the past and squid is crashing. Read it as hardly to exploit. This version also containes more upstream bugfixes wrt. dots in hostnames and unproper HTML quoting. We recommend you upgrade your squid package.. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. Source archives: MD5 checksum: 8475d28db69cd901609a384a7a72d45c MD5 checksum: 43da73f621704331add0a4a990a96676 MD5 checksum: 3ae40a4f21b110553446fe3d92ed2bda Intel ia32 architecture: MD5 checksum: bd1fcb943bb2c2ea86f95a1e0a5fa482 MD5 checksum: 04ccb01c216b5beb3949c751121c8fcb MD5 checksum: 39bfe66b003157e90937d28ab6a0193a Motorola 680x0 architecture: MD5 checksum: e6453913239ea696d787eeef61121cac MD5 checksum: ed57e5456e081e260747b24f108a1d10 MD5 checksum: 4a1e67b863e26764608f991f93be00e7 Sun Sparc architecture: MD5 checksum: 998349778feeb91ba09b439d9c9325f9 MD5 checksum: 8a58eb2f68da8de395cc8dcca9a0b125 MD5 checksum: a0f62d653e0a2dd21db6455385947942 Alpha architecture: MD5 checksum: 690dda904ac988b608e1878356038b7d MD5 checksum: 4ee17e8c212edb9bc6f19e21a659a5d3 MD5 checksum: 65d2a3acd6d9e135abecae651b09adab PowerPC architecture: MD5 checksum: 8bec2a10ddc72244988a61f75f810162 MD5 checksum: 8f9e7cb06a0b658726d3d18223998df2 MD5 checksum: 70a37ca9316e19ae7b0c4a601b0bfc97 ARM architecture: MD5 checksum: 6d32d86539aed7825d3fcc0d4f19c951 MD5 checksum: 55089f6f4eee2b34327c6959685a7cf9 MD5 checksum: b5daf01c8627f099595e2435fc53ddea These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Upgrade Squid to mitigate path traversal risk, affecting administrators' email alerts on Debian systems.. Squid Security Advisory, Debian DSA-019-1, Email Notification Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 25, 2001 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200