Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
91

Gentoo: GLSA-202310-34 Moderate: Filezilla RCE Security Flaw Announced

An insecure temporary file usage has been reported in TkMan, allowing for symlink attacks.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200909-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TkMan: Insecure temporary file usage Date: September 09, 2009 Bugs: #247540 ID: 200909-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An insecure temporary file usage has been reported in TkMan, allowing for symlink attacks. Background ========= TkMan is a graphical, hypertext manual page and Texinfo browser for UNIX. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/tkman < 2.2-r1 > = 2.2-r1 Description ========== Dmitry E. Oboukhov reported that TkMan does not handle the "/tmp/tkman#####" and "/tmp/ll" temporary files securely. Impact ===== A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All TkMan users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose =app-text/tkman-2.2-r1 References ========= [ 1 ] CVE-2008-5137 https://www.cve.org/CVERecord?id=CVE-2008-5137 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200909-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Advisory GLSA 202203-11 highlights a vulnerability in OpenSSH that poses a medium severity risk; updates recommended.. Gentoo Advisory, TkMan Security, Symlink Risks, Temporary File Issues. . LinuxSecurity.com Team

Calendar%202 Sep 09, 2009 Gentoo
91

Gentoo: 200809-08 Moderate: Amarok Symlink Attack Risk Report

Amarok uses temporary files in an insecure manner, allowing for a symlink attack.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Amarok: Insecure temporary file creation Date: September 08, 2008 Bugs: #234689 ID: 200809-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Amarok uses temporary files in an insecure manner, allowing for a symlink attack. Background ========= Amarok is an advanced music player. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/amarok < 1.4.10 > = 1.4.10 Description ========== Dwayne Litzenberger reported that the MagnatuneBrowser::listDownloadComplete() function in magnatunebrowser/magnatunebrowser.cpp uses the album_info.xml temporary file in an insecure manner. Impact ===== A local attacker could perform a symlink attack to overwrite arbitrary files on the system with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Amarok users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/amarok-1.4.10" References ========= [ 1 ] CVE-2008-3699 https://www.cve.org/CVERecord?id=CVE-2008-3699 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200809-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Enhance Amarok to mitigate symlink threat vulnerabilities stemming from inadequate temporary file management. Discover additional details today!. Amarok Symlink Attack, Insecure File Handling, Gentoo Security Advisory. . LinuxSecurity.com Team

Calendar%202 Sep 08, 2008 Gentoo
87

Debian: DSA-1492-1 Moderate: WML Local Denial of Service

Frank Lichtenheld and Nico Golde discovered that WML, an off-line HTML generation toolkit, creates insecure temporary files in the eperl and ipp backends and in the wmg.cgi script, which could lead to local denial of service by overwriting files.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1492-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 10, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : wml Vulnerability : insecure temporary files Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-0665 CVE-2008-0666 Debian Bug : 463907 Frank Lichtenheld and Nico Golde discovered that WML, an off-line HTML generation toolkit, creates insecure temporary files in the eperl and ipp backends and in the wmg.cgi script, which could lead to local denial of service by overwriting files. For the stable distribution (etch), these problems have been fixed in version 2.0.11-1etch1. The old stable distribution (sarge) is not affected. We recommend that you upgrade your wml packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 656 3c12d2b00552d3db815957c01c73b2cf Size/MD5 checksum: 3115230a26feebf4e59e9a6940f54c69dde05b5 Size/MD5 checksum: 24577 3242a88ced8598120cf6aba2bf9f69c4 alpha architecture (DEC Alpha) Size/MD5 checksum: 453998 29f9f2cffcd5becc205ba36a988a216f amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 452700 88033d2e3347e9b94061826b7856cdb0 hppa architecture (HP PA RISC) Size/MD5 checksum: 454656 5dd770e936b54880605d9d8c5c639d10 i386 architecture (Intel ia32) Size/MD5 checksum: 451672 be10fe25928ce83aadf119d98eb5cd43 ia64 architecture (Intel ia64) Size/MD5 checksum: 458406 c153522ee017b612f57a40b2e87787cb mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 450848 8dc62d7f99bf8a7e55b4ebf825cc8500 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 449418 32d7a95ff9c4a184fe7f23f1e8a1cea3 powerpc architecture (PowerPC) Size/MD5 checksum: 452594 65e04ee9b968599ec772c95c7c24ee41 s390 architecture (IBM S/390) Size/MD5 checksum: 451058 dbbcea5a32cdcd5e6a0407665270fdd6 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 450772 297e44c330a2acc9c4829b46f53f1004 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-1492-1 http://www.debian.org/security/ Moritz Muehlenhoff February 10, . frank, lichtenheld, golde, off-line, generation, toolkit, creates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 10, 2008 Important Debian
87

Debian 3.0 & 3.1 DSA-960-3 Critical: File Handling Issue

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 960-3 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze March 20th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : libmail-audit-perl Vulnerability : insecure temporay file createion Problem type : local Debian-specific: no CVE ID : CVE-2005-4536 Debian Bug : 344029 The former update caused temporary files to be created in the current working directory due to a wrong function argument. This update will create temporary files in the users home directory if HOME is set or in the common temporary directory otherwise, usually /tmp. For completeness below is a copy of the original advisory text: Niko Tyni discovered that the Mail::Audit module, a Perl library for creating simple mail filters, logs to a temporary file with a predictable filename in an insecure fashion when logging is turned on, which is not the case by default. For the old stable distribution (woody) these problems have been fixed in version 2.0-4woody3. For the stable distribution (sarge) these problems have been fixed in version 2.1-5sarge4. For the unstable distribution (sid) these problems have been fixed in version 2.1-5.1. We recommend that you upgrade your libmail-audit-perl package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 aliaswoody - -------------------------------- Source archives: Size/MD5 checksum: 665 62b652343a832093ba685dd9d3b18ab8 Size/MD5 checksum: 6129 0b41c98f1bb290f6603aeb93729d3a30 Size/MD5 checksum: 12526 3bc6043611f0fabdd856498e25bd48f6 Architecture independent components: Size/MD5 checksum: 29620 444067ca6bd1319996aab95fa9390de0 Size/MD5 checksum: 8952 c984bed8ff43153a00a9f4b63069d2d7 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 788 f313503b8ffc6df1cbd903666ca8a6fc Size/MD5 checksum: 4919 a3cff1ec8634add1753db93a6dccc402 Size/MD5 checksum: 21669 b52b1142fa9ed7d847c531186f913ea6 Architecture independent components: Size/MD5 checksum: 42056 dd9859e1298376d1bde353fb33af4e72 Size/MD5 checksum: 12306 96515c877e6155fc4836d1b19674b28a These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The advisory from Debian highlights vulnerabilities in libmail-audit-perl related to improper file management, urging users to upgrade promptly for security.. libmail-audit-perl Update, Debian Security Fix, File Handling Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 20, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200