Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 18 articles for you...
202

openSUSE: 2023:0371-1 Moderate: jhead Patch for Autorotation Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0371-1 Rating: moderate References: #1207150 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - Fixed autorotation problem caused by CVE-2022-41751 patch. [boo#1207150] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-371=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp155.5.3.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1207150 . Critical patch available for jhead on openSUSE; addresses a significant security flaw with detailed installation guidelines included.. openSUSE Update,jhead Security Patch,jhead Vulnerability Fix,Software Update. . LinuxSecurity.com Team

Calendar%202 Nov 15, 2023 OpenSUSE
172

Ubuntu 20.04 LTS USN-6098-1 Critical: Jhead Crash Risks

Several security issues were fixed in Jhead.. =========================================================================Ubuntu Security Notice USN-6098-1 May 23, 2023 Jhead vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS (Available with Ubuntu Pro) - Ubuntu 14.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Jhead. Software Description: - jhead: Manipulate the non-image part of Exif compliant JPEG files Details: It was discovered that Jhead did not properly handle certain crafted images while processing the JFIF markers. An attacker could cause Jhead to crash. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, and Ubuntu 18.04 LTS. (CVE-2019-19035) It was discovered that Jhead did not properly handle certain crafted images while processing longitude tags. An attacker could cause Jhead to crash. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-1010301) It was discovered that Jhead did not properly handle certain crafted images while processing IPTC data. An attacker could cause Jhead to crash. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-1010302) Binbin Li discovered that Jhead did not properly handle certain crafted images while processing the DQT data. An attacker could cause Jhead to crash. (CVE-2020-6624) Binbin Li discovered that Jhead did not properly handle certain crafted images while processing longitude data. An attacker could cause Jhead to crash. (CVE-2020-6625) Feng Zhao Yang discovered that Jhead did not properly handle certain crafted images while reading JPEG sections. An attacker could cause Jhead to crash. (CVE-2020-26208) It was discovered that Jhead did not properly handle certain crafted images while processing Canon images. An attacker could cause Jhead tocrash. (CVE-2021-28276) It was discovered that Jhead did not properly handle certain crafted images when removing a certain type of sections. An attacker could cause Jhead to crash. (CVE-2021-28278) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: jhead 1:3.04-1ubuntu0.1 Ubuntu 18.04 LTS: jhead 1:3.00-8~ubuntu0.1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): jhead 1:3.00-4+deb9u1ubuntu0.1~esm1 Ubuntu 14.04 LTS (Available with Ubuntu Pro): jhead 1:2.97-1+deb8u2ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6098-1 CVE-2019-1010301, CVE-2019-1010302, CVE-2019-19035, CVE-2020-26208, CVE-2020-6624, CVE-2020-6625, CVE-2021-28276, CVE-2021-28278 Package Information: https://launchpad.net/ubuntu/+source/jhead/1:3.04-1ubuntu0.1 https://launchpad.net/ubuntu/+source/jhead/1:3.00-8~ubuntu0.1 . Several Jhead vulnerabilities identified for Ubuntu versions 14.04 through 20.04 LTS may lead to system instability stemming from manipulated image files.. Ubuntu Security Notice, Jhead Fixes, Software Update Instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 23, 2023 Critical Ubuntu
202

openSUSE 2023:0054-1 Moderate: Jhead Update for Security Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0054-1 Rating: moderate References: #1207150 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - Fixed autorotation problem caused by CVE-2022-41751 patch. [boo#1207150] Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-54=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.9.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1207150 . This enhancement for jhead on openSUSE mitigates a moderate risk by resolving a documented concern.. openSUSE Security Update,jhead Update,System Security Fix,OpenSUSE Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 20, 2023 Important OpenSUSE
202

openSUSE: 2022:10203-1 Critical: jhead Out of Bounds Issue

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10203-1 Rating: important References: #1205167 Cross-References: CVE-2021-34055 CVSS scores: CVE-2021-34055 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: * CVE-2021-34055: Fix out of bounds write in ClearOrientation() due to unchecked error (boo#1205167) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP3: zypper in -t patch openSUSE-2022-10203=1 Package List: - openSUSE Backports SLE-15-SP3 (aarch64 i586 ppc64le s390x x86_64): jhead-3.00-bp153.3.6.1 References: https://www.suse.com/security/cve/CVE-2021-34055.html https://bugzilla.suse.com/1205167 . A significant patch for jhead resolves a crucial vulnerability (CVE-2021-34055) affecting openSUSE users. Discover further details.. OpenSUSE Security Update, Jhead Vulnerability, Important Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 14, 2022 Important OpenSUSE
202

openSUSE: 2022:10202-2 Critical: jhead Security Patch Released

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10202-1 Rating: important References: #1205167 Cross-References: CVE-2021-34055 CVSS scores: CVE-2021-34055 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: * CVE-2021-34055: Fix out of bounds write in ClearOrientation() due to unchecked error (boo#1205167) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10202=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.6.1 References: https://www.suse.com/security/cve/CVE-2021-34055.html https://bugzilla.suse.com/1205167 . Important: jhead has received an update addressing the critical security vulnerability CVE-2021-34055 in openSUSE Backports SLE-15-SP4. Please ensure to install the update immediately!. openSUSE Patch, jhead Update, CVE-2021-34055 Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 14, 2022 Important OpenSUSE
89

Fedora 37: jhead 2022-628829f0e6 Critical: OS Command Injection Update

added patches to fix CVE-2022-41751. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-628829f0e6 2022-11-10 22:04:44.631614 --------------------------------------------------------------------------------Name : jhead Product : Fedora 37 Version : 3.06.0.1 Release : 5.fc37 URL : https://www.sentex.ca/~mwandel/jhead/ Summary : Tool for displaying EXIF data embedded in JPEG images Description : Jhead displays and manipulates the non-image portions of EXIF formatted JPEG images, such as the images produced by most digital cameras. --------------------------------------------------------------------------------Update Information: added patches to fix CVE-2022-41751 --------------------------------------------------------------------------------ChangeLog: * Tue Oct 18 2022 Adrian Reber - 3.06.0.1-5 - added patches to fix CVE-2022-41751 --------------------------------------------------------------------------------References: [ 1 ] Bug #2135591 - CVE-2022-41751 jhead: arbitrary OS commands by placing them in a JPEG filename https://bugzilla.redhat.com/show_bug.cgi?id=2135591 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-628829f0e6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . To address the CVE-2022-41751 vulnerability related to JPEG files, update the jhead package on Fedora 37 using the command below in your terminal. Fedora Jhead Fix, OS Command Injection, Critical Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 10, 2022 Critical Fedora
202

openSUSE: 2022:10179-1 Important: Shell Injection Fix for jhead

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for jhead ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10179-1 Rating: important References: #1204409 Cross-References: CVE-2022-41751 CVSS scores: CVE-2022-41751 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jhead fixes the following issues: - CVE-2022-41751: Fixed shell injection via filenames (boo#1204409) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10179=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): jhead-3.06.0.1-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-41751.html https://bugzilla.suse.com/1204409 . Critical openSUSE Security Patch released for jhead targeting security flaws. Prompt action advised for all users.. openSUSE Security Update,jhead software,important update,shell injection fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 31, 2022 Important OpenSUSE
91

Gentoo: GLSA-202210-17 Low Severity: JHead Denial Of Service Threat

Multiple vulnerabilities have been found in JHead, the worst of which could result in denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202210-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: JHead: Multiple Vulnerabilities Date: October 31, 2022 Bugs: #730746 ID: 202210-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in JHead, the worst of which could result in denial of service. Background ========= JHead is an EXIF JPEG header manipulation tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/jhead < 3.06.0.1 > = 3.06.0.1 Description ========== Multiple vulnerabilities have been discovered in JHead. Please review the CVE identifiers referenced below for details. Impact ===== Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All JHead users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/jhead-3.06.0.1" References ========= [ 1 ] CVE-2021-3496 https://nvd.nist.gov/vuln/detail/CVE-2021-3496 [ 2 ] CVE-2021-28275 https://nvd.nist.gov/vuln/detail/CVE-2021-28275 [ 3 ] CVE-2021-28276 https://nvd.nist.gov/vuln/detail/CVE-2021-28276 [ 4 ] CVE-2021-28277 https://nvd.nist.gov/vuln/detail/CVE-2021-28277 [ 5 ] CVE-2021-28278 https://nvd.nist.gov/vuln/detail/CVE-2021-28278 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202210-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The JHead package in Gentoo Linux contains several security flaws, with the most severe potentially leading to a denial of service. It is advised to perform an update.. Gentoo Security Advisory, JHead Update, Denial of Service. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Oct 30, 2022 Low Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200