Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 24: 2017-40d29c8e84 moderate: kopete user impersonation

Latest stable upstream release, includes security fix for CVE-2017-5593. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-40d29c8e84 2017-02-23 14:52:56.160315 -------------------------------------------------------------------------------- Name : kopete Product : Fedora 24 Version : 16.12.2 Release : 2.fc24 URL : Summary : Instant messenger Description : Instant messenger. -------------------------------------------------------------------------------- Update Information: Latest stable upstream release, includes security fix for CVE-2017-5593 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1421069 - CVE-2017-5593 psi-plus: User impersonation vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1421069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kopete' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An update for Kopete in Fedora 24 resolves a vulnerability related to user impersonation, enhancing the security of communications.. Fedora Update, Kopete Security Fix, User Impersonation. . LinuxSecurity.com Team

Calendar%202 Feb 23, 2017 Fedora
89

Fedora 25: Update for Kopete User Impersonation Security Flaw

Latest stable upstream release, includes security fix for CVE-2017-5593. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-3fb57530fb 2017-02-23 14:53:55.960773 -------------------------------------------------------------------------------- Name : kopete Product : Fedora 25 Version : 16.12.2 Release : 2.fc25 URL : Summary : Instant messenger Description : Instant messenger. -------------------------------------------------------------------------------- Update Information: Latest stable upstream release, includes security fix for CVE-2017-5593 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1421069 - CVE-2017-5593 psi-plus: User impersonation vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1421069 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade kopete' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Applies the most recent kopete security patch addressing user impersonation vulnerabilities in Fedora 25. Get updated now for improved safety.. Kopete Security Fix, Fedora Update, User Impersonation Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 23, 2017 Important Fedora
89

Fedora: 2005-624 Critical: Kopete Integer Overflow Remote Attack

Multiple integer overflow flaws were found in the way Kopete processes Gadu-Gadu messages. A remote attacker could send a specially crafted Gadu-Gadu message which would cause Kopete to crash or possibly execute arbitrary code.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-624 2005-07-22 ---------------------------------------------------------------------Product : Fedora Core 4 Name : kdenetwork Version : 3.4.1 Release : 0.fc4.2 Summary : K Desktop Environment - Network Applications Description : Networking applications for the K Desktop Environment. ---------------------------------------------------------------------Update Information: Multiple integer overflow flaws were found in the way Kopete processes Gadu-Gadu messages. A remote attacker could send a specially crafted Gadu-Gadu message which would cause Kopete to crash or possibly execute arbitrary code. The Common Vulnerabilities and Exposures project assigned the name CAN-2005-1852 to this issue. Users of Kopete should update to these packages which contain a patch to correct this issue. ---------------------------------------------------------------------* Thu Jul 21 2005 Than Ngo 7:3.4.1-0.fc4.2 - fix crash in kopete - apply patch to fix libgadu vulnerabilities #163811, CVE CAN-2005-1852 thank to kde security team ---------------------------------------------------------------------This update can be downloaded from: 4e3db27303568ad94e65d82ffd1189f9 SRPMS/kdenetwork-3.4.1-0.fc4.2.src.rpm fb065037fb526cd9bb933c3c076a9dec ppc/kdenetwork-3.4.1-0.fc4.2.ppc.rpm 1b26b336de353a59dd7dffe5816e0951 ppc/kdenetwork-devel-3.4.1-0.fc4.2.ppc.rpm 971510423874ce1b9339a9989044f194 ppc/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.ppc.rpm ecd5ecaf2c3b2de2b9d1997f71d37183 x86_64/kdenetwork-3.4.1-0.fc4.2.x86_64.rpm 98e9c1a88792e0df169887f669608fa6 x86_64/kdenetwork-devel-3.4.1-0.fc4.2.x86_64.rpm 4d189d1a3c8c2abe037c9254a3cffeb8 x86_64/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.x86_64.rpm 54fd9578f7ab23e8d35d7e85e1b3e493 i386/kdenetwork-3.4.1-0.fc4.2.i386.rpm 12b717074ad81ed6c120d028684c3e6f i386/kdenetwork-devel-3.4.1-0.fc4.2.i386.rpm d1b78acac0474698c261d117ce9832c7 i386/debug/kdenetwork-debuginfo-3.4.1-0.fc4.2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Fedora Core 4 patch resolves integer overflow vulnerabilities in Kopete, effectively thwarting possible remote exploitation.. Kopete Update,Fedora Network Security,Integer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 22, 2005 Critical Fedora
91

Gentoo: 200305-03 Critical Advisory for Kopete Remote Exploit

The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200305-03 - - - --------------------------------------------------------------------- PACKAGE : kopete SUMMARY : Unsafe command line cleansing DATE : 2003-05-14 07:39 UTC EXPLOIT : remote VERSIONS AFFECTED : =kopete-0.6.2 CVE : CAN-2003-0256 - - - --------------------------------------------------------------------- The GnuPG plugin in kopete before 0.6.2 does not properly cleanse the command line when executing gpg, which allows remote attackers to execute arbitrary commands. SOLUTION It is recommended that all Gentoo Linux users who are running net-im/kopete upgrade to kopete-0.6.2 as follows: emerge sync emerge kopete emerge clean - - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - - - --------------------------------------------------------------------- . Hackers could exploit a flaw in the messaging software kopete, potentially leading to code execution. To mitigate possible risks, ensure you upgrade to version 0.6.2.. Kopete Upgrade Advisory, Command Execution Risk, Gentoo Security Alert. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 14, 2003 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200