Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 2 articles for you...
203

Mageia 8/9: 2023-0300 Moderate: Libcue Out-Of-Bounds Code Execution

Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to . MGASA-2023-0300 - Updated libcue packages fix a security vulnerability Publication date: 23 Oct 2023 URL: https://advisories.mageia.org/MGASA-2023-0300.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-43641 Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpage. Because the file is saved to `~/Downloads`, it is then automatically scanned by tracker-miners. And because it has a .cue filename extension, tracker-miners use libcue to parse the file. The file exploits the vulnerability in libcue to gain code execution. (CVE-2023-43641) References: - https://bugs.mageia.org/show_bug.cgi?id=32372 - https://www.openwall.com/lists/oss-security/2023/10/09/3 - https://www.cve.org/CVERecord?id=CVE-2023-43641 SRPMS: - 9/core/libcue-2.3.0-1.mga9 - 8/core/libcue-2.3.0-1.mga8 . Mageia 2023-0301 tackles vulnerabilities in libcue, providing enhancements for KDE users to mitigate potential exploit attempts.. Mageia Security Update, Libcue Exploit Fix, Out-of-Bounds Risk. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 23, 2023 Important Mageia
172

Ubuntu 23.10: USN-6423-2 Critical Libcue Arbitrary Code Execution

CUE could be made to execute arbitrary code if it received a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-6423-2 October 17, 2023 libcue vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: Summary: CUE could be made to execute arbitrary code if it received a specially crafted file. Software Description: Details: USN-6423-1 fixed a vulnerability in CUE. This update provides the corresponding updates for Ubuntu 23.10. Original advisory details: It was discovered that CUE incorrectly handled certain files. An attacker could possibly use this issue to expose sensitive information or execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6423-1 CVE-2023-43641 . A critical vulnerability permits unauthorized code execution through specially designed files. Patches for Ubuntu distributions are now released.. Ubuntu Libcue Update, Arbitrary Code Threat, Security Notice. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 17, 2023 Critical Ubuntu
100

SUSE: 2023:4090-1 Important: Libcue Buffer Overflow Threat

* bsc#1215728 Cross-References: * CVE-2023-43641 . # Security update for libcue Announcement ID: SUSE-SU-2023:4090-1 Rating: important References: * bsc#1215728 Cross-References: * CVE-2023-43641 CVSS scores: * CVE-2023-43641 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2023-43641 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP4 * Desktop Applications Module 15-SP5 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Workstation Extension 15 SP4 * SUSE Linux Enterprise Workstation Extension 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for libcue fixes the following issues: * CVE-2023-43641: Fixed a buffer overflow while parsinga malicious file (bsc#1215728). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP4-2023-4090=1 * Desktop Applications Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP5-2023-4090=1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2023-4090=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-ESPOS-2023-4090=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 zypper in -t patch SUSE-SLE-Product-HPC-15-SP3-LTSS-2023-4090=1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2023-4090=1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 zypper in -t patch SUSE-SLE-Product-SLES-15-SP3-LTSS-2023-4090=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2023-4090=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2023-4090=1 * SUSE Linux Enterprise Workstation Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-WE-15-SP4-2023-4090=1 * SUSE Linux Enterprise Workstation Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-WE-15-SP5-2023-4090=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2023-4090=1 ## Package List: * Desktop Applications Module 15-SP4 (aarch64 ppc64le s390x x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * Desktop Applications Module 15-SP5 (aarch64 ppc64le s390x x86_64) *libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS 15-SP2 (aarch64 x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP3 (aarch64 x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 (aarch64 x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP2 LTSS 15-SP2 (aarch64 ppc64le s390x x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP3 LTSS 15-SP3 (aarch64 ppc64le s390x x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 (ppc64le x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Workstation Extension 15 SP4 (x86_64) * libcue-debugsource-2.1.0-150000.3.3.1 * libcue-devel-2.1.0-150000.3.3.1 * SUSE Linux Enterprise Workstation Extension 15 SP5 (x86_64) * libcue-debugsource-2.1.0-150000.3.3.1 * libcue-devel-2.1.0-150000.3.3.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * libcue2-2.1.0-150000.3.3.1 * libcue-debugsource-2.1.0-150000.3.3.1 * libcue2-debuginfo-2.1.0-150000.3.3.1 ## References: *https://www.suse.com/security/cve/CVE-2023-43641.html * https://bugzilla.suse.com/show_bug.cgi?id=1215728 . Secure your system by installing the vital libcue security update to fix a buffer overflow vulnerability with these detailed SUSE instructions. libcue Security, SUSE Updates, Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 17, 2023 Important SuSE
89

Fedora 37: 2023-1fe05ac8d9 Critical: libcue Arbitrary Code Execution

This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-1fe05ac8d9 2023-10-13 01:31:55.137994 -------------------------------------------------------------------------------- Name : libcue Product : Fedora 37 Version : 2.2.1 Release : 13.fc37 URL : https://github.com/lipnitsk/libcue Summary : Cue sheet parser library Description : Libcue is intended for parsing a so-called cue sheet from a char string or a file pointer. For handling of the parsed data a convenient API is available. -------------------------------------------------------------------------------- Update Information: This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Adam Williamson - 2.2.1-13 - Fix CVE-2023-43641 (Kevin Backhouse) * Thu Jul 20 2023 Fedora Release Engineering - 2.2.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild * Thu Jan 19 2023 Fedora Release Engineering - 2.2.1-11 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242943 - 1-Click RCE Exploit in Libcue (CVE-2023-43641) https://bugzilla.redhat.com/show_bug.cgi?id=2242943 [ 2 ] Bug #2243167 - CVE-2023-43641 libcue: a out-of-bounds array access leads to RCE [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243167 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-1fe05ac8d9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . This revision for Fedora introduces a remedy for a critical security vulnerability in libcue, which has the potential to result in unauthorized code execution.. libcue RCE fix,Fedora security update,libcue backport,security advisory Fedora,arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2023 Critical Fedora
89

Fedora 38: FEDORA-2023-eec9ce5935 Critical: Libcue RCE Fix

This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-eec9ce5935 2023-10-12 01:44:15.277132 -------------------------------------------------------------------------------- Name : libcue Product : Fedora 38 Version : 2.2.1 Release : 13.fc38 URL : https://github.com/lipnitsk/libcue Summary : Cue sheet parser library Description : Libcue is intended for parsing a so-called cue sheet from a char string or a file pointer. For handling of the parsed data a convenient API is available. -------------------------------------------------------------------------------- Update Information: This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Adam Williamson - 2.2.1-13 - Fix CVE-2023-43641 (Kevin Backhouse) * Thu Jul 20 2023 Fedora Release Engineering - 2.2.1-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242943 - 1-Click RCE Exploit in Libcue (CVE-2023-43641) https://bugzilla.redhat.com/show_bug.cgi?id=2242943 [ 2 ] Bug #2243167 - CVE-2023-43641 libcue: a out-of-bounds array access leads to RCE [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2243167 -------------------------------------------------------------------------------- Thisupdate can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-eec9ce5935' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important patch for Fedora 38 tackles potential code execution vulnerabilities in libcue. Discover more about the resolution today!. Fedora Security Update, libcue RCE Fix, Fedora 38 Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 12, 2023 Critical Fedora
197

Debian 10 DLA-3615-1 Moderate: Libcue Out-Of-Bounds Access Warning

Kevin Backhouse discovered an out-of-bounds array access in Libcue, a library for parsing CD metadata, which could result in the execution of arbitrary code. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3615-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz October 12, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libcue Version : 2.2.1-2+deb10u1 CVE ID : CVE-2023-43641 Kevin Backhouse discovered an out-of-bounds array access in Libcue, a library for parsing CD metadata, which could result in the execution of arbitrary code. For Debian 10 buster, this problem has been fixed in version 2.2.1-2+deb10u1. We recommend that you upgrade your libcue packages. For the detailed security status of libcue please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libcue Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A security update for libcue addresses an out-of-bounds memory access vulnerability that could potentially allow attackers to execute arbitrary code.. Debian Update, Libcue Security, Out-of-Bounds Access, Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar%202 Oct 11, 2023 Debian LTS
89

Fedora 39: 2023-f4e74a94a2 Critical: Libcue Arbitrary Code Execution

This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-f4e74a94a2 2023-10-11 18:50:45.975453 -------------------------------------------------------------------------------- Name : libcue Product : Fedora 39 Version : 2.2.1 Release : 13.fc39 URL : https://github.com/lipnitsk/libcue Summary : Cue sheet parser library Description : Libcue is intended for parsing a so-called cue sheet from a char string or a file pointer. For handling of the parsed data a convenient API is available. -------------------------------------------------------------------------------- Update Information: This update backports the fix for a serious security issue that could cause arbitrary code execution, tracked as CVE-2023-43641. See [this write-up by Kevin Backhouse](- gnome-cve-2023-43641/) for details. Thanks to Kevin for discovering the issue and writing the fix. -------------------------------------------------------------------------------- ChangeLog: * Tue Oct 10 2023 Adam Williamson - 2.2.1-13 - Fix CVE-2023-43641 (Kevin Backhouse) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2242943 - 1-Click RCE Exploit in Libcue (CVE-2023-43641) https://bugzilla.redhat.com/show_bug.cgi?id=2242943 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-f4e74a94a2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . An update addresses a critical vulnerability leading to unauthorized operations in libcue, designated as Fed-2023-f4e74b95b3.. Fedora Security Update, Libcue Execution Risk, Fedora 39 Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 11, 2023 Critical Fedora
87

Debian: DSA-5524-1 Important: Libcue Out-Of-Bounds Access Notice

Kevin Backhouse discovered an out-of-bounds array access in Libcue, a library for parsing CD metadata, which could result in the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5524-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 11, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libcue CVE ID : CVE-2023-43641 Kevin Backhouse discovered an out-of-bounds array access in Libcue, a library for parsing CD metadata, which could result in the execution of arbitrary code. For the oldstable distribution (bullseye), this problem has been fixed in version 2.2.1-3+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 2.2.1-4+deb12u1. We recommend that you upgrade your libcue packages. For the detailed security status of libcue please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libcue Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A serious vulnerability has been found in the libcue library affecting Debian systems, risking unauthorized code execution and data compromise. Debian Security, Libcue Out-Of-Bounds, Code Execution Vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 11, 2023 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200