Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 8 articles for you...
100

SUSE: 2024:3007-1 Moderate: Issue with Null Pointer in Libofx Library

* bsc#1129596 Cross-References: * CVE-2019-9656 . # Security update for libofx Announcement ID: SUSE-SU-2024:3007-1 Rating: moderate References: * bsc#1129596 Cross-References: * CVE-2019-9656 CVSS scores: * CVE-2019-9656 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2019-9656 ( SUSE ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2019-9656 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-9656 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libofx fixes the following issues: * CVE-2019-9656: Fixed null pointer dereference in function OFXApplication:startElement in lib/ofx_sgml.cpp (bsc#1129596) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-3007=1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 zypper in -t patch SUSE-SLE-WE-12-SP5-2024-3007=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libofx-debuginfo-0.9.9-3.10.1 * libofx-debugsource-0.9.9-3.10.1 * libofx-devel-0.9.9-3.10.1 * libofx-0.9.9-3.10.1 * SUSE Linux Enterprise Workstation Extension 12 12-SP5 (x86_64) * libofx-debuginfo-0.9.9-3.10.1 * libofx-debugsource-0.9.9-3.10.1 * libofx6-debuginfo-0.9.9-3.10.1 * libofx-0.9.9-3.10.1 * libofx6-0.9.9-3.10.1 ## References: *https://www.suse.com/security/cve/CVE-2019-9656.html * https://bugzilla.suse.com/show_bug.cgi?id=1129596 . A recent patch for libofx resolves a critical null pointer vulnerability, enhancing overall reliability throughout various SUSE systems.. libofx, SUSE Security, software update, system reliability, SUSE Linux. . LinuxSecurity.com Team

Calendar%202 Aug 23, 2024 SuSE
203

Mageia 8 Critical Advisory: 2022-0368 Libofx Memory Flaw Fix

The updated packages fix memory issues in libofx. (rhbz#2127755) References: - https://bugs.mageia.org/show_bug.cgi?id=30900 - https://bugzilla.redhat.com/show_bug.cgi?id=2127755 . MGASA-2022-0368 - Updated libofx packages fix security vulnerability Publication date: 13 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0368.html Type: security Affected Mageia releases: 8 The updated packages fix memory issues in libofx. (rhbz#2127755) References: - https://bugs.mageia.org/show_bug.cgi?id=30900 - https://bugzilla.redhat.com/show_bug.cgi?id=2127755 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/YP7TQYRM2UPP5R5NKSEGDFKJARD7VN4A/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/KB467JGE4PFVR3LULWPIHJNHW4ORBRRJ/ - https://bugzilla.redhat.com/show_bug.cgi?id=2130201 - https://github.com/libofx/libofx/issues/86 SRPMS: - 8/core/libofx-0.9.15-2.1.mga8 . Recent libofx updates in Mageia have fixed significant memory problems, greatly enhancing system safety and stability.. libofx update,Mageia security,security patch,software vulnerability,package fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 13, 2022 Critical Mageia
89

Fedora 35: 2022-c9028047bf High: LibOFX Memory Issues Fix

Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c9028047bf 2022-09-29 02:20:21.539366 --------------------------------------------------------------------------------Name : libofx Product : Fedora 35 Version : 0.10.7 Release : 2.fc35 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. * Fri Sep 9 2022 Gwyn Ciesla - 0.10.7-1 - 0.10.7 --------------------------------------------------------------------------------References: [ 1 ] Bug #2130202 - libofx: memory issues in libofx [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2130202 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c9028047bf' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send anemail to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Enhancements in memory handling for libofx within Fedora 35 bolster security and resolve multiple concerns. Discover further specifics here.. Memory Security Fixes, Fedora Update, LibOFX Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 28, 2022 Important Fedora
89

Fedora 36 FEDORA-2022-95000d85e2 Moderate Memory Issue in libofx

Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-95000d85e2 2022-09-28 12:10:21.036669 --------------------------------------------------------------------------------Name : libofx Product : Fedora 36 Version : 0.10.7 Release : 2.fc36 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. --------------------------------------------------------------------------------References: [ 1 ] Bug #2130202 - libofx: memory issues in libofx [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2130202 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-95000d85e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Critical memory-focused updates for libofx on Fedora 36 boosting user security and system reliability.. Fedora Update, LibOFX Library, Memory Fixes, Security Patches. . LinuxSecurity.com Team

Calendar%202 Sep 28, 2022 Fedora
89

Fedora 37: FEDORA-2022-cfb44eb79a Moderate: Libofx Memory Fix

Memory-related security fixes, BZ 2127755. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-cfb44eb79a 2022-09-24 00:15:02.320539 --------------------------------------------------------------------------------Name : libofx Product : Fedora 37 Version : 0.10.7 Release : 2.fc37 URL : https://github.com/libofx/libofx Summary : A library for supporting Open Financial Exchange (OFX) Description : This is the LibOFX library. It is a API designed to allow applications to very easily support OFX command responses, usually provided by financial institutions. See for details and specification. --------------------------------------------------------------------------------Update Information: Memory-related security fixes, BZ 2127755 --------------------------------------------------------------------------------ChangeLog: * Mon Sep 19 2022 Gwyn Ciesla - 0.10.8-1 - Patches from BZ 2127755. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-cfb44eb79a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives:https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Updates addressing memory vulnerabilities in libofx within Fedora 37 bolster security and fortify the system against potential risks.. libofx Update, Fedora Security, Memory Fixes, Open Financial Exchange. . LinuxSecurity.com Team

Calendar%202 Sep 23, 2022 Fedora
172

Ubuntu 16.04 LTS USN-4523-1 Critical: LibOFX Denial Of Service

LibOFX could be made to crash.. =========================================================================Ubuntu Security Notice USN-4523-1 September 21, 2020 libofx vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: LibOFX could be made to crash. Software Description: - libofx: client-side implementation of Open Financial Exchange specification Details: It was discovered that LibOFX did not properly check for errors in certain situations, leading to a NULL pointer dereference. A remote attacker could use this issue to cause a denial of service attack. (CVE-2019-9656) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: libofx-dev 1:0.9.10-1+deb8u2build0.16.04.1 libofx6 1:0.9.10-1+deb8u2build0.16.04.1 ofx 1:0.9.10-1+deb8u2build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4523-1 CVE-2019-9656 Package Information: https://launchpad.net/ubuntu/+source/libofx/1:0.9.10-1+deb8u2build0.16.04.1 . Ubuntu Security Notice USN-4523-2 informs about a vulnerability in libofx that could lead to a denial of service stemming from a NULL pointer dereferencing issue.. libofx, denial of service, Ubuntu security, remote exploit, vulnerability management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2020 Critical Ubuntu
203

Mageia 7: MGASA-2019-0409 Critical: Libofx NULL Pointer Dereference

Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656). . MGASA-2019-0409 - Updated libofx packages fix security vulnerability Publication date: 25 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0409.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-9656 Updated libofx packages fix security vulnerability: There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump (CVE-2019-9656). References: - https://bugs.mageia.org/show_bug.cgi?id=25732 - https://lists.debian.org/debian-lts-announce/2019/11/msg00021.html - https://www.cve.org/CVERecord?id=CVE-2019-9656 SRPMS: - 7/core/libofx-0.9.15-1.mga7 . Recent libofx updates resolve NULL pointer vulnerabilities, strengthening security for Mageia 7 users. Ensure your system remains secure with this crucial patch.. Mageia Update, Libofx Patch, Security Maintenance, Software Vulnerability, Linux Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2019 Critical Mageia
197

Debian 8: DLA-2001-1 Moderate: libofx NULL Pointer Issue

There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump. . Package : libofx Version : 1:0.9.10-1+deb8u2 CVE ID : CVE-2019-9656 Debian Bug : #924350 There is a NULL pointer dereference in the function OFXApplication::startElement in the file lib/ofx_sgml.cpp, as demonstrated by ofxdump. For Debian 8 "Jessie", this problem has been fixed in version 1:0.9.10-1+deb8u2. We recommend that you upgrade your libofx packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : libofx Version : 1:0.9.10-1+deb8u2 CVE ID : CVE-2019-9656 Debian Bug : #924350 There is a . there, pointer, dereference, function, ofxapplication, startelement, lib/ofx. . LinuxSecurity.com Team

Calendar%202 Nov 23, 2019 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200