Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
200

Scientific Linux: SLSA-2015:1482-1 Critical: libuser Privilege Escalation

Important: libuser security update. Date: Mon, 3 Aug 2015 15:32:23 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA Important: libuser on SL6.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: libuser security update Advisory ID: SLSA-2015:1482-1 Issue Date: 2015-07-23 CVE Numbers: CVE-2015-3245 CVE-2015-3246 -- Two flaws were found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root. (CVE-2015-3245, CVE-2015-3246) -- SL6 x86_64 libuser-0.56.13-8.el6_7.i686.rpm libuser-0.56.13-8.el6_7.x86_64.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-python-0.56.13-8.el6_7.x86_64.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.x86_64.rpm i386 libuser-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-python-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm - Scientific Linux Development Team . Crucial enhancement released for libuser on SL6.x, tackling access vulnerabilities that could result in possible privilege elevation.. libuser security update, SCILinux patch news, security flaws in libuser. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 03, 2015 Important Scientific Linux
202

openSUSE 13.2: 2015:1233-2 Critical Libuser Escalation Vulnerability Alert

An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available. An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for libuser ______________________________________________________________________________ Announcement ID: openSUSE-SU-2015:1332-1 Rating: important References: #937533 Cross-References: CVE-2015-3246 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: libuser was updated to fix on security issue. The following vulnerability was fixed: * CVE-2015-3246: local root exploit through passwd file handling (boo#937533) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2015-529=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): libuser-0.60-3.3.1 libuser-debuginfo-0.60-3.3.1 libuser-debugsource-0.60-3.3.1 libuser-devel-0.60-3.3.1 libuser-python-0.60-3.3.1 libuser-python-debuginfo-0.60-3.3.1 libuser1-0.60-3.3.1 libuser1-debuginfo-0.60-3.3.1 - openSUSE 13.2 (noarch): libuser-lang-0.60-3.3.1 References: https://www.suse.com/security/cve/CVE-2015-3246.html https://bugzilla.suse.com/show_bug.cgi?id=937533 . Crucial openSUSE security patch for libuser, addressing a local privilege escalation vulnerability via passwd file processing.. openSUSE, libuser, security update, local root exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 03, 2015 Important OpenSUSE
89

Fedora: 2015-12064 Critical: libuser Security Flaws Addressed

Security fix for CVE-2015-3245, CVE-2015-3246. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12064 2015-07-29 21:35:17 -------------------------------------------------------------------------------- Name : libuser Product : Fedora 21 Version : 0.62 Release : 1.fc21 URL : https://fedoraproject.org/wiki/Infrastructure/Fedorahosted-retirement Summary : A user and group account administration library Description : The libuser library implements a standardized interface for manipulating and administering user and group accounts. The library uses pluggable back-ends to interface to its data sources. Sample applications modeled after those included with the shadow password suite are included. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3245, CVE-2015-3246 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Miloslav Trmač - 0.62-1 - Update to libuser-0.62 Resolves: #1246225 (CVE-2015-3245, CVE-2015-3246) * Wed Jun 17 2015 Fedora Release Engineering - 0.61-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed Mar 25 2015 Miloslav Trmač - 0.61-1 - Update to libuser-0.61, notably adding Python 3 bindings Resolves: #1014555 - Filter out libuser plugin and Python extension Provides: * Sat Feb 21 2015 Till Maas - 0.60-7 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field https://bugzilla.redhat.com/show_bug.cgi?id=1233043 [ 2 ] Bug #1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file https://bugzilla.redhat.com/show_bug.cgi?id=1233052 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libuser' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . OpenSUSE's package manager update resolves CVE-2022-3456 and CVE-2022-3457, providing patches and remediation guidelines.. libuser Security, Fedora Update, User Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 03, 2015 Critical Fedora
89

Fedora 22: FEDORA-2015-12301 Critical: Libuser DoS Threat

Security fix for CVE-2015-3245, CVE-2015-3246. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12301 2015-07-29 21:45:05 -------------------------------------------------------------------------------- Name : libuser Product : Fedora 22 Version : 0.62 Release : 1.fc22 URL : https://fedoraproject.org/wiki/Infrastructure/Fedorahosted-retirement Summary : A user and group account administration library Description : The libuser library implements a standardized interface for manipulating and administering user and group accounts. The library uses pluggable back-ends to interface to its data sources. Sample applications modeled after those included with the shadow password suite are included. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2015-3245, CVE-2015-3246 -------------------------------------------------------------------------------- ChangeLog: * Thu Jul 23 2015 Miloslav Trmač - 0.62-1 - Update to libuser-0.62 Resolves: #1246225 (CVE-2015-3245, CVE-2015-3246) * Wed Jun 17 2015 Fedora Release Engineering - 0.61-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild * Wed Mar 25 2015 Miloslav Trmač - 0.61-1 - Update to libuser-0.61, notably adding Python 3 bindings Resolves: #1014555 - Filter out libuser plugin and Python extension Provides: * Sat Feb 21 2015 Till Maas - 0.60-7 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field https://bugzilla.redhat.com/show_bug.cgi?id=1233043 [ 2 ] Bug #1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file https://bugzilla.redhat.com/show_bug.cgi?id=1233052 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libuser' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important patch release for libuser in Fedora 22 tackling significant vulnerabilities and improving user account protection.. Libuser Security, Fedora Update, User Account Management, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 30, 2015 Critical Fedora
198

Arch Linux: 201507-19 Critical Advisory for Libuser Privilege Escalation

The package libuser before version 0.62-1 is vulnerable to privilege escalation and denial of service. . Arch Linux Security Advisory ASA-201507-19 ========================================= Severity: Critical Date : 2015-07-24 CVE-ID : CVE-2015-3245 CVE-2015-3246 Package : libuser Type : multiple issues Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package libuser before version 0.62-1 is vulnerable to privilege escalation and denial of service. Resolution ========= Upgrade to 0.62-1. # pacman -Syu "libuser> =0.62-1" The problems have been fixed upstream in version 0.62. Workaround ========= None. Description ========== - CVE-2015-3245 (denial of service) It was found that libuser, as used by the chfn userhelper functionality, did not properly filter out newline characters in GECOS fields. A local, authenticated user could use this flaw to corrupt the /etc/passwd file, resulting in a denial-of-service on the system. - CVE-2015-3246 (privilege escalation) A flaw was found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root. Impact ===== A local authenticated user is able to use an application compiled against libuser to escalate privileges to root or perform a denial-of-service attack on the system by corrupting the /etc/passwd file. References ========= https://seclists.org/oss-sec/2015/q3/185 https://access.redhat.com/security/cve/CVE-2015-3245 https://access.redhat.com/security/cve/CVE-2015-3246 . Essential Security Notice for Arch Linux: Update libuser to mitigate risks of privilege escalation and denial-of-service vulnerabilities.. Privilege Escalation, Denial of Service, Arch Linux Security, libuser Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 24, 2015 Critical ArchLinux
200

Scientific Linux SL7: SLSA-2015:1483-1 Important libuser Denial of Service

Important: libuser security update. Date: Fri, 24 Jul 2015 13:08:08 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: libuser on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Important: libuser security update Advisory ID: SLSA-2015:1483-1 Issue Date: 2015-07-23 CVE Numbers: CVE-2015-3245 CVE-2015-3246 -- Two flaws were found in the way the libuser library handled the /etc/passwd file. A local attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root. (CVE-2015-3245, CVE-2015-3246) -- SL7 x86_64 libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-0.60-7.el7_1.i686.rpm libuser-0.60-7.el7_1.x86_64.rpm libuser-python-0.60-7.el7_1.x86_64.rpm libuser-devel-0.60-7.el7_1.i686.rpm libuser-devel-0.60-7.el7_1.x86_64.rpm - Scientific Linux Development Team . Critical libuser patch released to fix vulnerabilities that might permit privilege elevation and denial-of-service in Scientific Linux.. libuser security update, SL7.x issues, Scientific Linux flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 24, 2015 Important Scientific Linux
98

Red Hat Enterprise Linux 6 RHSA-2015:1482-01 Important Denial of Service

Updated libuser packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: libuser security update Advisory ID: RHSA-2015:1482-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:1482.html Issue date: 2015-07-23 CVE Names: CVE-2015-3245 CVE-2015-3246 ==================================================================== 1. Summary: Updated libuser packages that fix two security issues are now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The libuser library implements a standardized interface for manipulating and administering user and group accounts. Sample applications that are modeled after applications from the shadow password suite (shadow-utils) are included in these packages. Two flaws were found in the way the libuser library handled the /etc/passwd file. Alocal attacker could use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root. (CVE-2015-3245, CVE-2015-3246) Red Hat would like to thank Qualys for reporting these issues. All libuser users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field 1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: libuser-0.56.13-8.el6_7.src.rpm i386: libuser-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-python-0.56.13-8.el6_7.i686.rpm x86_64: libuser-0.56.13-8.el6_7.i686.rpm libuser-0.56.13-8.el6_7.x86_64.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-python-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm x86_64: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: libuser-0.56.13-8.el6_7.src.rpm x86_64: libuser-0.56.13-8.el6_7.i686.rpm libuser-0.56.13-8.el6_7.x86_64.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-python-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v.6): x86_64: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: libuser-0.56.13-8.el6_7.src.rpm i386: libuser-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-python-0.56.13-8.el6_7.i686.rpm ppc64: libuser-0.56.13-8.el6_7.ppc.rpm libuser-0.56.13-8.el6_7.ppc64.rpm libuser-debuginfo-0.56.13-8.el6_7.ppc.rpm libuser-debuginfo-0.56.13-8.el6_7.ppc64.rpm libuser-python-0.56.13-8.el6_7.ppc64.rpm s390x: libuser-0.56.13-8.el6_7.s390.rpm libuser-0.56.13-8.el6_7.s390x.rpm libuser-debuginfo-0.56.13-8.el6_7.s390.rpm libuser-debuginfo-0.56.13-8.el6_7.s390x.rpm libuser-python-0.56.13-8.el6_7.s390x.rpm x86_64: libuser-0.56.13-8.el6_7.i686.rpm libuser-0.56.13-8.el6_7.x86_64.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-python-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 6): i386: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm ppc64: libuser-debuginfo-0.56.13-8.el6_7.ppc.rpm libuser-debuginfo-0.56.13-8.el6_7.ppc64.rpm libuser-devel-0.56.13-8.el6_7.ppc.rpm libuser-devel-0.56.13-8.el6_7.ppc64.rpm s390x: libuser-debuginfo-0.56.13-8.el6_7.s390.rpm libuser-debuginfo-0.56.13-8.el6_7.s390x.rpm libuser-devel-0.56.13-8.el6_7.s390.rpm libuser-devel-0.56.13-8.el6_7.s390x.rpm x86_64: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: libuser-0.56.13-8.el6_7.src.rpm i386: libuser-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-python-0.56.13-8.el6_7.i686.rpm x86_64: libuser-0.56.13-8.el6_7.i686.rpm libuser-0.56.13-8.el6_7.x86_64.rpm libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-python-0.56.13-8.el6_7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm x86_64: libuser-debuginfo-0.56.13-8.el6_7.i686.rpm libuser-debuginfo-0.56.13-8.el6_7.x86_64.rpm libuser-devel-0.56.13-8.el6_7.i686.rpm libuser-devel-0.56.13-8.el6_7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-3245 https://access.redhat.com/security/cve/CVE-2015-3246 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVsVKrXlSAg2UNWIIRAjpOAJ9DwfF87lCuvgBqDezv+SqnN/WNMgCdHRoE rXyJf0kCR3YTxcOuV8FFzbE=W9F2 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Address critical vulnerabilities in libuser for Red Hat Enterprise Linux 6 users. Apply updates promptly!. Libuser Security Issues, Red Hat Linux Security Update, Important Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2015 Important Red Hat
98

Red Hat 7 RHSA-2015-1483-01 Critical libuser Denial of Service Risk

Updated libuser packages that fix two security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: libuser security update Advisory ID: RHSA-2015:1483-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:1483.html Issue date: 2015-07-23 CVE Names: CVE-2015-3245 CVE-2015-3246 ==================================================================== 1. Summary: Updated libuser packages that fix two security issues are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The libuser library implements a standardized interface for manipulating and administering user and group accounts. Sample applications that are modeled after applications from the shadow password suite (shadow-utils) are included in these packages. Two flaws were found in the way the libuser library handled the /etc/passwd file. A local attackercould use an application compiled against libuser (for example, userhelper) to manipulate the /etc/passwd file, which could result in a denial of service or possibly allow the attacker to escalate their privileges to root. (CVE-2015-3245, CVE-2015-3246) Red Hat would like to thank Qualys for reporting these issues. All libuser users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1233043 - CVE-2015-3245 libuser does not filter newline characters in the GECOS field 1233052 - CVE-2015-3246 libuser: Security flaw in handling /etc/passwd file 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: libuser-0.60-7.el7_1.src.rpm x86_64: libuser-0.60-7.el7_1.i686.rpm libuser-0.60-7.el7_1.x86_64.rpm libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-python-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-devel-0.60-7.el7_1.i686.rpm libuser-devel-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: libuser-0.60-7.el7_1.src.rpm x86_64: libuser-0.60-7.el7_1.i686.rpm libuser-0.60-7.el7_1.x86_64.rpm libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-python-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-devel-0.60-7.el7_1.i686.rpm libuser-devel-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: libuser-0.60-7.el7_1.src.rpm ppc64: libuser-0.60-7.el7_1.ppc.rpm libuser-0.60-7.el7_1.ppc64.rpm libuser-debuginfo-0.60-7.el7_1.ppc.rpm libuser-debuginfo-0.60-7.el7_1.ppc64.rpm libuser-python-0.60-7.el7_1.ppc64.rpm s390x: libuser-0.60-7.el7_1.s390.rpm libuser-0.60-7.el7_1.s390x.rpm libuser-debuginfo-0.60-7.el7_1.s390.rpm libuser-debuginfo-0.60-7.el7_1.s390x.rpm libuser-python-0.60-7.el7_1.s390x.rpm x86_64: libuser-0.60-7.el7_1.i686.rpm libuser-0.60-7.el7_1.x86_64.rpm libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-python-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: libuser-0.60-7.ael7b_1.src.rpm ppc64le: libuser-0.60-7.ael7b_1.ppc64le.rpm libuser-debuginfo-0.60-7.ael7b_1.ppc64le.rpm libuser-python-0.60-7.ael7b_1.ppc64le.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64: libuser-debuginfo-0.60-7.el7_1.ppc.rpm libuser-debuginfo-0.60-7.el7_1.ppc64.rpm libuser-devel-0.60-7.el7_1.ppc.rpm libuser-devel-0.60-7.el7_1.ppc64.rpm s390x: libuser-debuginfo-0.60-7.el7_1.s390.rpm libuser-debuginfo-0.60-7.el7_1.s390x.rpm libuser-devel-0.60-7.el7_1.s390.rpm libuser-devel-0.60-7.el7_1.s390x.rpm x86_64: libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-devel-0.60-7.el7_1.i686.rpm libuser-devel-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): ppc64le: libuser-debuginfo-0.60-7.ael7b_1.ppc64le.rpm libuser-devel-0.60-7.ael7b_1.ppc64le.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libuser-0.60-7.el7_1.src.rpm x86_64: libuser-0.60-7.el7_1.i686.rpm libuser-0.60-7.el7_1.x86_64.rpm libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-python-0.60-7.el7_1.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: libuser-debuginfo-0.60-7.el7_1.i686.rpm libuser-debuginfo-0.60-7.el7_1.x86_64.rpm libuser-devel-0.60-7.el7_1.i686.rpm libuser-devel-0.60-7.el7_1.x86_64.rpm These packages are GPG signed by Red Hat forsecurity. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2015-3245 https://access.redhat.com/security/cve/CVE-2015-3246 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFVsVK7XlSAg2UNWIIRAkWhAJwK0UBF7Q37z7j2hKsjYxwXvq+TaQCfWVvM hq94ftcCu6cx0aYH6VYBv1A=CXDY -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . New libuser packages have been released for Red Hat Enterprise Linux 7, rectifying significant security vulnerabilities and implementing necessary patches.. libuser Security Update, Red Hat Enterprise Linux, Important Security Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 23, 2015 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200