Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
198

Arch Linux: ASA-201706-25 Medium: lxterminal Access Control Bypass

The package lxterminal before version 0.3.0-2 is vulnerable to access restriction bypass. . Arch Linux Security Advisory ASA-201706-25 ========================================= Severity: Medium Date : 2017-06-22 CVE-ID : CVE-2016-10369 Package : lxterminal Type : access restriction bypass Remote : No Link : https://security.archlinux.org/AVG-264 Summary ====== The package lxterminal before version 0.3.0-2 is vulnerable to access restriction bypass. Resolution ========= Upgrade to 0.3.0-2. # pacman -Syu "lxterminal> =0.3.0-2" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control). Impact ===== A local attacker might be able to cause a denial of service or bypass the terminal access control to gain privileges or access sensitive information. References ========= ;a=commitdiff;h=f99163c6ff8b2f57c5f37b1ce5d62cf7450d4648 https://unix.stackexchange.com/questions/333539/lxterminal-in-the-netstat-output/333578 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=862098 https://security.archlinux.org/CVE-2016-10369 . Arch Linux Security Advisory ASA-202109-15 tackles a moderate severity privilege escalation vulnerability in gnome-terminal.. lxterminal Update, Access Control, Arch Linux Advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 22, 2017 Medium ArchLinux
89

Fedora 26 lxterminal Update: CVE-2016-10369 DoS Risk Mitigated

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-e9936d561b 2017-06-09 18:48:36.531419 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 26 Version : 0.3.0 Release : 3.fc26 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Dealing with a vulnerability in lxterminal on Fedora 26 involved socket-related issues, with patches accessible via system updates.. lxterminal security flaw,fedora 26 update,DoS prevention. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2017 Critical Fedora
89

Fedora 24 lxterminal 0.3.0 Security Fix For Socket Threat

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 24 Version : 0.3.0 Release : 3.fc24 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An important patch for Fedora 24 has been released to mitigate a potential denial-of-service vulnerability stemming from an issue in the socket generation of lxterminal.. lxterminal Security, Fedora Security Update, Socket Issue, Linux Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 30, 2017 Important Fedora
89

Fedora 24 pcmanfm Update Critical: lxterminal Denial of Service Fix

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : pcmanfm Product : Fedora 24 Version : 1.2.5 Release : 2.fc24 URL : Summary : Extremly fast and lightweight file manager Description : PCMan File Manager is an extremly fast and lightweight file manager which features tabbed browsing and user-friendly interface. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcmanfm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . A vulnerability in lxterminal and various LXDE applications has been resolved with updated RPM packages for Fedora 24.. Fedora Update, PCManFM Fix, LXDE Security, Denial of Service Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 30, 2017 Critical Fedora
89

Fedora 24 Moderate Advisory: Menu-Cache DoS Risk Due To Socket Creation

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3f2d5790d2 2017-05-30 15:08:36.562803 --------------------------------------------------------------------------------Name : menu-cache Product : Fedora 24 Version : 1.0.2 Release : 4.D20170514git56f6668459.fc24 URL : Summary : Caching mechanism for freedesktop.org compliant menus Description : Menu-cache is a caching mechanism for freedesktop.org compliant menus to speed up parsing of the menu entries. It is currently used by some of components of the LXDE desktop environment such as LXPanel or LXLauncher. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function[fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade menu-cache' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch addresses vulnerabilities in LXDE, mitigating potential DoS through socket instantiation. User re-login necessary post-installation.. Fedora Update, LXDE Security, DoS Prevention, Menu-Cache Fix. . LinuxSecurity.com Team

Calendar%202 May 30, 2017 Fedora
89

Fedora 25 lxterminal Update: CVE-2016-10369 Moderate DoS Threat

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-6950ea5d05 2017-05-17 03:56:11.755807 --------------------------------------------------------------------------------Name : lxterminal Product : Fedora 25 Version : 0.3.0 Release : 3.fc25 URL : Summary : Desktop-independent VTE-based terminal emulator Description : LXterminal is a VTE-based terminal emulator with support for multiple tabs. It is completely desktop-independent and does not have any unnecessary dependencies. In order to reduce memory usage and increase the performance all instances of the terminal are sharing a single process. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creationin get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade lxterminal' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An identified weakness in LXDE's lxterminal results in potential DOS threats. Make sure to update immediately for resolution and enhanced functionality.. Fedora Security Update,LXDE DOS Risk,LXterminal Patch. . LinuxSecurity.com Team

Calendar%202 May 17, 2017 Fedora
89

Fedora 25: pcmanfm Moderate DoS Threat Addressed via RPMs

A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-6950ea5d05 2017-05-17 03:56:11.755807 --------------------------------------------------------------------------------Name : pcmanfm Product : Fedora 25 Version : 1.2.5 Release : 2.fc25 URL : Summary : Extremly fast and lightweight file manager Description : PCMan File Manager is an extremly fast and lightweight file manager which features tabbed browsing and user-friendly interface. --------------------------------------------------------------------------------Update Information: A potential security flaw is found on LXDE products, which create socket under /tmp with some predictable names, which may leads to DOS. The security flow on lxterminal is now assigned as CVE-2016-10369. Some other components also had similar issues. These new rpms should fix these issues. At least relogin is required to make this fix effect. --------------------------------------------------------------------------------References: [ 1 ] Bug #1449114 - CVE-2016-10369 lxterminal: Insecure use of /tmp for a socket file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1449114 [ 2 ] Bug #1451070 - CVE-2017-8933 menu-cache: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451070 [ 3 ] Bug #1451065 - CVE-2017-8934 pcmanfm: Insecure temporary file creation in get_socket_name function [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451065 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade pcmanfm' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The gnome-shell security patch resolves a possible DDoS vulnerability in GNOME applications with refreshed RPMs. Session restart needed.. Fedora PCManFM Update, DoS Threats, LXDE Vulnerability Fix. . LinuxSecurity.com Team

Calendar%202 May 17, 2017 Fedora
197

Debian Wheezy DLA-935-1 Moderate: Lxterminal Local DoS Issue

It was discovered that there was a local denial of service vulnerability in lxterminal, the terminal emulator for the LXDE desktop environment. This was caused by an insecure use of temporary files for a socket file. . Hash: SHA256 Package : lxterminal Version : 0.1.11-4+deb7u1 CVE ID : CVE-2016-10369 Debian Bug : #862098 It was discovered that there was a local denial of service vulnerability in lxterminal, the terminal emulator for the LXDE desktop environment. This was caused by an insecure use of temporary files for a socket file. For Debian 7 "Wheezy", this issue has been fixed in lxterminal version 0.1.11-4+deb7u1. We recommend that you upgrade your lxterminal packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . A specific denial of service vulnerability related to lxterminal has been discovered and successfully addressed in the recent package updates for Debian.. lxterminal Security, Debian Package Update, Service Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 May 10, 2017 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200