Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia: 2020-0010 Critical: Cyrus-IMAPD Access Control Issue

Updated cyrus-imapd packages fix security vulnerability: It was discovered that the lmtpd component of the Cyrus IMAP server created mailboxes with administrator privileges if the "fileinto" was used, bypassing ACL checks (CVE-2019-19783). . MGASA-2020-0010 - Updated cyrus-imapd packages fix security vulnerability Publication date: 05 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0010.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-19783 Updated cyrus-imapd packages fix security vulnerability: It was discovered that the lmtpd component of the Cyrus IMAP server created mailboxes with administrator privileges if the "fileinto" was used, bypassing ACL checks (CVE-2019-19783). References: - https://bugs.mageia.org/show_bug.cgi?id=25913 - https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.12.html - https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.13.html - - https://www.cyrusimap.org/imap/download/release-notes/2.5/x/2.5.15.html - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/PHV3TUU53WCKJ3BBRK2EHAF44MSZEFK6/ - https://lists.debian.org/debian-security-announce/2019/msg00244.html - https://www.cve.org/CVERecord?id=CVE-2019-19783 SRPMS: - 7/core/cyrus-imapd-2.5.15-1.mga7 . Revised dovecot packages address security vulnerability in Manjaro distribution concerning unauthorized access to email accounts.. cyrus imapd update, mailbox permissions, Mageia security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 05, 2020 Critical Mageia
200

Scientific Linux: Low Severity Mailbox Permissions Issue in Shadow-Utils

Low: shadow-utils security and bug fix update. Date: Fri, 15 Jun 2007 17:29:05 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for shadow-utils on SL3,x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Low: shadow-utils security and bug fix update Issue date: 2007-06-11 CVE Names: CVE-2006-1174 A flaw was found in the useradd tool in shadow-utils. A new user's mailbox, when created, could have random permissions for a short period. This could allow a local attacker to read or modify the mailbox. (CVE-2006-1174) SL 3.0.x SRPMS: shadow-utils-4.0.3-29.RHEL3.src.rpm i386: shadow-utils-4.0.3-29.RHEL3.i386.rpm x86_64: shadow-utils-4.0.3-29.RHEL3.x86_64.rpm -Connie Sieh -Troy Dawson . The latest update to the Shadow-utils package for Scientific Linux resolves security issues and bugs related to access permissions in newly created user email directories.. shadow-utils update, Scientific Linux security, mailbox permissions, security fix. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jun 15, 2007 Low Scientific Linux
98

Red Hat Enterprise Linux 3 RHSA-2007:0431-01 Low: Mailbox Issue

An updated shadow-utils package that fixes a security issue and several bugs is now available.A flaw was found in the useradd tool in shadow-utils. A new user's mailbox, when created, could have random permissions for a short period. This could allow a local attacker to read or modify the mailbox. This update has been rated as having low security impact by the Red Hat Security Response Team.. - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Low: shadow-utils security and bug fix update Advisory ID: RHSA-2007:0431-01 Advisory URL: https://access.redhat.com/errata/RHSA-2007:0431.html Issue date: 2007-06-07 Updated on: 2007-06-11 Product: Red Hat Enterprise Linux Keywords: mailbox race condition CVE Names: CVE-2006-1174 - ---------------------------------------------------------------------1. Summary: An updated shadow-utils package that fixes a security issue and several bugs is now available. This update has been rated as having low security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Problem description: The shadow-utils package includes the necessary programs for converting UNIX password files to the shadow password format, as well as programs for managing user and group accounts. A flaw was found in the useradd tool in shadow-utils. A new user's mailbox, when created, could have random permissions for a short period. This could allow a local attacker to read or modify the mailbox. (CVE-2006-1174) This update also fixes the following bugs: * shadow-utils debuginfo package was empty. * chage.1 and chage -l gave incorrect information aboutsp_inact. All users of shadow-utils are advised to upgrade to this updated package, which contains backported patches to resolve these issues. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Use Red Hat Network to download and update your packages. To launch the Red Hat Update Agent, use the following command: up2date For information on how to install packages manually, refer to the following Web page for the System Administration or Customization guide specific to your system: https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/10/ 5. Bug IDs fixed (http://bugzilla.redhat.com/): 176949 - shadow-utils-debuginfo is empty 216635 - chage does not show the Account Expires if its shadow field is 0. 229194 - CVE-2006-1174 shadow-utils mailbox creation race condition 6. RPMs required: Red Hat Enterprise Linux AS version 3: SRPMS: 966d844be451d09e732289fcf217af85 shadow-utils-4.0.3-29.RHEL3.src.rpm i386: 70b7cf4df9bd1bee11c1f290ae3a1bbe shadow-utils-4.0.3-29.RHEL3.i386.rpm 2878f009ae2277881d44c4f05fec1671 shadow-utils-debuginfo-4.0.3-29.RHEL3.i386.rpm ia64: 83ccf4e549535ebe265043c2ebdd6a40 shadow-utils-4.0.3-29.RHEL3.ia64.rpm 5f83cb4808a46b52282e1acbce406a70 shadow-utils-debuginfo-4.0.3-29.RHEL3.ia64.rpm ppc: c686de929e196cd87b203e1ab85bbd01 shadow-utils-4.0.3-29.RHEL3.ppc.rpm 1a7206beb87ea524d7fafa5f69a7beff shadow-utils-debuginfo-4.0.3-29.RHEL3.ppc.rpm s390: 7badcd687970e0393547cac663e4d5b8 shadow-utils-4.0.3-29.RHEL3.s390.rpm a24128e6b4f152c0cdbeec5d671b6578 shadow-utils-debuginfo-4.0.3-29.RHEL3.s390.rpm s390x: cdd3cc34271e7b59c0374f03a46e8715 shadow-utils-4.0.3-29.RHEL3.s390x.rpm 107d87178483ddb3c93342dfb7ba5120 shadow-utils-debuginfo-4.0.3-29.RHEL3.s390x.rpm x86_64: e6661e59bc80a8bb3f49566183a082a0 shadow-utils-4.0.3-29.RHEL3.x86_64.rpm a380a8d6aabd84211c8b5850299a3ea1 shadow-utils-debuginfo-4.0.3-29.RHEL3.x86_64.rpm RedHat Desktop version 3: SRPMS: 966d844be451d09e732289fcf217af85 shadow-utils-4.0.3-29.RHEL3.src.rpm i386: 70b7cf4df9bd1bee11c1f290ae3a1bbe shadow-utils-4.0.3-29.RHEL3.i386.rpm 2878f009ae2277881d44c4f05fec1671 shadow-utils-debuginfo-4.0.3-29.RHEL3.i386.rpm x86_64: e6661e59bc80a8bb3f49566183a082a0 shadow-utils-4.0.3-29.RHEL3.x86_64.rpm a380a8d6aabd84211c8b5850299a3ea1 shadow-utils-debuginfo-4.0.3-29.RHEL3.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 966d844be451d09e732289fcf217af85 shadow-utils-4.0.3-29.RHEL3.src.rpm i386: 70b7cf4df9bd1bee11c1f290ae3a1bbe shadow-utils-4.0.3-29.RHEL3.i386.rpm 2878f009ae2277881d44c4f05fec1671 shadow-utils-debuginfo-4.0.3-29.RHEL3.i386.rpm ia64: 83ccf4e549535ebe265043c2ebdd6a40 shadow-utils-4.0.3-29.RHEL3.ia64.rpm 5f83cb4808a46b52282e1acbce406a70 shadow-utils-debuginfo-4.0.3-29.RHEL3.ia64.rpm x86_64: e6661e59bc80a8bb3f49566183a082a0 shadow-utils-4.0.3-29.RHEL3.x86_64.rpm a380a8d6aabd84211c8b5850299a3ea1 shadow-utils-debuginfo-4.0.3-29.RHEL3.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 966d844be451d09e732289fcf217af85 shadow-utils-4.0.3-29.RHEL3.src.rpm i386: 70b7cf4df9bd1bee11c1f290ae3a1bbe shadow-utils-4.0.3-29.RHEL3.i386.rpm 2878f009ae2277881d44c4f05fec1671 shadow-utils-debuginfo-4.0.3-29.RHEL3.i386.rpm ia64: 83ccf4e549535ebe265043c2ebdd6a40 shadow-utils-4.0.3-29.RHEL3.ia64.rpm 5f83cb4808a46b52282e1acbce406a70 shadow-utils-debuginfo-4.0.3-29.RHEL3.ia64.rpm x86_64: e6661e59bc80a8bb3f49566183a082a0 shadow-utils-4.0.3-29.RHEL3.x86_64.rpm a380a8d6aabd84211c8b5850299a3ea1 shadow-utils-debuginfo-4.0.3-29.RHEL3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-1174 https://access.redhat.com/security/updates/classification#low 8. Contact: The Red Hat security contact is . Morecontact details at https://access.redhat.com/security/team/contact/ Copyright 2007 Red Hat, Inc. . A new release for shadow-utils rectifies vulnerabilities and issues in Red Hat Enterprise Linux, classified as low severity.. shadow-utils update, mailbox permissions, bug fixes. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jun 11, 2007 Low Red Hat
200

Scientific Linux 4: Low Severity Advisory for Shadow-Utils Security Issue

Low: shadow-utils security and bug fix update. Date: Mon, 14 May 2007 15:53:43 -0500 Reply-To: Connie Sieh Sender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for shadow-utils on SL4.x i386/x86_64 Comments: To: scientific Synopsis: Low: shadow-utils security and bug fix update Issue date: 2007-05-01 CVE Names: CVE-2006-1174 A flaw was found in the useradd tool in shadow-utils. A new user's mailbox, when created, could have random permissions for a short period. This could allow a local attacker to read or modify the mailbox. (CVE-2006-1174) SRPMS: shadow-utils-4.0.3-61.RHEL4.src.rpm i386: shadow-utils-4.0.3-61.RHEL4.i386.rpm x86_64: shadow-utils-4.0.3-61.RHEL4.x86_64.rpm -Connie Sieh -Troy Dawson . A minor update for shadow-utils fixes a permissions flaw in mailboxes that could lead to potential local access vulnerabilities.. shadow-utils update, Scientific Linux advisory, security patch, bug fix update. . Severity: Low. LinuxSecurity.com Team

Calendar 2 May 14, 2007 Low Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here