Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian: DSA-3040-1 Critical: Rsyslog DoS Vulnerability Report

Rainer Gerhards, the rsyslog project leader, reported a vulnerability in Rsyslog, a system for log processing. As a consequence of this vulnerability an attacker can send malformed messages to a server, if this one accepts data from untrusted sources, and trigger a denial of . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3040-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ September 30, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : rsyslog CVE ID : CVE-2014-3634 Rainer Gerhards, the rsyslog project leader, reported a vulnerability in Rsyslog, a system for log processing. As a consequence of this vulnerability an attacker can send malformed messages to a server, if this one accepts data from untrusted sources, and trigger a denial of service attack. For the stable distribution (wheezy), this problem has been fixed in version 5.8.11-3+deb7u1. For the unstable distribution (sid), this problem has been fixed in version 8.4.1-1. We recommend that you upgrade your rsyslog packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-3041-1 resolves a severe vulnerability in syslog-ng that permits a malicious actor to leverage corrupted packets leading to service disruption.. Rsyslog, Debian Security, Denial of Service, System Update, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 30, 2014 Critical Debian
91

Gentoo: GLSA-200506-17 Moderate: SpamAssassin DoS Risk Resolution

SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin 3, Vipul's Razor: Denial of Service vulnerability Date: June 21, 2005 Bugs: #94722, #95492 ID: 200506-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SpamAssassin and Vipul's Razor are vulnerable to a Denial of Service attack when handling certain malformed messages. Background ========= SpamAssassin is an extensible email filter which is used to identify junk email. Vipul's Razor is a client for a distributed, collaborative spam detection and filtering network. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin < 3.0.4 > = 3.0.4 < 3.0.1 2 mail-filter/razor < 2.71 > = 2.71 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== SpamAssassin and Vipul's Razor contain a Denial of Service vulnerability when handling special misformatted long message headers. Impact ===== By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin/Vipul's Razorserver. Workaround ========= There is no known workaround at this time. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/spamassassin-3.0.4" All Vipul's Razor users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-filter/razor-2.71" References ========= [ 1 ] CAN-2005-1266 https://www.cve.org/CVERecord?id=CVE-CAN-2005-1266 [ 2 ] SpamAssassin Announcement https://lists.apache.org/thread/%This email address is being protected from spambots. You need JavaScript enabled to view it.%3E [ 3 ] Vipul's Razor Announcement ;forum_id=4259 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200506-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . A security flaw related to Denial of Service has been identified in both SpamAssassin and Vipul's Razor that impacts Gentoo environments. Timely upgrades are crucial.. Denial Of Service,Gentoo Security,SpamAssassin,Vipul's Razor,Update. . LinuxSecurity.com Team

Calendar%202 Jun 21, 2005 Gentoo
91

Gentoo: GLSA-200408-06 Advisory: SpamAssassin DoS Vulnerability

SpamAssassin is vulnerable to a Denial of Service attack when handling certain malformed messages.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: SpamAssassin: Denial of Service vulnerability Date: August 09, 2004 Bugs: #59483 ID: 200408-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= SpamAssassin is vulnerable to a Denial of Service attack when handling certain malformed messages. Background ========= SpamAssassin is an extensible email filter which is used to identify spam. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-filter/spamassassin = 2.64 Description ========== SpamAssassin contains an unspecified Denial of Service vulnerability. Impact ===== By sending a specially crafted message an attacker could cause a Denial of Service attack against the SpamAssassin service. Workaround ========= There is no known workaround at this time. All users are encouraged to upgrade to the latest available version of SpamAssassin. Resolution ========= All SpamAssassin users should upgrade to the latest version: # emerge sync # emerge -pv "> =mail-filter/spamassassin-2.64" # emerge "> =mail-filter/spamassassin-2.64" References ========= [ 1 ] SpamAssassin Release Announcement http://marc.theaimsgroup.com/?l=spamassassin-announce&m=109168121628767&w=2 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200408-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBF9N1zKC5hMHO6rkRAjo2AJ9xHeR8k8af8/7TZAIGWepDzOUkLACfSutp bq76MNaf0/5m8TfAiyfe5IY=ZqtN -----END PGP SIGNATURE----- . Security vulnerability in SpamAssassin on Gentoo has been identified; users should review details and apply solutions. Prompt upgrade advised for protection.. SpamAssassin Vulnerability,Gentoo Security Advisory,Denial of Service Attack. . LinuxSecurity.com Team

Calendar%202 Aug 09, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200