Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Marcin Nowak discovered that dbclient(1) hostname arguments with a comma (for multihop) are passed to the shell which could result in running arbitrary shell commands locally. That could be a security issue in situations where dbclient(1) is passed untrusted hostname arguments. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4169-1
* bsc#1216588 Cross-References: * CVE-2023-46137 . # Security update for python-Twisted Announcement ID: SUSE-SU-2023:4608-1 Rating: moderate References: * bsc#1216588 Cross-References: * CVE-2023-46137 CVSS scores: * CVE-2023-46137 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2023-46137 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * Python 3 Module 15-SP4 * Python 3 Module 15-SP5 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-Twisted fixes the following issues: * CVE-2023-46137: Fixed issue inside serializing pipelined HTTP requests. (bsc#1216588) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2023-4608=1 openSUSE-SLE-15.4-2023-4608=1 * openSUSE Leap 15.5 zypper in -t patch openSUSE-SLE-15.5-2023-4608=1 * Python 3 Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Python3-15-SP4-2023-4608=1 * Python 3 Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Python3-15-SP5-2023-4608=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-Twisted-22.10.0-150400.5.13.1 * python311-Twisted-conch_nacl-22.10.0-150400.5.13.1 * python311-Twisted-serial-22.10.0-150400.5.13.1 * python311-Twisted-tls-22.10.0-150400.5.13.1 * python311-Twisted-contextvars-22.10.0-150400.5.13.1 * python311-Twisted-http2-22.10.0-150400.5.13.1 * python311-Twisted-conch-22.10.0-150400.5.13.1 * python311-Twisted-all_non_platform-22.10.0-150400.5.13.1 * openSUSE Leap 15.5 (noarch) * python311-Twisted-22.10.0-150400.5.13.1 * python311-Twisted-conch_nacl-22.10.0-150400.5.13.1 * python311-Twisted-serial-22.10.0-150400.5.13.1 * python311-Twisted-tls-22.10.0-150400.5.13.1 * python311-Twisted-contextvars-22.10.0-150400.5.13.1 * python311-Twisted-http2-22.10.0-150400.5.13.1 * python311-Twisted-conch-22.10.0-150400.5.13.1 * python311-Twisted-all_non_platform-22.10.0-150400.5.13.1 * Python 3 Module 15-SP4 (noarch) * python311-Twisted-22.10.0-150400.5.13.1 * python311-Twisted-conch_nacl-22.10.0-150400.5.13.1 * python311-Twisted-serial-22.10.0-150400.5.13.1 * python311-Twisted-tls-22.10.0-150400.5.13.1 * python311-Twisted-contextvars-22.10.0-150400.5.13.1 * python311-Twisted-http2-22.10.0-150400.5.13.1 * python311-Twisted-conch-22.10.0-150400.5.13.1 * python311-Twisted-all_non_platform-22.10.0-150400.5.13.1 * Python 3 Module 15-SP5 (noarch) * python311-Twisted-22.10.0-150400.5.13.1 * python311-Twisted-conch_nacl-22.10.0-150400.5.13.1 * python311-Twisted-serial-22.10.0-150400.5.13.1 * python311-Twisted-tls-22.10.0-150400.5.13.1 * python311-Twisted-contextvars-22.10.0-150400.5.13.1 * python311-Twisted-http2-22.10.0-150400.5.13.1 * python311-Twisted-conch-22.10.0-150400.5.13.1 * python311-Twisted-all_non_platform-22.10.0-150400.5.13.1 ## References: * https://www.suse.com/security/cve/CVE-2023-46137.html * https://bugzilla.suse.com/show_bug.cgi?id=1216588 . Please note the latest moderate security notice regarding python-Twisted on SUSE. Examine CVE-2023-46137 for details and implement necessary installations.. Python Security, SUSE Updates, OpenSUSE Patches. . LinuxSecurity.com Team
## 2021-10-12, Version 14.18.1 'Fermium' (LTS), @danielleadams This is a security release. ### Notable changes * **CVE-2021-22959**: HTTP Request Smuggling due to spaced in headers (Medium) * The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will be available at. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-cbad295a90 2021-10-23 03:24:50.227257 --------------------------------------------------------------------------------Name : nodejs Product : Fedora 33 Version : 14.18.1 Release : 1.fc33 URL : https://nodejs.org/en/ Summary : JavaScript runtime Description : Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. --------------------------------------------------------------------------------Update Information: ## 2021-10-12, Version 14.18.1 'Fermium' (LTS), @danielleadams This is a security release. ### Notable changes * **CVE-2021-22959**: HTTP Request Smuggling due to spaced in headers (Medium) * The http parser accepts requests with a space (SP) right after the header name before the colon. This can lead to HTTP Request Smuggling (HRS). More details will be available at [CVE-2021-22959](https://www.cve.org/CVERecord?id=CVE-2021-22959) after publication. * **CVE-2021-22960**: HTTP Request Smuggling when parsing the body (Medium) * The parse ignores chunk extensions when parsing the body of chunked requests. This leads to HTTP Request Smuggling (HRS) under certain conditions. More details will be available at [CVE-2021-22960](https://www.cve.org/CVERecord?id=CVE-2021-22960) afterpublication. --------------------------------------------------------------------------------ChangeLog: * Thu Oct 14 2021 Stephen Gallagher - 1:14.18.1-1 - Update to security release 14.18.1 - --------------------------------------------------------------------------------References: [ 1 ] Bug #2014059 - CVE-2021-22960 llhttp: HTTP Request Smuggling when parsing the body https://bugzilla.redhat.com/show_bug.cgi?id=2014059 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-cbad295a90' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
The package cups before version 1:2.3.3op2-1 is vulnerable to information disclosure. . Arch Linux Security Advisory ASA-202102-13 ========================================= Severity: Medium Date : 2021-02-06 CVE-ID : CVE-2020-10001 Package : cups Type : information disclosure Remote : No Link : https://security.archlinux.org/AVG-1529 Summary ====== The package cups before version 1:2.3.3op2-1 is vulnerable to information disclosure. Resolution ========= Upgrade to 1:2.3.3op2-1. # pacman -Syu "cups> =1:2.3.3op2-1" The problem has been fixed upstream in version 2.3.3op2. Workaround ========= None. Description ========== A security issue was found in cups before version 2.3.3op2. A missing length check in the ippReadIO function could lead to a buffer over-read. Impact ===== A remote attacker might be able to cause a denial of service or access sensitive information. References ========= https://bugzilla.redhat.com/show_bug.cgi?id=1921680 https://bugzilla-attachments.redhat.com/attachment.cgi?id=1752147 https://github.com/OpenPrinting/cups/commit/efbea1742bd30f842fbbfb87a473e5c84f4162f9 https://security.archlinux.org/CVE-2020-10001 . Arch Linux Security Notice ASA-202305-04: Sudo Privilege Escalation Issue Resolved. Take Immediate Action to Protect Your Environments.. cups package issue, information disclosure, arch linux advisory. . Severity: Medium. LinuxSecurity.com Team
An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm security update Advisory ID: RHSA-2018:1660-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:1660 Issue date: 2018-05-21 CVE Names: CVE-2018-3639 ==================================================================== 1. Summary: An update for qemu-kvm is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Kernel-based Virtual Machine (KVM) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm packages provide the user-space component for running virtual machines that use KVM. Security Fix(es): * An industry-wide issue was found in the way many modern microprocessor designs have implemented speculative execution of Load & Store instructions (a commonly used performance optimization). It relies on the presence of a precisely-defined instruction sequence in the privileged code as well as the fact that memory read from address to which a recent memory write has occurred maysee an older value and subsequently cause an update into the microprocessor's data cache even for speculatively executed instructions that never actually commit (retire). As a result, an unprivileged attacker could use this flaw to read privileged memory by conducting targeted cache side-channel attacks. (CVE-2018-3639) Note: This is the qemu-kvm side of the CVE-2018-3639 mitigation. Red Hat would like to thank Ken Johnson (Microsoft Security Response Center) and Jann Horn (Google Project Zero) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1566890 - CVE-2018-3639 hw: cpu: speculative store bypass 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: qemu-kvm-0.12.1.2-2.503.el6_9.6.src.rpm i386: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.i686.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.i686.rpm x86_64: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-img-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.503.el6_9.6.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: qemu-kvm-0.12.1.2-2.503.el6_9.6.src.rpm x86_64: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-img-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.503.el6_9.6.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: qemu-kvm-0.12.1.2-2.503.el6_9.6.src.rpm i386: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.i686.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.i686.rpm ppc64: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.ppc64.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.ppc64.rpm x86_64: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-img-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.503.el6_9.6.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: qemu-kvm-0.12.1.2-2.503.el6_9.6.src.rpm i386: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.i686.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.i686.rpm x86_64: qemu-guest-agent-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-img-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-debuginfo-0.12.1.2-2.503.el6_9.6.x86_64.rpm qemu-kvm-tools-0.12.1.2-2.503.el6_9.6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-3639 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/security/vulnerabilities/ssbd 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBWwNSlNzjgjWX9erEAQjErA//RtyIIc3nO5wa7asPZn0LmqWcT2V5+1zM BUvmxq0GweXvrXTXEKd+ml0bWbak5//XbtZi/tSSf72yOsIWiPx5Z5pZXWt3CP2e +8qOBOMkWs9+pgeD8bGBhqABUTFlmQPV2rvOQS+mLscDT8w/HrmZVTw5DySLxL01 YKruEqNpDBNvd/HLC7psv2pljEO0GFOmI97WBbRyFbILRt30b+m0ZqVcK4IW8Pdf 5HXUahoU+s8eaPwhHl2t8PW1Kb6D2BZncyKERWg+MbY2Z3lHlgSTE4DYaHuIwf/k xSVj+/cieW0I9HcsB9NzkzdSl19NudA2ZkCbG3Xv8yMU6HPxxFz9vs98HcWwBf36 T2Gwf8bUQ2ameGVPdaWvrmN+RxKtqGm7/spyH44K+Isiw5dNwAn1v690FqzDbPFe a+ArBrRu6roIIKs/i5H1EtJaPQyXdUCUmmS+dJn7ylzJYfSU+odYM73/JwQncV5V RvG8dBGm/mIFqrfzu67ylEz+OnMFBScY/AEqxXbwmoRtQE3yMjo9iXPuIDbNdEMC oxGoDoYuVHEx7mLnQZBfRyMBxVO0O1Qo4W66gd9xD4HXCAmHJY5bOpXG+xBnXkNa s/OmiYgTeYf7o1muJiXoCaC2AqLolQ4GiC1VDuL2PbLnP/u30q78EDiRvRC0JAA8 4eSsYpriN0Y=4FRp -----END PGP SIGNATURE----- -- RHSA-announce mailing list
The package websvn before version 2.3.3-7 is vulnerable to several cross-site scripting issues. . Arch Linux Security Advisory ASA-201608-11 ========================================= Severity: Medium Date : 2016-08-11 CVE-ID : CVE-2016-1236 Package : websvn Type : cross-site scripting Remote : Yes Link : https://wiki.archlinux.org/title/CVE Summary ====== The package websvn before version 2.3.3-7 is vulnerable to several cross-site scripting issues. Resolution ========= Upgrade to 2.3.3-7. # pacman -Syu "websvn> =2.3.3-7" The problem has not been fixed upstream yet. Workaround ========= None. Description ========== Multiple cross-site scripting (XSS) vulnerabilities in revision.php, log.php, listing.php, and comp.php in WebSVN allow context-dependent attackers to inject arbitrary web script or HTML via the name of a file or directory in a repository. Impact ===== A remote attacker can execute arbitrary javascript code in the victim's browser by creating a file or a directory with a specially crafted name in a SVN repository. References ========= https://bugs.archlinux.org/task/50344 https://www.openwall.com/lists/oss-security/2016/05/05/22 https://access.redhat.com/security/cve/CVE-2016-1236 . The Arch Linux Security Notice ASA-202109-22 outlines a significant SQL injection flaw within the PHPMyAdmin application, necessitating an immediate update.. Arch Linux, WebSVN, Cross-Site Scripting. . Severity: Medium. LinuxSecurity.com Team
This update provides the new upstream patch release of ownCloud (7.0.12 for EPEL 6, 8.0.10 for all other distributions). It also adds a 'well-known' redirect for WebDAV (alongside the existing ones for CalDAV and CardDAV) - if you don't know what this is, don't worry. These are bugfix updates which include fixes for some security vulnerabilities rated 'low' and 'medium' by upstream. For full detai [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a576196426 2016-01-23 22:27:57.585196 -------------------------------------------------------------------------------- Name : owncloud Product : Fedora 23 Version : 8.0.10 Release : 1.fc23 URL : https://owncloud.com/ Summary : Private file sync and share server Description : ownCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. ownCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: This update provides the new upstream patch release of ownCloud (7.0.12 for EPEL 6, 8.0.10 for all other distributions). It also adds a 'well-known' redirect for WebDAV (alongside the existing ones for CalDAV and CardDAV) - if you don't know what this is, don't worry. These are bugfix updates which include fixes for some security vulnerabilities rated 'low' and 'medium' by upstream. For full details on the changes, see the [upstream changelog](https://owncloud.com/changelog) and the security advisories: [OC- SA-2016-001](), [OC- SA-2016-002](), [OC- SA-2016-003](), [OC- SA-2016-004](). -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update owncloud' at thecommand line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Update to Qt 5.4.1. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-4564 2015-03-26 16:38:59 -------------------------------------------------------------------------------- Name : mingw-qt5-qtimageformats Product : Fedora 21 Version : 5.4.1 Release : 1.fc21 URL : https://contribute.qt-project.org/ Summary : Qt5 for Windows - QtImageFormats component Description : This package contains the Qt software toolkit for developing cross-platform applications. This is the Windows version of Qt, for use in conjunction with the Fedora Windows cross-compiler. -------------------------------------------------------------------------------- Update Information: Update to Qt 5.4.1 -------------------------------------------------------------------------------- ChangeLog: * Sun Mar 22 2015 Erik van Pienbroek - 5.4.1-1 - Update to 5.4.1 * Thu Jan 1 2015 Erik van Pienbroek - 5.4.0-1 - Update to 5.4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1204798 - mingw-qt5-qtwebkit: qt5-qtwebkit: QtWebKit logs visited URLs to WebpageIcons.db in private browsing mode [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1204798 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mingw-qt5-qtimageformats' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.