Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 33: 2021-5f7da70bfe Moderate: Monitorix Basic Auth Bypass Fix

Security fix for [CVE-2021-3325]. This new version fixes a security bug introduced in the 3.13.0 version that lead the HTTP built-in server to bypass the Basic Authentication when the option hosts_deny is not defined, which is the default. Besides this fix, this version also updates the main configuration file to add the option hosts_deny = all by default inside the auth subsection,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-5f7da70bfe 2021-02-05 01:57:58.090629 --------------------------------------------------------------------------------Name : monitorix Product : Fedora 33 Version : 3.13.1 Release : 1.fc33 URL : https://www.monitorix.org/ Summary : A free, open source, lightweight system monitoring tool Description : Monitorix is a free, open source and lightweight system monitoring tool designed to monitor as many services and system resources as possible. It has been created to be used under production Linux/UNIX servers, but due to its simplicity and small size may also be used on embedded devices as well. --------------------------------------------------------------------------------Update Information: Security fix for [CVE-2021-3325]. This new version fixes a security bug introduced in the 3.13.0 version that lead the HTTP built-in server to bypass the Basic Authentication when the option hosts_deny is not defined, which is the default. Besides this fix, this version also updates the main configuration file to add the option hosts_deny = all by default inside the auth subsection, in an attempt to make the default behaviour more clear. All users using the 3.13.0 version are advised and encouraged to upgrade to this new version, which resolves the security issue. ---- This new version introduces three new modules: the long-awaited pgsql.pm capable of monitoring up to 9 databases of an unlimited number of PostgreSQL servers, the redis.pm and tinyproxy.pm whichare both also capable of monitoring an unlimited number of Redis and Tinyproxy servers respectively. This version also includes some interesting new features. The new CSS theming support will allow people to create their own color themes. The new support for the ss command in port.pm and nginx.pm modules. The ability to map the device names and also to include a title name in disk.pm module. The new stacked visualization of network stats available on a number of modules, and more. Also with this new version, Monitorix is able to be executed as a regular user instead of root. This is of course subject to the capabilities of each module to get statistics without using the superuser. The rest of new features, changes and bugs fixed are, as always, reflected in the Changes file. --------------------------------------------------------------------------------ChangeLog: * Wed Jan 27 2021 Jordi Sanfeliu - 3.13.1-1 - Updated to 3.13.1. * Fri Jan 22 2021 Jordi Sanfeliu - 3.13.0-1 - Updated to 3.13.0. --------------------------------------------------------------------------------References: [ 1 ] Bug #1920998 - monitorix-3.13.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1920998 [ 2 ] Bug #1921333 - CVE-2021-3325 monitorix: Basic Authentication bypass in a default installatio [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1921333 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-5f7da70bfe' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Monitorix upgrade addresses vulnerability in Basic Authentication for Fedora users. Update advised for improved security.. Monitorix Security Fix,Fedora Update,Basic Auth Bypass,Open Source Monitoring Tools. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 04, 2021 Important Fedora
89

Fedora 32: 2021-fc24737ebc Moderate: Monitorix Basic Auth Bypass Fix

Security fix for [CVE-2021-3325]. This new version fixes a security bug introduced in the 3.13.0 version that lead the HTTP built-in server to bypass the Basic Authentication when the option hosts_deny is not defined, which is the default. Besides this fix, this version also updates the main configuration file to add the option hosts_deny = all by default inside the auth subsection,. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-fc24737ebc 2021-02-05 01:31:59.053776 --------------------------------------------------------------------------------Name : monitorix Product : Fedora 32 Version : 3.13.1 Release : 1.fc32 URL : https://www.monitorix.org/ Summary : A free, open source, lightweight system monitoring tool Description : Monitorix is a free, open source and lightweight system monitoring tool designed to monitor as many services and system resources as possible. It has been created to be used under production Linux/UNIX servers, but due to its simplicity and small size may also be used on embedded devices as well. --------------------------------------------------------------------------------Update Information: Security fix for [CVE-2021-3325]. This new version fixes a security bug introduced in the 3.13.0 version that lead the HTTP built-in server to bypass the Basic Authentication when the option hosts_deny is not defined, which is the default. Besides this fix, this version also updates the main configuration file to add the option hosts_deny = all by default inside the auth subsection, in an attempt to make the default behaviour more clear. All users using the 3.13.0 version are advised and encouraged to upgrade to this new version, which resolves the security issue. ---- This new version introduces three new modules: the long-awaited pgsql.pm capable of monitoring up to 9 databases of an unlimited number of PostgreSQL servers, the redis.pm and tinyproxy.pm whichare both also capable of monitoring an unlimited number of Redis and Tinyproxy servers respectively. This version also includes some interesting new features. The new CSS theming support will allow people to create their own color themes. The new support for the ss command in port.pm and nginx.pm modules. The ability to map the device names and also to include a title name in disk.pm module. The new stacked visualization of network stats available on a number of modules, and more. Also with this new version, Monitorix is able to be executed as a regular user instead of root. This is of course subject to the capabilities of each module to get statistics without using the superuser. The rest of new features, changes and bugs fixed are, as always, reflected in the Changes file. --------------------------------------------------------------------------------ChangeLog: * Wed Jan 27 2021 Jordi Sanfeliu - 3.13.1-1 - Updated to 3.13.1. * Fri Jan 22 2021 Jordi Sanfeliu - 3.13.0-1 - Updated to 3.13.0. --------------------------------------------------------------------------------References: [ 1 ] Bug #1919169 - monitorix-3.13.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1919169 [ 2 ] Bug #1920998 - monitorix-3.13.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1920998 [ 3 ] Bug #1921333 - CVE-2021-3325 monitorix: Basic Authentication bypass in a default installatio [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1921333 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-fc24737ebc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest Monitorix update for Fedora addresses a security vulnerability related to Basic Authentication, incorporating enhanced default configurations for increased protection.. Monitorix Update,Fedora Security Fix,Basic Authentication Bypass,System Monitoring Tool,Open Source Software. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 04, 2021 Important Fedora
89

Fedora 22: 2015-23791fb868 High: Monitorix CSRF And Security Flaws

This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-12813acfa3 2015-11-19 07:46:18.494361 -------------------------------------------------------------------------------- Name : monitorix Product : Fedora 22 Version : 3.8.1 Release : 1.fc22 URL : https://www.monitorix.org/ Summary : A free, open source, lightweight system monitoring tool Description : Monitorix is a free, open source, lightweight system monitoring tool designed to monitor as many services and system resources as possible. It has been created to be used under production Linux/UNIX servers, but due to its simplicity and small size may also be used on embedded devices as well. -------------------------------------------------------------------------------- Update Information: This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could lead in the creation of an enormous amount of .png files in the imgs directory of the server. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1281979 - monitorix-3.8.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1281979 -------------------------------------------------------------------------------- This update can be installed with the"yum" update program. Use su -c 'yum update monitorix' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Tackling significant CSRF and DDoS vulnerabilities in monitorix through this Fedora upgrade to improve overall system resilience and protection.. Fedora Security Update, Monitorix XSS, DoS Vulnerability, System Monitoring Fixes, Open Source Maintenance. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 19, 2015 Important Fedora
89

Fedora 23: Security Advisory for Monitorix XSS and DoS Threats

This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-b6b8582f4e 2015-11-19 08:18:45.206738 -------------------------------------------------------------------------------- Name : monitorix Product : Fedora 23 Version : 3.8.1 Release : 1.fc23 URL : https://www.monitorix.org/ Summary : A free, open source, lightweight system monitoring tool Description : Monitorix is a free, open source, lightweight system monitoring tool designed to monitor as many services and system resources as possible. It has been created to be used under production Linux/UNIX servers, but due to its simplicity and small size may also be used on embedded devices as well. -------------------------------------------------------------------------------- Update Information: This is a maintenance release that mainly fixes a Document Object Model (DOM)-based cross-site scripting (XSS) vulnerability in the monitorix.cgi file. Such vulnerability is by injection a JS code in the when parameter of the URL shown after generating the graphs. Additionally, a potential denial of service (DoS) issue was discovered in the same when parameter of the URL which could lead in the creation of an enormous amount of .png files in the imgs directory of the server. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1281979 - monitorix-3.8.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=1281979 -------------------------------------------------------------------------------- This update can be installed with the"yum" update program. Use su -c 'yum update monitorix' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . This patch update resolves vulnerabilities associated with XSS and DoS in Monitorix for Fedora 23, bolstering user security substantially.. Monitorix Update, Fedora Security, Cross-Site Scripting, DoS Vulnerability, Linux Admin. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 19, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200