Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
172

Ubuntu 16.04: USN-4585-1 Critical: newsbeuter Remote Code Execution

Newsbeuter could be made to crash or run programs as your login if it opened a malicious file.. =========================================================================Ubuntu Security Notice USN-4585-1 October 15, 2020 newsbeuter vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Newsbeuter could be made to crash or run programs as your login if it opened a malicious file. Software Description: - newsbeuter: open-source RSS/Atom feed reader for text terminals Details: It was discovered that Newsbeuter didn't handle the command line input properly. An remote attacker could use it to ran remote code by crafting a special input file. (CVE-2017-12904) It was discovered that Newsbeuter didn't handle metacharacters in its filename properly. An remote attacker could use it to ran remote code by crafting a special filename. (CVE-2017-14500) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: newsbeuter 2.9-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4585-1 CVE-2017-12904, CVE-2017-14500 Package Information: https://launchpad.net/ubuntu/+source/newsbeuter/2.9-3ubuntu0.1 . Upgrade your Ubuntu 16.04 LTS system because of vulnerabilities in newsbeuter that could lead to crashes or enable remote code execution through harmful files.. newsbeuter vulnerabilities, Ubuntu 16.04, remote code execution, system update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 15, 2020 Critical Ubuntu
202

openSUSE Leap 42.x 2018:0229-1 Important: Newsbeuter Code Execution

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for newsbeuter ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0229-1 Rating: important References: #1059057 Cross-References: CVE-2017-14500 Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for newsbeuter fixes one issues. This security issue was fixed: - CVE-2017-14500: Improper Neutralization of special elements allowed remote attackers to perform user-assisted code execution by crafting an RSS item with a media enclosure that includes shell metacharacters in its filename (bsc#1059057). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-92=1 - openSUSE Leap 42.2: zypper in -t patch openSUSE-2018-92=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (x86_64): newsbeuter-2.9-8.1 newsbeuter-debuginfo-2.9-8.1 newsbeuter-debugsource-2.9-8.1 - openSUSE Leap 42.3 (noarch): newsbeuter-lang-2.9-8.1 - openSUSE Leap 42.2 (noarch): newsbeuter-lang-2.9-2.6.1 - openSUSE Leap 42.2 (x86_64): newsbeuter-2.9-2.6.1 newsbeuter-debuginfo-2.9-2.6.1 newsbeuter-debugsource-2.9-2.6.1 References: https://www.suse.com/security/cve/CVE-2017-14500.html https://bugzilla.suse.com/show_bug.cgi?id=1059057 -- . Critical openSUSE security patch released for newsbeuter. Addresses vulnerability allowing code execution in specific versions.. OpenSUSE, Newsbeuter, Code Execution, Security Update. . Severity:Important. LinuxSecurity.com Team

Calendar 2 Jan 26, 2018 Important OpenSUSE
202

openSUSE Leap 42.3: 2018:0166-1 Important: newsbeuter Remote Code Execution

An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for newsbeuter ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:0166-1 Rating: important References: #1054578 Cross-References: CVE-2017-12904 Affected Products: openSUSE Leap 42.3 openSUSE Leap 42.2 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for newsbeuter fixes one issues. This security issue was fixed: - CVE-2017-12904: Improper neutralization of special elements allowed remote attackers to perform user-assisted code execution by crafting an RSS item that includes shell code in its title and/or URL (bsc#1054578). Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-62=1 - openSUSE Leap 42.2: zypper in -t patch openSUSE-2018-62=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.3 (x86_64): newsbeuter-2.9-5.1 newsbeuter-debuginfo-2.9-5.1 newsbeuter-debugsource-2.9-5.1 - openSUSE Leap 42.3 (noarch): newsbeuter-lang-2.9-5.1 - openSUSE Leap 42.2 (noarch): newsbeuter-lang-2.9-2.3.1 - openSUSE Leap 42.2 (x86_64): newsbeuter-2.9-2.3.1 newsbeuter-debuginfo-2.9-2.3.1 newsbeuter-debugsource-2.9-2.3.1 References: https://www.suse.com/security/cve/CVE-2017-12904.html https://bugzilla.suse.com/show_bug.cgi?id=1054578 -- . A recent update for newsbeuter on openSUSE resolves a critical vulnerability linked to remote code execution. Discover further details here.. openSUSE, security update, newsbeuter, remote execution. . Severity: Important.LinuxSecurity.com Team

Calendar 2 Jan 20, 2018 Important OpenSUSE
197

Debian 7 Wheezy DLA-1104-1 Critical: Newsbeuter Remote Execution

It was discovered that podbeuter, the podcast fetcher in newsbeuter, a text-mode RSS feed reader, did not properly escape the name of the media enclosure (the podcast file), allowing a remote attacker to run an arbitrary shell command on the client machine. This is only exploitable . Hash: SHA256 Package : newsbeuter Version : 2.5-2+deb7u3 CVE ID : CVE-2017-14500 Debian Bug : 876004 It was discovered that podbeuter, the podcast fetcher in newsbeuter, a text-mode RSS feed reader, did not properly escape the name of the media enclosure (the podcast file), allowing a remote attacker to run an arbitrary shell command on the client machine. This is only exploitable if the file is also played in podbeuter. For Debian 7 "Wheezy", these problems have been fixed in version 2.5-2+deb7u3. We recommend that you upgrade your newsbeuter packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your newsbeuter setup to address a significant vulnerability that permits unauthorized command execution from a distance.. text-mode RSS, newsbeuter security, Debian update, remote execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 21, 2017 Critical Debian LTS
198

Arch Linux: ASA-201708-15 High: Newsbeuter Remote Command Execution

The package newsbeuter before version 2.9-7 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201708-15 ========================================= Severity: High Date : 2017-08-20 CVE-ID : CVE-2017-12904 Package : newsbeuter Type : arbitrary code execution Remote : Yes Link : https://security.archlinux.org/AVG-384 Summary ====== The package newsbeuter before version 2.9-7 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 2.9-7. # pacman -Syu "newsbeuter> =2.9-7" The problem has been fixed upstream but no release is available yet. Workaround ========= Don't bookmark items. Description ========== An attacker can craft an RSS item with shell code in the title and/or URL. When such an item is bookmarked, the shell will execute that code. The vulnerability is triggered when bookmark-cmd is called. Impact ===== A remote attacker can execute an arbitrary command on the affected host by tricking a user into bookmarking a specially crafted RSS item. References ========= https://github.com/akrennmair/newsbeuter/issues/591 https://groups.google.com/forum/#!topic/newsbeuter/iFqSE7Vz-DE https://security.archlinux.org/CVE-2017-12904 . Arch Linux Security Announcement ASA-202309-10 details a critical vulnerability leading to potential remote code execution in newsboat.. Arbitrary Code Execution, Newsbeuter, High Severity Advisory. . LinuxSecurity.com Team

Calendar 2 Aug 21, 2017 ArchLinux
197

Debian 7 Wheezy: DLA-1061-1 High: Newsbeuter Remote Command Issue

Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an . Hash: SHA512 Package : newsbeuter Version : 2.5-2+deb7u2 CVE ID : CVE-2017-12904 Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an arbitrary shell command on the client machine. For Debian 7 "Wheezy", these problems have been fixed in version 2.5-2+deb7u2. We recommend that you upgrade your newsbeuter packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Patch for newsbeuter addresses a significant vulnerability identified by Jeriko One, mitigating threats of unauthorized command execution.. newsbeuter Security, Debian LTS, Remote Command Execution, Patch Update, Text-Mode Reader. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 19, 2017 Important Debian LTS
87

Ubuntu: USN-3947-1 High: newsbeuter Remote Code Execution

Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an arbitrary shell command on the client machine. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3947-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond August 18, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : newsbeuter CVE ID : CVE-2017-12904 Jeriko One discovered that newsbeuter, a text-mode RSS feed reader, did not properly escape the title and description of a news article when bookmarking it. This allowed a remote attacker to run an arbitrary shell command on the client machine. For the oldstable distribution (jessie), this problem has been fixed in version 2.8-2+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 2.9-5+deb9u1. We recommend that you upgrade your newsbeuter packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-1234-2 highlights a critical vulnerability in streamlink enabling unauthorized access to sensitive information.. newsbeuter Security Update,debian security advisory,text-mode RSS reader. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 18, 2017 Important Debian
91

Gentoo: GLSA-200809-12 Normal: Newsbeuter Remote Code Execution

Insufficient input validation in newsbeuter may allow remote attackers to execute arbitrary shell commands.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Newsbeuter: User-assisted execution of arbitrary code Date: September 22, 2008 Bugs: #236506 ID: 200809-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Insufficient input validation in newsbeuter may allow remote attackersto execute arbitrary shell commands. Background ========= Newsbeuter is a RSS/Atom feed reader for the text console. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-news/newsbeuter < 1.2 > = 1.2 Description ========== J.H.M. Dassen reported that the open-in-browser command does not properly escape shell metacharacters in the URL before passing it to system(). Impact ===== A remote attacker could entice a user to open a feed with specially crafted URLs, possibly resulting in the remote execution of arbitrary shell commands with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Newsbeuter users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-news/newsbeuter-1.2" References ========= [ 1 ] CVE-2008-3907 https://www.cve.org/CVERecord?id=CVE-2008-3907 Availability =========== This GLSA and any updates to itare available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200809-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Debian Security Advisory DSA-1234-1 addresses a vulnerability in Apache server's handling of requests that could potentially enable unauthorized access.. Newsbeuter Exploit, Gentoo Security Flaw, User-Assisted Code Execution. . LinuxSecurity.com Team

Calendar 2 Sep 22, 2008 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here