Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges

Alerts This Week
Warning Icon 1 488
Alerts This Week
Warning Icon 1 488

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian LTS DLA-3149-1 Critical: Nokogiri Command Injection & XXE Issues

Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS). . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3149-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sylvain Beucler October 12, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : ruby-nokogiri Version : 1.10.0+dfsg1-2+deb10u1 CVE ID : CVE-2019-5477 CVE-2020-26247 CVE-2022-24836 Debian Bug : 934802 978967 1009787 Multiple vulnerabilities were discovered in Nokogiri, an HTML/XML/SAX/Reader parser for the Ruby programming language, leading to command injection, XML external entity injection (XXE), and denial-of-service (DoS). CVE-2019-5477 A command injection vulnerability allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::Tokenizer#load_file` is being called with unsafe user input as the filename. This vulnerability appears in code generated by the Rexical gem versions v1.0.6 and earlier. Rexical is used by Nokogiri to generate lexical scanner code for parsing CSS queries. CVE-2020-26247 XXE vulnerability: XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. CVE-2022-24836 Nokogiri contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. ForDebian 10 buster, these problems have been fixed in version 1.10.0+dfsg1-2+deb10u1. We recommend that you upgrade your ruby-nokogiri packages. For the detailed security status of ruby-nokogiri please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-nokogiri Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Nokogiri experienced multiple security flaws leading to potential command execution, XML parameter injection, and service disruption issues within Debian.. ruby-nokogiri,vulnerability management,debian security updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 12, 2022 Critical Debian LTS
172

Ubuntu 19.10: USN-4175-1 Critical: Nokogiri Remote Code Execution

Nokogiri could be made to execute programs if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4175-1 November 05, 2019 ruby-nokogiri vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Nokogiri could be made to execute programs if it received specially crafted input. Software Description: - ruby-nokogiri: HTML, XML, SAX, and Reader parser for Ruby Details: It was discovered that Nokogiri incorrectly handled inputs. A remote attacker could possibly use this issue to execute arbitrary OS commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: ruby-nokogiri 1.10.3+dfsg1-2ubuntu0.1 Ubuntu 19.04: ruby-nokogiri 1.10.0+dfsg1-2ubuntu0.1 Ubuntu 18.04 LTS: ruby-nokogiri 1.8.2-1ubuntu0.1 Ubuntu 16.04 LTS: ruby-nokogiri 1.6.7.2-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4175-1 CVE-2019-5477 Package Information: https://launchpad.net/ubuntu/+source/ruby-nokogiri/1.10.3+dfsg1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/ruby-nokogiri/1.10.0+dfsg1-2ubuntu0.1 https://launchpad.net/ubuntu/+source/ruby-nokogiri/1.8.2-1ubuntu0.1 https://launchpad.net/ubuntu/+source/ruby-nokogiri/1.6.7.2-3ubuntu0.1 . Ubuntu Security Announcement USN-4175-1 highlights a vulnerability in ruby-nokogiri that poses a risk of remote code execution. Ensure your system is updated immediately!. Nokogiri Vulnerability, Ubuntu Security Notice, Remote Code Execution, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 05, 2019 Critical Ubuntu
197

Debian: DLA-1933-1 Critical: Ruby-Nokogiri Command Injection

A command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby's `Kernel.open` method. For Debian 8 "Jessie", this problem has been fixed in version . Package : ruby-nokogiri Version : 1.6.3.1+ds-1+deb8u1 CVE ID : CVE-2019-5477 A command injection vulnerability in Nokogiri allows commands to be executed in a subprocess by Ruby's `Kernel.open` method. For Debian 8 "Jessie", this problem has been fixed in version 1.6.3.1+ds-1+deb8u1. We recommend that you upgrade your ruby-nokogiri packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ruby-nokogiri 1.6.3.1+ds-1+deb8u1 has been released to address a command injection vulnerability on Debian.. command injection,nokogiri,vulnerability fix,debian security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 26, 2019 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200