Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
98

RedHat: RHSA-2022-5121-01 Important: Puppet-Configurator Patch

An update for puppet-firewall is now available for Red Hat OpenStack Platform 16.2.3 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: Red Hat OpenStack Platform 16.2 (puppet-firewall) security update Advisory ID: RHSA-2022:5116-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2022:5116 Issue date: 2022-06-22 CVE Names: CVE-2022-0675 ==================================================================== 1. Summary: An update for puppet-firewall is now available for Red Hat OpenStack Platform 16.2.3 (Train). Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 16.2 - noarch 3. Description: Manages Firewalls such as iptables Security Fix(es): * unmanaged rules could leave system in an unsafe state via duplicate comment (CVE-2022-0675) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2071567 - CVE-2022-0675 puppetlabs-firewall: unmanaged rules could leave system in an unsafe state via duplicate comment 6. Package List: Red Hat OpenStack Platform16.2: Source: puppet-firewall-3.4.0-1.94f707cgit.el8ost.src.rpm noarch: puppet-firewall-3.4.0-1.94f707cgit.el8ost.noarch.rpm Red Hat OpenStack Platform 16.2: Source: puppet-firewall-3.4.0-1.94f707cgit.el8ost.src.rpm noarch: puppet-firewall-3.4.0-1.94f707cgit.el8ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2022-0675 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYrNY+9zjgjWX9erEAQjp3g//dr6StKxO2eItYO72aTw0lhuSlnbuVBi4 XjyoK/MmgMD7mmIOivMH8x0SQez3i8bbVuNBxY0vzKaBCt2F0A0rvAjU6CfHfQ9X /W0vgYVU25JqCkLa1LKA/uAS4wU3q2RsmRQQkozh93oKGvrxyv1Oavopct34sDUL RaQmvWNpGDM7N4fwsZjZlAaF+zs/LcjnFavBnRM/2V7J49C/SfINpwDWj80rek+j OY234ef9l1QnbKybUX6HVCiQv7aGifcJSqK/Eg+DrZ5U0CaDGYM4zPECIg/HbW44 Z59ezU0gOMOZKbFDd/JsP7F6r0CGEZn+7buL2pDplXJiXQU+/KCb9GGW1kavIJ8B PjuXMG38UwTJTDFJ88sPJlU2nHvGADAUPciymUBCJ/uRYemN5g2qpUw3XNUGPXrD zDsP6SY0CTjWDTcdq8fY6m3H1sqe+cICxww/gWhRf+uLaCHtAN/Blt9rKAkdXxNn +BPlNcSUtCStt7B1WWA0kiU+uE84t9if4jSQ9E30qusYYkAOhoJG2mIMBnCuaRoX MOE8X87XJMSFptq+y0rHQnPeG++W/qnsZ1Ck++9rNQwrP0Qme7PbcyLn9Yozkd00 4QqyaBWq+CwKGAkO6CCkloq8HImfelXPr1lq2GdartSiZoLnbOITLL+cqmmBV61W c2vGSnm9MKo=lq7X -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Explore the substantial security patch for Red Hat OpenStack Platform 16.2 which tackles puppet-firewall vulnerabilities.. Red Hat OpenStack, Puppet-Firewall Update, Security Impact. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 22, 2022 Important Red Hat
98

Red Hat OpenStack Platform 10: Important Security Update for qemu-kvm-rhev

An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm-rhev security update Advisory ID: RHSA-2020:4176-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:4176 Issue date: 2020-10-05 CVE Names: CVE-2020-14364 ==================================================================== 1. Summary: An update for qemu-kvm-rhev is now available for Red Hat OpenStack Platform 10 (Newton). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 10.0 - x86_64 3. Description: KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on a variety of architectures. The qemu-kvm-rhev packages provide the user-space component for running virtual machines that use KVM in environments managed by Red Hat products. Security Fix(es): * usb: out-of-bounds r/w access issue while processing usb packets (CVE-2020-14364) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1869201 - CVE-2020-14364 QEMU: usb: out-of-bounds r/w access issue whileprocessing usb packets 6. Package List: Red Hat OpenStack Platform 10.0: Source: qemu-kvm-rhev-2.12.0-33.el7_7.12.src.rpm x86_64: qemu-img-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-common-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-rhev-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-rhev-debuginfo-2.12.0-33.el7_7.12.x86_64.rpm qemu-kvm-tools-rhev-2.12.0-33.el7_7.12.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-14364 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBX3uF3tzjgjWX9erEAQizvxAAmS4bb6OAiD6o1/jDymcGuVra8q80zIuJ 26Egxf0mtoz5ztjdk9mLhJvns/1IgmPexZE1OegPsvHk1EAaZp1FEBRG41ltiikh KoOTzrCcb+cWsnMVKmSG55s4tyi006tEk40xWQR69++kVGUCns/aCQaJR5GQQkWQ K6lqh/05EYKw4rKZev1Diu8d5iVXpQ96EdRZrl41AFWGOr9TtFv+N0b9QeJJ4IFh CoXDDjhJHBDOXRh4MAZnXiQUQN4KfpJhocer5uELT8/p52+sJwQGsis1QjBYJzM1 ZEADJh9VD8rIMSXgTCAh6+jsH1fEm0bFV403Yzv2aWr9m9VxZkiMd1bX7W9UV4vw c/hrtHoqoGeidRz/nwTeGSmsVenpwlAmi/A0BS2CyVKEl/p5KKkMIlH2/sGo498e 61ua3OEzqJhMn14SShxsVKNyf2DCGfh0R8dmVqqq0J74Z4PqsyEDuyQzCfz6OjZW GxfoSBImpwEPf6+7Oj2tp2nDjwtqgKNHLIr4TkqVZsEU75ZyhOQSTz4memfd1+gC ny2OPPQw34qqFe+aLuyCEhpQsueMZ1SNuxIAn0X/Vjr+pdHAHxrbHLm0kXRY3u+b pU88UYRMvu19FDnPeYy9hii8BrwbtfSwGQoZee40Ez6NzaY6q9qioFTGgpC99wtz L/K/dHsOl4s=B5HA -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical releases significant libvirt security patch for Ubuntu Cloud Infrastructure correcting major privilege vulnerabilities.. Red Hat OpenStack, qemu-kvm security, out-of-bounds access, important update, software security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 05, 2020 Important Red Hat
98

Red Hat OpenStack 13: RHSA-2020-2732-01 Important: Keystone Threat Fix

An update for openstack-keystone is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: openstack-keystone security update Advisory ID: RHSA-2020:2732-01 Product: Red Hat OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2020:2732 Issue date: 2020-06-24 CVE Names: CVE-2020-12689 CVE-2020-12691 CVE-2020-12692 ==================================================================== 1. Summary: An update for openstack-keystone is now available for Red Hat OpenStack Platform 13 (Queens). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 - noarch Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server - noarch 3. Description: The OpenStack Identity service (keystone) authenticates and authorizes OpenStack users by keeping track of users and their permitted activities. The Identity service supports multiple forms of authentication, including user name and password credentials, token-based systems, and AWS-style logins. Security Fix(es): * EC2 and credential endpoints are not protected from a scoped context (CVE-2020-12689) * Credentials endpoint policy logic allows changing credential owner and target project ID (CVE-2020-12691) * failure to check signature TTL of the EC2 credential auth method (CVE-2020-12692) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other relatedinformation, refer to the CVE page listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1830384 - CVE-2020-12691 openstack-keystone: Credentials endpoint policy logic allows changing credential owner and target project ID 1830396 - CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context 1831566 - Rebase openstack-keystone to 0cbf809 1833164 - CVE-2020-12692 openstack-keystone: failure to check signature TTL of the EC2 credential auth method 6. Package List: Red Hat OpenStack Platform 13.0 for RHEL 7.6 EUS Server: Source: openstack-keystone-13.0.4-3.el7ost.src.rpm noarch: openstack-keystone-13.0.4-3.el7ost.noarch.rpm python-keystone-13.0.4-3.el7ost.noarch.rpm Red Hat OpenStack Platform 13.0: Source: openstack-keystone-13.0.4-3.el7ost.src.rpm noarch: openstack-keystone-13.0.4-3.el7ost.noarch.rpm python-keystone-13.0.4-3.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2020-12689 https://access.redhat.com/security/cve/CVE-2020-12691 https://access.redhat.com/security/cve/CVE-2020-12692 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXvNJOtzjgjWX9erEAQim9A//VIs4m8x+I0OEsFRt/cpfNUFkqxkSNmbg PJVaniOZ9CQdWHJ9KLnhBc8ftmgfli0ofPchfAW6NytgIqENq7HA5LAwlkWokpzf sWrHHtPf4+4DSBJpysjtmowMTY3xtDB81/zN2RIwfybklcgGbuIt91OwyE7WfpRA 8M3/luRntGiez+HXrVZ+HDhJ/dw76rJkLlN4+xts4cHekefRmrLLWYLUEP9m5Tw0 WnrFCeqoXZxFF9Ea1o55Dtpb0w3FG/+lLYP86ys7nXf9uwQElthTGlZwBrUQZcUw pCIrxcY8vumGA8XL++OTGNq5QTgxuZGEjNPmjKal2vB6lw6jIOM64tFNbtvL0smX yPeooRNvCs6e/wU5nV+NB2DBd8A+NhyAQL8APKOQ2r2GoIV/BaVYkLDfNg9kmeuJ 4IbLL6uoBeVMWQfQC33wq4Ri4vWAxzHwECMY5Io19i/YC6lHDvRs+/tKBV8ybawv agZVG6gNCGzJccsY3/xmyrf8jq3xVanLx9Pcd39NSJk2vJC6PpeJYu15saxqpIlv qIpjSypwgoWfGLht4Adcj7zy61VKCG0Zi//sakN/CAoI47iCiaaVI2IIvDm+zEXG 8K9ExTkmgpiTsDZ8mzJ0hgTk0Fsk3eLXlEeaTVwPEocQN7dWoH17/OaOHOAVG9V8 +ABChT2GyAs=B6VQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Significant announcement regarding openstack-neutron tackles vital vulnerabilities within Red Hat OpenStack Platform 13.. security update, openstack keystone, Red Hat platform, important update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2020 Important Red Hat
98

Red Hat Enterprise 7: RHSA-2016-0506-01 Moderate: Django Security Issues

An update for python-django is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: python-django security update Advisory ID: RHSA-2016:0506-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2016:0506.html Issue date: 2016-03-24 CVE Names: CVE-2016-2512 CVE-2016-2513 ==================================================================== 1. Summary: An update for python-django is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7 - noarch 3. Description: Django is a high-level Python Web framework that encourages rapid development and a clean, pragmatic design. It focuses on automating as much as possible and adhering to the DRY (Don't Repeat Yourself) principle. Security Fix(es): * An open-redirect flaw was found in the way Django's django.utils.http.is_safe_url() function filtered authentication URLs. An attacker able to trick a victim into visiting a crafted URL could use this flaw to redirect that victim to a malicious site. (CVE-2016-2512) * A timing attack flaw was found in the way Django's PBKDF2PasswordHasher performed password hashing. Passwords hashed with an older version of PBKDF2PasswordHasher used less hashing iterations, and thusallowed an attacker to enumerate existing users based on the time differences in the login requests. (CVE-2016-2513) Red Hat would like to thank the Django project for reporting these issues. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1311431 - CVE-2016-2512 python-django: Malicious redirect and possible XSS attack via user-supplied redirect URLs containing basic auth 1311438 - CVE-2016-2513 python-django: User enumeration through timing difference on password hasher work factor upgrade 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 for RHEL 7: Source: python-django-1.6.11-5.el7ost.src.rpm noarch: python-django-1.6.11-5.el7ost.noarch.rpm python-django-bash-completion-1.6.11-5.el7ost.noarch.rpm python-django-doc-1.6.11-5.el7ost.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2016-2512 https://access.redhat.com/security/cve/CVE-2016-2513 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFW80ATXlSAg2UNWIIRAqBqAKC3N4s79g9FPICgbkgkO5gI/b210QCfSPt4 i9S/jMzYcdR6JuRwhsLqDi4=XEMO -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu issues a security bulletin concerning php-mysql highlighting significant vulnerabilities with solutions to mitigate risks.. Red Hat, Python-Django, Security Fix, OpenStack, Enterprise Linux. . LinuxSecurity.com Team

Calendar%202 Mar 24, 2016 Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200