Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for libtasn1 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3797-1 Rating: critical References: #1040621 #1105435 #1204690 Cross-References: CVE-2017-6891 CVE-2018-1000654 CVE-2021-46848 CVSS scores: CVE-2017-6891 (NVD) : 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2017-6891 (SUSE): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVE-2018-1000654 (NVD) : 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2018-1000654 (SUSE): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-46848 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2021-46848 (SUSE): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: SUSE Linux Enterprise Server 12-SP2-BCL ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libtasn1 fixes the following issues: Security issue fixed: - CVE-2018-1000654: Fixed a denial of service in the asn1 parser (bsc#1105435). - CVE-2017-6891: Added safety check to fix a stack overflow issue (bsc#1040621). - CVE-2021-46848: Fixed off-by-one array size check that affects asn1_encode_simple_der (bsc#1204690) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2022-3797=1 Package List: - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): libtasn1-3.7-13.7.1 libtasn1-6-3.7-13.7.1 libtasn1-6-32bit-3.7-13.7.1 libtasn1-6-debuginfo-3.7-13.7.1 libtasn1-6-debuginfo-32bit-3.7-13.7.1 libtasn1-debuginfo-3.7-13.7.1 libtasn1-debugsource-3.7-13.7.1 References: https://www.suse.com/security/cve/CVE-2017-6891.html https://www.suse.com/security/cve/CVE-2018-1000654.html https://www.suse.com/security/cve/CVE-2021-46848.html https://bugzilla.suse.com/1040621 https://bugzilla.suse.com/1105435 https://bugzilla.suse.com/1204690 . SUSE has released a Security Update for OpenSSL to tackle severe vulnerabilities, such as remote execution threats and memory corruption. Learn more!. SUSE Linux Enterprise, libtasn1, security update. . Severity: Critical. LinuxSecurity.com Team
The container suse/sle15 was updated. The following patches have been included in this update:. SUSE Container Update Advisory: suse/sle15 ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2022:2644-1 Container Tags : bci/bci-base:15.3 , bci/bci-base:15.3.17.20.52 , suse/sle15:15.3 , suse/sle15:15.3.17.20.52 Container Release : 17.20.52 Severity : critical Type : security References : 1204357 CVE-2022-3515 ----------------------------------------------------------------- The container suse/sle15 was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2022:3683-1 Released: Fri Oct 21 11:48:39 2022 Summary: Security update for libksba Type: security Severity: critical References: 1204357,CVE-2022-3515 This update for libksba fixes the following issues: - CVE-2022-3515: Fixed a possible overflow in the TLV parser (bsc#1204357). The following package changes have been done: - libksba8-1.3.5-150000.4.3.1 updated . SUSE Container has released important security updates, featuring essential fixes for libksba that rectify a serious overflow vulnerability.. SUSE Container Advisory,SUSE-SU-2022-3683-1,Libksba Patch,Overflow Fix. . Severity: Critical. LinuxSecurity.com Team
Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode - CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-3969b64d4b 2022-07-17 00:57:11.020145 --------------------------------------------------------------------------------Name : golang-github-shulhan-bindata Product : Fedora 35 Version : 3.6.1 Release : 4.fc35 URL : https://github.com/shuLhan/go-bindata Summary : A small utility which generates Go code from any file Description : A small utility which generates Go code from any file. Useful for embedding binary data in a Go program. --------------------------------------------------------------------------------Update Information: Rebuild for CVE-2022-{24675,28327,29526} in golang and other go ecosystem CVEs --- This contains the result from the mass rebuild in F35 for all packages that require `golang` and provide binaries to mitigate the following CVEs: `golang` itself: - CVE-2022-24675 golang: encoding/pem: fix stack overflow in Decode -CVE-2022-28327 golang: crypto/elliptic: panic caused by oversized scalar -CVE-2022-29526 golang: syscall: faccessat checks wrong group (There are some Go CVEs that are a little bit older that will also be mitigated by the rebuild for packages that haven't been updated recently) CVEs in other golang libraries that affect a subset of Go packages: - CVE-2022-21698 golang-github-prometheus-client: prometheus/client_golang: Denial of service using InstrumentHandlerCounter - CVE-2022-1996 go-restful: Authorization Bypass Through User-Controlled Key ---- Initial import for golang-github-a8m-envsubst Resolves:rhbz#2074406 ---- Initial package Resolves: rhbz#2074438 ----Update to v3.14.0 (close rhbz#2105612) ---- Fix merge ---- Update to 1.22.1 - Close: rhbz#2077577 --------------------------------------------------------------------------------ChangeLog: * Sat Jul 9 2022 Maxwell G - 3.6.1-4 - Rebuild for CVE-2022-{24675,28327,29526} in golang --------------------------------------------------------------------------------References: [ 1 ] Bug #2074406 - Review Request: golang-github-a8m-envsubst - Environment variables substitution for Go https://bugzilla.redhat.com/show_bug.cgi?id=2074406 [ 2 ] Bug #2074438 - Review Request: golang-github-goccy-yaml - YAML support for the Go language https://bugzilla.redhat.com/show_bug.cgi?id=2074438 [ 3 ] Bug #2077577 - powerline-go-1.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2077577 [ 4 ] Bug #2105612 - golang-github-task-3.14.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2105612 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-3969b64d4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
It was discovered that there was an overflow issue in runc, the runtime for the Open Container Project, often used with Docker. The Netlink 'bytemsg' length field could have allowed an attacker to override Netlink-based container configurations. This vulnerability required the attacker to have some control over the configuration of the container, but . MGASA-2021-0553 - Updated opencontainers-runc packages fix security vulnerability Publication date: 10 Dec 2021 URL: https://advisories.mageia.org/MGASA-2021-0553.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43784 It was discovered that there was an overflow issue in runc, the runtime for the Open Container Project, often used with Docker. The Netlink 'bytemsg' length field could have allowed an attacker to override Netlink-based container configurations. This vulnerability required the attacker to have some control over the configuration of the container, but would have allowed the attacker to bypass the namespace restrictions of the container by simply adding their own Netlink payload which disables all namespaces. (CVE-2021-43784) References: - https://bugs.mageia.org/show_bug.cgi?id=29738 - https://lists.debian.org/debian-lts-announce/2021/12/msg00005.html - https://www.cve.org/CVERecord?id=CVE-2021-43784 SRPMS: - 8/core/opencontainers-runc-1.0.3-1.mga8 . Tackling the overflow problem in runc by implementing critical security patches ensures the safeguarding of Mageia 8 container setups.. Mageia Update, runc Overflow, container runtime, security fix. . LinuxSecurity.com Team
An update that solves 6 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for curl ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:1786-1 Rating: moderate References: #1175109 #1177976 #1179398 #1179399 #1179593 #1183933 #1186114 Cross-References: CVE-2020-8231 CVE-2020-8284 CVE-2020-8285 CVE-2020-8286 CVE-2021-22876 CVE-2021-22898 CVSS scores: CVE-2020-8231 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVE-2020-8231 (SUSE): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2020-8284 (NVD) : 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2020-8284 (SUSE): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVE-2020-8285 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2020-8285 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2020-8286 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVE-2020-8286 (SUSE): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVE-2021-22876 (NVD) : 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE-2021-22876 (SUSE): 6.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:N/A:N CVE-2021-22898 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 SUSE Linux Enterprise Server for SAP 12-SP4 SUSE Linux Enterprise Server 12-SP4-LTSS ______________________________________________________________________________ An update that solves 6 vulnerabilities and has one errata is now available. Description: This update for curl fixes the following issues: - CVE-2021-22898: TELNETstack contents disclosure (bsc#1186114) - CVE-2021-22876: The automatic referer leaks credentials (bsc#1183933) - CVE-2020-8286: Inferior OCSP verification (bsc#1179593) - CVE-2020-8285: FTP wildcard stack overflow (bsc#1179399) - CVE-2020-8284: Trusting FTP PASV responses (bsc#1179398) - CVE-2020-8231: libcurl will pick and use the wrong connection with multiple requests with libcurl's multi API and the 'CURLOPT_CONNECT_ONLY' option (bsc#1175109) - Fix: SFTP uploads result in empty uploaded files (bsc#1177976) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2021-1786=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2021-1786=1 - SUSE Linux Enterprise Server for SAP 12-SP4: zypper in -t patch SUSE-SLE-SAP-12-SP4-2021-1786=1 - SUSE Linux Enterprise Server 12-SP4-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP4-LTSS-2021-1786=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): curl-7.60.0-4.20.1 curl-debuginfo-7.60.0-4.20.1 curl-debugsource-7.60.0-4.20.1 libcurl4-32bit-7.60.0-4.20.1 libcurl4-7.60.0-4.20.1 libcurl4-debuginfo-32bit-7.60.0-4.20.1 libcurl4-debuginfo-7.60.0-4.20.1 - SUSE OpenStack Cloud 9 (x86_64): curl-7.60.0-4.20.1 curl-debuginfo-7.60.0-4.20.1 curl-debugsource-7.60.0-4.20.1 libcurl4-32bit-7.60.0-4.20.1 libcurl4-7.60.0-4.20.1 libcurl4-debuginfo-32bit-7.60.0-4.20.1 libcurl4-debuginfo-7.60.0-4.20.1 - SUSE Linux Enterprise Server for SAP 12-SP4 (ppc64le x86_64): curl-7.60.0-4.20.1 curl-debuginfo-7.60.0-4.20.1 curl-debugsource-7.60.0-4.20.1 libcurl4-7.60.0-4.20.1 libcurl4-debuginfo-7.60.0-4.20.1 - SUSE Linux EnterpriseServer for SAP 12-SP4 (x86_64): libcurl4-32bit-7.60.0-4.20.1 libcurl4-debuginfo-32bit-7.60.0-4.20.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (aarch64 ppc64le s390x x86_64): curl-7.60.0-4.20.1 curl-debuginfo-7.60.0-4.20.1 curl-debugsource-7.60.0-4.20.1 libcurl4-7.60.0-4.20.1 libcurl4-debuginfo-7.60.0-4.20.1 - SUSE Linux Enterprise Server 12-SP4-LTSS (s390x x86_64): libcurl4-32bit-7.60.0-4.20.1 libcurl4-debuginfo-32bit-7.60.0-4.20.1 References: https://www.suse.com/security/cve/CVE-2020-8231.html https://www.suse.com/security/cve/CVE-2020-8284.html https://www.suse.com/security/cve/CVE-2020-8285.html https://www.suse.com/security/cve/CVE-2020-8286.html https://www.suse.com/security/cve/CVE-2021-22876.html https://www.suse.com/security/cve/CVE-2021-22898.html https://bugzilla.suse.com/1175109 https://bugzilla.suse.com/1177976 https://bugzilla.suse.com/1179398 https://bugzilla.suse.com/1179399 https://bugzilla.suse.com/1179593 https://bugzilla.suse.com/1183933 https://bugzilla.suse.com/1186114 . The latest SUSE Security Update resolves multiple vulnerabilities found in curl. This release enhances system protection and corrects possible threats.. SUSE Security Update,curl vulnerabilities,moderate threat,software update. . LinuxSecurity.com Team
The 4.18.10 update contains a number of important fixes across the tree. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c0a1284064 2018-10-01 01:22:14.379199 --------------------------------------------------------------------------------Name : kernel-tools Product : Fedora 27 Version : 4.18.10 Release : 100.fc27 URL : https://www.kernel.org/ Summary : Assortment of tools for the Linux kernel Description : This package contains the tools/ directory from the kernel source and the supporting documentation. --------------------------------------------------------------------------------Update Information: The 4.18.10 update contains a number of important fixes across the tree --------------------------------------------------------------------------------References: [ 1 ] Bug #1626035 - CVE-2018-14633 kernel: stack-based buffer overflow in chap_server_compute_md5() in iscsi target https://bugzilla.redhat.com/show_bug.cgi?id=1626035 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c0a1284064' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Several vulnerabilities have been discovered in the chromium web browser. CVE-2017-5029 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3810-1
This update backports an overflow fix. ---- Backport fix for three memory disclosure/corruption bugs from insufficient parameter validation leading to integer overflow.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-a29a0e8250 2016-10-12 18:56:55.303262 -------------------------------------------------------------------------------- Name : python-pillow Product : Fedora 23 Version : 3.0.0 Release : 6.fc23 URL : / Summary : Python image processing library Description : Python image processing library, fork of the Python Imaging Library (PIL) This library provides extensive file format support, an efficient internal representation, and powerful image processing capabilities. There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt), devel (development) and doc (documentation). -------------------------------------------------------------------------------- Update Information: This update backports an overflow fix. ---- Backport fix for three memory disclosure/corruption bugs from insufficient parameter validation leading to integer overflow. -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update python-pillow' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.