Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Dmidecode allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. (CVE-2023-30630) References: . MGASA-2023-0180 - Updated dmidecode packages fix security vulnerability Publication date: 21 May 2023 URL: https://advisories.mageia.org/MGASA-2023-0180.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-30630 Dmidecode allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. (CVE-2023-30630) References: - https://bugs.mageia.org/show_bug.cgi?id=31883 - https://lists.suse.com/pipermail/sle-security-updates/2023-April/014548.html - - https://www.cve.org/CVERecord?id=CVE-2023-30630 SRPMS: - 8/core/dmidecode-3.5-1.mga8 . DMGASA-2023-0192 enhances netstat to address a severe vulnerabilities linked to unauthorized access. Discover further details.. dmidecode update, mageia security, local file execution, overwrite vulnerability. . Severity: Critical. LinuxSecurity.com Team
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for rubygem-archive-tar-minitar ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0115-1 Rating: moderate References: #1021740 Cross-References: CVE-2016-10173 Affected Products: SUSE Linux Enterprise Module for Containers 12 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for rubygem-archive-tar-minitar fixes one security issue: - CVE-2016-10173: Archives with files containing '..' in the extracted filename could have been used to overwrite arbitrary files (bsc#1021740). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Containers 12: zypper in -t patch SUSE-SLE-Module-Containers-12-2021-115=1 Package List: - SUSE Linux Enterprise Module for Containers 12 (ppc64le s390x x86_64): ruby2.1-rubygem-archive-tar-minitar-0.5.2-7.3.65 References: https://www.suse.com/security/cve/CVE-2016-10173.html https://bugzilla.suse.com/1021740 . The newly released version of rubygem-archive-tar-minitar patches a critical security flaw found in SUSE Linux distributions, ensuring enhanced protection against potential threats.. rubygem archive tar, suse update, security patch. . LinuxSecurity.com Team
npm/fstream could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-4123-1 September 05, 2019 npm/fstream vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS Summary: npm/fstream could be made to overwrite files. Software Description: - node-fstream: Advanced filesystem streaming tools for Node.js Details: It was discovered that npm/fstream incorrectly handled certain crafted tarballs. An attacker could use this vulnerability to write aritrary files to the filesystem. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: node-fstream 1.0.10-1ubuntu0.19.04.2 Ubuntu 18.04 LTS: node-fstream 1.0.10-1ubuntu0.18.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4123-1 CVE-2019-13173 Package Information: https://launchpad.net/ubuntu/+source/node-fstream/1.0.10-1ubuntu0.19.04.2 https://launchpad.net/ubuntu/+source/node-fstream/1.0.10-1ubuntu0.18.04.1 . Ubuntu Security Advisory USN-4124-1 outlines a severe vulnerability in npm/tar that permits unauthorized file access.. npm fstream file overwrite exploit linux. . Severity: Critical. LinuxSecurity.com Team
Sigil could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-4085-1 August 01, 2019 Sigil vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Sigil could be made to overwrite files. Software Description: - sigil: multi-platform ebook editor Details: Mike Salvatore discovered that Sigil mishandled certain malformed EPUB files. An attacker could use this vulnerability to write arbitrary files to the filesystem. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04: sigil 0.9.13+dfsg-1ubuntu0.1 sigil-data 0.9.13+dfsg-1ubuntu0.1 Ubuntu 18.04 LTS: sigil 0.9.9+dfsg-1ubuntu0.1~esm1 sigil-data 0.9.9+dfsg-1ubuntu0.1~esm1 Ubuntu 16.04 LTS: sigil 0.9.5+dfsg-0ubuntu1+esm1 sigil-data 0.9.5+dfsg-0ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4085-1 CVE-2019-14452 Package Information: https://launchpad.net/ubuntu/+source/sigil/0.9.13+dfsg-1ubuntu0.1 https://launchpad.net/ubuntu/+source/sigil/0.9.9+dfsg-1ubuntu0.1~esm1 https://launchpad.net/ubuntu/+source/sigil/0.9.5+dfsg-0ubuntu1+esm1 . The Ubuntu Security Notice USN-4086-1 highlights a significant privilege escalation vulnerability in the Dovecot service that impacts various releases of Ubuntu.. Sigil, Ubuntu Security, File Overwrite Issue, Linux Vulnerability. . Severity: Critical. LinuxSecurity.com Team
New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] sudo (SSA:2017-150-01) New sudo packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/sudo-1.8.20p1-i586-1_slack14.2.txz: Upgraded. This update fixes a potential overwrite of arbitrary system files. This bug was discovered and analyzed by Qualys, Inc. For more information, see: http://www.openwall.com/lists/oss-security/2017/05/30/16 https://www.cve.org/CVERecord?id=CVE-2017-1000367 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project!:-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: 8c1ea5cd672021f4e407732f45fc9203 sudo-1.8.20p1-i486-1_slack13.0.txz Slackware x86_64 13.0 package: f8738cf9bec91237be6b5b48632a8fac sudo-1.8.20p1-x86_64-1_slack13.0.txz Slackware 13.1 package: 70295b740650a6c84abcfccdd78b4b8d sudo-1.8.20p1-i486-1_slack13.1.txz Slackware x86_64 13.1package: ec0bc3ae692016772212785f0916ad4f sudo-1.8.20p1-x86_64-1_slack13.1.txz Slackware 13.37 package: c302d5ebfe2aeae2001eb557cd821170 sudo-1.8.20p1-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 3c6c302932e9364639f72a1594351e58 sudo-1.8.20p1-x86_64-1_slack13.37.txz Slackware 14.0 package: 91f1dc8be0d2170ebc3a13cc12646abb sudo-1.8.20p1-i486-1_slack14.0.txz Slackware x86_64 14.0 package: b13651d5096988427c9f815a223f18ea sudo-1.8.20p1-x86_64-1_slack14.0.txz Slackware 14.1 package: 3b2865f68a89a19fd25302b75247804b sudo-1.8.20p1-i486-1_slack14.1.txz Slackware x86_64 14.1 package: a98c5b6895ca074716a94e6258bbc9c9 sudo-1.8.20p1-x86_64-1_slack14.1.txz Slackware 14.2 package: f56fc8af9d77cb8f3148bff1c4e8777d sudo-1.8.20p1-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 67122eef4ec81519c5811b69db4ede6d sudo-1.8.20p1-x86_64-1_slack14.2.txz Slackware -current package: 0fe479206c589b565260ad554186c6d9 ap/sudo-1.8.20p1-i586-1.txz Slackware x86_64 -current package: 9282f5947a6236893fa30e4711575af8 ap/sudo-1.8.20p1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg sudo-1.8.20p1-i586-1_slack14.2.txz +-----+ . Recent updates to sudo packages resolve potential conflicts across various Slackware releases. Update now for enhanced security.. sudo packages, Slackware update, system security, patch installation, security fix. . Severity: Critical. LinuxSecurity.com Team
devscripts could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-2649-1 June 16, 2015 devscripts vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: devscripts could be made to overwrite files. Software Description: - devscripts: scripts to make the life of a Debian Package maintainer easier Details: It was discovered that the uupdate tool incorrectly handled symlinks. If a user or automated system were tricked into processing specially crafted files, a remote attacker could possibly replace arbitrary files, leading to a privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: devscripts 2.14.6ubuntu0.1 Ubuntu 14.04 LTS: devscripts 2.14.1ubuntu0.1 Ubuntu 12.04 LTS: devscripts 2.11.6ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2649-1 CVE-2014-1833 Package Information: https://launchpad.net/ubuntu/+source/devscripts/2.14.6ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.14.1ubuntu0.1 https://launchpad.net/ubuntu/+source/devscripts/2.11.6ubuntu1.7 . A vulnerability present in devscripts for Ubuntu may enable remote malicious actors to replace files, potentially resulting in elevated privileges.. Ubuntu Devscripts Update, File Overwrite Risk, Privilege Escalation Prevention. . Severity: Important. LinuxSecurity.com Team
NTFS-3G could be made to overwrite files as the administrator.. =========================================================================Ubuntu Security Notice USN-2617-3 May 27, 2015 ntfs-3g vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.04 Summary: NTFS-3G could be made to overwrite files as the administrator. Software Description: - ntfs-3g: read/write NTFS driver for FUSE Details: USN-2617-1 fixed a vulnerability in NTFS-3G. The original patch did not completely address the issue. This update fixes the problem. Original advisory details: Tavis Ormandy discovered that FUSE incorrectly filtered environment variables. A local attacker could use this issue to gain administrative privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: ntfs-3g 1:2014.2.15AR.3-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2617-3 https://ubuntu.com/security/notices/USN-2617-1 CVE-2015-3202 Package Information: https://launchpad.net/ubuntu/+source/ntfs-3g/1:2014.2.15AR.3-1ubuntu0.2 . =========================================================================Ubuntu Security Notice USN-. ntfs-3g, overwrite, files, administrator, =====================================. . Severity: Critical. LinuxSecurity.com Team
Dan Rosenberg discovered that fastjar incorrectly handled file paths containing ".." when unpacking archives. If a user or an automated system were tricked into unpacking a specially crafted jar file, arbitrary files could be overwritten with user privileges. [More...]. ==========================================================Ubuntu Security Notice USN-953-1 June 21, 2010 fastjar vulnerability CVE-2010-0831 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 Ubuntu 10.04 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: fastjar 2:0.95-1ubuntu2.1 Ubuntu 9.04: fastjar 2:0.97-3ubuntu0.1 Ubuntu 9.10: fastjar 2:0.98-1ubuntu0.9.10.1 Ubuntu 10.04 LTS: fastjar 2:0.98-1ubuntu0.10.04.1 In general, a standard system update will make all the necessary changes. Details follow: Dan Rosenberg discovered that fastjar incorrectly handled file paths containing ".." when unpacking archives. If a user or an automated system were tricked into unpacking a specially crafted jar file, arbitrary files could be overwritten with user privileges. Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 14652 0bbecbfd445a41af5fac64225180626f Size/MD5: 688 37c0afbe767cd560f19f444c518f9e9a Size/MD5: 593955 92a70f9e56223b653bce0f58f90cf950 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 84840 92c639fcce37474a468a243a26a9ead6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 45128 b0d21c6467fe96f13ed0b6c71c96fd76 lpia architecture (Low Power Intel Architecture): Size/MD5: 45394082ac97eca4af7ed2e04576027240d98 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 47688 b5b71b34bd0d6933356e0f667be92d34 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 46654 cd6104ab543567ea3b9d3af71812cb64 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 4303 f685e7715cc6ef5f819cb1408d4fadba Size/MD5: 1077 4ea02be4634886678ad56803e595a74c Size/MD5: 676393 2659f09c2e43ef8b7d4406321753f1b2 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 91000 834e980e9d7f6f58ee0a861f96a374f2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 48910 416f5950f1d5f679aaf69977bdf3e893 lpia architecture (Low Power Intel Architecture): Size/MD5: 49010 4d5680c65c5b00559cfd11eb3d05ab18 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 50538 e2dca54f24d0c4a0adc6f8b56639a7f4 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 50536 6d85158ea3212a93e5dc36ee9829d5e1 Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 4095 fa64ab3ca694288d157c37b4571a1781 Size/MD5: 1097 85d8021aa363a9a2ca0025b994408139 http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98.orig.tar.gz Size/MD5: 717984 d2d264d343d4d0e1575832cc1023c3bf amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 91004 ed7dedc416f0c2f94c9a941cbffb8f98 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 48924 338dd4ba551b8217917e36846ef6e199 lpia architecture (Low Power Intel Architecture): Size/MD5: 49194 1cd1de1d62b913a4ceca1a7f9837d8c0 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 50286 4b43f23dbac8b065e984e23906328671 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 50428 30ff3e7a9e9a88383d2113fcd38a9f1a Updated packagesfor Ubuntu 10.04: Source archives: Size/MD5: 4192 d1079eedbcf9a0bfb3fd270a91e49fb9 Size/MD5: 1101 feeaadc1dc54e396da69a69ade68116a http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98.orig.tar.gz Size/MD5: 717984 d2d264d343d4d0e1575832cc1023c3bf amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 90958 a088a28e94c4d3240ffa5394d3ead692 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 49018 567ebb9983b24d76b7e0149f8a03a959 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 50532 47cf2e79000cb83f550d01e9748eedfc sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 51216 8ce8b35ae84d7f33fb499a99432ffb64 . Ubuntu Security Alert USN-953-1 addresses vulnerabilities associated with fastjar file directory concerns that can jeopardize user safety.. Fastjar Patch, Ubuntu Security Notice, File Handling Issue. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.