Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian: DSA-3373-1 Important: Vulnerability Risks in ownCloud Exploit

Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more. These flaws may lead to the execution of arbitrary code, authorization bypass, information disclosure, cross-site scripting or denial of service. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3373-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso October 18, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : owncloud CVE ID : CVE-2015-4716 CVE-2015-4717 CVE-2015-4718 CVE-2015-5953 CVE-2015-5954 CVE-2015-6500 CVE-2015-6670 CVE-2015-7699 Debian Bug : 800126 Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more. These flaws may lead to the execution of arbitrary code, authorization bypass, information disclosure, cross-site scripting or denial of service. For the stable distribution (jessie), these problems have been fixed in version 7.0.4+dfsg-4~deb8u3. For the testing distribution (stretch), these problems have been fixed in version 7.0.10~dfsg-2 or earlier versions. For the unstable distribution (sid), these problems have been fixed in version 7.0.10~dfsg-2 or earlier versions. We recommend that you upgrade your owncloud packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Fedora security announcement FSA-2045-3 tackles severe vulnerabilities in Nextcloud, bolstering defenses against various attack vectors.. ownCloud Security, Debian Advisory, Code Execution Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 18, 2015 Important Debian
87

Debian: DSA-3245-1 Moderate: Nextcloud CSRF And Authentication Flaw

Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more. CVE-2015-3011 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3244-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso May 02, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : owncloud CVE ID : CVE-2015-3011 CVE-2015-3012 CVE-2015-3013 Multiple vulnerabilities were discovered in ownCloud, a cloud storage web service for files, music, contacts, calendars and many more. CVE-2015-3011 Hugh Davenport discovered that the "contacts" application shipped with ownCloud is vulnerable to multiple stored cross-site scripting attacks. This vulnerability is effectively exploitable in any browser. CVE-2015-3012 Roy Jansen discovered that the "documents" application shipped with ownCloud is vulnerable to multiple stored cross-site scripting attacks. This vulnerability is not exploitable in browsers that support the current CSP standard. CVE-2015-3013 Lukas Reschke discovered a blacklist bypass vulnerability, allowing authenticated remote attackers to bypass the file blacklist and upload files such as the .htaccess files. An attacker could leverage this bypass by uploading a .htaccess and execute arbitrary PHP code if the /data/ directory is stored inside the web root and a web server that interprets .htaccess files is used. On default Debian installations the data directory is outside of the web root and thus this vulnerability is not exploitable by default. For the stable distribution (jessie), these problems have been fixed in version 7.0.4+dfsg-4~deb8u1. For the testing distribution (stretch), these problems have been fixed in version 7.0.4+dfsg-3. For the unstable distribution(sid), these problems have been fixed in version 7.0.4+dfsg-3. We recommend that you upgrade your owncloud packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Delve into critical security enhancements outlined in Debian Security Advisory DSA-3244-1 for ownCloud, addressing multiple vulnerabilities in the application framework.. ownCloud Security, Debian Advisory, Cross-Site Scripting, Upload Bypass, Cloud Storage Risks. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 02, 2015 Important Debian
89

Fedora 21: 2015-4476 Critical: ownCloud Security Update Release 7.0.5

This update provides the new release 7.0.5, which resolves currently undisclosed security vulnerabilities in ownCloud. It is a minor version update and should apply without any issues or special handling, but as usual, we recommend backing up your data, configuration, and database before updating. We have also backported a post-7.0.5 fix for a 'critical' issue: [More...]. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-4476 2015-03-26 16:35:19 -------------------------------------------------------------------------------- Name : owncloud Product : Fedora 21 Version : 7.0.5 Release : 2.fc21 URL : https://owncloud.com/ Summary : Private file sync and share server Description : ownCloud gives you universal access to your files through a web interface or WebDAV. It also provides a platform to easily view & sync your contacts, calendars and bookmarks across all your devices and enables basic editing right on the web. ownCloud is extendable via a simple but powerful API for applications and plugins. -------------------------------------------------------------------------------- Update Information: This update provides the new release 7.0.5, which resolves currently undisclosed security vulnerabilities in ownCloud. It is a minor version update and should apply without any issues or special handling, but as usual, we recommend backing up your data, configuration, and database before updating. We have also backported a post-7.0.5 fix for a 'critical' issue: https://github.com/owncloud/core/issues/14843 . -------------------------------------------------------------------------------- ChangeLog: * Tue Mar 24 2015 Adam Williamson - 7.0.5-2 - fix patch backported in previous build (upstream made a booboo) * Mon Mar 23 2015 Adam Williamson - 7.0.5-1 - new release 7.0.5 (fixes yet-undisclosed vulns, #1204821 #1204823) - also backport fix for 'severe' upstream issue #14843 * Sun Feb 22 2015 Adam Williamson - 7.0.4-3 - revise and strengthen Apache configuration layout, fix external apps - fix external apps for Nginx * Sat Dec 20 2014 Adam Williamson - 7.0.4-2 - backport upstream support for google PHP lib 1.x and unbundle it * Tue Dec 9 2014 Adam Williamson - 7.0.4-1 - new release 7.0.4 * Tue Nov 25 2014 Adam Williamson - 7.0.3-3 - fix dropbox autoload patch (thanks Tomas Dolezal) #1168082 * Tue Nov 11 2014 Adam Williamson - 7.0.3-2 - drop unnecessary bits from 3rdparty_includes.patch - split Dropbox loading changes into a separate patch (submitted upstream) * Mon Nov 10 2014 Adam Williamson - 7.0.3-1 - new release 7.0.3 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1204821 - owncloud: new security issues fixed upstream in 6.0.7 and 7.0.5 https://bugzilla.redhat.com/show_bug.cgi?id=1204821 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update owncloud' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Version 7.0.5 for ownCloud addresses significant security vulnerabilities in Fedora 21. It is advisable to create a backup prior to implementing the updates.. ownCloud Update 7.0.5,Fedora Security Notification,File Sync Server. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 18, 2015 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here