Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian DSA-6197-3 Dovecot Important Path Normalization Flaw

The oldstable (bookworm) backport of the security fix for CVE-2026-0394 introduced a regression in the passwd-file path normalization. Updated packages are now available to correct this issue. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u4.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6197-3 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 01, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : dovecot Debian Bug : 1134464 The oldstable (bookworm) backport of the security fix for CVE-2026-0394 introduced a regression in the passwd-file path normalization. Updated packages are now available to correct this issue. For the oldstable distribution (bookworm), this problem has been fixed in version 1:2.3.19.1+dfsg1-2.1+deb12u4. We recommend that you upgrade your dovecot packages. For the detailed security status of dovecot please refer to its security tracker page at: https://security-tracker.debian.org/tracker/dovecot Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Updated dovecot packages for Debian oldstable fix path normalization regression issue from CVE-2026-0394.. Debian Dovecot path normalization fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 01, 2026 Important Debian
172

Ubuntu 8.10 & 9.04: USN-788-1 Critical: Tomcat Access Issues

Iida Minehiko discovered that Tomcat did not properly normalise paths. A remote attacker could send specially crafted requests to the server and bypass security restrictions, gaining access to sensitive content. (CVE-2008-5515) [More...]. ==========================================================Ubuntu Security Notice USN-788-1 June 15, 2009 tomcat6 vulnerabilities CVE-2008-5515, CVE-2009-0033, CVE-2009-0580, CVE-2009-0781, CVE-2009-0783 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: libtomcat6-java 6.0.18-0ubuntu3.2 tomcat6-examples 6.0.18-0ubuntu3.2 Ubuntu 9.04: libtomcat6-java 6.0.18-0ubuntu6.1 tomcat6-examples 6.0.18-0ubuntu6.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Iida Minehiko discovered that Tomcat did not properly normalise paths. A remote attacker could send specially crafted requests to the server and bypass security restrictions, gaining access to sensitive content. (CVE-2008-5515) Yoshihito Fukuyama discovered that Tomcat did not properly handle errors when the Java AJP connector and mod_jk load balancing are used. A remote attacker could send specially crafted requests containing invalid headers to the server and cause a temporary denial of service. (CVE-2009-0033) D. Matscheko and T. Hackner discovered that Tomcat did not properly handle malformed URL encoding of passwords when FORM authentication is used. A remote attacker could exploit this in order to enumerate valid usernames. (CVE-2009-0580) Deniz Cevik discovered that Tomcat did not properly escape certain parameters in the example calendar application whichcould result in browsers becoming vulnerable to cross-site scripting attacks when processing the output. With cross-site scripting vulnerabilities, if a user were tricked into viewing server output during a crafted server request, a remote attacker could exploit this to modify the contents, or steal confidential data (such as passwords), within the same domain. (CVE-2009-0781) Philippe Prados discovered that Tomcat allowed web applications to replace the XML parser used by other web applications. Local users could exploit this to bypass security restrictions and gain access to certain sensitive files. (CVE-2009-0783) Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 22010 87c6105cd78ea5a8dbf62054fc4ba0aa Size/MD5: 1378 823c008ffc927c0f3f5686fc6f5188d0 Size/MD5: 3484249 9bdbb1c1d79302c80057a70b18fe6721 Architecture independent packages: Size/MD5: 174164 dd24331b2709bd6641b4055d0b052eae Size/MD5: 2961944 63c8c3e0300ed70a240b79ddd3299efb Size/MD5: 37370 b9b1bd6dc9cfb52107811295401c09e4 Size/MD5: 53488 5006e5c394ec815f6d36c335d9f0abaf Size/MD5: 714516 768cacbb74453b1a2a49e55d61b7bedd Size/MD5: 419180 0663de0611fb9792d44aebad8aa24cc4 Size/MD5: 18612 95544319007f1f90321469c5d314c72e Size/MD5: 24156 9f4d7a0671e9330ff2fa1a1c13a20c58 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 24779 221e0f51259495fd01da2a6b67358b17 Size/MD5: 1411 e3bac3c39b2e6db3267699a533b17add Size/MD5: 3484249 9bdbb1c1d79302c80057a70b18fe6721 Architecture independent packages: Size/MD5: 246196 54e990e7893923b8b6df4bcce9f3ba22 Size/MD5: 172500 abf989790a45def65d5de9a7f9b010df Size/MD5: 2846254 c1c0180751500ce58c51b97de9f2d6d9 Size/MD5: 37874 e7d401faba215af22ecff31b4a675fad Size/MD5: 53184 194153ab21adac9a47baaf92ea8d2acb Size/MD5: 714212 d52e9abc75108a8f059346e09d47b511 Size/MD5: 418316 3a7110c9da4bd72a7019cbb75651da73 Size/MD5: 20520 ea5e54c91e7055e281d61e63f0e140f2 Size/MD5: 24952 ec80f910d6c8e606c090ba8dd737bc4c . Immediate Attention: Upgrade Tomcat on Ubuntu to mitigate severe security vulnerabilities impacting availability and service integrity.. Tomcat Security Issues, Ubuntu Advisory, Access Issues, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 15, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200