Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 16.04 LTS: USN-6050-2 Critical: Git Path Overwrite & Injection

Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-6050-2 May 17, 2023 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: USN-6050-1 fixed several vulnerabilities in Git. This update provides the corresponding updates for CVE-2023-25652 and CVE-2023-29007 on Ubuntu 16.04 LTS. Original advisory details: It was discovered that Git incorrectly handled certain commands. An attacker could possibly use this issue to overwrite paths. (CVE-2023-25652) André Baptista and Vítor Pinho discovered that Git incorrectly handled certain configurations. An attacker could possibly use this issue to achieve arbitrary configuration injection. (CVE-2023-29007) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS (Available with Ubuntu Pro): git 1:2.7.4-0ubuntu1.10+esm7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6050-2 https://ubuntu.com/security/notices/USN-6050-1 CVE-2023-25652, CVE-2023-29007 . Several vulnerabilities in Git have been resolved in Ubuntu 16.04 LTS, tackling concerns related to path overwriting and potential configuration injection.. Git Security Issues, Ubuntu 16.04 LTS, Path Overwrite Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 17, 2023 Critical Ubuntu
89

Fedora 37: 2023-4d2a1d3e5e High: Git Sensitive Information Leak

Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://raw.githubusercontent.com/git/git/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q . --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-2b3acb6cfd 2023-02-22 11:06:32.700077 --------------------------------------------------------------------------------Name : git Product : Fedora 36 Version : 2.39.2 Release : 1.fc36 URL : https://git-scm.com/ Summary : Fast Version Control System Description : Git is a fast, scalable, distributed revision control system with an unusually rich command set that provides both high-level operations and full access to internals. The git rpm installs common set of tools which are usually using with small amount of dependencies. To install all git packages, including tools for integrating with other SCMs, install the git-all meta-package. --------------------------------------------------------------------------------Update Information: Update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) Refer to the [upstream release notes](https://raw.githubusercontent.com/git/git/v2.39.2/Documentation/RelNotes/2.30.8.txt) and the security advisories ([CVE-2023-22490](https://github.com/git/git/security/advisories/GHSA-gw92-x3fm-3g3q), [CVE-2023-23946]() for details. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 14 2023 Todd Zullinger - 2.39.2-1 - update to 2.39.2 (CVE-2023-22490, CVE-2023-23946) * Fri Feb 3 2023 Todd Zullinger - 2.39.1-2 - drop perl Email::Valid dep on RHEL (#2166718) * Thu Jan 19 2023 Fedora Release Engineering - 2.39.1-1.1 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2168160 - CVE-2023-22490 git: data exfiltration with maliciously crafted repository https://bugzilla.redhat.com/show_bug.cgi?id=2168160 [ 2 ] Bug #2168161 - CVE-2023-23946 git: git apply: a path outside the working tree can be overwritten with crafted input https://bugzilla.redhat.com/show_bug.cgi?id=2168161 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-2b3acb6cfd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . The Fedora 36 release of Git version 2.39.2 addresses critical security issues, including vulnerabilities that could lead to data breaches and path manipulation.. Fedora Security,GIT Update,Data Exfiltration,Path Overwrite,Moderate Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 22, 2023 Important Fedora
100

SUSE: 2020:0043-1 Important: Nodejs8 Update for Web Scripting

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for nodejs8 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:0043-1 Rating: important References: #1149792 #1159352 Cross-References: CVE-2019-16775 CVE-2019-16776 CVE-2019-16777 Affected Products: SUSE Linux Enterprise Module for Web Scripting 15-SP1 SUSE Linux Enterprise Module for Web Scripting 15 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for nodejs8 to version 8.17.0 fixes the following issues: Security issues fixed: - CVE-2019-16777, CVE-2019-16776, CVE-2019-16775: Updated npm to 6.13.4, fixing an arbitrary path overwrite and access via "bin" field (bsc#1159352). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Web Scripting 15-SP1: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP1-2020-43=1 - SUSE Linux Enterprise Module for Web Scripting 15: zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-2020-43=1 Package List: - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15-SP1 (noarch): nodejs8-docs-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (aarch64 ppc64le s390x x86_64): nodejs8-8.17.0-3.25.1 nodejs8-debuginfo-8.17.0-3.25.1 nodejs8-debugsource-8.17.0-3.25.1 nodejs8-devel-8.17.0-3.25.1 npm8-8.17.0-3.25.1 - SUSE Linux Enterprise Module for Web Scripting 15 (noarch): nodejs8-docs-8.17.0-3.25.1 References: https://www.suse.com/security/cve/CVE-2019-16775.html https://www.suse.com/security/cve/CVE-2019-16776.html https://www.suse.com/security/cve/CVE-2019-16777.html https://bugzilla.suse.com/1149792 https://bugzilla.suse.com/1159352 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a vital security update for nodejs8 that tackles three severe vulnerabilities and enhances overall protection. It is imperative to apply the recommended fixes promptly.. SUSE Security Update,nodejs8 fix,important security,Web Scripting module. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 08, 2020 Important SuSE
172

Ubuntu 19.10 USN-4220-1: Critical Git Code Execution Risks

Several security issues were fixed in Git.. =========================================================================Ubuntu Security Notice USN-4220-1 December 10, 2019 git vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 19.10 - Ubuntu 19.04 - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Git. Software Description: - git: fast, scalable, distributed revision control system Details: Joern Schneeweisz and Nicolas Joly discovered that Git contained various security flaws. An attacker could possibly use these issues to overwrite arbitrary paths, execute arbitrary code, and overwrite files in the .git directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 19.10: git 1:2.20.1-2ubuntu1.19.10.1 Ubuntu 19.04: git 1:2.20.1-2ubuntu1.19.04.1 Ubuntu 18.04 LTS: git 1:2.17.1-1ubuntu0.5 Ubuntu 16.04 LTS: git 1:2.7.4-0ubuntu1.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4220-1 CVE-2019-1348, CVE-2019-1349, CVE-2019-1350, CVE-2019-1351, CVE-2019-1352, CVE-2019-1353, CVE-2019-1354, CVE-2019-1387, CVE-2019-19604 Package Information: https://launchpad.net/ubuntu/+source/git/1:2.20.1-2ubuntu1.19.04.1 https://launchpad.net/ubuntu/+source/git/1:2.17.1-1ubuntu0.5 https://launchpad.net/ubuntu/+source/git/1:2.7.4-0ubuntu1.7 . Several Git security flaws have been addressed in Ubuntu 19.10 and earlier iterations. Ensure your system is updated for enhanced security.. Git Security Issues, Ubuntu Git Update, Software Fixes, System Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 10, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200