Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
98

Ubuntu Server 20.04 Security Notice USN-2022-7448-01 for Pcs Auth

An update for pcs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: pcs security, bug fix, and enhancement update Advisory ID: RHSA-2022:7447-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7447 Issue date: 2022-11-08 CVE Names: CVE-2022-1049 ==================================================================== 1. Summary: An update for pcs is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux High Availability (v. 8) - aarch64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Resilient Storage (v. 8) - ppc64le, s390x, x86_64 3. Description: The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): * pcs: improper authentication via PAM (CVE-2022-1049) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1730232 - [RFE] Provide easier management of constraints created by pcs move command 1786964 - pcs booth ticket add does not recognize mode option 1791661 - booth: pcs should validate ticket names 1791670 - booth: pcs should check that '/etc/booth' exists 1874624 - [RFE] Provide method to export commands to create all resources 1909904 - [RFE] Provide method to export commands to create all fence devices 1950551 - [RFE] Generate UUID for each cluster 1954099 - Prevent fence_sbd in combination with stonith-watchdog-timeout> 0 2019894 - A user that is not authorized to run "pcs status" is able to get "pcs status" output anyhow 2023845 - [RFE] Provide a way to add a scsi **mpath** fencing device to a cluster without requiring a restart of all cluster resources 2059500 - pcs rebase bz for 8.7 2064805 - man pcs suggests using 'stickiness' instead of 'resource-stickiness' in 'pcs resource meta' 2066629 - CVE-2022-1049 pcs: improper authentication via PAM 2115326 - Cannot remove a quorum device 2117650 - [Web-UI] It is not possible to enable SBD using web UI 6. Package List: Red Hat Enterprise Linux High Availability (v. 8): Source: pcs-0.10.14-5.el8.src.rpm aarch64: pcs-0.10.14-5.el8.aarch64.rpm pcs-snmp-0.10.14-5.el8.aarch64.rpm ppc64le: pcs-0.10.14-5.el8.ppc64le.rpm pcs-snmp-0.10.14-5.el8.ppc64le.rpm s390x: pcs-0.10.14-5.el8.s390x.rpm pcs-snmp-0.10.14-5.el8.s390x.rpm x86_64: pcs-0.10.14-5.el8.x86_64.rpm pcs-snmp-0.10.14-5.el8.x86_64.rpm Red Hat Enterprise Linux Resilient Storage (v. 8): Source: pcs-0.10.14-5.el8.src.rpm ppc64le: pcs-0.10.14-5.el8.ppc64le.rpm pcs-snmp-0.10.14-5.el8.ppc64le.rpm s390x: pcs-0.10.14-5.el8.s390x.rpm pcs-snmp-0.10.14-5.el8.s390x.rpm x86_64: pcs-0.10.14-5.el8.x86_64.rpm pcs-snmp-0.10.14-5.el8.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7.References: https://access.redhat.com/security/cve/CVE-2022-1049 https://access.redhat.com/security/updates/classification#moderate https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/8.7_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBY2pSrdzjgjWX9erEAQiQ2A/7BIGlVRr+6bWfTBHqvpu45HYAPKp9P4l6 8GpHO7gZoWUoNWeQAvkwEd0ScT+T4irO0XD99OMqWSvZpHw7xOeNp+SQU2+CYx8p HGBZ0O2hpT7ZVvEKOxF5KwMUeROxDFREvMMnVrj5ji79yNqbqThBHcZ/SvM7aLDy shyq4V99yX9msgfNIUVGbao/lnujexZ1kQHN8mW+CvQxOwTDqGIo7aGUgvppmWZx 7P7fWtNYLMCykyoXiPBVtrJiRMRLdbzkU3Q3rNG/3fIRBLn0kFQGeAQthl9N3zHo /Z6opJXBw7BXH2m+5r6abcXAxcEBtd95ZyTYaibT4EMSW60T2iE03ZdGFrCAG3tS haVZr2haBZSVDgcNx45Hdm669uLG2HlioRj8tqvrBX+28D1m+Sro1ROBSARRlBbY LR2DPA2BPRHMY1WnyxVIRanadAjfqtSms/VvpAxhnW3QFvvQDd5kZJ1/96DKeVES xpAjj2X+K1pSFNq+BmQbAY7rXVIP+53n2VPQ/E802xow/+B6yX4ekLFEVSSrKjo+ LBrbmoj0A64mj2oGqa9yXV9qNK7zXLEg+ZDFevaZmWNuuTG8LqGNc9IRDaNo2kcx qhxaSwuLqTGJI4LzCEOZgvzgCCNf/bKjxDBGVyoSs42RgDl0f3eBXB0d8tA3AHeX jlLqeRYEZFY=R8xQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A recent patch for pcs boosts security measures for Red Hat Enterprise Linux 8, incorporating moderate-level corrections and enhancements.. pcs update, Red Hat Enterprise, security fix, bug enhancement, moderate severity. . LinuxSecurity.com Team

Calendar%202 Nov 08, 2022 Red Hat
98

RedHat 7: RHSA-2022-7343 Critical pcs Update: DoS, RCE Issues

An update for pcs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: pcs security update Advisory ID: RHSA-2022:7343-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2022:7343 Issue date: 2022-11-02 CVE Names: CVE-2019-11358 CVE-2022-30123 ==================================================================== 1. Summary: An update for pcs is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server High Availability (v. 7) - ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Resilient Storage (v. 7) - ppc64le, s390x, x86_64 3. Description: The pcs packages provide a command-line configuration system for the Pacemaker and Corosync utilities. Security Fix(es): * rubygem-rack: crafted requests can cause shell escape sequences (CVE-2022-30123) * jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection (CVE-2019-11358) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, referto: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1701972 - CVE-2019-11358 jquery: Prototype pollution in object's prototype leading to denial of service, remote code execution, or property injection 2099524 - CVE-2022-30123 rubygem-rack: crafted requests can cause shell escape sequences 6. Package List: Red Hat Enterprise Linux Server High Availability (v. 7): Source: pcs-0.9.169-3.el7_9.3.src.rpm ppc64le: pcs-0.9.169-3.el7_9.3.ppc64le.rpm pcs-debuginfo-0.9.169-3.el7_9.3.ppc64le.rpm pcs-snmp-0.9.169-3.el7_9.3.ppc64le.rpm s390x: pcs-0.9.169-3.el7_9.3.s390x.rpm pcs-debuginfo-0.9.169-3.el7_9.3.s390x.rpm pcs-snmp-0.9.169-3.el7_9.3.s390x.rpm x86_64: pcs-0.9.169-3.el7_9.3.x86_64.rpm pcs-debuginfo-0.9.169-3.el7_9.3.x86_64.rpm pcs-snmp-0.9.169-3.el7_9.3.x86_64.rpm Red Hat Enterprise Linux Server Resilient Storage (v. 7): Source: pcs-0.9.169-3.el7_9.3.src.rpm ppc64le: pcs-0.9.169-3.el7_9.3.ppc64le.rpm pcs-debuginfo-0.9.169-3.el7_9.3.ppc64le.rpm pcs-snmp-0.9.169-3.el7_9.3.ppc64le.rpm s390x: pcs-0.9.169-3.el7_9.3.s390x.rpm pcs-debuginfo-0.9.169-3.el7_9.3.s390x.rpm pcs-snmp-0.9.169-3.el7_9.3.s390x.rpm x86_64: pcs-0.9.169-3.el7_9.3.x86_64.rpm pcs-debuginfo-0.9.169-3.el7_9.3.x86_64.rpm pcs-snmp-0.9.169-3.el7_9.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-11358 https://access.redhat.com/security/cve/CVE-2022-30123 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2022 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBY2K9MNzjgjWX9erEAQidcA/8CUbH4WDxWDMMNSSKsc1vptCYXSg3/P52 LArMtnekhn6ZEle0RsB+d7WuHFnA9uQNSKo0pV8ppegAUQqBnfdJlltk43BGjbA2 mGVa2/DCJn80WcWw17vzNO3T/1HM9hbIo0APahsfafuQVGXTHkjBKLM8tpL+ie3G 2aAKrDpziMf1/gTg/YxS4jm7pqjIFXJAOVdDZ0jNit9wnzkFJ5JVrAY1GV9+Ckwk uAFomsDExOuGR6ZWE1LDona68EaLgamT9F5O1+z5Z7TejbG2ZkEEAAlFmi5Z7tS/ EuVvR9BjCU8+gvV700HiguD1Ip2hPGVObKjPSFIwSvNf2siuL64/AZs3yaYOTvhf u5IHHJPXjCO7FeGSWY0/IH5nohb4Dtz2TK+cUg9ItbDg0k0FwMx/UfZsNwVl7asn kfUwf4os/ZuFGn5CcnyqN6wo/sc/0VfNCZ2ldFz0yhaLaJPIWCso1sTxww+ZLlgV XQAirYvcug3IdyK5wusZytMPwjghGICgMidxXUttk8cv0jAC1yFM4x1B/BLqjhWS uKCh7zDJB2GcBH0M4THybXYG5OwHk2QfoqW103O8ELoaZsBJg6OAYzqHXvCjivsa tmt7XbY9xymrVb6JOrXiTqhDGBayqxuc+OzhnzXMHwrfrZMCO78u25zb+te9EzOy vveGvf6xVl4=RMfQ -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Server 20.04 provides an essential kernel patch that addresses severe vulnerabilities, including local privilege escalation. pcs update, Red Hat security, important advisory, Linux patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 02, 2022 Important Red Hat
200

Scientific Linux SL7: 2015:0980-1 Important pcs Security Issue

Important: pcs security and bug fix update. Date: Wed, 13 May 2015 15:28:46 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: pcs on SL7.x x86_64 MIME-Version: 1.0 Synopsis: Important: pcs security and bug fix update Advisory ID: SLSA-2015:0980-1 Issue Date: 2015-05-12 CVE Numbers: CVE-2015-1848 -- It was found that the pcs daemon did not sign cookies containing session data that were sent to clients connecting via the pcsd web UI. A remote attacker could use this flaw to forge cookies and bypass authorization checks, possibly gaining elevated privileges in the pcsd web UI. (CVE-2015-1848) This update also fixes the following bug: * Previously, the Corosync tool allowed the two_node option and the auto_tie_breaker option to exist in the corosync.conf file at the same time. As a consequence, if both options were included, auto_tie_breaker was silently ignored and the two_node fence race decided which node would survive in the event of a communication break. With this update, the pcs daemon has been fixed so that it does not produce corosync.conf files with both two_node and auto_tie_breaker included. In addition, if both two_node and auto_tie_breaker are detected in corosync.conf, Corosync issues a message at start-up and disables two_node mode. As a result, auto_tie_breaker effectively overrides two_node mode if both options are specified. After installing the updated packages, the pcsd daemon will be restarted automatically. -- SL7 x86_64 pcs-0.9.137-13.el7_1.2.x86_64.rpm pcs-debuginfo-0.9.137-13.el7_1.2.x86_64.rpm python-clufter-0.9.137-13.el7_1.2.x86_64.rpm - Scientific Linux Development Team . pcs daemon refresh optimizes connectivity vulnerabilities and patches errors for SCILINUX SL7.x x86_64.. pcs Update, Scientific Linux Security, Important Bug Fix, Remote Access Threats. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 13, 2015 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200