Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 9: DLA-2625-1 Moderate: Courier-Authlib Permissions Exposure

The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2625-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta April 14, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : courier-authlib Version : 0.66.4-9+deb9u1 CVE ID : CVE-2021-28374 Debian Bug : 984810 The Debian courier-authlib package before 0.71.1-2 for Courier Authentication Library creates a /run/courier/authdaemon directory with weak permissions, allowing an attacker to read user information. This may include a cleartext password in some configurations. In general, it includes the user's existence, uid and gids, home and/or Maildir directory, quota, and some type of password information (such as a hash). For Debian 9 stretch, this problem has been fixed in version 0.66.4-9+deb9u1. We recommend that you upgrade your courier-authlib packages. For the detailed security status of courier-authlib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/courier-authlib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance courier-authlib to address inadequate permissions, safeguarding user information from potential risks linked to security flaws.. Debian Security, Courier Authlib Patch, Authentication Risks, User Data Protection. . LinuxSecurity.com Team

Calendar 2 Apr 14, 2021 Debian LTS
87

Debian: DSA-4850-1 Critical: World-Readable Permissions in Libzstd

It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 10, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libzstd Debian Bug : 981404 It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. For the stable distribution (buster), this problem has been fixed in version 1.3.8+dfsg-3+deb10u1. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-4851-1 for libxcrypt resolves insecure, universal access permissions flaw. Upgrade is advised.. libzstd permissions exposure, debian security advisory, compression utility issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 10, 2021 Critical Debian
197

Debian 9: DLA-1500-2 Low: SystemD Resource Leak Vulnerability

The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo . Package : sssd Version : 1.11.7-3+deb8u1 CVE ID : CVE-2018-10852 Debian Bug : 902860 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can read the sudo rules available for any user. For Debian 8 "Jessie", these problems have been fixed in version 1.11.7-3+deb8u1. We recommend that you upgrade your sssd packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance SSSD performance on Debian 8 to resolve sudo rule visibility issues by backing up first, updating via package manager, tweaking configs, and restarting the service for best results. Sssd Security Update, Debian 8 Update, Permissions Exposure, Security Advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Jul 16, 2018 Low Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here