Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
202

openSUSE 13.2: SUSE-SU-2016:1274-1 Important: PHP5 Remote Execution

An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available. An update that fixes 6 vulnerabilities is now available.. openSUSE Security Update: Security update for php5 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1274-1 Rating: important References: #976775 #976996 #976997 #977000 #977003 #977005 Cross-References: CVE-2015-8866 CVE-2015-8867 CVE-2016-3074 CVE-2016-4070 CVE-2016-4071 CVE-2016-4073 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that fixes 6 vulnerabilities is now available. Description: This update for php5 fixes the following issues: - CVE-2016-4073: A remote attacker could have caused denial of service, or possibly execute arbitrary code, due to incorrect handling of string length calculations in mb_strcut() (bsc#977003) - CVE-2016-3074: Signedness vulnerability in bundled libgd may have resulted in a heap overflow when processing compressed gd2 data. (boo#976775) - CVE-2015-8867: The PHP function openssl_random_pseudo_bytes() did not return cryptographically secure random bytes (bsc#977005) - CVE-2016-4070: The libxml_disable_entity_loader() setting was shared between threads, which could have resulted in XML external entity injection and entity expansion issues (bsc#976997) - CVE-2015-8866: A remote attacker could have caused denial of service due to incorrect handling of large strings in php_raw_url_encode() (bsc#976996) - CVE-2016-4071: A remote attacker could have caused denial of service, or possibly execute arbitrary code, due to incorrect handling of string formatting in php_snmp_error() (bsc#977000) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-576=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): apache2-mod_php5-5.6.1-57.1 apache2-mod_php5-debuginfo-5.6.1-57.1 php5-5.6.1-57.1 php5-bcmath-5.6.1-57.1 php5-bcmath-debuginfo-5.6.1-57.1 php5-bz2-5.6.1-57.1 php5-bz2-debuginfo-5.6.1-57.1 php5-calendar-5.6.1-57.1 php5-calendar-debuginfo-5.6.1-57.1 php5-ctype-5.6.1-57.1 php5-ctype-debuginfo-5.6.1-57.1 php5-curl-5.6.1-57.1 php5-curl-debuginfo-5.6.1-57.1 php5-dba-5.6.1-57.1 php5-dba-debuginfo-5.6.1-57.1 php5-debuginfo-5.6.1-57.1 php5-debugsource-5.6.1-57.1 php5-devel-5.6.1-57.1 php5-dom-5.6.1-57.1 php5-dom-debuginfo-5.6.1-57.1 php5-enchant-5.6.1-57.1 php5-enchant-debuginfo-5.6.1-57.1 php5-exif-5.6.1-57.1 php5-exif-debuginfo-5.6.1-57.1 php5-fastcgi-5.6.1-57.1 php5-fastcgi-debuginfo-5.6.1-57.1 php5-fileinfo-5.6.1-57.1 php5-fileinfo-debuginfo-5.6.1-57.1 php5-firebird-5.6.1-57.1 php5-firebird-debuginfo-5.6.1-57.1 php5-fpm-5.6.1-57.1 php5-fpm-debuginfo-5.6.1-57.1 php5-ftp-5.6.1-57.1 php5-ftp-debuginfo-5.6.1-57.1 php5-gd-5.6.1-57.1 php5-gd-debuginfo-5.6.1-57.1 php5-gettext-5.6.1-57.1 php5-gettext-debuginfo-5.6.1-57.1 php5-gmp-5.6.1-57.1 php5-gmp-debuginfo-5.6.1-57.1 php5-iconv-5.6.1-57.1 php5-iconv-debuginfo-5.6.1-57.1 php5-imap-5.6.1-57.1 php5-imap-debuginfo-5.6.1-57.1 php5-intl-5.6.1-57.1 php5-intl-debuginfo-5.6.1-57.1 php5-json-5.6.1-57.1 php5-json-debuginfo-5.6.1-57.1 php5-ldap-5.6.1-57.1 php5-ldap-debuginfo-5.6.1-57.1 php5-mbstring-5.6.1-57.1 php5-mbstring-debuginfo-5.6.1-57.1 php5-mcrypt-5.6.1-57.1 php5-mcrypt-debuginfo-5.6.1-57.1 php5-mssql-5.6.1-57.1 php5-mssql-debuginfo-5.6.1-57.1 php5-mysql-5.6.1-57.1 php5-mysql-debuginfo-5.6.1-57.1 php5-odbc-5.6.1-57.1 php5-odbc-debuginfo-5.6.1-57.1 php5-opcache-5.6.1-57.1 php5-opcache-debuginfo-5.6.1-57.1 php5-openssl-5.6.1-57.1 php5-openssl-debuginfo-5.6.1-57.1 php5-pcntl-5.6.1-57.1 php5-pcntl-debuginfo-5.6.1-57.1 php5-pdo-5.6.1-57.1 php5-pdo-debuginfo-5.6.1-57.1 php5-pgsql-5.6.1-57.1 php5-pgsql-debuginfo-5.6.1-57.1 php5-phar-5.6.1-57.1 php5-phar-debuginfo-5.6.1-57.1 php5-posix-5.6.1-57.1 php5-posix-debuginfo-5.6.1-57.1 php5-pspell-5.6.1-57.1 php5-pspell-debuginfo-5.6.1-57.1 php5-readline-5.6.1-57.1 php5-readline-debuginfo-5.6.1-57.1 php5-shmop-5.6.1-57.1 php5-shmop-debuginfo-5.6.1-57.1 php5-snmp-5.6.1-57.1 php5-snmp-debuginfo-5.6.1-57.1 php5-soap-5.6.1-57.1 php5-soap-debuginfo-5.6.1-57.1 php5-sockets-5.6.1-57.1 php5-sockets-debuginfo-5.6.1-57.1 php5-sqlite-5.6.1-57.1 php5-sqlite-debuginfo-5.6.1-57.1 php5-suhosin-5.6.1-57.1 php5-suhosin-debuginfo-5.6.1-57.1 php5-sysvmsg-5.6.1-57.1 php5-sysvmsg-debuginfo-5.6.1-57.1 php5-sysvsem-5.6.1-57.1 php5-sysvsem-debuginfo-5.6.1-57.1 php5-sysvshm-5.6.1-57.1 php5-sysvshm-debuginfo-5.6.1-57.1 php5-tidy-5.6.1-57.1 php5-tidy-debuginfo-5.6.1-57.1 php5-tokenizer-5.6.1-57.1 php5-tokenizer-debuginfo-5.6.1-57.1 php5-wddx-5.6.1-57.1 php5-wddx-debuginfo-5.6.1-57.1 php5-xmlreader-5.6.1-57.1 php5-xmlreader-debuginfo-5.6.1-57.1 php5-xmlrpc-5.6.1-57.1 php5-xmlrpc-debuginfo-5.6.1-57.1 php5-xmlwriter-5.6.1-57.1 php5-xmlwriter-debuginfo-5.6.1-57.1 php5-xsl-5.6.1-57.1 php5-xsl-debuginfo-5.6.1-57.1 php5-zip-5.6.1-57.1 php5-zip-debuginfo-5.6.1-57.1 php5-zlib-5.6.1-57.1 php5-zlib-debuginfo-5.6.1-57.1 - openSUSE 13.2 (noarch): php5-pear-5.6.1-57.1 References: https://www.suse.com/security/cve/CVE-2015-8866.html https://www.suse.com/security/cve/CVE-2015-8867.html https://www.suse.com/security/cve/CVE-2016-3074.html https://www.suse.com/security/cve/CVE-2016-4070.html https://www.suse.com/security/cve/CVE-2016-4071.html https://www.suse.com/security/cve/CVE-2016-4073.html https://bugzilla.suse.com/show_bug.cgi?id=976775 https://bugzilla.suse.com/show_bug.cgi?id=976996 https://bugzilla.suse.com/show_bug.cgi?id=976997 https://bugzilla.suse.com/show_bug.cgi?id=977000 https://bugzilla.suse.com/show_bug.cgi?id=977003 https://bugzilla.suse.com/show_bug.cgi?id=977005 . An important PHP5 upgrade for openSUSE resolves 6 significant problems, including risks of remote code execution and denial of service vulnerabilities.. openSUSE PHP5 Security Update, Remote Code Execution, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2016 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200