Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 615
Alerts This Week
Warning Icon 1 615

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
87

Debian: DSA-2752-1 Medium: phpBB Local Permissions Risk

Andreas Beckmann discovered that phpBB, a web forum, as installed in Debian, sets incorrect permissions for cached files, allowing a malicious local user to overwrite them. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2752-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst September 07, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : phpbb3 Vulnerability : permissions too wide Problem type : local Debian-specific: yes Debian Bug : 711172 Andreas Beckmann discovered that phpBB, a web forum, as installed in Debian, sets incorrect permissions for cached files, allowing a malicious local user to overwrite them. For the oldstable distribution (squeeze), this problem has been fixed in version 3.0.7-PL1-4+squeeze1. For the stable distribution (wheezy), this problem has been fixed in version 3.0.10-4+deb7u1. For the unstable distribution (sid), this problem has been fixed in version 3.0.11-4. We recommend that you upgrade your phpbb3 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The phpBB security update DSA-2752-2 resolves issues related to improper access rights in the Debian system that could impact local user accounts.. phpBB Update, Permissions Issue, Debian Security. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Sep 07, 2013 Medium Debian
87

Debian: DSA-1488-1 Moderate: Remote Access Attack on phpBB2

Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board.Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1488-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst February 09, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : phpbb2 Vulnerability : several Problem type : remote Debian-specific: no CVE Id(s) : CVE-2006-4758 CVE-2006-6839 CVE-2006-6840 CVE-2006-6508 CVE-2006-6841 CVE-2008-0471 Debian Bug : 388120 405980 463589 Several remote vulnerabilities have been discovered in phpBB, a web based bulletin board. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2008-0471 Private messaging allowed cross site request forgery, making it possible to delete all private messages of a user by sending them to a crafted web page. CVE-2006-6841 / CVE-2006-6508 Cross site request forgery enabled an attacker to perform various actions on behalf of a logged in user. (Applies to sarge only) CVE-2006-6840 A negative start parameter could allow an attacker to create invalid output. (Applies to sarge only) CVE-2006-6839 Redirection targets were not fully checked, leaving room for unauthorised external redirections via a phpBB forum. (Applies to sarge only) CVE-2006-4758 An authenticated forum administrator may upload files of any type by using specially crafted filenames. (Applies to sarge only) For the stable distribution (etch), these problems have been fixed in version 2.0.21-7. For the old stable distribution (sarge), these problems have been fixed in version 2.0.13+1-6sarge4. For the unstabledistribution (sid) these problems have been fixed in version 2.0.22-3. We recommend that you upgrade your phpbb2 package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - --------------------------------Source archives: Size/MD5 checksum: 67912 c403597d08f4c5af0f62b84c5ee72a7e Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78 Size/MD5 checksum: 1011 d5ca94a7a4c2b3468428a993a1dbc5cc Architecture independent packages: Size/MD5 checksum: 37766 f0df2114bd60d9b84fbda1d241294fdd Size/MD5 checksum: 526154 944e55e056fc34d970e95b78201589fe Size/MD5 checksum: 2868920 f10c4962035ede6e02417b8098efeda0 Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 1051 88ad3a4f2ee714cce779873b53ebd323 Size/MD5 checksum: 3203456 30383a9bf6c5d21736e4bdf9ec7852d5 Size/MD5 checksum: 90580 896f80500e90867741c516e57fc8bfcc Architecture independent packages: Size/MD5 checksum: 2791410 afd8a0fe8138c8a5cf00a3e4ac10ac59 Size/MD5 checksum: 554842 e8825ef3431bfe7ccf72f9f59f13a119 Size/MD5 checksum: 53706 49baf96bcc1c273a93e8bb5169dca722 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . -------------------------------------------------------------------------Debian Security Advisory D. remote, vulnerabilities, phpbb, based, bulletin, board, private. . LinuxSecurity.com Team

Calendar%202 Feb 08, 2008 Debian
91

Gentoo GLSA-200507-03 High: phpBB Arbitrary Command Execution

A vulnerability in phpBB allows a remote attacker to execute arbitrary commands with the rights of the web server.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: phpBB: Arbitrary command execution Date: July 04, 2005 Bugs: #97278 ID: 200507-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in phpBB allows a remote attacker to execute arbitrary commands with the rights of the web server. Background ========= phpBB is an Open Source bulletin board package. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpBB < 2.0.16 > = 2.0.16 Description ========== Ron van Daal discovered that phpBB contains a vulnerability in the highlighting code. Impact ===== Successful exploitation would grant an attacker unrestricted access to the PHP exec() or system() functions, allowing the execution of arbitrary commands with the rights of the web server. Workaround ========= Please follow the instructions given in the phpBB announcement. Resolution ========= The phpBB package is no longer supported by Gentoo Linux and has been removed from the Portage repository, no further announcements will be issued regarding phpBB updates. Users who wish to continue using phpBB are advised to monitor and refer to www.phpbb.com for more information. To continue using the Gentoo-provided phpBB package, please refer to the Portage documentation on unmasking packages and upgrade to2.0.16. References ========= [ 1 ] phpBB Announcement ;t=302011 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200507-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Critical security advisory regarding phpBB command execution flaws and the recommended fix from Gentoo Linux.. phpBB Exploit, Command Execution Risk, Gentoo Advisory. . LinuxSecurity.com Team

Calendar%202 Jul 04, 2005 Gentoo
91

Gentoo GLSA-200411-32 High Severity: phpBB Remote Command Execution

phpBB contains a vulnerability which allows a remote attacker to execute arbitrary commands with the rights of the web server user.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: phpBB: Remote command execution Date: November 24, 2004 Bugs: #71681 ID: 200411-32 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= phpBB contains a vulnerability which allows a remote attacker to execute arbitrary commands with the rights of the web server user. Background ========= phpBB is an Open Source bulletin board package. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/phpbb < 2.0.10 > = 2.0.11 Description ========== phpBB contains a vulnerability in the highlighting code and several vulnerabilities in the username handling code. Impact ===== An attacker can exploit the highlighting vulnerability to access the PHP exec() function without restriction, allowing them to run arbitrary commands with the rights of the web server user (for example the apache user). Furthermore, the username handling vulnerability might be abused to execute SQL statements on the phpBB database. Workaround ========= There is a one-line patch which will remediate the remote execution vulnerability. Locate the following block of code in viewtopic.php: // // Was a highlight request part of the URI? // $highlight_match = $highlight = '; if (isset($HTTP_GET_VARS['highlight'])) { // Split words and phrases $words = explode(' ', trim(htmlspecialchars(urldecode($HTTP_GET_VARS['highlight'])))); for($i = 0; $i < sizeof($words); $i++) { Replace with the following: // // Was a highlight request part of the URI? // $highlight_match = $highlight = '; if (isset($HTTP_GET_VARS['highlight'])) { // Split words and phrases $words = explode(' ', trim(htmlspecialchars($HTTP_GET_VARS['highlight']))); for($i = 0; $i < sizeof($words); $i++) { Resolution ========= All phpBB users should upgrade to the latest version to fix all known vulnerabilities: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/phpbb-2.0.11" References ========= [ 1 ] phpBB.com Announcement Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200411-32 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Critical Gentoo GLSA highlights essential security patches for phpBB, addressing serious remote command injection risks, and outlines the measures needed for safeguarding systems.. phpBB Security,Gentoo Advisory,Command Execution,Remote Exploit. . LinuxSecurity.com Team

Calendar%202 Nov 24, 2004 Gentoo
91

Gentoo: 200306-15 Severe: phpBB SQL Injection Remote Threat

QL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15 - - - --------------------------------------------------------------------- PACKAGE : phpbb SUMMARY : sql injection DATE : 2003-06-28 20:22 UTC EXPLOIT : remote VERSIONS AFFECTED : =phpbb-2.0.5 CVE : CAN-2003-0486 - - - --------------------------------------------------------------------- quote from cve: "SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter." SOLUTION It is recommended that all Gentoo Linux users who are running net-www/phpbb upgrade to phpbb-2.0.5 as follows emerge sync emerge phpbb emerge clean - - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at This email address is being protected from spambots. You need JavaScript enabled to view it. - - - --------------------------------------------------------------------- . A new Gentoo security advisory reveals a critical phpBB vulnerability, enabling remote attackers to extract password hashes via SQL injection. Quick updates are recommended.. phpbb Security, SQL Injection Risk, Gentoo Safety, Remote Exploitation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 01, 2003 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200