Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-7090749bf4 2022-10-03 00:17:00.182937 --------------------------------------------------------------------------------Name : enlightenment Product : Fedora 37 Version : 0.25.4 Release : 1.fc37 URL : https://www.enlightenment.org/ Summary : Enlightenment window manager Description : Enlightenment window manager is a lean, fast, modular and very extensible window manager for X11 and Linux. It is classed as a "desktop shell" providing the things you need to operate your desktop (or laptop), but is not a whole ' application suite. This covered launching applications, managing their windows and doing other system tasks like suspending, reboots, managing files etc. --------------------------------------------------------------------------------Update Information: Update efl to 1.26.3, enlightenment to 0.25.4. Fixes CVE-2022-37706 --------------------------------------------------------------------------------ChangeLog: * Sat Sep 24 2022 Tom Callaway - 0.25.4-1 - update to 0.25.4 --------------------------------------------------------------------------------References: [ 1 ] Bug #2128741 - CVE-2022-37706 enlightenment: elevate privileges to root. https://bugzilla.redhat.com/show_bug.cgi?id=2128741 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-7090749bf4' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes two vulnerabilities is now available. . openSUSE Security Update: Security update for zsh ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0735-1 Rating: important References: #1163882 #1196435 Cross-References: CVE-2019-20044 CVE-2021-45444 CVSS scores: CVE-2019-20044 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2019-20044 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-45444 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-45444 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Leap 15.3 openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for zsh fixes the following issues: - CVE-2021-45444: Fixed a vulnerability where arbitrary shell commands could be executed related to prompt expansion (bsc#1196435). - CVE-2019-20044: Fixed a vulnerability where shell privileges would not be properly dropped when unsetting the PRIVILEGED option (bsc#1163882). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-SLE-15.4-2022-735=1 - openSUSE Leap 15.3: zypper in -t patch openSUSE-SLE-15.3-2022-735=1 Package List: - openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 zsh-htmldoc-5.6-7.5.1 - openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 zsh-htmldoc-5.6-7.5.1 References: https://www.suse.com/security/cve/CVE-2019-20044.html https://www.suse.com/security/cve/CVE-2021-45444.html https://bugzilla.suse.com/1163882 https://bugzilla.suse.com/1196435 . Urgent patch release for zsh in openSUSE addressing vulnerability in command execution and user privilege escalation.. openSUSE Zsh Update, Shell Command Security, Command Execution Risk. . Severity: Important. LinuxSecurity.com Team
Rich Mirch discovered that the pg_ctlcluster script didn't drop privileges when creating socket/statistics temporary directories, which could result in local privilege escalation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4568-1
An update that fixes two vulnerabilities is now available.. SUSE Security Update: Security update for the Linux Kernel (Live Patch 22 for SLE 12) ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:0244-1 Rating: important References: #1069708 #1071471 Cross-References: CVE-2017-15868 CVE-2017-16939 Affected Products: SUSE Linux Enterprise Server 12-LTSS ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 3.12.61-52_77 fixes one issue. The following security issues were fixed: - CVE-2017-15868: The bnep_add_connection function in net/bluetooth/bnep/core.c did not ensure that an l2cap socket is available, which allowed local users to gain privileges via a crafted application (bsc#1071471). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 12-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-2018-163=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 12-LTSS (x86_64): kgraft-patch-3_12_61-52_77-default-8-2.1 kgraft-patch-3_12_61-52_77-xen-8-2.1 References: https://www.suse.com/security/cve/CVE-2017-15868.html https://www.suse.com/security/cve/CVE-2017-16939.html https://bugzilla.suse.com/1069708 https://bugzilla.suse.com/1071471 -- . SUSE Security Patch for the Linux Kernel (Live Update 22 for SLE 12) successfully resolves two critical vulnerabilities.. Linux Kernel Update,SUSE Security Patch,Kernel Issues Fix. . Severity: Important. LinuxSecurity.com Team
Jann Horn of Google Project Zero discovered that NTFS-3G, a read-write NTFS driver for FUSE, does not scrub the environment before executing modprobe with elevated privileges. A local user can take advantage of this flaw for local root privilege escalation. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3780-1
Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1060-1
Anyone who has manually suid /usr/bin/cdrecord should update to this version.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-297 2004-09-09 --------------------------------------------------------------------- Product : Fedora Core 1 Name : cdrtools Version : 2.01 Release : 0.a19.2.FC1.1 Summary : A collection of CD/DVD utilities. Description : cdrtools is a collection of CD/DVD utilities. --------------------------------------------------------------------- Update Information: Anyone who has manually suid /usr/bin/cdrecord should update to this version. CVE -CVE-2004-0806 --------------------------------------------------------------------- * Wed Sep 08 2004 Harald Hoyer - 8:2.01-0.a19.2.FC1.1 - added patch for CAN-2004-0806, if s.o. is so stupid to make cdrecord suid --------------------------------------------------------------------- This update can be downloaded from: 8c5baaa4f091b16370a2fc6e92684246 SRPMS/cdrtools-2.01-0.a19.2.FC1.1.src.rpm c3ce28f3c5b3190fd888db13f6a4de4c x86_64/cdrecord-2.01-0.a19.2.FC1.1.x86_64.rpm 32c300cf4f4bafd083782de090375c15 x86_64/cdrecord-devel-2.01-0.a19.2.FC1.1.x86_64.rpm e6a285ccdeba93bd15488ebb8ea29690 x86_64/mkisofs-2.01-0.a19.2.FC1.1.x86_64.rpm 86dde7afac3d91514876e876cf96c4e2 x86_64/cdda2wav-2.01-0.a19.2.FC1.1.x86_64.rpm c9cbb9577b4574f33357cb058eae6de4 x86_64/debug/cdrtools-debuginfo-2.01-0.a19.2.FC1.1.x86_64.rpm 02d85342deaca913ffb55b97bba42e10 i386/cdrecord-2.01-0.a19.2.FC1.1.i386.rpm 2c2ecccb5de0d111e1d23bc40d70cfdc i386/cdrecord-devel-2.01-0.a19.2.FC1.1.i386.rpm 969a9959cb2dac9295cb6a1fd6c48a49 i386/mkisofs-2.01-0.a19.2.FC1.1.i386.rpm 3df104a4966c5c075a8acbdc7248d362 i386/cdda2wav-2.01-0.a19.2.FC1.1.i386.rpm 1101f36dc1b269f940805eea77fd4da8 i386/debug/cdrtools-debuginfo-2.01-0.a19.2.FC1.1.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. --------------------------------------------------------------------- . Crucial update for Fedora Core 1 addresses cdrtools security flaw. Protect your system's integrity by executing the newest update without delay.. cdrtools update,Fedora security,cdrtools suid fix,Fedora Core 1. . Severity: Important. LinuxSecurity.com Team
Updated OpenLDAP packages are now available for Red Hat Linux 7, 7.1, and7.2. These updates resolve a vulnerability which would allow users toremove non-mandatory attributes from any object in a directory.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated OpenLDAP packages available Advisory ID: RHSA-2002:014-07 Issue date: 2002-01-14 Updated on: 2002-01-22 Product: Red Hat Linux Keywords: openldap acl Cross references: Obsoletes: RHSA-2001:098 --------------------------------------------------------------------- 1. Topic: Updated OpenLDAP packages are now available for Red Hat Linux 7, 7.1, and 7.2. These updates resolve a vulnerability which would allow users to remove non-mandatory attributes from any object in a directory. 2. Relevant releases/architectures: Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 Red Hat Linux 7.2 - i386, ia64 3. Problem description: Versions of OpenLDAP from 2.0.0 through 2.0.19 do not check permissions using access control lists when a user attempts to remove an attribute from an object in the directory by replacing its values with an empty list. Because schema checking is still enforced, a user can only remove attributes which the schema does not require the object to possess. These packages update OpenLDAP to version 2.0.21 which is not vulnerable to this problem. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Pleasenote that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: Red Hat Linux 7.2: SRPMS: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 621a273d4fd00814d9f5be4952e1da24 7.0/en/os/SRPMS/openldap-2.0.21-0.7.1.src.rpm adb5c0f9f48c628e838e10d9209ca33e 7.0/en/os/alpha/openldap-2.0.21-0.7.1.alpha.rpm 2fff8e15781a76117ffc849bf8c196e0 7.0/en/os/alpha/openldap-clients-2.0.21-0.7.1.alpha.rpm 0afbfe730aafb65faf84302ec3f1fb89 7.0/en/os/alpha/openldap-devel-2.0.21-0.7.1.alpha.rpm ec6df8d880e76595ae1d7772a09a8ded 7.0/en/os/alpha/openldap-servers-2.0.21-0.7.1.alpha.rpm 4c9884f16c8c6faae1311b5f7f53e7a9 7.0/en/os/i386/openldap-2.0.21-0.7.1.i386.rpm 1381cc0aee8127b57bc621ff8df6b52f 7.0/en/os/i386/openldap-clients-2.0.21-0.7.1.i386.rpm 739ceb89c3c88198e2145b3a661a1fb4 7.0/en/os/i386/openldap-devel-2.0.21-0.7.1.i386.rpm 970ebb03d448f637c07b6cf7b419cd8b 7.0/en/os/i386/openldap-servers-2.0.21-0.7.1.i386.rpm 621a273d4fd00814d9f5be4952e1da24 7.1/en/os/SRPMS/openldap-2.0.21-0.7.1.src.rpm adb5c0f9f48c628e838e10d9209ca33e 7.1/en/os/alpha/openldap-2.0.21-0.7.1.alpha.rpm 2fff8e15781a76117ffc849bf8c196e0 7.1/en/os/alpha/openldap-clients-2.0.21-0.7.1.alpha.rpm 0afbfe730aafb65faf84302ec3f1fb89 7.1/en/os/alpha/openldap-devel-2.0.21-0.7.1.alpha.rpm ec6df8d880e76595ae1d7772a09a8ded 7.1/en/os/alpha/openldap-servers-2.0.21-0.7.1.alpha.rpm 4c9884f16c8c6faae1311b5f7f53e7a97.1/en/os/i386/openldap-2.0.21-0.7.1.i386.rpm 1381cc0aee8127b57bc621ff8df6b52f 7.1/en/os/i386/openldap-clients-2.0.21-0.7.1.i386.rpm 739ceb89c3c88198e2145b3a661a1fb4 7.1/en/os/i386/openldap-devel-2.0.21-0.7.1.i386.rpm 970ebb03d448f637c07b6cf7b419cd8b 7.1/en/os/i386/openldap-servers-2.0.21-0.7.1.i386.rpm 14bd6db0758dc071f8e23339d15b2220 7.1/en/os/ia64/openldap-2.0.21-0.7.1.ia64.rpm f88040707cc20e71f4b94da154b8ef43 7.1/en/os/ia64/openldap-clients-2.0.21-0.7.1.ia64.rpm 3cb633c9f7ed221c45f2701da7c8dd7e 7.1/en/os/ia64/openldap-devel-2.0.21-0.7.1.ia64.rpm c01d0d619c62fced192418cdeddcae76 7.1/en/os/ia64/openldap-servers-2.0.21-0.7.1.ia64.rpm baad341d94bae309895765c10fd397cd 7.2/en/os/SRPMS/openldap-2.0.21-1.src.rpm d6b0b4383d02c0c26b3b146384b238fb 7.2/en/os/i386/openldap-2.0.21-1.i386.rpm 8bec3cac0671d97b8f68895c2a3a0a27 7.2/en/os/i386/openldap-clients-2.0.21-1.i386.rpm 38165c13288cee96680fb35368ca1c7b 7.2/en/os/i386/openldap-devel-2.0.21-1.i386.rpm 0f74a1e19ac767ce3e1a2b0b4a9a99ef 7.2/en/os/i386/openldap-servers-2.0.21-1.i386.rpm 4685917c60c02f0c1ce0eaac2ed53136 7.2/en/os/ia64/openldap-2.0.21-1.ia64.rpm 397407675083f4d44692313f077a5dc0 7.2/en/os/ia64/openldap-clients-2.0.21-1.ia64.rpm 5643cbabd72ac60145212f915fc5fa21 7.2/en/os/ia64/openldap-devel-2.0.21-1.ia64.rpm 5d62ffeedcdd02b9f41f77ea0fd65ecf 7.2/en/os/ia64/openldap-servers-2.0.21-1.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: OpenLDAP 2.0 Security Advisory Copyright(c) 2000, 2001, 2002 Red Hat, Inc. `. The newly launched OpenLDAP patches for CentOS tackle serious authorization flaws in directory management. Safeguard your environment by implementing this update.. OpenLDAP Updates, Red Hat Advisory, Privilege Escalation Fix,Directory Security Patches. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.