Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Fix for CVE-2020-17354. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-6edb8fab0d 2023-04-26 01:51:30.091229 --------------------------------------------------------------------------------Name : lilypond-doc Product : Fedora 36 Version : 2.24.1 Release : 1.fc36 URL : https://lilypond.org Summary : HTML documentation for LilyPond Description : LilyPond is an automated music engraving system. It formats music beautifully and automatically, and has a friendly syntax for its input files. This package contains the HTML documentation for LilyPond. --------------------------------------------------------------------------------Update Information: Fix for CVE-2020-17354 --------------------------------------------------------------------------------ChangeLog: * Mon Apr 17 2023 Gwyn Ciesla - 2.24.1-1 - 2.24.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2187167 - CVE-2020-17354 lilypond: Lilypond allows attackers to bypass the -dsafe protection mechanism [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2187167 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-6edb8fab0d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This kernel update is based on upstream 5.10.25 and fixes atleast the following security issues: Unprivileged BPF programs running on affected systems can bypass the protection and execute speculatively out-of-bounds loads from any location . MGASA-2021-0151 - Updated kernel packages fix security issues Publication date: 22 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0151.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-27170, CVE-2020-27171, CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28375 This kernel update is based on upstream 5.10.25 and fixes atleast the following security issues: Unprivileged BPF programs running on affected systems can bypass the protection and execute speculatively out-of-bounds loads from any location within the kernel memory. This can be abused to extract contents of kernel memory via side-channel (CVE-2020-27170). Unprivileged BPF programs running on affected 64-bit systems can exploit this to execute speculatively out-of-bounds loads from 4GB window within the kernel memory. This can be abused to extract contents of kernel memory via side-channel (CVE-2020-27171). An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transport_handle function (in drivers/scsi/scsi_transport_iscsi.c) is called, which leaks the handle. This handle is actually the pointer to an iscsi_transport struct in the kernel module's global variables (CVE-2021-27363). An issue was discovered in the Linux kernel through 5.11.3. drivers/scsi/ scsi_transport_iscsi.c is adversely affected by the ability of an unprivileged user to craft Netlink messages (CVE-2021-27364). An issue was discovered in the Linux kernel through5.11.3. Certain iSCSI data structures do not have appropriate length constraints or checks, and can exceed the PAGE_SIZE value. An unprivileged user can send a Netlink message that is associated with iSCSI, and has a length up to the maximum length of a Netlink message (CVE-2021-27365). An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages (CVE-2021-28375). It also adds the following fixes: - arm(64): enable W1_MASTER_GPIO (mga#28596) - wireguard-tools have been updated to v1.0.20210315 For other upstream fixes, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=28610 - https://bugs.mageia.org/show_bug.cgi?id=28596 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.21 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.22 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.23 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.24 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.25 - https://www.cve.org/CVERecord?id=CVE-2020-27170 - https://www.cve.org/CVERecord?id=CVE-2020-27171 - https://www.cve.org/CVERecord?id=CVE-2021-27363 - https://www.cve.org/CVERecord?id=CVE-2021-27364 - https://www.cve.org/CVERecord?id=CVE-2021-27365 - https://www.cve.org/CVERecord?id=CVE-2021-28375 SRPMS: - 7/core/kernel-5.10.25-1.mga7 - 7/core/kmod-virtualbox-6.1.18-11.mga7 - 7/core/kmod-xtables-addons-3.13-17.mga7 - 7/core/wireguard-tools-1.0.20210315-1.mga7 - 8/core/kernel-5.10.25-1.mga8 - 8/core/kmod-virtualbox-6.1.18-21.mga8 - 8/core/kmod-xtables-addons-3.13-37.mga8 - 8/core/wireguard-tools-1.0.20210315-1.mga8 . MGASA-2021-0151 - Updated kernel packages fix security issues Publication date: 22 Mar 2021 URL: htt. kernel, update, based, upstream, fixes, atleast, security. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2019-16275. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-0e0b28001d 2019-11-07 01:17:00.131701 --------------------------------------------------------------------------------Name : wpa_supplicant Product : Fedora 31 Version : 2.9 Release : 2.fc31 URL : http://w1.fi/wpa_supplicant/ Summary : WPA/WPA2/IEEE 802.1X Supplicant Description : wpa_supplicant is a WPA Supplicant for Linux, BSD and Windows with support for WPA and WPA2 (IEEE 802.11i / RSN). Supplicant is the IEEE 802.1X/WPA component that is used in the client stations. It implements key negotiation with a WPA Authenticator and it controls the roaming and IEEE 802.11 authentication/association of the wlan driver. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-16275 --------------------------------------------------------------------------------ChangeLog: * Wed Oct 30 2019 Davide Caratti - 1:2.9-2 - fix AP mode PMF disconnection protection bypass (CVE-2019-16275, rh #1767026) --------------------------------------------------------------------------------References: [ 1 ] Bug #1767023 - CVE-2019-16275 wpa_supplicant: AP mode PMF disconnection protection bypass https://bugzilla.redhat.com/show_bug.cgi?id=1767023 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-0e0b28001d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libxslt ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1221-2 Rating: moderate References: #1132160 Cross-References: CVE-2019-11068 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libxslt fixes the following issues: Security issue fixed: - CVE-2019-11068: Fixed a protection mechanism bypass where callers of xsltCheckRead() and xsltCheckWrite() would permit access upon receiving an error (bsc#1132160). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-1221=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-1221=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): libxslt-python-1.1.32-3.3.1 libxslt-python-debuginfo-1.1.32-3.3.1 libxslt-python-debugsource-1.1.32-3.3.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (x86_64): libxslt-debugsource-1.1.32-3.3.1 libxslt-devel-32bit-1.1.32-3.3.1 libxslt1-32bit-1.1.32-3.3.1 libxslt1-32bit-debuginfo-1.1.32-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libxslt-debugsource-1.1.32-3.3.1 libxslt-devel-1.1.32-3.3.1 libxslt-tools-1.1.32-3.3.1 libxslt-tools-debuginfo-1.1.32-3.3.1 libxslt1-1.1.32-3.3.1 libxslt1-debuginfo-1.1.32-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-11068.html https://bugzilla.suse.com/1132160 _______________________________________________ sle-security-updates mailing list
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libxslt ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1221-1 Rating: moderate References: #1132160 Cross-References: CVE-2019-11068 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libxslt fixes the following issues: Security issue fixed: - CVE-2019-11068: Fixed a protection mechanism bypass where callers of xsltCheckRead() and xsltCheckWrite() would permit access upon receiving an error (bsc#1132160). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-1221=1 - SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1221=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libxslt-python-1.1.32-3.3.1 libxslt-python-debuginfo-1.1.32-3.3.1 libxslt-python-debugsource-1.1.32-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libxslt-debugsource-1.1.32-3.3.1 libxslt-devel-1.1.32-3.3.1 libxslt-tools-1.1.32-3.3.1 libxslt-tools-debuginfo-1.1.32-3.3.1 libxslt1-1.1.32-3.3.1 libxslt1-debuginfo-1.1.32-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-11068.html https://bugzilla.suse.com/1132160 _______________________________________________ sle-security-updates mailing list
GRUB password protection can be bypassed.. =========================================================================Ubuntu Security Notice USN-2836-1 December 15, 2015 grub2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 15.04 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: GRUB password protection can be bypassed. Software Description: - grub2: GRand Unified Bootloader Details: Hector Marco and Ismael Ripoll discovered that GRUB incorrectly handled the backspace key when configured to use authentication. A local attacker could use this issue to bypass GRUB password protection. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: grub2-common 2.02~beta2-29ubuntu0.2 Ubuntu 15.04: grub2-common 2.02~beta2-22ubuntu1.4 Ubuntu 14.04 LTS: grub2-common 2.02~beta2-9ubuntu1.6 Ubuntu 12.04 LTS: grub2-common 1.99-21ubuntu3.19 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2836-1 CVE-2015-8370 Package Information: https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-29ubuntu0.2 https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-22ubuntu1.4 https://launchpad.net/ubuntu/+source/grub2/2.02~beta2-9ubuntu1.6 https://launchpad.net/ubuntu/+source/grub2/1.99-21ubuntu3.19 . Ubuntu Security Announcement USN-2837-1 addresses vulnerabilities in GRUB bootloader that allow for unauthorized access and provides updates for affected systems.. Grub Protection Bypass, Ubuntu Security Advisory, GRUB Issue. . Severity: Important. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now An update that fixes three vulnerabilities is now available. It includes one version update. available. It includes one version update.. SUSE Security Update: Security update for flash-player ______________________________________________________________________________ Announcement ID: SUSE-SU-2014:0897-1 Rating: critical References: #886472 Cross-References: CVE-2014-0537 CVE-2014-0539 CVE-2014-4671 Affected Products: SUSE Linux Enterprise Desktop 11 SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. It includes one version update. Description: flash-player was updated to version 11.2.202.394 to fix security protection bypass issues. (CVE-2014-0537, CVE-2014-0539, CVE-2014-4671) Security Issues references: * CVE-2014-0537 * CVE-2014-0539 * CVE-2014-4671 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-flash-player-9508 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64) [New Version: 11.2.202.394]: flash-player-11.2.202.394-0.3.1 flash-player-gnome-11.2.202.394-0.3.1 flash-player-kde4-11.2.202.394-0.3.1 References: https://www.suse.com/security/cve/CVE-2014-0537.html https://www.suse.com/security/cve/CVE-2014-0539.html https://www.suse.com/security/cve/CVE-2014-4671.html https://login.microfocus.com/nidp/app/login?sid=0 https://scc.suse.com:443/patches/ . SUSE swift patch for Flash Player addresses three significant security flaws. Upgrade your system immediately!. SUSE LinuxSecurity, Flash Player Update, Critical Advisory, Protection Bypass Issues, Software Patch. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.