Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 10 articles for you...
203

Mageia 8: MGASA-2021-0382 Critical: Quassel SSL Support Issue

Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as . MGASA-2021-0382 - Updated quassel packages fix a security vulnerability Publication date: 27 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0382.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-34825 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system (CVE-2021-34825). Also, the default IRC server has been changed from Freenode to Libera Chat, as upstream has moved their #quassel channel there. References: - https://bugs.mageia.org/show_bug.cgi?id=29193 - https://quassel-irc.org/node/136 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/7ZFWRN5P2WG23MWMVAEVV3YBHGFJHDSW/ - https://www.cve.org/CVERecord?id=CVE-2021-34825 SRPMS: - 8/core/quassel-0.13.1-6.2.mga8 . The recent Quassel update addresses a significant SSL vulnerability in Mageia. Refer to the security advisory MGASA-2021-0382 to ensure your safety.. Quassel Update, Mageia Security Advisory, SSL Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2021 Critical Mageia
172

Ubuntu 18.04 LTS: USN-4594-1 Critical: Quassel Remote Code Execution

Quassel could be made to crash or run programs if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4594-1 October 20, 2020 quassel vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Quassel could be made to crash or run programs if it received specially crafted network traffic. Software Description: - quassel: distributed IRC client - monolithic core+client Details: It was discovered that Quassel incorrectly handled Qdatastream protocol. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2018-1000178) It was discovered that Quassel incorrectly handled certain login requests. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2018-1000179) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: quassel 1:0.12.4-3ubuntu1.18.04.3 quassel-core 1:0.12.4-3ubuntu1.18.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4594-1 CVE-2018-1000178, CVE-2018-1000179 Package Information: https://launchpad.net/ubuntu/+source/quassel/1:0.12.4-3ubuntu1.18.04.3 . Ubuntu Security Notice USN-4595-1 highlights significant vulnerabilities in qemu that affect system reliability and overall safety.. Quassel Vulnerability, Ubuntu Security, Remote Code Exploit, Denial of Service, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 20, 2020 Critical Ubuntu
91

Gentoo: GLSA-201806-04 Normal: Quassel Remote Code Execution Threat

Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201806-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Quassel: Multiple vulnerabilities Date: June 14, 2018 Bugs: #653834 ID: 201806-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Quassel, the worst of which could allow remote attackers to execute arbitrary code. Background ========= Quassel is a Qt4/KDE4 IRC client suppporting a remote daemon for 24/7 connectivity. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/quassel < 0.12.5 > = 0.12.5 Description ========== Multiple vulnerabilities have been discovered in Quassel. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could cause arbitrary code execution or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Quassel users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/quassel-0.12.5" References ========= [ 1 ] CVE-2018-1000178 https://nvd.nist.gov/vuln/detail/CVE-2018-1000178 [ 2 ] CVE-2018-1000179 https://nvd.nist.gov/vuln/detail/CVE-2018-1000179 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201806-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous weaknesses have been discovered in Quassel, posing a risk for possible remote code exploitation. Please update to mitigate dangers.. Quassel Security Advisory, Gentoo Remote Code Execution, Denial of Service Issues, Quassel Vulnerabilities. . LinuxSecurity.com Team

Calendar%202 Jun 14, 2018 Gentoo
89

Fedora 27: 2018-bd73ec6f3a Moderate: Quassel Update Available

Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-bd73ec6f3a 2018-05-11 01:48:15.641788 --------------------------------------------------------------------------------Name : quassel Product : Fedora 27 Version : 0.12.5 Release : 1.fc27 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). * Fri Feb 9 2018 Fedora Release Engineering - 0.12.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering - 0.12.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering - 0.12.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-bd73ec6f3a' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Quassel security patch for Fedora 27 resolves various vulnerabilities present in the current upstream versions and enhances overall reliability.. Fedora Quassel Security Update, Software Release Update, IRC Client Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 11, 2018 Important Fedora
89

Fedora 28 Update: 2018-9617cb1088 Critical Quassel Security Alert

Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-9617cb1088 2018-05-11 01:22:39.912107 --------------------------------------------------------------------------------Name : quassel Product : Fedora 28 Version : 0.12.5 Release : 1.fc28 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-9617cb1088' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Quassel on Fedora 28 gets vital patch fixing various vulnerabilities and improving user interface features.. Fedora 28 Quassel Advisories, Quassel Security Risks, Security Update Fedora. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 11, 2018 Critical Fedora
89

Fedora 26: FEDORA-2018-5e8de70380 Moderate: Quassel Fixes

Updated to latest upstream release (#1571443, #1573318, #1573319).. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5e8de70380 2018-05-11 01:00:00.882738 --------------------------------------------------------------------------------Name : quassel Product : Fedora 26 Version : 0.12.5 Release : 1.fc26 URL : https://quassel-irc.org/ Summary : A modern distributed IRC system Description : Quassel IRC is a modern, distributed IRC client, meaning that one (or multiple) client(s) can attach to and detach from a central core --much like the popular combination of screen and a text-based IRC client such as WeeChat, but graphical --------------------------------------------------------------------------------Update Information: Updated to latest upstream release (#1571443, #1573318, #1573319). --------------------------------------------------------------------------------ChangeLog: * Mon Apr 30 2018 Ben Rosser - 0.12.5-1 - Updated to latest upstream release (#1571443, #1573318, #1573319). * Fri Feb 9 2018 Fedora Release Engineering - 0.12.4-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Thu Aug 3 2017 Fedora Release Engineering - 0.12.4-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild * Thu Jul 27 2017 Fedora Release Engineering - 0.12.4-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1573318 - quassel: multiple vulnerabilities fixed in 0.12.5 https://bugzilla.redhat.com/show_bug.cgi?id=1573318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-5e8de70380' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Quassel has received a new update from the upstream source, fixing various security vulnerabilities identified in previous iterations.. quassel IRC update, fedora 26 advisory, security fixes, distributed client, upstream release. . LinuxSecurity.com Team

Calendar%202 May 11, 2018 Fedora
197

Debian 7: DLA-1370-1 Critical: Quassel Remote Code Exec

It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. . Package : quassel Version : 0.8.0-1+deb7u4 CVE ID : CVE-2018-1000178 It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. For Debian 7 "Wheezy", these problems have been fixed in version 0.8.0-1+deb7u4. We recommend that you upgrade your quassel packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Quassel IRC client has issued a critical security update to address remote code execution vulnerabilities impacting Debian 7 Wheezy. Users should update immediately. Quassel IRC, Remote Code Execution, Debian 7 Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 04, 2018 Critical Debian LTS
87

Debian: DSA-4189-1 Moderate: Quassel Arbitrary Code Execution Risk

Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the 'quasselcore' service after upgrading . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4189-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 02, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : quassel CVE ID : CVE-2018-1000178 CVE-2018-1000179 Two vulnerabilities were found in the Quassel IRC client, which could result in the execution of arbitrary code or denial of service. Note that you need to restart the 'quasselcore' service after upgrading the Quassel packages. For the oldstable distribution (jessie), these problems have been fixed in version 1:0.10.0-2.3+deb8u4. For the stable distribution (stretch), these problems have been fixed in version 1:0.12.4-2+deb9u1. We recommend that you upgrade your quassel packages. For the detailed security status of quassel please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/quassel Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical update is necessary for the Quassel IRC client due to two vulnerabilities that expose users to potential arbitrary code execution and denial of service threats.. Debian Security, Quassel Update, IRC Client Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 02, 2018 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200