Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
87

Debian: DSA-4743-1 Moderate: ruby-kramdown Code Execution Risk

A flaw was discovered in ruby-kramdown, a fast, pure ruby, Markdown parser and converter, which could result in unintended read access to files or unintended embedded Ruby code execution when the {::options /} extension is used together with the 'template' option. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4743-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 10, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ruby-kramdown CVE ID : CVE-2020-14001 Debian Bug : 965305 A flaw was discovered in ruby-kramdown, a fast, pure ruby, Markdown parser and converter, which could result in unintended read access to files or unintended embedded Ruby code execution when the {::options /} extension is used together with the 'template' option. The Update introduces a new option 'forbidden_inline_options' to restrict the options allowed with the {::options /} extension. By default the 'template' option is forbidden. For the stable distribution (buster), this problem has been fixed in version 1.17.0-1+deb10u1. We recommend that you upgrade your ruby-kramdown packages. For the detailed security status of ruby-kramdown please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/ruby-kramdown Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-4744-2 highlights a vulnerability in python-requests that compromises data integrity and remote code execution.. ruby-kramdown, markdown security, debian security advisory. . LinuxSecurity.com Team

Calendar%202 Aug 10, 2020 Debian
197

Debian 9: DLA-2316-1 Critical: ruby-kramdown Code Execution Issue

ruby-kramdown processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://

Calendar%202 Aug 09, 2020 Critical Debian LTS
202

openSUSE 13.2 Security Update: Systemd Read Access Fixes

An update that solves two vulnerabilities and has 8 fixes An update that solves two vulnerabilities and has 8 fixes An update that solves two vulnerabilities and has 8 fixes is now available. is now available.. openSUSE Security Update: Security update for systemd ______________________________________________________________________________ Announcement ID: openSUSE-SU-2016:1101-1 Rating: important References: #959886 #960158 #963230 #964355 #965897 #967122 #970423 #970860 #972612 #972727 Cross-References: CVE-2014-9770 CVE-2015-8842 Affected Products: openSUSE 13.2 ______________________________________________________________________________ An update that solves two vulnerabilities and has 8 fixes is now available. Description: This update for systemd fixes several issues. These security issues were fixed: - CVE-2014-9770, CVE-2015-8842: Don't allow read access to journal files to users (boo#972612) These non-security issues were fixed: - Import commit 523777609a04fe9e590420e89f94ef07e3719baa: e5e362a udev: exclude MD from block device ownership event locking 8839413 udev: really exclude device-mapper from block device ownership event locking 66782e6 udev: exclude device-mapper from block device ownership event locking (boo#972727) 1386f57 tmpfiles: explicitly set mode for /run/log faadb74 tmpfiles: don't allow read access to journal files to users not in systemd-journal 9b1ef37 tmpfiles: don't apply sgid and executable bit to journal files, only the directories they are contained in 011c39f tmpfiles: add ability to mask access mode by pre-existing access mode on files/directories 07e2d60 tmpfiles: get rid of "m" lines d504e28 tmpfiles: various modernizations f97250d systemctl: no need to pass --all if inactive is explicitly requested in list-units (boo#967122) 2686573 fstab-generator: fix automount option and don't start associated mountunit at boot (boo#970423) 5c1637d login: support more than just power-gpio-key (fate#318444) (boo#970860) 2c95ecd logind: add standard gpio power button support (fate#318444) (boo#970860) af3eb93 Revert "log-target-null-instead-kmsg" 555dad4 shorten hostname before checking for trailing dot (boo#965897) 522194c Revert "log: honour the kernel's quiet cmdline argument" (boo#963230) cc94e47 transaction: downgrade warnings about wanted unit which are not found (boo#960158) eb3cfb3 Revert "vhangup-on-all-consoles" 0c28752 remove WorkingDirectory parameter from emergency, rescue and console-shell.service (boo#959886) 1d6d840 Fix wrong substitution variable name in systemd-udev-root-symlink.service.in (boo#964355) - Don't ship boot.udev and systemd-journald.init anymore. It was used during the systemd transition when both sysvinit and systemd could be used on the same system Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 13.2: zypper in -t patch openSUSE-2016-487=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 13.2 (i586 x86_64): libgudev-1_0-0-210.1459453449.5237776-25.37.1 libgudev-1_0-0-debuginfo-210.1459453449.5237776-25.37.1 libgudev-1_0-devel-210.1459453449.5237776-25.37.1 libudev-devel-210.1459453449.5237776-25.37.1 libudev-mini-devel-210.1459453449.5237776-25.37.1 libudev-mini1-210.1459453449.5237776-25.37.1 libudev-mini1-debuginfo-210.1459453449.5237776-25.37.1 libudev1-210.1459453449.5237776-25.37.1 libudev1-debuginfo-210.1459453449.5237776-25.37.1 nss-myhostname-210.1459453449.5237776-25.37.1 nss-myhostname-debuginfo-210.1459453449.5237776-25.37.1 systemd-210.1459453449.5237776-25.37.1 systemd-debuginfo-210.1459453449.5237776-25.37.1 systemd-debugsource-210.1459453449.5237776-25.37.1 systemd-devel-210.1459453449.5237776-25.37.1 systemd-journal-gateway-210.1459453449.5237776-25.37.1 systemd-journal-gateway-debuginfo-210.1459453449.5237776-25.37.1 systemd-logger-210.1459453449.5237776-25.37.1 systemd-mini-210.1459453449.5237776-25.37.1 systemd-mini-debuginfo-210.1459453449.5237776-25.37.1 systemd-mini-debugsource-210.1459453449.5237776-25.37.1 systemd-mini-devel-210.1459453449.5237776-25.37.1 systemd-mini-sysvinit-210.1459453449.5237776-25.37.1 systemd-sysvinit-210.1459453449.5237776-25.37.1 typelib-1_0-GUdev-1_0-210.1459453449.5237776-25.37.1 udev-210.1459453449.5237776-25.37.1 udev-debuginfo-210.1459453449.5237776-25.37.1 udev-mini-210.1459453449.5237776-25.37.1 udev-mini-debuginfo-210.1459453449.5237776-25.37.1 - openSUSE 13.2 (noarch): systemd-bash-completion-210.1459453449.5237776-25.37.1 - openSUSE 13.2 (x86_64): libgudev-1_0-0-32bit-210.1459453449.5237776-25.37.1 libgudev-1_0-0-debuginfo-32bit-210.1459453449.5237776-25.37.1 libudev1-32bit-210.1459453449.5237776-25.37.1 libudev1-debuginfo-32bit-210.1459453449.5237776-25.37.1 nss-myhostname-32bit-210.1459453449.5237776-25.37.1 nss-myhostname-debuginfo-32bit-210.1459453449.5237776-25.37.1 systemd-32bit-210.1459453449.5237776-25.37.1 systemd-debuginfo-32bit-210.1459453449.5237776-25.37.1 References: https://www.suse.com/security/cve/CVE-2014-9770.html https://www.suse.com/security/cve/CVE-2015-8842.html https://bugzilla.suse.com/959886 https://bugzilla.suse.com/960158 https://bugzilla.suse.com/963230 https://bugzilla.suse.com/964355 https://bugzilla.suse.com/965897 https://bugzilla.suse.com/967122 https://bugzilla.suse.com/970423 https://bugzilla.suse.com/970860 https://bugzilla.suse.com/972612 https://bugzilla.suse.com/972727 . The latest systemd update for openSUSE 13.2 addresses critical vulnerabilities and important bug fixes to enhance stability andperformance, urging users to update promptly. systemd Security Update, openSUSE 13.2 Patch, read access CVE Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 19, 2016 Important OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200