Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
200

Scientific Linux SL7.x Advisory 2015:2184-7 Moderate: realmd Update

Moderate: realmd security, bug fix, and enhancement update. Date: Mon, 21 Dec 2015 23:16:31 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: realmd on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: realmd security, bug fix, and enhancement update Advisory ID: SLSA-2015:2184-7 Issue Date: 2015-11-19 CVE Numbers: CVE-2015-2704 -- A flaw was found in the way realmd parsed certain input when writing configuration into the sssd.conf or smb.conf file. A remote attacker could use this flaw to inject arbitrary configurations into these files via a newline character in an LDAP response. (CVE-2015-2704) It was found that the realm client would try to automatically join an active directory domain without authentication, which could potentially lead to privilege escalation within a specified domain. The realmd packages have been upgraded to upstream version 0.16.1, which provides a number of bug fixes and enhancements over the previous version. This update also fixes the following bugs: * Joining a Scientific Linux machine to a domain using the realm utility creates /home/domainname/[username]/ directories for domain users. Previously, SELinux labeled the domain users' directories incorrectly. As a consequence, the domain users sometimes experienced problems with SELinux policy. This update modifies the realmd service default behavior so that the domain users' directories are compatible with the standard SELinux policy. * Previously, the realm utility was unable to join or discover domains with domain names containing underscore (_). The realmd service has been modified to process underscores in domain names correctly, which fixes the described bug. In addition, this update adds the following enhancement: * The realmd utility now allows the user to disable automatic ID mapping from the command line. To disable the mapping, pass the "--automatic-id- mapping=no" option to the realmd utility. -- SL7 x86_64 realmd-0.16.1-5.el7.x86_64.rpm realmd-debuginfo-0.16.1-5.el7.x86_64.rpm realmd-devel-docs-0.16.1-5.el7.x86_64.rpm - Scientific Linux Development Team . Balanced realmd security patch rectifies issues and improves capabilities for Scientific Linux SL7.x x86_64.. realmd security update, bug fix, scientific linux enhancement. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 21, 2015 Important Scientific Linux
98

Red Hat 7 Advisory RHSA-2015:2184-07 Moderate: Realmd Configuration Issues

Updated realmd packages that fix two security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: realmd security, bug fix, and enhancement update Advisory ID: RHSA-2015:2184-07 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2015:2184.html Issue date: 2015-11-19 CVE Names: CVE-2015-2704 ==================================================================== 1. Summary: Updated realmd packages that fix two security issues, several bugs, and add various enhancements are now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having Moderate security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - aarch64, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The realmd DBus system service manages discovery of and enrollment in realms and domains, such as Active Directory or Identity Management (IdM). The realmd service detects available domains, automatically configures the system, and joins itas an account to a domain. A flaw was found in the way realmd parsed certain input when writing configuration into the sssd.conf or smb.conf file. A remote attacker could use this flaw to inject arbitrary configurations into these files via a newline character in an LDAP response. (CVE-2015-2704) It was found that the realm client would try to automatically join an active directory domain without authentication, which could potentially lead to privilege escalation within a specified domain. (BZ#1205751) The realmd packages have been upgraded to upstream version 0.16.1, which provides a number of bug fixes and enhancements over the previous version. (BZ#1174911) This update also fixes the following bugs: * Joining a Red Hat Enterprise Linux machine to a domain using the realm utility creates /home/domainname/[username]/ directories for domain users. Previously, SELinux labeled the domain users' directories incorrectly. As a consequence, the domain users sometimes experienced problems with SELinux policy. This update modifies the realmd service default behavior so that the domain users' directories are compatible with the standard SELinux policy. (BZ#1241832) * Previously, the realm utility was unable to join or discover domains with domain names containing underscore (_). The realmd service has been modified to process underscores in domain names correctly, which fixes the described bug. (BZ#1243771) In addition, this update adds the following enhancement: * The realmd utility now allows the user to disable automatic ID mapping from the command line. To disable the mapping, pass the "--automatic-id-mapping=no" option to the realmd utility. (BZ#1230941) All realmd users are advised to upgrade to these updated packages, which correct these issues and add these enhancements. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed(https://bugzilla.redhat.com/): 1142191 - realm command crashes when no input password 1174911 - Rebase to 0.16.x 1205751 - realmd: unauthenticated Active Directory join 1205752 - CVE-2015-2704 realmd: untrusted data is used when configuring sssd.conf and/or smb.conf 1241832 - Wrong SELinux label on domain users home folders1243771 - realm fails to join domain names with underscore in name 1271618 - net ads keytab add fails on system joined to AD with RHEL 7.2 realm join 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: realmd-0.16.1-5.el7.src.rpm x86_64: realmd-0.16.1-5.el7.x86_64.rpm realmd-debuginfo-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: realmd-debuginfo-0.16.1-5.el7.x86_64.rpm realmd-devel-docs-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: realmd-0.16.1-5.el7.src.rpm x86_64: realmd-0.16.1-5.el7.x86_64.rpm realmd-debuginfo-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: realmd-debuginfo-0.16.1-5.el7.x86_64.rpm realmd-devel-docs-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: realmd-0.16.1-5.el7.src.rpm aarch64: realmd-0.16.1-5.el7.aarch64.rpm realmd-debuginfo-0.16.1-5.el7.aarch64.rpm ppc64: realmd-0.16.1-5.el7.ppc64.rpm realmd-debuginfo-0.16.1-5.el7.ppc64.rpm ppc64le: realmd-0.16.1-5.el7.ppc64le.rpm realmd-debuginfo-0.16.1-5.el7.ppc64le.rpm s390x: realmd-0.16.1-5.el7.s390x.rpm realmd-debuginfo-0.16.1-5.el7.s390x.rpm x86_64: realmd-0.16.1-5.el7.x86_64.rpm realmd-debuginfo-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): aarch64: realmd-debuginfo-0.16.1-5.el7.aarch64.rpm realmd-devel-docs-0.16.1-5.el7.aarch64.rpm ppc64: realmd-debuginfo-0.16.1-5.el7.ppc64.rpm realmd-devel-docs-0.16.1-5.el7.ppc64.rpm ppc64le: realmd-debuginfo-0.16.1-5.el7.ppc64le.rpm realmd-devel-docs-0.16.1-5.el7.ppc64le.rpm s390x: realmd-debuginfo-0.16.1-5.el7.s390x.rpm realmd-devel-docs-0.16.1-5.el7.s390x.rpm x86_64: realmd-debuginfo-0.16.1-5.el7.x86_64.rpm realmd-devel-docs-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: realmd-0.16.1-5.el7.src.rpm x86_64: realmd-0.16.1-5.el7.x86_64.rpm realmd-debuginfo-0.16.1-5.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): x86_64: realmd-debuginfo-0.16.1-5.el7.x86_64.rpm realmd-devel-docs-0.16.1-5.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2015-2704 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2015 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFWTkEFXlSAg2UNWIIRArkYAKCDNOG9yQ9fS/YfMW6QOjCN6EOdxwCgu7PC C6ysi14xA8Yx7xTqC3kO6Vk=bl2G -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Newly released realmd updates address security vulnerabilities, resolve bugs, and offer improvements for users of Red Hat Enterprise Linux 7.. Realmd Update, Bug Fix, Security Advisory, Linux Enhancement. . LinuxSecurity.com Team

Calendar 2 Nov 19, 2015 Red Hat
89

Fedora 21: FEDORA-2015-6387 Critical: realmd Configuration Issues

Fixes for security issues: rhbz#1205752 rhbz#1205753. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6387 2015-04-18 05:44:22 -------------------------------------------------------------------------------- Name : realmd Product : Fedora 21 Version : 0.15.2 Release : 2.fc21 URL : Summary : Kerberos realm enrollment service Description : realmd is a DBus system service which manages discovery and enrollment in realms and domains like Active Directory or IPA. The control center uses realmd as the back end to 'join' a domain simply and automatically configure things correctly. -------------------------------------------------------------------------------- Update Information: Fixes for security issues: rhbz#1205752 rhbz#1205753 -------------------------------------------------------------------------------- ChangeLog: * Tue Apr 14 2015 Stef Walter - 0.15.2-2 - Fixes for security issues: rhbz#1205752 rhbz#1205753 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1205752 - CVE-2015-2704 realmd: untrusted data is used when configuring sssd.conf and/or smb.conf https://bugzilla.redhat.com/show_bug.cgi?id=1205752 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update realmd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Updates targetingvulnerabilities within realmd in Fedora 21 deliver enhancements aimed at bolstering both system security and overall reliability against potential risks.. Fedora 21 Updates, realmd Security Fixes, System Service Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 08, 2015 Critical Fedora
89

Fedora 22: 2015-6124 Moderate: Realmd Active Directory Join Failures

Updated to upstream 0.16.0 Fix issue introduced by a samba subpackage split resulting in realmd failing to join Active Directory domains.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6124 2015-04-14 21:07:12 -------------------------------------------------------------------------------- Name : realmd Product : Fedora 22 Version : 0.16.0 Release : 1.fc22 URL : Summary : Kerberos realm enrollment service Description : realmd is a DBus system service which manages discovery and enrollment in realms and domains like Active Directory or IPA. The control center uses realmd as the back end to 'join' a domain simply and automatically configure things correctly. -------------------------------------------------------------------------------- Update Information: Updated to upstream 0.16.0 Fix issue introduced by a samba subpackage split resulting in realmd failing to join Active Directory domains. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1205752 - CVE-2015-2704 realmd: untrusted data is used when configuring sssd.conf and/or smb.conf https://bugzilla.redhat.com/show_bug.cgi?id=1205752 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update realmd' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Enhance your Fedora 22 realmd setup byapplying this crucial security patch that resolves issues related to joining Active Directory.. realmd Security Update, Fedora 22, Active Directory Failures, Samba Package Issues. . LinuxSecurity.com Team

Calendar 2 Apr 22, 2015 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here