Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

SUSE Linux Enterprise Micro 5.5 Advisory: Important CUPS Security Update

* bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235 . # Security update for cups Announcement ID: SUSE-SU-2024:2003-2 Rating: important References: * bsc#1223179 * bsc#1225365 Cross-References: * CVE-2024-35235 CVSS scores: * CVE-2024-35235 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for cups fixes the following issues: * CVE-2024-35235: Fixed a bug in cupsd that could allow an attacker to change the permissions of other files in the system. (bsc#1225365) * Handle local 'Negotiate' authentication response for cli clients (bsc#1223179) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2024-2003=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libcups2-2.2.7-150000.3.59.1 * cups-debuginfo-2.2.7-150000.3.59.1 * cups-debugsource-2.2.7-150000.3.59.1 * libcups2-debuginfo-2.2.7-150000.3.59.1 * cups-config-2.2.7-150000.3.59.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35235.html * https://bugzilla.suse.com/show_bug.cgi?id=1223179 * https://bugzilla.suse.com/show_bug.cgi?id=1225365 . Crucial patch for CUPS resolves possible alterations in file access rights for SUSE Linux Enterprise Micro 5.5.. SUSE Linux Enterprise, CUPS Update, Important Security Advisory, File Permission Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 12, 2024 Important SuSE
98

RedHat: RHSA-2019-1131 Important: FreeRADIUS Authentication Bypass

An update for freeradius is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: freeradius security update Advisory ID: RHSA-2019:1131-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1131 Issue date: 2019-05-09 CVE Names: CVE-2019-11234 CVE-2019-11235 ==================================================================== 1. Summary: An update for freeradius is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, ppc64le, s390x 3. Description: FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network. Security Fix(es): * freeradius: eap-pwd: authentication bypass via an invalid curve attack (CVE-2019-11235) * freeradius: eap-pwd: fakeauthentication using reflection (CVE-2019-11234) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1695748 - CVE-2019-11235 freeradius: eap-pwd: authentication bypass via an invalid curve attack 1695783 - CVE-2019-11234 freeradius: eap-pwd: fake authentication using reflection 6. Package List: Red Hat Enterprise Linux Server (v. 7): Source: freeradius-3.0.13-10.el7_6.src.rpm ppc64: freeradius-3.0.13-10.el7_6.ppc64.rpm freeradius-debuginfo-3.0.13-10.el7_6.ppc64.rpm ppc64le: freeradius-3.0.13-10.el7_6.ppc64le.rpm freeradius-debuginfo-3.0.13-10.el7_6.ppc64le.rpm s390x: freeradius-3.0.13-10.el7_6.s390x.rpm freeradius-debuginfo-3.0.13-10.el7_6.s390x.rpm x86_64: freeradius-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7): Source: freeradius-3.0.13-10.el7_6.src.rpm aarch64: freeradius-3.0.13-10.el7_6.aarch64.rpm freeradius-debuginfo-3.0.13-10.el7_6.aarch64.rpm ppc64le: freeradius-3.0.13-10.el7_6.ppc64le.rpm freeradius-debuginfo-3.0.13-10.el7_6.ppc64le.rpm s390x: freeradius-3.0.13-10.el7_6.s390x.rpm freeradius-debuginfo-3.0.13-10.el7_6.s390x.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: freeradius-debuginfo-3.0.13-10.el7_6.ppc.rpm freeradius-debuginfo-3.0.13-10.el7_6.ppc64.rpm freeradius-devel-3.0.13-10.el7_6.ppc.rpm freeradius-devel-3.0.13-10.el7_6.ppc64.rpm freeradius-doc-3.0.13-10.el7_6.ppc64.rpm freeradius-krb5-3.0.13-10.el7_6.ppc64.rpm freeradius-ldap-3.0.13-10.el7_6.ppc64.rpm freeradius-mysql-3.0.13-10.el7_6.ppc64.rpm freeradius-perl-3.0.13-10.el7_6.ppc64.rpm freeradius-postgresql-3.0.13-10.el7_6.ppc64.rpm freeradius-python-3.0.13-10.el7_6.ppc64.rpm freeradius-sqlite-3.0.13-10.el7_6.ppc64.rpm freeradius-unixODBC-3.0.13-10.el7_6.ppc64.rpm freeradius-utils-3.0.13-10.el7_6.ppc64.rpm ppc64le: freeradius-debuginfo-3.0.13-10.el7_6.ppc64le.rpm freeradius-devel-3.0.13-10.el7_6.ppc64le.rpm freeradius-doc-3.0.13-10.el7_6.ppc64le.rpm freeradius-krb5-3.0.13-10.el7_6.ppc64le.rpm freeradius-ldap-3.0.13-10.el7_6.ppc64le.rpm freeradius-mysql-3.0.13-10.el7_6.ppc64le.rpm freeradius-perl-3.0.13-10.el7_6.ppc64le.rpm freeradius-postgresql-3.0.13-10.el7_6.ppc64le.rpm freeradius-python-3.0.13-10.el7_6.ppc64le.rpm freeradius-sqlite-3.0.13-10.el7_6.ppc64le.rpm freeradius-unixODBC-3.0.13-10.el7_6.ppc64le.rpm freeradius-utils-3.0.13-10.el7_6.ppc64le.rpm s390x: freeradius-debuginfo-3.0.13-10.el7_6.s390.rpm freeradius-debuginfo-3.0.13-10.el7_6.s390x.rpm freeradius-devel-3.0.13-10.el7_6.s390.rpm freeradius-devel-3.0.13-10.el7_6.s390x.rpm freeradius-doc-3.0.13-10.el7_6.s390x.rpm freeradius-krb5-3.0.13-10.el7_6.s390x.rpm freeradius-ldap-3.0.13-10.el7_6.s390x.rpm freeradius-mysql-3.0.13-10.el7_6.s390x.rpm freeradius-perl-3.0.13-10.el7_6.s390x.rpm freeradius-postgresql-3.0.13-10.el7_6.s390x.rpm freeradius-python-3.0.13-10.el7_6.s390x.rpm freeradius-sqlite-3.0.13-10.el7_6.s390x.rpm freeradius-unixODBC-3.0.13-10.el7_6.s390x.rpm freeradius-utils-3.0.13-10.el7_6.s390x.rpm x86_64: freeradius-debuginfo-3.0.13-10.el7_6.i686.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm freeradius-devel-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.13-10.el7_6.x86_64.rpm freeradius-doc-3.0.13-10.el7_6.x86_64.rpm freeradius-krb5-3.0.13-10.el7_6.x86_64.rpm freeradius-ldap-3.0.13-10.el7_6.x86_64.rpm freeradius-mysql-3.0.13-10.el7_6.x86_64.rpm freeradius-perl-3.0.13-10.el7_6.x86_64.rpm freeradius-postgresql-3.0.13-10.el7_6.x86_64.rpm freeradius-python-3.0.13-10.el7_6.x86_64.rpm freeradius-sqlite-3.0.13-10.el7_6.x86_64.rpm freeradius-unixODBC-3.0.13-10.el7_6.x86_64.rpm freeradius-utils-3.0.13-10.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v.7): aarch64: freeradius-debuginfo-3.0.13-10.el7_6.aarch64.rpm freeradius-devel-3.0.13-10.el7_6.aarch64.rpm freeradius-doc-3.0.13-10.el7_6.aarch64.rpm freeradius-krb5-3.0.13-10.el7_6.aarch64.rpm freeradius-ldap-3.0.13-10.el7_6.aarch64.rpm freeradius-mysql-3.0.13-10.el7_6.aarch64.rpm freeradius-perl-3.0.13-10.el7_6.aarch64.rpm freeradius-postgresql-3.0.13-10.el7_6.aarch64.rpm freeradius-python-3.0.13-10.el7_6.aarch64.rpm freeradius-sqlite-3.0.13-10.el7_6.aarch64.rpm freeradius-unixODBC-3.0.13-10.el7_6.aarch64.rpm freeradius-utils-3.0.13-10.el7_6.aarch64.rpm ppc64le: freeradius-debuginfo-3.0.13-10.el7_6.ppc64le.rpm freeradius-devel-3.0.13-10.el7_6.ppc64le.rpm freeradius-doc-3.0.13-10.el7_6.ppc64le.rpm freeradius-krb5-3.0.13-10.el7_6.ppc64le.rpm freeradius-ldap-3.0.13-10.el7_6.ppc64le.rpm freeradius-mysql-3.0.13-10.el7_6.ppc64le.rpm freeradius-perl-3.0.13-10.el7_6.ppc64le.rpm freeradius-postgresql-3.0.13-10.el7_6.ppc64le.rpm freeradius-python-3.0.13-10.el7_6.ppc64le.rpm freeradius-sqlite-3.0.13-10.el7_6.ppc64le.rpm freeradius-unixODBC-3.0.13-10.el7_6.ppc64le.rpm freeradius-utils-3.0.13-10.el7_6.ppc64le.rpm s390x: freeradius-debuginfo-3.0.13-10.el7_6.s390.rpm freeradius-debuginfo-3.0.13-10.el7_6.s390x.rpm freeradius-devel-3.0.13-10.el7_6.s390.rpm freeradius-devel-3.0.13-10.el7_6.s390x.rpm freeradius-doc-3.0.13-10.el7_6.s390x.rpm freeradius-krb5-3.0.13-10.el7_6.s390x.rpm freeradius-ldap-3.0.13-10.el7_6.s390x.rpm freeradius-mysql-3.0.13-10.el7_6.s390x.rpm freeradius-perl-3.0.13-10.el7_6.s390x.rpm freeradius-postgresql-3.0.13-10.el7_6.s390x.rpm freeradius-python-3.0.13-10.el7_6.s390x.rpm freeradius-sqlite-3.0.13-10.el7_6.s390x.rpm freeradius-unixODBC-3.0.13-10.el7_6.s390x.rpm freeradius-utils-3.0.13-10.el7_6.s390x.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: freeradius-3.0.13-10.el7_6.src.rpm x86_64: freeradius-3.0.13-10.el7_6.x86_64.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): x86_64: freeradius-debuginfo-3.0.13-10.el7_6.i686.rpm freeradius-debuginfo-3.0.13-10.el7_6.x86_64.rpm freeradius-devel-3.0.13-10.el7_6.i686.rpm freeradius-devel-3.0.13-10.el7_6.x86_64.rpm freeradius-doc-3.0.13-10.el7_6.x86_64.rpm freeradius-krb5-3.0.13-10.el7_6.x86_64.rpm freeradius-ldap-3.0.13-10.el7_6.x86_64.rpm freeradius-mysql-3.0.13-10.el7_6.x86_64.rpm freeradius-perl-3.0.13-10.el7_6.x86_64.rpm freeradius-postgresql-3.0.13-10.el7_6.x86_64.rpm freeradius-python-3.0.13-10.el7_6.x86_64.rpm freeradius-sqlite-3.0.13-10.el7_6.x86_64.rpm freeradius-unixODBC-3.0.13-10.el7_6.x86_64.rpm freeradius-utils-3.0.13-10.el7_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-11234 https://access.redhat.com/security/cve/CVE-2019-11235 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXNRC0dzjgjWX9erEAQipFQ//R37CJofWgyEAlXtSUHeT7vvlmsWIV2IW fyJwS5bkVG+5i8ijoE9nLbJQ7lZDHeF6uAtUeVDt6x/O7YH1VfYi6sTOF4dGDmyH 77j2eSBRYmaIJirTvpaVYY4vTRn57Kx507tPdlhjKI6vNN4fEzb6tOZHEbLYI4Hi s2ANb/hq3ZQnKg9n1QMCCtOgUgPmiNEsS8+j5gxqGDtHLTXWUnCz2XWbFI4QleQm q/99clzidN/CsGkG9OaJQPFX6Rpazneooqifntgc8ZoyNS2r0mz8mYtXqhrcKZ+h AW8XW19hLRm/EgosIo146br7XBFvCZ8DQDl0WCpunvuAJK87exj9nzcjYufEdOmI BG2Qmg/fxax52cX8g94PaOy3kR4EuVOm2O2bM1IAbaz4lIUE1d2v0f0eb6/Dq5KC gYsG1NN8Y+7EcbZf5ih1dXlUSnXq3FtDQj5T3xhER8o2hLZsZBfoDXSCph09cK1L LxE3bMP6X/3dxERqSuYvPoxxULC52FoM7CL2BAcQau/1p7ArT+pSnqf2XEiYvWH6 UTKNCPF1B2mPp5X+Zuf4YIlR269EEEZWf+GSFj3vQBPBGKDPQQyG9WzJwQrxgi4p SVrhjSPmWFt6weic9mMuALu64mWIyHSiRpN7Ss1n7DkHU44NEgYBRE+XAIZWilQe FvgiOlbe2LI=j5lk -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNEDMESSAGE----- Hash: SHA256 ====================================================. update, freeradius, enterprise, linux, product, security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 09, 2019 Important Red Hat
89

Fedora 26 SSSD Security Update: Important Fix for Authentication Issues

Security fix for [CVE-2017-12173]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-65b543b628 2017-10-21 19:43:49.633966 --------------------------------------------------------------------------------Name : sssd Product : Fedora 26 Version : 1.15.3 Release : 5.fc26 URL : https://pagure.io/SSSD/sssd/ Summary : System Security Services Daemon Description : Provides a set of daemons to manage access to remote directories and authentication mechanisms. It provides an NSS and PAM interface toward the system and a plug-gable back-end system to connect to multiple different account sources. It is also the basis to provide client auditing and policy services for projects like FreeIPA. The sssd sub-package is a meta-package that contains the daemon as well as all the existing back ends. --------------------------------------------------------------------------------Update Information: Security fix for [CVE-2017-12173] --------------------------------------------------------------------------------References: [ 1 ] Bug #1498173 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database https://bugzilla.redhat.com/show_bug.cgi?id=1498173 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sssd' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . An update for Fedora 26 addresses a security vulnerability in sssd, enhancing the system's security. Install it via 'sudo dnf update sssd' for protection against potential exploits.. Fedora 26, SSSD Patch, Security Fix, Authentication Services. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 21, 2017 Important Fedora
172

Ubuntu 16.04: USN-2950-5 Moderate Samba Regression Issue Fix

USN-2950-1 introduced a regression in Samba.. =========================================================================Ubuntu Security Notice USN-2950-5 May 25, 2016 samba regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 15.10 - Ubuntu 14.04 LTS Summary: USN-2950-1 introduced a regression in Samba. Software Description: - samba: SMB/CIFS file, print, and login server for Unix Details: USN-2950-1 fixed vulnerabilities in Samba. USN-2950-3 updated Samba to version 4.3.9, which introduced a regression when using the ntlm_auth tool. This update fixes the problem. Original advisory details: Jouni Knuutinen discovered that Samba contained multiple flaws in the DCE/RPC implementation. A remote attacker could use this issue to perform a denial of service, downgrade secure connections by performing a man in the middle attack, or possibly execute arbitrary code. (CVE-2015-5370) Stefan Metzmacher discovered that Samba contained multiple flaws in the NTLMSSP authentication implementation. A remote attacker could use this issue to downgrade connections to plain text by performing a man in the middle attack. (CVE-2016-2110) Alberto Solino discovered that a Samba domain controller would establish a secure connection to a server with a spoofed computer name. A remote attacker could use this issue to obtain sensitive information. (CVE-2016-2111) Stefan Metzmacher discovered that the Samba LDAP implementation did not enforce integrity protection. A remote attacker could use this issue to hijack LDAP connections by performing a man in the middle attack. (CVE-2016-2112) Stefan Metzmacher discovered that Samba did not validate TLS certificates. A remote attacker could use this issue to spoof a Samba server. (CVE-2016-2113) Stefan Metzmacher discovered that Samba did not enforce SMB signing even if configured to. Aremote attacker could use this issue to perform a man in the middle attack. (CVE-2016-2114) Stefan Metzmacher discovered that Samba did not enable integrity protection for IPC traffic. A remote attacker could use this issue to perform a man in the middle attack. (CVE-2016-2115) Stefan Metzmacher discovered that Samba incorrectly handled the MS-SAMR and MS-LSAD protocols. A remote attacker could use this flaw with a man in the middle attack to impersonate users and obtain sensitive information from the Security Account Manager database. This flaw is known as Badlock. (CVE-2016-2118) Samba has been updated to 4.3.8 in Ubuntu 14.04 LTS and Ubuntu 15.10. Ubuntu 12.04 LTS has been updated to 3.6.25 with backported security fixes. In addition to security fixes, the updated packages contain bug fixes, new features, and possibly incompatible changes. Configuration changes may be required in certain environments. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: samba 2:4.3.9+dfsg-0ubuntu0.16.04.2 Ubuntu 15.10: samba 2:4.3.9+dfsg-0ubuntu0.15.10.2 Ubuntu 14.04 LTS: samba 2:4.3.9+dfsg-0ubuntu0.14.04.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2950-5 https://ubuntu.com/security/notices/USN-2950-1 https://bugs.launchpad.net/ubuntu/+source/samba/+bug/1578576 Package Information: https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.16.04.2 https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.15.10.2 https://launchpad.net/ubuntu/+source/samba/2:4.3.9+dfsg-0ubuntu0.14.04.3 . USN-4061-1 tackles critical Apache flaws affecting various Ubuntu distributions. Upgrade for improved protection.. Ubuntu Samba Security Update, Samba Regression Fix, Denial Of Service Threats, RemoteAuthentication Issues. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 25, 2016 Important Ubuntu
89

Fedora 23 gsi-openssh 2016-188267b485 Critical: Remote Authentication Issue

Sync with openssh package.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-188267b485 2016-04-25 18:03:33.085699 -------------------------------------------------------------------------------- Name : gsi-openssh Product : Fedora 23 Version : 7.2p2 Release : 1.fc23 URL : https://www.openssh.org/portable.html Summary : An implementation of the SSH protocol with GSI authentication Description : SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This version of OpenSSH has been modified to support GSI authentication. This package includes the core files necessary for both the gsissh client and server. To make this package useful, you should also install gsi-openssh-clients, gsi-openssh-server, or both. -------------------------------------------------------------------------------- Update Information: Sync with openssh package. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1318201 - CVE-2016-3115 gsi-openssh: openssh: missing sanitisation of input for X11 forwarding [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1318201 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update gsi-openssh' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Essential patch released for gsi-openssh in Fedora 23 bolsters secure SSH operations and enhances X11 forwarding capabilities.. gsi-openssh security update,Fedora 23,SSH enhancement,network security update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 25, 2016 Critical Fedora
100

SUSE: 2015:0290-2 Important: KRB5 Remote Authenticator Issues

An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available. An update that fixes 5 vulnerabilities is now available.. SUSE Security Update: Security update for krb5 ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:0290-2 Rating: important References: #897874 #898439 #912002 Cross-References: CVE-2014-5351 CVE-2014-5352 CVE-2014-9421 CVE-2014-9422 CVE-2014-9423 Affected Products: SUSE Linux Enterprise Software Development Kit 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Build System Kit 12 ______________________________________________________________________________ An update that fixes 5 vulnerabilities is now available. Description: MIT kerberos krb5 was updated to fix several security issues and bugs. Security issues fixed: CVE-2014-5351: The kadm5_randkey_principal_3 function in lib/kadm5/srv/svr_principal.c in kadmind in MIT Kerberos 5 (aka krb5) sent old keys in a response to a -randkey -keepold request, which allowed remote authenticated users to forge tickets by leveraging administrative access. CVE-2014-5352: In the MIT krb5 libgssapi_krb5 library, after gss_process_context_token() is used to process a valid context deletion token, the caller was left with a security context handle containing a dangling pointer. Further uses of this handle would have resulted in use-after-free and double-free memory access violations. libgssrpc server applications such as kadmind were vulnerable as they can be instructed to call gss_process_context_token(). CVE-2014-9421: If the MIT krb5 kadmind daemon receives invalid XDR data from an authenticated user, it may have performed use-after-free and double-free memory access violations while cleaning up the partial deserialization results. Other libgssrpc server applications might also been vulnerable if they contain insufficiently defensive XDR functions. CVE-2014-9422: The MIT krb5 kadmind daemon incorrectly accepted authentications to two-component server principals whose first component is a left substring of "kadmin" or whose realm is a left prefix of the default realm. CVE-2014-9423: libgssrpc applications including kadmind output four or eight bytes of uninitialized memory to the network as part of an unused "handle" field in replies to clients. Bugs fixed: - Work around replay cache creation race; (bnc#898439). Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 12: zypper in -t patch SUSE-SLE-SDK-12-2015-74=1 - SUSE Linux Enterprise Server 12: zypper in -t patch SUSE-SLE-SERVER-12-2015-74=1 - SUSE Linux Enterprise Desktop 12: zypper in -t patch SUSE-SLE-DESKTOP-12-2015-74=1 - SUSE Linux Enterprise Build System Kit 12: zypper in -t patch SUSE-SLE-BSK-12-2015-74=1 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Software Development Kit 12 (x86_64): krb5-debuginfo-1.12.1-9.1 krb5-debugsource-1.12.1-9.1 krb5-devel-1.12.1-9.1 - SUSE Linux Enterprise Server 12 (x86_64): krb5-1.12.1-9.1 krb5-32bit-1.12.1-9.1 krb5-client-1.12.1-9.1 krb5-client-debuginfo-1.12.1-9.1 krb5-debuginfo-1.12.1-9.1 krb5-debuginfo-32bit-1.12.1-9.1 krb5-debugsource-1.12.1-9.1 krb5-doc-1.12.1-9.1 krb5-plugin-kdb-ldap-1.12.1-9.1 krb5-plugin-kdb-ldap-debuginfo-1.12.1-9.1 krb5-plugin-preauth-otp-1.12.1-9.1 krb5-plugin-preauth-otp-debuginfo-1.12.1-9.1 krb5-plugin-preauth-pkinit-1.12.1-9.1 krb5-plugin-preauth-pkinit-debuginfo-1.12.1-9.1 krb5-server-1.12.1-9.1 krb5-server-debuginfo-1.12.1-9.1 - SUSE Linux Enterprise Desktop 12 (x86_64): krb5-1.12.1-9.1 krb5-32bit-1.12.1-9.1 krb5-client-1.12.1-9.1 krb5-client-debuginfo-1.12.1-9.1 krb5-debuginfo-1.12.1-9.1 krb5-debuginfo-32bit-1.12.1-9.1 krb5-debugsource-1.12.1-9.1 - SUSE Linux Enterprise Build System Kit 12 (x86_64): krb5-mini-1.12.1-9.1 krb5-mini-debuginfo-1.12.1-9.1 krb5-mini-debugsource-1.12.1-9.1 krb5-mini-devel-1.12.1-9.1 References: https://www.suse.com/security/cve/CVE-2014-5351.html https://www.suse.com/security/cve/CVE-2014-5352.html https://www.suse.com/security/cve/CVE-2014-9421.html https://www.suse.com/security/cve/CVE-2014-9422.html https://www.suse.com/security/cve/CVE-2014-9423.html https://bugzilla.suse.com/show_bug.cgi?id=897874 https://bugzilla.suse.com/show_bug.cgi?id=898439 https://bugzilla.suse.com/show_bug.cgi?id=912002 . Critical SUSE security patch for krb5 addresses numerous vulnerabilities. Refer to advisory SUSE-SU-2015:0291-3 for further information.. SUSE Security Update, krb5 Patch, Important Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 16, 2015 Important SuSE
91

Gentoo: GLSA-201309-02 Low Severity: strongSwan Denial of Service

Multiple vulnerabilities have been found in strongSwan, possibly allowing remote attackers to authenticate as other users or cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201309-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: strongSwan: Multiple vulnerabilities Date: September 01, 2013 Bugs: #468504, #479396, #483202 ID: 201309-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in strongSwan, possibly allowing remote attackers to authenticate as other users or cause a Denial of Service condition. Background ========= strongSwan is an IPSec implementation for Linux. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/strongswan < 5.1.0 > = 5.1.0 Description ========== Multiple vulnerabilities have been discovered in strongSwan. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could use ECDSA to authenticate as another user with an invalid signature. Additionally, a remote attacker could send a specially crafted request, possibly resulting in a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All strongSwan users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/strongswan-5.1.0" References ========= [ 1 ] CVE-2013-2054 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2054 [ 2 ]CVE-2013-2944 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2944 [ 3 ] CVE-2013-5018 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-5018 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201309-02 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2013 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous weaknesses in strongSwan may lead to remote threats; it is recommended to update for enhanced safety on Gentoo platforms.. strongSwan,Gentoo Linux,remote access security. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 02, 2013 Low Gentoo
172

Ubuntu: 6.06, 7.10 USN-669-1 Critical: Gnome-Screensaver Access Flaws

It was discovered that the notify feature in gnome-screensaver could let a local attacker read the clipboard contents of a locked session by using Ctrl-V. (CVE-2007-6389) Alan Matsuoka discovered that gnome-screensaver did not properly handle network outages when using a remote authentication service. During a network interruption, or by disconnecting the network cable, a local attacker could gain access to locked sessions. (CVE-2008-0887) . ==========================================================Ubuntu Security Notice USN-669-1 November 11, 2008 gnome-screensaver vulnerabilities CVE-2007-6389, CVE-2008-0887 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: gnome-screensaver 2.14.3-0ubuntu1.1 Ubuntu 7.10: gnome-screensaver 2.20.0-0ubuntu4.3 After a standard system upgrade you need to restart all user sessions on your computer to effect the necessary changes. Details follow: It was discovered that the notify feature in gnome-screensaver could let a local attacker read the clipboard contents of a locked session by using Ctrl-V. (CVE-2007-6389) Alan Matsuoka discovered that gnome-screensaver did not properly handle network outages when using a remote authentication service. During a network interruption, or by disconnecting the network cable, a local attacker could gain access to locked sessions. (CVE-2008-0887) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 14632 858a17bd71cf1969f89c9f7248840e0b Size/MD5: 1515 100a66b14d50912bd73b49b6915d849b Size/MD5: 2122211 9c95c9d0ad4c44a215546dd4b95992b0 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1502090 d5bfdd6505afe949c6414fb01dab0bb9 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1483824 bcb42c8bb0a73fbc06c5a465a75fa299 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1499086 d7e65422d70d2ff6405b0472f03b1c1f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1486326 bff6d9f48780721f2621a0c6895aa143 Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 25605 044d070d183f0e073dc1ac81945b0cc5 Size/MD5: 1695 472b10fdbd46177cbe20b58350265d64 Size/MD5: 2320018 db71d89c66fa3a96b3b276403b5bb723 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 1587388 6655526c8225d3b139eb36c1cbbf948a i386 architecture (x86 compatible Intel/AMD): Size/MD5: 1570386 456e6a56f46efac8de675aa906bf70c2 lpia architecture (Low Power Intel Architecture): Size/MD5: 1569166 c7f1ce8eeee0127cd557a78cf9591b36 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 1606010 a65b33b3a95a7d23bcbdd5e894785852 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 1576698 1566098fa61738a75ecaf0c98886eac1 --=-4IVhQM1uIY3V+c53vAYj Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part -----BEGIN PGP SIGNATURE-----Version: GnuPG v1.4.9 (GNU/Linux) iEYEABECAAYFAkkZ6YMACgkQLMAs/0C4zNqEIQCdEUWEt3CYBpeUaE+twytiUGPA g/gAnRoDkRs4ytcBYz2oK0i1G2Exq61n =WxiA -----END PGP SIGNATURE-------=-4IVhQM1uIY3V+c53vAYj-- --============== 13297292607603603=Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce --============== 13297292607603603==-- .==========================================================Ubuntu Security Notice USN-669-1 November . notify, feature, gnome-screensaver, local, attacker. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 11, 2008 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200