Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
172

Ubuntu 16.04 Ruby Critical IMAP Injection Buffer Overflow USN-8556-1

Several security issues were fixed in Ruby.. ========================================================================== Ubuntu Security Notice USN-8556-1 July 16, 2026 ruby2.3 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: Several security issues were fixed in Ruby. Software Description: - ruby2.3: Object-oriented scripting language Details: It was discovered that the Net::IMAP client in Ruby did not properly sanitize Symbol arguments passed to IMAP commands. A remote attacker controlling a malicious IMAP server, or able to influence command arguments, could use this to inject arbitrary IMAP commands via CRLF sequences. (CVE-2026-42258) It was discovered that the Zlib::GzipReader in Ruby did not correctly ensure sufficient buffer capacity in the zstream_buffer_ungets function. An attacker could use this to craft a gzip stream that, when processed, could cause a buffer overflow, resulting in memory corruption and possibly arbitrary code execution. (CVE-2026-27820) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS libruby2.3 2.3.1-2~ubuntu16.04.16+esm15 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8556-1 CVE-2026-27820, CVE-2026-42258 . Security issues in Ruby for Ubuntu 16.04 LTS addressed with recommended updates to prevent exploitation.. Ruby security patch, Ubuntu system update, buffer overflow fix, command injection vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 16, 2026 Critical Ubuntu
217

Oracle Linux 8: ELSA-2025-0083 low: cups command injection

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-0083 http://linux.oracle.com/errata/ELSA-2025-0083.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: cups-2.2.6-62.el8_10.x86_64.rpm cups-client-2.2.6-62.el8_10.x86_64.rpm cups-devel-2.2.6-62.el8_10.i686.rpm cups-devel-2.2.6-62.el8_10.x86_64.rpm cups-filesystem-2.2.6-62.el8_10.noarch.rpm cups-ipptool-2.2.6-62.el8_10.x86_64.rpm cups-libs-2.2.6-62.el8_10.i686.rpm cups-libs-2.2.6-62.el8_10.x86_64.rpm cups-lpd-2.2.6-62.el8_10.x86_64.rpm aarch64: cups-2.2.6-62.el8_10.aarch64.rpm cups-client-2.2.6-62.el8_10.aarch64.rpm cups-devel-2.2.6-62.el8_10.aarch64.rpm cups-filesystem-2.2.6-62.el8_10.noarch.rpm cups-ipptool-2.2.6-62.el8_10.aarch64.rpm cups-libs-2.2.6-62.el8_10.aarch64.rpm cups-lpd-2.2.6-62.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//cups-2.2.6-62.el8_10.src.rpm Related CVEs: CVE-2024-47175 Description of changes: [1:2.2.6-62] - RHEL-60338 CVE-2024-47175 cups: remote command injection via attacker controlled data in PPD file _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux ELSA-2025-0021 introduces enhancements for apache to mitigate potential security vulnerabilities.. Oracle Linux, cups updates, security advisory, low severity, command injection. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jan 11, 2025 Low Oracle
217

Oracle Linux 9 ELSA-2024-9470: Low Severity cups Command Injection

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-9470 http://linux.oracle.com/errata/ELSA-2024-9470.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cups-2.3.3op2-31.el9_5.x86_64.rpm cups-client-2.3.3op2-31.el9_5.x86_64.rpm cups-devel-2.3.3op2-31.el9_5.i686.rpm cups-devel-2.3.3op2-31.el9_5.x86_64.rpm cups-filesystem-2.3.3op2-31.el9_5.noarch.rpm cups-ipptool-2.3.3op2-31.el9_5.x86_64.rpm cups-libs-2.3.3op2-31.el9_5.i686.rpm cups-libs-2.3.3op2-31.el9_5.x86_64.rpm cups-lpd-2.3.3op2-31.el9_5.x86_64.rpm cups-printerapp-2.3.3op2-31.el9_5.x86_64.rpm aarch64: cups-2.3.3op2-31.el9_5.aarch64.rpm cups-client-2.3.3op2-31.el9_5.aarch64.rpm cups-devel-2.3.3op2-31.el9_5.aarch64.rpm cups-filesystem-2.3.3op2-31.el9_5.noarch.rpm cups-ipptool-2.3.3op2-31.el9_5.aarch64.rpm cups-libs-2.3.3op2-31.el9_5.aarch64.rpm cups-lpd-2.3.3op2-31.el9_5.aarch64.rpm cups-printerapp-2.3.3op2-31.el9_5.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//cups-2.3.3op2-31.el9_5.src.rpm Related CVEs: CVE-2024-47175 Description of changes: [1:2.3.3op2-31] - RHEL-60343 CVE-2024-47175 cups: remote command injection via attacker controlled data in PPD file _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Linux Security Notice RHSA-2024-1234 reports enhancements for sshd mitigating unauthorized access vulnerabilities.. Oracle Linux Security, cups updates, command injection, security advisory. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Nov 22, 2024 Low Oracle
217

Oracle Linux 8: ELSA-2024-7463 critical: cups-filters command injection

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7463 http://linux.oracle.com/errata/ELSA-2024-7463.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: cups-filters-1.20.0-35.0.1.el8_10.x86_64.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.i686.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.x86_64.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.i686.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.x86_64.rpm aarch64: cups-filters-1.20.0-35.0.1.el8_10.aarch64.rpm cups-filters-libs-1.20.0-35.0.1.el8_10.aarch64.rpm cups-filters-devel-1.20.0-35.0.1.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates//cups-filters-1.20.0-35.0.1.el8_10.src.rpm Related CVEs: CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 Description of changes: [1.20.0-35.0.1] - header/footer not being printed in banner page. [Orabug: 28265099] (This email address is being protected from spambots. You need JavaScript enabled to view it.) - Fixes [Orabug: 29163824] source indentation not following convention (This email address is being protected from spambots. You need JavaScript enabled to view it.) [1.20.0-35] - CVE-2024-47175 cups-filters: remote command injection via attacker controlled data in PPD file - CVE-2024-47076 cups-filters: cfGetPrinterAttributes API does not perform sanitization on returned IPP attributes - CVE-2024-47176 cups-filters: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux ELSA-2024-7464 patches for nss-pam-ldapd rectify numerous severe vulnerabilities, notably privilege escalation.. Oracle Linux, cups-filters, security advisory, remote code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 02, 2024 Critical Oracle
217

Oracle9: ELSA-2024-7346 cups-filters critical security fixes

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-7346 http://linux.oracle.com/errata/ELSA-2024-7346.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: cups-filters-1.28.7-17.0.1.el9_4.x86_64.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.i686.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.x86_64.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.i686.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.x86_64.rpm aarch64: cups-filters-1.28.7-17.0.1.el9_4.aarch64.rpm cups-filters-libs-1.28.7-17.0.1.el9_4.aarch64.rpm cups-filters-devel-1.28.7-17.0.1.el9_4.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates//cups-filters-1.28.7-17.0.1.el9_4.src.rpm Related CVEs: CVE-2024-47076 CVE-2024-47175 CVE-2024-47176 Description of changes: [1.28.7-17.0.1] - header/footer not being printed in banner page. [Orabug: 28265099] (This email address is being protected from spambots. You need JavaScript enabled to view it.) - Fixes [Orabug: 29163824] source indentation not following convention (This email address is being protected from spambots. You need JavaScript enabled to view it.) [1.28.7-17] - fix rpmverify error [1.28.7-16] - CVE-2024-47175 cups-filters: remote command injection via attacker controlled data in PPD file - CVE-2024-47076 cups-filters: cfGetPrinterAttributes API does not perform sanitization on returned IPP attributes - CVE-2024-47176 cups-filters: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Important revisions for Oracle Linux 9 have been released concerning cups-filters, tackling various security vulnerabilities and improvements.. Oracle Linux, cups-filters updates, security fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 30, 2024 Critical Oracle
219

Rocky Linux 9 RLSA-2024:7346 Important: cups-filters command injection

Important: cups-filters security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:7346", "synopsis": "Important: cups-filters security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for cups-filters.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The cups-filters package contains back ends, filters, and other software that was once part of the core Common UNIX Printing System (CUPS) distribution but is now maintained independently. \n\nSecurity Fix(es):\n\n* cups-browsed: cups-browsed binds on UDP INADDR_ANY:631 trusting any packet from any source ()\n\n* cups-filters: libcupsfilters: `cfGetPrinterAttributes` API does not perform sanitization on returned IPP attributes (CVE-2024-47076)\n\n* cups: libppd: remote command injection via attacker controlled data in PPD file ()\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2314252", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314252", "description": ""}, {"ticket": "2314253", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314253", "description": ""}, {"ticket": "2314256", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2314256", "description": ""}], "cves": [{"name": "CVE-2024-47076", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47076", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}, {"name": "CVE-2024-47175", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47175", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe":"UNKNOWN"}, {"name": "CVE-2024-47176", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2024-47176", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-09-30T14:31:39.795853Z", "rpms": {"Rocky Linux 9": {"nvras": ["cups-filters-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-0:1.28.7-17.el9_4.src.rpm", "cups-filters-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-debuginfo-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-debugsource-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.i686.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-devel-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.i686.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-libs-0:1.28.7-17.el9_4.x86_64.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.aarch64.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.ppc64le.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.s390x.rpm", "cups-filters-libs-debuginfo-0:1.28.7-17.el9_4.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Significant cups-filters enhancement for Rocky Linux 9 resolves various security vulnerabilities, bolstering overall system protection.. cups filters update, rocky linux security, 2024 security advisories. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 30, 2024 Important Rocky Linux
89

Fedora 28: 2018-ca5321b5ff Moderate: mmm_agentd Remote Command Injection

# Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ca5321b5ff 2018-05-15 20:03:56.912735 --------------------------------------------------------------------------------Name : mysql-mmm Product : Fedora 28 Version : 2.2.1 Release : 20.fc28 URL : https://mysql-mmm.org/ Summary : Multi-Master Replication Manager for MySQL Description : MMM (MySQL Master-Master Replication Manager) is a set of flexible scripts to perform monitoring/failover and management of MySQL Master-Master replication configurations (with only one node writable at any time). The toolset also has the ability to read balance standard master/slave configurations with any number of slaves, so you can use it to move virtual IP addresses around a group of servers depending on whether they are behind in replication. In addition to that, it also has scripts for data backups, resynchronization between nodes etc. --------------------------------------------------------------------------------Update Information: # Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by default. A specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privilegesof the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger these vulnerabilities. The impact of these vulnerabilities can be lessened by configuring mmm_agentd to require TLS mutual authentication and by using network ACLs to prevent hosts other than legitimate mmm_mond hosts from accessing mmm_agentd. For example on Linux iptables rules can be used to block access to the port mmm_agent is listening on from all hosts except the mmm_monitor. The configuration of ssl can be used where firewall rules are not practical. See Socket Documentation https://mysql-mmm.org/mysql-mmm.html Add to mmm_common.conf type ssl cert_file /etc/ssl/certs/www..bundle.crt key_file /etc/ssl/certs/www..key ca_file /etc/ssl/certs/ca-bundle.crt # or ca-certificates.crt Now only those with access to the private key can send commands. Whilst your web server certificate will do the job, you may consider registering a dedicated certificate just for this task. NOTE: By now there are a some good alternatives to MySQL-MMM. Maybe you want to check out Galera Cluster which is part of MariaDB Galera Cluster and Percona XtraDB Cluster. - https://mysql-mmm.org/ - https://galeracluster.com/ - https://mariadb.com/kb/en/what-is-mariadb-galera-cluster/ ---------------------------------------------------------------------------------ChangeLog: * Wed May 2 2018 David Beveridge 2.2.1-20 - Patch for mmm_agentd Remote Command Injection Vulnerabilities - TALOS-2017-0501, CVE-2017-14474 - CVE-2017-14481 * Thu Feb 8 2018 Fedora Release Engineering - 2.2.1-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1575161 https://bugzilla.redhat.com/show_bug.cgi?id=1575161 --------------------------------------------------------------------------------This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2018-ca5321b5ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Update Alert for Fedora 28: php-mysql enhancements mitigate code injection vulnerabilities in mysql_agent for safer operations.. MySQL Management, Remote Command Injection, Fedora Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2018 Important Fedora
89

Fedora 27: FEDORA-2018-e31f52c5ee Moderate: MySQL-MMM Command Injection

# Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-e31f52c5ee 2018-05-15 19:52:12.739386 --------------------------------------------------------------------------------Name : mysql-mmm Product : Fedora 27 Version : 2.2.1 Release : 20.fc27 URL : https://mysql-mmm.org/ Summary : Multi-Master Replication Manager for MySQL Description : MMM (MySQL Master-Master Replication Manager) is a set of flexible scripts to perform monitoring/failover and management of MySQL Master-Master replication configurations (with only one node writable at any time). The toolset also has the ability to read balance standard master/slave configurations with any number of slaves, so you can use it to move virtual IP addresses around a group of servers depending on whether they are behind in replication. In addition to that, it also has scripts for data backups, resynchronization between nodes etc. --------------------------------------------------------------------------------Update Information: # Multi-Master Replication Manager for MySQL mmm_agentd Remote Command Injection Vulnerabilities This update adds data sanitization to inputs for the mmm agent. Multiple exploitable remote command injection vulnerabilities exist in the MySQL Master-Master Replication Manager (MMM) mmm_agentd daemon 2.2.1. mmm_agentd commonly runs with root privileges and does not require authentication by default. A specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privilegesof the mmm_agentd process. An attacker that can initiate a TCP session with mmm_agentd can trigger these vulnerabilities. The impact of these vulnerabilities can be lessened by configuring mmm_agentd to require TLS mutual authentication and by using network ACLs to prevent hosts other than legitimate mmm_mond hosts from accessing mmm_agentd. For example on Linux iptables rules can be used to block access to the port mmm_agent is listening on from all hosts except the mmm_monitor. The configuration of ssl can be used where firewall rules are not practical. See Socket Documentation https://mysql-mmm.org/mysql-mmm.html Add to mmm_common.conf type ssl cert_file /etc/ssl/certs/www..bundle.crt key_file /etc/ssl/certs/www..key ca_file /etc/ssl/certs/ca-bundle.crt # or ca-certificates.crt Now only those with access to the private key can send commands. Whilst your web server certificate will do the job, you may consider registering a dedicated certificate just for this task. NOTE: By now there are a some good alternatives to MySQL-MMM. Maybe you want to check out Galera Cluster which is part of MariaDB Galera Cluster and Percona XtraDB Cluster. - https://mysql-mmm.org/ - https://galeracluster.com/ - https://mariadb.com/kb/en/what-is-mariadb-galera-cluster/ ---------------------------------------------------------------------------------ChangeLog: * Wed May 2 2018 David Beveridge 2.2.1-20 - Patch for mmm_agentd Remote Command Injection Vulnerabilities - TALOS-2017-0501, CVE-2017-14474 - CVE-2017-14481 * Thu Feb 8 2018 Fedora Release Engineering - 2.2.1-19 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild * Wed Dec 20 2017 Ruben Kerkhof - 2.2.1-18 - Correct permissions for systemd units (#1527992) --------------------------------------------------------------------------------References: [ 1 ] Bug #1575161 https://bugzilla.redhat.com/show_bug.cgi?id=1575161 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-e31f52c5ee' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security enhancement for MySQL-MMM on Fedora 27 addressing command execution vulnerabilities and bolstering data entry safeguards.. MySQL MMM, Remote Command Injection, Fedora Update, System Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2018 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200