Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. (CVE-2021-38165) References: . MGASA-2021-0422 - Updated lynx packages fix security vulnerability Publication date: 23 Sep 2021 URL: https://advisories.mageia.org/MGASA-2021-0422.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-38165 Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. (CVE-2021-38165) References: - https://bugs.mageia.org/show_bug.cgi?id=29342 - https://www.openwall.com/lists/oss-security/2021/08/07/9 - https://lists.debian.org/debian-security-announce/2021/msg00136.html - https://www.cve.org/CVERecord?id=CVE-2021-38165 SRPMS: - 8/core/lynx-2.8.9-0.dev17.4.1.mga8 . New Lynx versions address security vulnerabilities in Mageia 8, released on 23 Sep 2021.. Mageia Lynx Security Fix, Credential Exposure, Remote Attack Mitigation. . Severity: Important. LinuxSecurity.com Team
A directory traversal was found in ZNC, allowing for overwriting of arbitrary files.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200909-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ZNC: Directory traversal Date: September 13, 2009 Bugs: #278684 ID: 200909-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A directory traversal was found in ZNC, allowing for overwriting of arbitrary files. Background ========= ZNC is an advanced IRC bouncer. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/znc < 0.074 > = 0.074 Description ========== The vendor reported a directory traversal vulnerability when processing DCC SEND requests. Impact ===== A remote, authenticated user could send a specially crafted DCC SEND request to overwrite arbitrary files with the privileges of the user running ZNC, and possibly cause the execution of arbitrary code e.g. by uploading a malicious ZNC module. Workaround ========= There is no known workaround at this time. Resolution ========= All ZNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose =net-irc/znc-0.074 References ========= [ 1 ] CVE-2009-2658 https://www.cve.org/CVERecord?id=CVE-2009-2658 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200909-17 Concerns? ======== Security is a primary focus of Gentoo Linuxand ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
It was discovered that the Apache 1.3 connector for the Tomcat Java servlet engine decoded request URLs multiple times, which can lead to information disclosure.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1312-1
Get the latest Linux and open source security news straight to your inbox.