Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple vulnerabilities have been found in Pure-FTPd, the worst of which could allow remote attackers to cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Pure-FTPd: Multiple vulnerabilities Date: March 25, 2020 Bugs: #711124 ID: 202003-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Pure-FTPd, the worst of which could allow remote attackers to cause a Denial of Service condition. Background ========= Pure-FTPd is a fast, production-quality and standards-compliant FTP server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-ftp/pure-ftpd < 1.0.49-r2 > = 1.0.49-r2 Description ========== Multiple vulnerabilities have been discovered in Pure-FTPd. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly cause a Denial of Service condition or cause an information disclosure. Workaround ========= There is no known workaround at this time. Resolution ========= All Pure-FTPd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-ftp/pure-ftpd-1.0.49-r2" References ========= [ 1 ] CVE-2020-9274 https://nvd.nist.gov/vuln/detail/CVE-2020-9274 [ 2 ] CVE-2020-9365 https://nvd.nist.gov/vuln/detail/CVE-2020-9365 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-54 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833. CentOS Errata and Security Advisory 2018:3833 Critical Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 9db402dc9f056bf640dc02800014ad688ac988ad10c7359fc66ea2b5538a951a firefox-60.4.0-1.el7.centos.i686.rpm 5553ef981d4841a3041e728e07169aad5a2d4ab0a4cd3fba5cddaefe7c9d0be9 firefox-60.4.0-1.el7.centos.x86_64.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Several security issues were fixed in PHP.. =========================================================================Ubuntu Security Notice USN-2254-1 June 23, 2014 php5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php5: HTML-embedded scripting language interpreter Details: Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM) set incorrect permissions on the UNIX socket. A local attacker could use this issue to possibly elevate their privileges. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185) Francisco Alonso discovered that the PHP Fileinfo component incorrectly handled certain CDF documents. A remote attacker could use this issue to cause PHP to hang or crash, resulting in a denial of service. (CVE-2014-0237, CVE-2014-0238) Stefan Esser discovered that PHP incorrectly handled DNS TXT records. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-4049) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.1 php5-cgi 5.5.9+dfsg-1ubuntu4.1 php5-cli 5.5.9+dfsg-1ubuntu4.1 php5-fpm 5.5.9+dfsg-1ubuntu4.1 Ubuntu 13.10: libapache2-mod-php5 5.5.3+dfsg-1ubuntu2.4 php5-cgi 5.5.3+dfsg-1ubuntu2.4 php5-cli 5.5.3+dfsg-1ubuntu2.4 php5-fpm 5.5.3+dfsg-1ubuntu2.4 Ubuntu 12.04 LTS: libapache2-mod-php5 5.3.10-1ubuntu3.12 php5-cgi 5.3.10-1ubuntu3.12 php5-cli 5.3.10-1ubuntu3.12 php5-fpm 5.3.10-1ubuntu3.12 Ubuntu 10.04 LTS: libapache2-mod-php5 5.3.2-1ubuntu4.25 php5-cgi 5.3.2-1ubuntu4.25 php5-cli 5.3.2-1ubuntu4.25 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2254-1 CVE-2014-0185, CVE-2014-0237, CVE-2014-0238, CVE-2014-4049 Package Information: https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1 https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4 https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12 https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25 . Various CVEs associated with PHP vulnerabilities have been announced and patched across different Ubuntu versions, addressing threats from both local and remote attackers.. PHP Risks, Ubuntu Security, Denial of Service. . Severity: Important. LinuxSecurity.com Team
Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.35. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2848-1
Several vulnerabilities were discovered in Icedove, Debian's version of the Mozilla Thunderbird mail and news client. CVE-2012-1948 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2528-1
Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2466-1
Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2432-1
Moderate: openssl security update. Date: Wed, 25 Jan 2012 09:53:09 -0600 Reply-To:
Get the latest Linux and open source security news straight to your inbox.