Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 11 articles for you...
91

Gentoo Linux: GLSA-202003-54 Low Severity: Pure-FTPd DoS Risk

Multiple vulnerabilities have been found in Pure-FTPd, the worst of which could allow remote attackers to cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202003-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Low Title: Pure-FTPd: Multiple vulnerabilities Date: March 25, 2020 Bugs: #711124 ID: 202003-54 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Pure-FTPd, the worst of which could allow remote attackers to cause a Denial of Service condition. Background ========= Pure-FTPd is a fast, production-quality and standards-compliant FTP server. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-ftp/pure-ftpd < 1.0.49-r2 > = 1.0.49-r2 Description ========== Multiple vulnerabilities have been discovered in Pure-FTPd. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly cause a Denial of Service condition or cause an information disclosure. Workaround ========= There is no known workaround at this time. Resolution ========= All Pure-FTPd users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-ftp/pure-ftpd-1.0.49-r2" References ========= [ 1 ] CVE-2020-9274 https://nvd.nist.gov/vuln/detail/CVE-2020-9274 [ 2 ] CVE-2020-9365 https://nvd.nist.gov/vuln/detail/CVE-2020-9365 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202003-54 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws in Pure-FTPd may result in service disruption. Promptly update to safeguard against external threats.. Gentoo Linux, Pure-FTPd, Denial of Service, Security Advisory, Remote Attacks. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Mar 25, 2020 Low Gentoo
199

CentOS: CESA-2018-3833 Critical Firefox Security Vulnerability Alert

Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833. CentOS Errata and Security Advisory 2018:3833 Critical Upstream details at : https://access.redhat.com/errata/RHSA-2018:3833 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: 9db402dc9f056bf640dc02800014ad688ac988ad10c7359fc66ea2b5538a951a firefox-60.4.0-1.el7.centos.i686.rpm 5553ef981d4841a3041e728e07169aad5a2d4ab0a4cd3fba5cddaefe7c9d0be9 firefox-60.4.0-1.el7.centos.x86_64.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #This email address is being protected from spambots. You need JavaScript enabled to view it. Twitter: @JohnnyCentOS _______________________________________________ CentOS-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . CentOS Errata and Security Advisory 2018:3833 Critical Upstream details at : https://access.redhat.c. upstream, details, https, //access, redhat, com/errata/rhsa-2018, centos, errata, security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 21, 2018 Critical CentOS
172

Ubuntu 14.04 LTS USN-2254-1 Moderate: PHP Local And Remote Risks

Several security issues were fixed in PHP.. =========================================================================Ubuntu Security Notice USN-2254-1 June 23, 2014 php5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php5: HTML-embedded scripting language interpreter Details: Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM) set incorrect permissions on the UNIX socket. A local attacker could use this issue to possibly elevate their privileges. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185) Francisco Alonso discovered that the PHP Fileinfo component incorrectly handled certain CDF documents. A remote attacker could use this issue to cause PHP to hang or crash, resulting in a denial of service. (CVE-2014-0237, CVE-2014-0238) Stefan Esser discovered that PHP incorrectly handled DNS TXT records. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-4049) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.1 php5-cgi 5.5.9+dfsg-1ubuntu4.1 php5-cli 5.5.9+dfsg-1ubuntu4.1 php5-fpm 5.5.9+dfsg-1ubuntu4.1 Ubuntu 13.10: libapache2-mod-php5 5.5.3+dfsg-1ubuntu2.4 php5-cgi 5.5.3+dfsg-1ubuntu2.4 php5-cli 5.5.3+dfsg-1ubuntu2.4 php5-fpm 5.5.3+dfsg-1ubuntu2.4 Ubuntu 12.04 LTS: libapache2-mod-php5 5.3.10-1ubuntu3.12 php5-cgi 5.3.10-1ubuntu3.12 php5-cli 5.3.10-1ubuntu3.12 php5-fpm 5.3.10-1ubuntu3.12 Ubuntu 10.04 LTS: libapache2-mod-php5 5.3.2-1ubuntu4.25 php5-cgi 5.3.2-1ubuntu4.25 php5-cli 5.3.2-1ubuntu4.25 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2254-1 CVE-2014-0185, CVE-2014-0237, CVE-2014-0238, CVE-2014-4049 Package Information: https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1 https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4 https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12 https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25 . Various CVEs associated with PHP vulnerabilities have been announced and patched across different Ubuntu versions, addressing threats from both local and remote attackers.. PHP Risks, Ubuntu Security, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2014 Important Ubuntu
87

Debian DSA-2848-1 MySQL 5.5 Critical Update for Remote Risks

Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.35. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2848-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso January 23, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mysql-5.5 Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2013-5891 CVE-2013-5908 CVE-2014-0386 CVE-2014-0393 CVE-2014-0401 CVE-2014-0402 CVE-2014-0412 CVE-2014-0420 CVE-2014-0437 Several issues have been discovered in the MySQL database server. The vulnerabilities are addressed by upgrading MySQL to the new upstream version 5.5.35. Please see the MySQL 5.5 Release Notes and Oracle's Critical Patch Update advisory for further details: http://dev.mysql.com/doc/relnotes/mysql/5.5/en/news-5-5-34.html https://www.oracle.com/security-alerts/cpujan2014.html For the stable distribution (wheezy), these problems have been fixed in version 5.5.35+dfsg-0+wheezy1. For the unstable distribution (sid), these problems have been fixed in version 5.5.35+dfsg-1. We recommend that you upgrade your mysql-5.5 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-1987-1 relates to multiple PostgreSQL vulnerabilities necessitating an update to version 9.3.21.. MySQL Security Update, Debian Advisory, Database Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 23, 2014 Critical Debian
87

Debian DSA-2528-1 Critical: Icedove Remote Exploitation Issues

Several vulnerabilities were discovered in Icedove, Debian's version of the Mozilla Thunderbird mail and news client. CVE-2012-1948 . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2528-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer August 14, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : icedove Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2012-1948 CVE-2012-1950 CVE-2012-1954 CVE-2012-1967 Several vulnerabilities were discovered in Icedove, Debian's version of the Mozilla Thunderbird mail and news client. CVE-2012-1948 Multiple unspecified vulnerabilities in the browser engine were fixed. CVE-2012-1950 The underlying browser engine allows address bar spoofing through drag-and-drop. CVE-2012-1954 A use-after-free vulnerability in the nsDocument::AdoptNode function allows remote attackers to cause a denial of service (heap memory corruption) or possibly execute arbitrary code. CVE-2012-1967 An error in the implementation of the Javascript sandbox allows execution of Javascript code with improper privileges using javascript: URLs. For the stable distribution (squeeze), these problems have been fixed in version 3.0.11-1+squeeze12. For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in version 10.0.6-1. We recommend that you upgrade your icedove packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Various vulnerabilities in Icedove necessitate prompt updates to safeguard against security breaches and mitigate risks associatedwith unauthorized code execution.. Debian Icedove Security Update, Remote Security Threats, Mozilla Thunderbird Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 14, 2012 Critical Debian
87

Debian Rails Critical Cross Site Scripting Risk DSA-2466-1

Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2466-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst May 09, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : rails Vulnerability : cross site scripting Problem type : remote Debian-specific: no CVE ID : CVE-2012-1099 Debian Bug : 668607 Sergey Nartimov discovered that in Rails, a Ruby based framework for web development, when developers generate html options tags manually, user input concatenated with manually built tags may not be escaped and an attacker can inject arbitrary HTML into the document. For the stable distribution (squeeze), this problem has been fixed in version 2.3.5-1.2+squeeze3. For the testing distribution (wheezy) and unstable distribution (sid), this problem has been fixed in version 2.3.14. We recommend that you upgrade your rails packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Notice DSA-2466-1 pertains to a vulnerability in Rails that permits XSS, enabling HTML code injection. It's advised to perform an upgrade to maintain security.. Debian Rails Security Update, XSS Issue, Remote Code Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 09, 2012 Critical Debian
87

Debian: DSA-2432-1 Critical: Libyaml-Libyaml-Perl Remote Threat

Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2432-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 12, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libyaml-libyaml-perl Vulnerability : format string vulnerabilities Problem type : remote Debian-specific: no CVE ID : CVE-2012-1152 Debian Bug : 661548 Dominic Hargreaves and Niko Tyni discovered two format string vulnerabilities in YAML::LibYAML, a Perl interface to the libyaml library. For the stable distribution (squeeze), this problem has been fixed in version 0.33-1+squeeze1. For the unstable distribution (sid), this problem has been fixed in version 0.38-2. We recommend that you upgrade your libyaml-libyaml-perl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Security patch advised for Ubuntu's libxml-saxon-java following remote input validation vulnerabilities found by Johansson.. libyaml, perl interface, debian update, security patch, remote risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 12, 2012 Critical Debian
200

Scientific Linux SL5 OpenSSL Moderate Threat CVE-2011-4108

Moderate: openssl security update. Date: Wed, 25 Jan 2012 09:53:09 -0600 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for Scientific Linux From: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: Security ERRATA Moderate: openssl on SL5.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: openssl security update Issue Date: 2012-01-24 CVE Numbers: CVE-2011-4108 CVE-2011-4109 CVE-2011-4576 CVE-2011-4619 OpenSSL is a toolkit that implements the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols, as well as a full-strength, general purpose cryptography library. It was discovered that the Datagram Transport Layer Security (DTLS) protocol implementation in OpenSSL leaked timing information when performing certain operations. A remote attacker could possibly use this flaw to retrieve plain text from the encrypted packets by using a DTLS server as a padding oracle. (CVE-2011-4108) A double free flaw was discovered in the policy checking code in OpenSSL. A remote attacker could use this flaw to crash an application that uses OpenSSL by providing an X.509 certificate that has specially-crafted policy extension data. (CVE-2011-4109) An information leak flaw was found in the SSL 3.0 protocol implementation in OpenSSL. Incorrect initialization of SSL record padding bytes could cause an SSL client or server to send a limited amount of possibly sensitive data to its SSL peer via the encrypted connection. (CVE-2011-4576) It was discovered that OpenSSL did not limit the number of TLS/SSL handshake restarts required to support Server Gated Cryptography. A remote attacker could use this flaw to make a TLS/SSL server using OpenSSL consume an excessive amount of CPU by continuously restarting the handshake. (CVE-2011-4619) All OpenSSL users should upgrade to these updated packages, which contain backported patches to resolve these issues. For the update to take effect, all services linked to the OpenSSL library must be restarted, or the system rebooted. SL5: i386 openssl-0.9.8e-20.el5_7.1.i386.rpm openssl-0.9.8e-20.el5_7.1.i686.rpm openssl-debuginfo-0.9.8e-20.el5_7.1.i386.rpm openssl-debuginfo-0.9.8e-20.el5_7.1.i686.rpm openssl-devel-0.9.8e-20.el5_7.1.i386.rpm openssl-perl-0.9.8e-20.el5_7.1.i386.rpm x86_64 openssl-0.9.8e-20.el5_7.1.i686.rpm openssl-0.9.8e-20.el5_7.1.x86_64.rpm openssl-debuginfo-0.9.8e-20.el5_7.1.i386.rpm openssl-debuginfo-0.9.8e-20.el5_7.1.i686.rpm openssl-debuginfo-0.9.8e-20.el5_7.1.x86_64.rpm openssl-devel-0.9.8e-20.el5_7.1.i386.rpm openssl-devel-0.9.8e-20.el5_7.1.x86_64.rpm openssl-perl-0.9.8e-20.el5_7.1.x86_64.rpm - Scientific Linux Development Team . A recent update to OpenSSL addresses various vulnerabilities affecting Scientific Linux.. openssl security update, scientific linux advisory, remote attack risk. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jan 25, 2012 moderate Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200