Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

SuSE: Local Root Exploit Advisory for SCCW Security Update Notice

sccw does insufficient bounds checking, trust it's environment and calls insecure system functions. On a default installation sccw is setuid root. . ______________________________________________________________________________ SuSE Security Announcement Package: sccw-1.x Date: Mon Sep 27 23:06:13 CEST 1999 Affected: all Linux distributions using sccw 1.x ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that that we provide this information on "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. _____________________________________________________________________________ 1. Problem Description sccw does insufficient bounds checking, trust it's environment and calls insecure system functions. On a default installation sccw is setuid root. 2. Impact These bugs lead to local root compromise. 3. Solution Updated the sccw package from our FTP server. ______________________________________________________________________________ Here are the md5 checksums of the upgrade packages, please verify these before installing the new packages: 3b2fc3d5025f1298e460ad26735af601 sccw-1.1-39.i386.rpm 373435f60b236c8d52ee535021471e4c sccw-1.1-39.src.rpm ______________________________________________________________________________ You will find the update on our ftp-Server: Webpage for patches: https://www.suse.com/de-de/ or try the following web pages for a list of mirrors: https://www.suse.com/de-de/ ______________________________________________________________________________ . ______________________________________________________________________________ SuSE Security Announc. insufficient, bounds, checking, trust, environment, calls, insecure, system, functions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 1999 Critical SuSE
100

SuSE Linux: Critical SCCW Information Disclosure Threat

The /usr/bin/sccw tool can be used to read any file on the system. . ______________________________________________________________________________ SuSE Security Announcement Package: sccw-1.1 and earlier Date: Mon Sep 20 23:40:09 CEST 1999 Affected: all Linux distributions using sccw _____________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that that we provide this information on as "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. _____________________________________________________________________________ 1. Problem Description The /usr/bin/sccw tool can be used to read any file on the system. 2. Impact An attacker can read e.g the /etc/shadow file or private email. 3. Solution Updated the sccw package from our FTP server. ______________________________________________________________________________ Here are the md5 checksums of the upgrade packages, please verify these before installing the new packages: f70f788861bf0ee402405a7dc14431a sccw-1.1-32.i386.rpm (6.2) ______________________________________________________________________________ You will find the update on our ftp-Server: Webpage for patches: https://www.suse.com/de-de/ or try the following web pages for a list of mirrors: https://www.suse.com/de-de/ ______________________________________________________________________________ SuSE has got two free security mailing list services to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - moderatedand for general/linux/SuSE security discussions. All SuSE security announcements are send to this list. This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, just send an emtpy message to This email address is being protected from spambots. You need JavaScript enabled to view it. or This email address is being protected from spambots. You need JavaScript enabled to view it. like this: echo | mail This email address is being protected from spambots. You need JavaScript enabled to view it. or echo | mail This email address is being protected from spambots. You need JavaScript enabled to view it. ______________________________________________________________________________ . Revise your sccw library to address vulnerabilities resulting from a security gap that permits unintended file access on the machine.. sccw access breach, SuSE patch, Linux security update, file permissions, system vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 1999 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200