Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
fix for CVE-2018-5704 (RHBZ 1534844). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-f0add5eed0 2019-03-02 01:20:05.967617 --------------------------------------------------------------------------------Name : openocd Product : Fedora 28 Version : 0.10.0 Release : 11.fc28 URL : https://sourceforge.net/projects/openocd/ Summary : Debugging, in-system programming and boundary-scan testing for embedded devices Description : The Open On-Chip Debugger (OpenOCD) provides debugging, in-system programming and boundary-scan testing for embedded devices. Various different boards, targets, and interfaces are supported to ease development time. Install OpenOCD if you are looking for an open source solution for hardware debugging. --------------------------------------------------------------------------------Update Information: fix for CVE-2018-5704 (RHBZ 1534844) --------------------------------------------------------------------------------ChangeLog: * Thu Feb 21 2019 Jiri Kastner - 0.10.0-11 - fix for CVE-2018-5704 (RHBZ 1534844) * Fri Feb 1 2019 Fedora Release Engineering - 0.10.0-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Mon Oct 22 2018 Jiri Kastner - 0.10.0-9 - fix openocd rules (RHBZ 1571599) * Sat Sep 22 2018 Lubomir Rintel - 0.10.0-8 - rebuild for jimtcl soname bump * Fri Jul 13 2018 Fedora Release Engineering - 0.10.0-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Thu Feb 8 2018 Fedora Release Engineering - 0.10.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1534843 - openocd: Cross protocol scripting vulnerability in telnet interface allows for remote command execution https://bugzilla.redhat.com/show_bug.cgi?id=1534843 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-f0add5eed0' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
libimobiledevice could be made to overwrite files as the administrator, or access device keys.. =========================================================================Ubuntu Security Notice USN-1927-1 August 14, 2013 libimobiledevice vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 Summary: libimobiledevice could be made to overwrite files as the administrator, or access device keys. Software Description: - libimobiledevice: Library for communicating with iPhone and iPod Touch devices Details: Paul Collins discovered that libimobiledevice incorrectly handled temporary files. A local attacker could possibly use this issue to overwrite arbitrary files and access device keys. In the default Ubuntu installation, this issue should be mitigated by the Yama link restrictions. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libimobiledevice3 1.1.4-1ubuntu6.2 Ubuntu 12.10: libimobiledevice3 1.1.4-1ubuntu3.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1927-1 CVE-2013-2142 Package Information: https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu6.2 https://launchpad.net/ubuntu/+source/libimobiledevice/1.1.4-1ubuntu3.2 . A serious alert about libimobiledevice highlights vulnerabilities that may allow unauthorized file overwrites and sensitive key exposure. Update your software now to mitigate risks. libimobiledevice, Ubuntu update, local attack, file access, security notice. . Severity: Important. LinuxSecurity.com Team
QL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter.. - - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200306-15 - - - --------------------------------------------------------------------- PACKAGE : phpbb SUMMARY : sql injection DATE : 2003-06-28 20:22 UTC EXPLOIT : remote VERSIONS AFFECTED : =phpbb-2.0.5 CVE : CAN-2003-0486 - - - --------------------------------------------------------------------- quote from cve: "SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashes via the topic_id parameter." SOLUTION It is recommended that all Gentoo Linux users who are running net-www/phpbb upgrade to phpbb-2.0.5 as follows emerge sync emerge phpbb emerge clean - - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.