Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
New net-tools packages are available for Slackware 15.0 and -current to fix a security issue.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] net-tools (SSA:2026-154-02) New net-tools packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/net-tools-20181103_0eebece-i586-4_slack15.0.txz: Rebuilt. This update fixes a security issue: interface.c: Stack-based Buffer Overflow in get_name(). For more information, see: https://www.cve.org/CVERecord?id=CVE-2025-46836 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (http://osuosl.org) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://slackware.com for additional mirror sites near you. Updated package for Slackware 15.0: ftp://ftp.slackware.com/pub/slackware/slackware-15.0/patches/packages/net-tools-20181103_0eebece-i586-4_slack15.0.txz Updated package for Slackware x86_64 15.0: ftp://ftp.slackware.com/pub/slackware/slackware64-15.0/patches/packages/net-tools-20181103_0eebece-x86_64-4_slack15.0.txz Updated package for Slackware -current: ftp://ftp.slackware.com/pub/slackware/slackware-current/slackware/n/net-tools-20181103_0eebece-i686-4.txz Updated package for Slackware x86_64 -current: ftp://ftp.slackware.com/pub/slackware/slackware64-current/slackware64/n/net-tools-20181103_0eebece-x86_64-4.txz MD5 signatures: +-------------+ Slackware 15.0 package: 828dd667d8030e4ddc4706730dd48eda net-tools-20181103_0eebece-i586-4_slack15.0.txz Slackware x86_64 15.0 package: b2ed660e6785b0a5f00e745c46b6055e net-tools-20181103_0eebece-x86_64-4_slack15.0.txz Slackware -current package: aba145e3ade4832f9f7bdeb3b670a42d n/net-tools-20181103_0eebece-i686-4.txz Slackware x86_64 -current package: 70893d47aabe9ebc1e8f2ed0cf46a19c n/net-tools-20181103_0eebece-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg net-tools-20181103_0eebece-i586-4_slack15.0.txz +-----+ . Critical security update for Slackware net-tools addresses buffer overflow risk with important instructions.. Slackware net-tools security update, buffer overflow fix, Linux application upgrade. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1785 https://linux.oracle.com/errata/ELSA-2024-1785.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: aarch64: xorg-x11-server-common-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-Xephyr-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-Xorg-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-devel-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-source-1.20.4-29.el7_9.noarch.rpm xorg-x11-server-Xdmx-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-Xnest-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-Xvfb-1.20.4-29.el7_9.aarch64.rpm xorg-x11-server-Xwayland-1.20.4-29.el7_9.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol7/SRPMS-updates//xorg-x11-server-1.20.4-29.el7_9.src.rpm Related CVEs: CVE-2024-31080 CVE-2024-31081 CVE-2024-31083 Description of changes: [1.20.4-29] - Fix regression caused by the fix for CVE-2024-31083 [1.20.4-28] - CVE fix for: CVE-2024-31080, CVE-2024-31081, CVE-2024-31082 and CVE-2024-31083 Resolves: Resolves: Resolves: - Add util-linux as a dependency of Xvfb - Fix compilation error on i686 _______________________________________________ El-errata mailing list
Upstream details at : https://access.redhat.com/errata/RHSA-2023:5461. CentOS Errata and Security Advisory 2023:5461 Important Upstream details at : https://access.redhat.com/errata/RHSA-2023:5461 The following updated files have been uploaded and are currently syncing to the mirrors: ( sha256sum Filename ) x86_64: cf312b0640aa93a5701862f262416738887b1618922b58eaadfe16d281c1fa7d ImageMagick-6.9.10.68-7.el7_9.i686.rpm a7b0d2e78f9226d952fd5d798225620b853fb2b0edd6abeda0fcca3095856f7a ImageMagick-6.9.10.68-7.el7_9.x86_64.rpm 342100bd7ce3ca8e951285697781ddb9192c0a02dd56cad55d48bdf20a74bec2 ImageMagick-c++-6.9.10.68-7.el7_9.i686.rpm f6a237d150654379162b6b0cb9396c65ec4227bf24e4b01d1dbb5180dc3b28be ImageMagick-c++-6.9.10.68-7.el7_9.x86_64.rpm e614cee98b3c2a67c0a489a233ca9a7a574ea6bc8dd166f835f26bca8d3d5f7c ImageMagick-c++-devel-6.9.10.68-7.el7_9.i686.rpm f613394ac503882a78ac261fc0ddce0cd6b033530342f31d88f080b4b99f51b0 ImageMagick-c++-devel-6.9.10.68-7.el7_9.x86_64.rpm 49ac1322f5ed8d216331f29c35eab930dc5be738f27bf00fca63036fbce5de80 ImageMagick-devel-6.9.10.68-7.el7_9.i686.rpm 0df91ae3f7e140e17025cfcac0a1bbb8507f665cf4f2ae6e8e6951f0fbc667e5 ImageMagick-devel-6.9.10.68-7.el7_9.x86_64.rpm f27e3d167e8d7cfb2c448d400f034b7443c2e076e94b38a67fddd951a9bf745e ImageMagick-doc-6.9.10.68-7.el7_9.x86_64.rpm af07229f94ef571d7d7fa63fd7b1e5c4feaf193b6302b4faf6e64302611433ce ImageMagick-perl-6.9.10.68-7.el7_9.x86_64.rpm Source: 35b591b827f3afea91c8c2cc8bff7ce66e8d5b5a4ed4d1b851e0748075220999 ImageMagick-6.9.10.68-7.el7_9.src.rpm -- Johnny Hughes CentOS Project { https://www.centos.org/ } irc: hughesjr, #
Several security vulnerabilities have been discovered in SnakeYaml, a YAML parser for Java, which could facilitate a denial of service attack whenever maliciously crafted input files are processed by SnakeYaml. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3132-1
**Version 5.0.3** (2020-10-09) - issue #15983 Require twig ^2.9 - issue Fix option to import files locally appearing as not available - issue #16048 Fix to allow NULL as a default bit value - issue #16062 Fix "htmlspecialchars() expects parameter 1 to be string, null given" on Export xml - issue #16078 Fix no charts in monitor when using a decimal separator "," - issue #16041 Fix. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-4e78c86902 2020-10-19 16:56:49.452622 --------------------------------------------------------------------------------Name : phpMyAdmin Product : Fedora 32 Version : 5.0.3 Release : 1.fc32 URL : https://www.phpmyadmin.net/ Summary : A web interface for MySQL and MariaDB Description : phpMyAdmin is a tool written in PHP intended to handle the administration of MySQL over the Web. Currently it can create and drop databases, create/drop/alter tables, delete/edit/add fields, execute any SQL statement, manage keys on fields, manage privileges,export data into various formats and is available in 50 languages --------------------------------------------------------------------------------Update Information: **Version 5.0.3** (2020-10-09) - issue #15983 Require twig ^2.9 - issue Fix option to import files locally appearing as not available - issue #16048 Fix to allow NULL as a default bit value - issue #16062 Fix "htmlspecialchars() expects parameter 1 to be string, null given" on Export xml - issue #16078 Fix no charts in monitor when using a decimal separator "," - issue #16041 Fix IN(...) clause doesn't permit multiple values on "Search" page - issue #14411 Support double tap to edit on mobile - issue #16043 Fix php error "Use of undefined constant MYSQLI_TYPE_JSON" when using the mysqlnd extension - issue #14611 Fix fatal JS error on index creation after using Enter key to submit the form - issue #16012 Set "axis-order" to swap lon and lat on MySQL > = 8.1 -issue #16104 Fixed overwriting a bookmarked query causes a PHP fatal error - issue Fix typo in a condition in the Sql class - issue #15996 Fix local setup doc links pointing to a wrong location - issue #16093 Fix error importing utf-8 with bom sql file - issue #16089 2FA UX enhancement: autofocus 2FA input - issue #16127 Fix table column description PHP error when ['DisableIS'] = true; - issue #16130 Fix local documentation links display when a PHP extension is missing -issue Fix some twig code deprecations for php 8 - issue Fix ENUM and SET display when editing procedures and functions - issue Keep full query state on "auto refresh" process list - issue Keep columns order on "auto refresh" process list - issue Fixed editing a failed query from the error message - issue #16166 Fix the alter user privileges query to make it MySQL 8.0.11+ compatible - issue Fix copy table to another database when the nbr of DBs is > $cfg['MaxDbList'] - issue #16157 Fix relations of tables having spaces or special chars not showing in the Designer - issue #16052 Fix a very rare JS error occuring on mousemove event - issue #16162 Make a foreign key link clickable in a new tab after the value was saved and replaced - issue #16163 Fixed a PHP notice "Undefined index: column_info" on views - issue #14478 Fix the data stream when exporting data in file mode - issue #16184 Fix templates/ directory not found error - issue #16184 Remove chdir logic to fix PHP fatal error "Uncaught TypeError: chdir()" - issue Support for Twig 3 - issue Allow phpmyadmin/twig-i18n-extension ^3.0 - issue #16201 Trim spaces for integer values in table search - issue #16076 Fixed cannot edit or export TIMESTAMP column with default CURRENT_TIMESTAMP in MySQL > = 8.0.13 -issue #16226 Fix error 500 after copying a table - issue #16222 Fixed can't use the search page when the table name has special characters - issue #16248 Fix zoom search is not performing input validation on INTcolumns - issue #16248 Fix javascript error when typing in INT fields on zoom search page - issue Fix type errors when using saved searches - issue #16261 Fix missing headings on modals of "User Accounts -> Export" - issue #16146 Fixed sorting did not keep the selector of number of rows - issue #16194 Fixed SQL query does not appear in case of editing view where definer is not you on MySQL 8 - issue #16255 Fix tinyint(1) shown as INT on Search page - issue #16256 Fix "Warning: error_reporting() has been disabled for security reasons" on php 7.x - issue #15367 Fix "Change or reconfigure primary server" link - issue #15367 Fix first replica links, start, stop, ignore links - issue #16058 Add "PMA_single_signon_HMAC_secret" for signon auths to make special links work and udate examples - issue #16269 Support ReCaptcha v2 checkbox width "$cfg['CaptchaMethod'] = 'checkbox';" - issue #14644 Use Doctum instead of Sami - issue #16086 Fix "Browse" headings shift when scrolling - issue #15328 Fix no message after import of zipped shapefile without php-zip - issue #14326 Fix PHP error when exporting without php-zip - issue #16318 Fix Profiling doesn't sum the number of calls - issue #16319 Fixed a Russian translation mistake on search results total text - issue #15634 Only use session_set_cookie_params once on PHP > = 7.3.0 versions for single signon auth - issue #14698 Fixed database named as 'New' (language variable) causes PHP fatal error - issue #16355 Make textareas both sides resizable - issue #16366 Fix column definition form not showing default value - issue #16342 Fixed multi-table query (db_multi_table_query.php) alias show the same alias for all columns - issue #15109 Fixed using ST_GeomFromText + GUI on insert throws an error - issue #16325 Fixed editing Geometry data throws error on using the GUI - issue [security] Fix XSS vulnerability with the transformation feature (**PMASA-2020-5, CVE-2020-26934**) - issue [security] Fix SQL injection vulnerability with searchfeature (**PMASA-2020-6, CVE-2020-26935**) --------------------------------------------------------------------------------ChangeLog: * Sat Oct 10 2020 Remi Collet - 5.0.3-1 - update to 5.0.3 (2020-10-10, security release) - raise dependency on twig 2.9 and allow v3 - allow phpmyadmin/twig-i18n-extension v3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1887249 - CVE-2020-26934 phpmyadmin: XSS relating to the transformation feature https://bugzilla.redhat.com/show_bug.cgi?id=1887249 [ 2 ] Bug #1887253 - CVE-2020-26935 phpmyadmin: SQL injection vulnerability in SearchController https://bugzilla.redhat.com/show_bug.cgi?id=1887253 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-4e78c86902' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-f244168d7f 2017-10-13 15:00:06.526552 --------------------------------------------------------------------------------Name : recode Product : Fedora 26 Version : 3.6 Release : 44.fc26 URL : Summary : Conversion between character sets and surfaces Description : The `recode' converts files between character sets and usages. It recognizes or produces nearly 150 different character sets and is able to transliterate files between almost any pair. When exact transliteration are not possible, it may get rid of the offending characters or fall back on approximations. Most RFC 1345 character sets are supported. --------------------------------------------------------------------------------Update Information: Security fix for buffer overflow due to long input filenames [see Bug 1422550 and 1422545] --------------------------------------------------------------------------------References: [ 1 ] Bug #1422550 - recode: Buffer overflow due to long input filenames [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1422550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade recode' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
from the Google Security Team discovered that the Evince document viewer made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely. . Hash: SHA256 Package : evince Version : 3.4.0-3.1+deb7u1 CVE ID : CVE-2017-1000083 Debian Bug : 868500 from the Google Security Team discovered that the Evince document viewer made insecure use of tar when opening tar comic book archives (CBT). Opening a malicious CBT archive could result in the execution of arbitrary code. This update disables the CBT format entirely. For Debian 7 "Wheezy", these problems have been fixed in version 3.4.0-3.1+deb7u1. We recommend that you upgrade your evince packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS patches LibreOffice to address vulnerabilities in document handling leading to potential data leakage. Update advised.. Debian LTS, Evince Security Update, Remote Code Execution, Document Viewer Security, Debian 7 Updates. . Severity: Critical. LinuxSecurity.com Team
This is the alpha-chip version of the kernel 2.2.x patch Debian released yesterday.. Debian Security Advisory DSA 454-1
Get the latest Linux and open source security news straight to your inbox.