Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The container bci/openjdk was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/openjdk ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:3383-1 Container Tags : bci/openjdk:11 , bci/openjdk:11-11.10 Container Release : 11.10 Severity : important Type : security References : 1214806 1215888 1215889 CVE-2023-38545 CVE-2023-38546 CVE-2023-4641 ----------------------------------------------------------------- The container bci/openjdk was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4024-1 Released: Tue Oct 10 13:24:40 2023 Summary: Security update for shadow Type: security Severity: low References: 1214806,CVE-2023-4641 This update for shadow fixes the following issues: - CVE-2023-4641: Fixed potential password leak (bsc#1214806). ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:4044-1 Released: Wed Oct 11 09:01:14 2023 Summary: Security update for curl Type: security Severity: important References: 1215888,1215889,CVE-2023-38545,CVE-2023-38546 This update for curl fixes the following issues: - CVE-2023-38545: Fixed a heap buffer overflow in SOCKS5. (bsc#1215888) - CVE-2023-38546: Fixed a cookie injection with none file. (bsc#1215889) The following package changes have been done: - login_defs-4.8.1-150400.10.12.1 updated - libcurl4-8.0.1-150400.5.32.1 updated - shadow-4.8.1-150400.10.12.1 updated - container:sles15-image-15.0.0-36.5.41 updated . The recent updates for bci/openjdk, curl, and shadow tackle various critical vulnerabilities, categorized under high severity.. bci/openjdk, container security, curl update, shadow issue. . Severity: Important. LinuxSecurity.com Team
The container bci/ruby was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/ruby ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1383-1 Container Tags : bci/ruby:2 , bci/ruby:2-34.38 , bci/ruby:2.5 , bci/ruby:2.5-34.38 , bci/ruby:latest Container Release : 34.38 Severity : moderate Type : security References : 1210507 CVE-2023-29383 ----------------------------------------------------------------- The container bci/ruby was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2066-1 Released: Fri Apr 28 13:54:17 2023 Summary: Security update for shadow Type: security Severity: moderate References: 1210507,CVE-2023-29383 This update for shadow fixes the following issues: - CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). The following package changes have been done: - login_defs-4.8.1-150400.10.6.1 updated - shadow-4.8.1-150400.10.6.1 updated . SUSE Container Maintenance Notice: bci/python provides essential security fixes and enhancements addressing critical reliability and regulatory challenges.. SUSE Containers, bci/ruby, security update, patches. . LinuxSecurity.com Team
The container bci/php was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/php ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1381-1 Container Tags : bci/php:8 , bci/php:8-2.39 Container Release : 2.39 Severity : moderate Type : security References : 1210507 CVE-2023-29383 ----------------------------------------------------------------- The container bci/php was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2066-1 Released: Fri Apr 28 13:54:17 2023 Summary: Security update for shadow Type: security Severity: moderate References: 1210507,CVE-2023-29383 This update for shadow fixes the following issues: - CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). The following package changes have been done: - login_defs-4.8.1-150400.10.6.1 updated - shadow-4.8.1-150400.10.6.1 updated . Patch announcement for bci/php with advisory reference SUSE-CU-2023:1381-1, focusing on critical issue fixes and associated remediation guidelines.. SUSE Container Advisory,Bci/PHP Update,Security Fix,Moderate Severity,Container Security. . LinuxSecurity.com Team
The container bci/dotnet-runtime was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/dotnet-runtime ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2023:1347-1 Container Tags : bci/dotnet-runtime:6.0 , bci/dotnet-runtime:6.0-30.15 , bci/dotnet-runtime:6.0.16 , bci/dotnet-runtime:6.0.16-30.15 Container Release : 30.15 Severity : moderate Type : security References : 1210507 CVE-2023-29383 ----------------------------------------------------------------- The container bci/dotnet-runtime was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2023:2066-1 Released: Fri Apr 28 13:54:17 2023 Summary: Security update for shadow Type: security Severity: moderate References: 1210507,CVE-2023-29383 This update for shadow fixes the following issues: - CVE-2023-29383: Fixed apparent /etc/shadow manipulation via chfn (bsc#1210507). The following package changes have been done: - login_defs-4.8.1-150400.10.6.1 updated - shadow-4.8.1-150400.10.6.1 updated . SUSE recently released an advisory for container users, enhancing bci/python with robust security updates to resolve CVE-2023-29384 comprehensively.. bci/dotnet-runtime,SUSE Container Update,security advisory. . LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for shadow ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2885-1 Rating: moderate References: #1106914 Cross-References: CVE-2018-16588 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for shadow fixes the following security issue: - CVE-2018-16588: Prevent useradd from creating intermediate directories with mode 0777 (bsc#1106914) This update was imported from the SUSE:SLE-12-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-1055=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): shadow-4.2.1-20.1 shadow-debuginfo-4.2.1-20.1 shadow-debugsource-4.2.1-20.1 References: https://www.suse.com/security/cve/CVE-2018-16588.html https://bugzilla.suse.com/show_bug.cgi?id=1106914 -- . In response to CVE-2021-34527, Ubuntu has released a patch to improve the functionality of systemd and strengthen overall protection.. openSUSE updates, shadow security, useradd vulnerabilities, moderate severity, system protection. . LinuxSecurity.com Team
New shadow packages are available for Slackware 13.1 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] shadow (SSA:2011-086-03) New shadow packages are available for Slackware 13.1 and -current to fix a security issue. Here are the details from the Slackware 13.1 ChangeLog: +--------------------------+ patches/packages/shadow-4.1.4.3-i486-1_slack13.1.txz: Rebuilt. This release fixes a security issue where local users may be able to add themselves to NIS groups through chfn and chsh. For more information, see: https://www.cve.org/CVERecord?id=CVE-2011-0721 (* Security fix *) Thanks to Gary Langshaw for collecting important additional patches from svn. +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.1 package: ba21ebb8fc8bc7b39644db3c5d4820da shadow-4.1.4.3-i486-1_slack13.1.txz Slackware x86_64 13.1 package: e693c9f69b414061de8041bdae8bed7a shadow-4.1.4.3-x86_64-1_slack13.1.txz Slackware -current package: d7e43c3da5bbb677587bbf275235f306 shadow-4.1.4.3-i486-1.txz Slackware x86_64 -current package: cc6dc5cf8d04bb61d0589911db8f3f64 shadow-4.1.4.3-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkgshadow-4.1.4.3-i486-1_slack13.1.txz +-----+ . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] shadow (SSA:2011-086-03) New shad. shadow, packages, slackware, -current, security, -----begi. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.