Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed.. openSUSE security update: security update for agama-web-ui ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20919-1 Rating: moderate References: * bsc#1246678 * bsc#1264160 * bsc#1264802 * bsc#1266256 Cross-References: * CVE-2025-7339 * CVE-2026-42041 * CVE-2026-42264 * CVE-2026-9277 CVSS scores: * CVE-2025-7339 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-7339 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-42041 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42041 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42264 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42264 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-9277 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9277 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves 4 vulnerabilities and has 4 bug fixes can now be installed. Description: This update for agama-web-ui fixes the following issues - CVE-2025-7339: on-headers: incorrect array handling may lead to HTTP response header manipulation (bsc#1246678). - CVE-2026-9277: shell-quote: improper escaping of newlines in object .op values by quote() can lead to shell command injection (bsc#1266256). - CVE-2026-42041: axios: authentication bypass via validateStatus prototype pollution gadget due to suppression of HTTP error (bsc#1264160). - CVE-2026-42264: axios: prototype pollution read-side gadgets in HTTP adapter can lead to credential injection and request h (bsc#1264802). Changes for agama-web-ui: - Update other dependencies reported by "npmaudit". Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-901=1 Package List: - openSUSE Leap 16.0: agama-web-ui-17+612.d8bf69336-160000.11.1 References: * https://www.suse.com/security/cve/CVE-2025-7339.html * https://www.suse.com/security/cve/CVE-2026-42041.html * https://www.suse.com/security/cve/CVE-2026-42264.html * https://www.suse.com/security/cve/CVE-2026-9277.html . An update for agama-web-ui fixes 4 issues including credential injection and HTTP response manipulation in openSUSE.. openSUSE security update, agama-web-ui vulnerability, http response manipulation. . Severity: moderate. LinuxSecurity.com Team
Several security issues were fixed in Emacs.. ========================================================================== Ubuntu Security Notice USN-8011-1 February 04, 2026 emacs vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in Emacs. Software Description: - emacs: An extensible, customizable, free/libre text editor \u2014 and more. Details: It was discovered that Emacs could trigger unsafe Lisp macro expansion, when a user invoked elisp-completion-at-point on untrusted Emacs Lisp source code. An attacker could possibly use this issue to execute arbitrary code. (CVE-2024-53920) It was discovered that Emacs did not properly sanitize input when handling certain URI schemes. An attacker could possibly use this issue to execute arbitrary shell commands by tricking a user into opening a specially crafted URL. (CVE-2025-1244) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS emacs 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-bin-common 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-common 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-el 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-gtk 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-lucid 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-nox 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro emacs-pgtk 1:29.3+1-1ubuntu2+esm3 Available with Ubuntu Pro Ubuntu 22.04 LTS emacs 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-bin-common 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-common 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-el 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-gtk 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-lucid 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro emacs-nox 1:27.1+1-3ubuntu5.2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS emacs 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-bin-common 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-common 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-el 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-gtk 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-lucid 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro emacs-nox 1:26.3+1-1ubuntu2+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8011-1 CVE-2024-53920, CVE-2025-1244 . Multiple security issues were resolved in Emacs, affecting several Ubuntu distributions with potentialarbitrary code execution risks.. Emacs security, arbitrary code execution, Ubuntu updates, Emacs vulnerabilities, Ubuntu security fixes. . Severity: Important. LinuxSecurity.com Team
* bsc#1249154 Cross-References: * CVE-2025-9566 . # Security update for podman Announcement ID: SUSE-SU-2025:03584-1 Release Date: 2025-10-13T06:59:34Z Rating: important References: * bsc#1249154 Cross-References: * CVE-2025-9566 CVSS scores: * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for podman fixes the following issues: * CVE-2025-9566: fixed an issue in kube play command that could cause overwriting host files (bsc#1249154) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2025-3584=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3584=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2025-3584=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3584=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2025-3584=1 * SUSE Linux Enterprise High PerformanceComputing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2025-3584=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2025-3584=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2025-3584=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-3584=1 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64 i586) * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-debuginfo-4.9.5-150400.4.53.1 * podmansh-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * openSUSE Leap 15.4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise HighPerformance Computing ESPOS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * podman-docker-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * podman-debuginfo-4.9.5-150400.4.53.1 * podman-remote-debuginfo-4.9.5-150400.4.53.1 * podman-remote-4.9.5-150400.4.53.1 * podman-4.9.5-150400.4.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * podman-docker-4.9.5-150400.4.53.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9566.html * https://bugzilla.suse.com/show_bug.cgi?id=1249154 . Podman security advisory for SUSE details fixes for significant issues impacting system integrity and command execution.. podman security update, SUSE advisory, important security fix. . Severity: Important. LinuxSecurity.com Team
The Rust Security Response WG was notified that the Rust standard library did not properly escape arguments when invoking batch files (with the bat and cmd extensions) on Windows using the Command API. An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping. . MGASA-2025-0136 - Updated rust packages fix security vulnerability Publication date: 17 Apr 2025 URL: https://advisories.mageia.org/MGASA-2025-0136.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-24576 The Rust Security Response WG was notified that the Rust standard library did not properly escape arguments when invoking batch files (with the bat and cmd extensions) on Windows using the Command API. An attacker able to control the arguments passed to the spawned process could execute arbitrary shell commands by bypassing the escaping. The severity of this vulnerability is critical if you are invoking batch files on Windows with untrusted arguments. No other platform or use is affected. We update to rust 1.78.0 for future mesa updates in mageia 9. References: - https://bugs.mageia.org/show_bug.cgi?id=34107 - http://www.openwall.com/lists/oss-security/2024/04/09/16 - https://github.com/rust-lang/rust/security/advisories/GHSA-q455-m56c-85mh - https://lists.fedoraproject.org/archives/list/
An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for zsh ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0735-1 Rating: important References: #1163882 #1196435 Cross-References: CVE-2019-20044 CVE-2021-45444 CVSS scores: CVE-2019-20044 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2019-20044 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-45444 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2021-45444 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Enterprise Storage 7 SUSE Linux Enterprise Desktop 15-SP3 SUSE Linux Enterprise Desktop 15-SP4 SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS SUSE Linux Enterprise High Performance Computing 15-SP3 SUSE Linux Enterprise High Performance Computing 15-SP4 SUSE Linux Enterprise Module for Basesystem 15-SP3 SUSE Linux Enterprise Module for Basesystem 15-SP4 SUSE Linux Enterprise Realtime Extension 15-SP2 SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server 15-SP2-BCL SUSE Linux Enterprise Server 15-SP2-LTSS SUSE Linux Enterprise Server 15-SP3 SUSE Linux Enterprise Server 15-SP4 SUSE Linux Enterprise Server for SAP 15-SP1 SUSE Linux Enterprise Server for SAP 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP3 SUSE Linux Enterprise Server for SAP Applications 15-SP4 SUSE Manager Proxy 4.1 SUSE Manager Proxy 4.2 SUSE Manager Retail Branch Server 4.1 SUSE Manager Server 4.1 SUSE Manager Server 4.2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for zsh fixes the following issues: - CVE-2021-45444: Fixed a vulnerability where arbitrary shell commands could be executed related to prompt expansion (bsc#1196435). - CVE-2019-20044: Fixed a vulnerability where shell privileges would not be properly dropped when unsetting the PRIVILEGED option (bsc#1163882). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Manager Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.1-2022-735=1 - SUSE Manager Retail Branch Server 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-Server-4.1-2022-735=1 - SUSE Manager Proxy 4.1: zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.1-2022-735=1 - SUSE Linux Enterprise Server for SAP 15-SP2: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP2-2022-735=1 - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-735=1 - SUSE Linux Enterprise Server 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP2-LTSS-2022-735=1 - SUSE Linux Enterprise Server 15-SP2-BCL: zypper in -t patchSUSE-SLE-Product-SLES-15-SP2-BCL-2022-735=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-735=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-735=1 - SUSE Linux Enterprise Realtime Extension 15-SP2: zypper in -t patch SUSE-SLE-Product-RT-15-SP2-2022-735=1 - SUSE Linux Enterprise Module for Basesystem 15-SP4: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP4-2022-735=1 - SUSE Linux Enterprise Module for Basesystem 15-SP3: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP3-2022-735=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-LTSS-2022-735=1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP2-ESPOS-2022-735=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-735=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-735=1 - SUSE Enterprise Storage 7: zypper in -t patch SUSE-Storage-7-2022-735=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-735=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Manager Server 4.1 (ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Manager Retail Branch Server 4.1 (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Manager Proxy 4.1 (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSELinux Enterprise Server for SAP 15-SP2 (ppc64le x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Server for SAP 15-SP1 (ppc64le x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Server 15-SP2-LTSS (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Server 15-SP2-BCL (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Server 15-SP1-BCL (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Realtime Extension 15-SP2 (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP4 (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise Module for Basesystem 15-SP3 (aarch64 ppc64le s390x x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-LTSS (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise High Performance Computing 15-SP2-ESPOS (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Enterprise Storage 7 (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE Enterprise Storage 6 (aarch64 x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 - SUSE CaaS Platform 4.0 (x86_64): zsh-5.6-7.5.1 zsh-debuginfo-5.6-7.5.1 zsh-debugsource-5.6-7.5.1 References: https://www.suse.com/security/cve/CVE-2019-20044.html https://www.suse.com/security/cve/CVE-2021-45444.html https://bugzilla.suse.com/1163882 https://bugzilla.suse.com/1196435 . Patches addressing critical vulnerabilities in zsh released via SUSE update. Comprehensive guidance offered for straightforward implementation.. SUSE Update,zsh Security Fix,Shell Command Threats. . Severity: Important. LinuxSecurity.com Team
An update for patch is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, . -----BEGIN PGP SIGNED MESSAGE-----Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: patch security update Advisory ID: RHSA-2019:3757-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:3757 Issue date: 2019-11-06 CVE Names: CVE-2018-20969 CVE-2019-13638 ==================================================================== 1. Summary: An update for patch is now available for Red Hat Enterprise Linux 7.5 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5) - x86_64 Red Hat Enterprise Linux Server EUS (v. 7.5) - ppc64, ppc64le, s390x, x86_64 3. Description: The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Security Fix(es): * patch: do_ed_script in pch.c does not block strings beginning with a ! character (CVE-2018-20969) * patch: OS shell command injection when processing crafted patch files (CVE-2019-13638) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s)listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1733916 - CVE-2019-13638 patch: OS shell command injection when processing crafted patch files 1746672 - CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character 6. Package List: Red Hat Enterprise Linux ComputeNode EUS (v. 7.5): Source: patch-2.7.1-11.el7_5.src.rpm x86_64: patch-2.7.1-11.el7_5.x86_64.rpm patch-debuginfo-2.7.1-11.el7_5.x86_64.rpm Red Hat Enterprise Linux Server EUS (v. 7.5): Source: patch-2.7.1-11.el7_5.src.rpm ppc64: patch-2.7.1-11.el7_5.ppc64.rpm patch-debuginfo-2.7.1-11.el7_5.ppc64.rpm ppc64le: patch-2.7.1-11.el7_5.ppc64le.rpm patch-debuginfo-2.7.1-11.el7_5.ppc64le.rpm s390x: patch-2.7.1-11.el7_5.s390x.rpm patch-debuginfo-2.7.1-11.el7_5.s390x.rpm x86_64: patch-2.7.1-11.el7_5.x86_64.rpm patch-debuginfo-2.7.1-11.el7_5.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-20969 https://access.redhat.com/security/cve/CVE-2019-13638 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE-----Version: GnuPGv1 iQIVAwUBXcL7n9zjgjWX9erEAQgvkA//UjT24+6d7pzhFFv91zXxNiqpDTL9Rq6k ihasvh4MPZuXIMXUumW2DxJRhiLmzn3MpKSvBZ68i1SqQRzxLojIIMDpfX0TYRqf 8ZmLdvZ/B3skXcJlDQ5wIqwkFYFtc1ecCkLgihnuv2ujM0hMxryxjpWZZCOZZAYa M8puFb0BI6Eei3Sm0eSQH6DPpdso7oP5/zjb6GHnP9q/zInNniOrt1m0ukQejB5q VXk/SmJiWxaK3mJ+bjY2yEBP0ikhMFT+uq7Ax7jXkxVNJfb+HkKRxOFhiQVALZub +bAD6t2bdClDsMkKIleNzRPou1KrjKnszCZp6nqlLP19LVd5CFLqpdfhmRwIGivQ kfuiKIriwS1Vup7SFVp80gsWYOB3WTPu14vC0lyKUillPwFeJIWY5UmoSdfZhPJY iCVyyOsP7Qs2TicXKqy08zMX9Ttv3YqcnAe2zrZY6J11esfW3+eG7qBzjSpJc/kF 8VkobZgw/Q+gFIVAbpNaL4lfvXqeq8ul3gC79UXHkjRJOd0QMmOHwH/1dOmtCDTx 1LApRZkXcXiOKDLf8XnccYV7B+L5EsFWnQYKGvPmrt5lkpHYrhRwCe/hCzzL+UbG DzDnT1CqGloW4jirI15PKDc4z8KP9BUGSEKJZKUGrIuGY3lJY2iiF3bJ4WwlzAHc EtuM6WbiN5c=yRB5 -----END PGP SIGNATURE-------RHSA-announce mailing list
Updated kconfig packages fix security vulnerability: Dominik Penner discovered that KConfig supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it's embedded into a downloaded archive and it gets . MGASA-2019-0278 - Updated kconfig packages fix security vulnerability Publication date: 15 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0278.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-14744 Updated kconfig packages fix security vulnerability: Dominik Penner discovered that KConfig supported a feature to define shell command execution in .desktop files. If a user is provided with a malformed .desktop file (e.g. if it's embedded into a downloaded archive and it gets opened in a file browser) arbitrary commands could get executed (CVE-2019-14744). This update fixes the security issue by removing the shell command feature. References: - https://bugs.mageia.org/show_bug.cgi?id=25250 - https://kde.org/info/security/advisory-20190807-1.txt - https://lists.debian.org/debian-security-announce/2019/msg00142.html - https://www.cve.org/CVERecord?id=CVE-2019-14744 SRPMS: - 6/core/kconfig-5.42.0-1.1.mga6 - 7/core/kconfig-5.57.0-1.1.mga7 . Revamped kconfig packages address a major vulnerability impacting Mageia. Secure your system immediately!. Kconfig Security, Mageia Update, Shell Command Execution, Vulnerability Repair. . LinuxSecurity.com Team
Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out . Package : kde4libs Version : 4:4.14.2-5+deb8u3 CVE ID : CVE-2019-14744 Debian Bug : 934268 Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out the icon for a file or any application using KConfig. Thus the entire feature of supporting shell commands in KConfig entries has been removed. For Debian 8 "Jessie", this problem has been fixed in version 4:4.14.2-5+deb8u3. We recommend that you upgrade your kde4libs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . CVE-2021-31529 affects libgtk in Ubuntu 20.04. Update promptly to protect against potential remote code execution vulnerabilities.. kde4libs Security Update, Debian 8 Update, Shell Command Vulnerability. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.