Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 11 Bullseye DLA-3891-1 Critical: MariaDB Remote Command Execution

A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3891-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Otto Kekäläinen September 18, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mariadb-10.5 Version : 1:10.5.26-0+deb11u2 CVE ID : CVE-2024-21096 Debian Bug : 1069189 1015293 A vulnerability was discovered in MariaDB, a SQL database server compatible with MySQL. An attacker could generate a malicious dump file which could execute shell commands from the MariaDB client. The fix may cause a compatibility issue with older MariaDB and MySQL clients, with existing workarounds, as detailed at: https://mariadb.org/mariadb-dump-file-compatibility-change/ This updates also includes bugfixes through the 10.5 maintenance branch, as detailed at: https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-24-release-notes https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-25-release-notes https://mariadb.com/docs/release-notes/community-server/old-releases/mariadb-10-5-series/mariadb-10-5-26-release-notes For Debian 11 bullseye, this problem has been fixed in version 1:10.5.26-0+deb11u2. We recommend that you upgrade your mariadb-10.5 packages. For the detailed security status of mariadb-10.5 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/mariadb-10.5 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A pressingalert for Debian LTS concerning a security vulnerability in MariaDB, which permits unauthorized remote execution of shell commands.. MariaDB, SQL Database, Debian LTS, Security Advisory, Remote Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 18, 2024 Critical Debian LTS
87

Debian: xpdf 0.90-7 Moderate: Unsafe Temp Files And Command Execution

Several vulnerabilities exist with xpdf that could allow the creation of unsafe termporary files and the running of arbitrary shell commands.. -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman September 10, 2000 - ------------------------------------------------------------------------ Package : xpdf Problem type : local exploit Debian-specific: no xpdf as distributed in Debian GNU/Linux 2.2 suffered from two problems: 1. creation of temporary files was not done safely which made xpdf vulnerable to a symlink attack. 2. when handling URLs in documents no checking was done for shell metacharacters before starting the browser. This makes it possible to construct a document which cause xpdf to run arbitrary commands when the user views an URL. Both problems have been fixed in version 0.90-7, and we recommend you upgrade your xpdf package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. At this moment no fixed package is available for arm machines. Source archives: MD5 checksum: e9b2584ea9dda178ed1a63771aa7019f MD5 checksum: 332ca1d9970dda5808538793bd3e346d MD5 checksum: a7678b64713a466279b61c28ba01134b Alpha architecture: MD5 checksum: cb4cf0761c5b5ae53c5fdbc84ef2b76d Intel ia32 architecture: MD5 checksum: 9c8379176a3af032d1e6ec96e084c0d4 Motorola 680x0 architecture: MD5 checksum: 9a1d4b46ef498bee595a028d96ff6ba4 PowerPC architecture: MD5 checksum: 489a06b7961873c2482e28108133d065 Sun Sparc architecture: MD5 checksum:46d1781a7d21f8ffb02137ebf22f20de These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable updates For dpkg-ftp: dists/stable/updates Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. - -- - ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable updates For dpkg-ftp: dists/stable/updates Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQB1AwUBObuLHajZR/ntlUftAQHgJwL/U1MmS29NHJHgrI6aBhBvTqM0wOKfbJVG cZadGyREEz3Gwu6ckmQi2SQiCzK4YtTptQBo/ID38eNojp56Qkf0G45bt1OaxCBy Fd+lDzrVnPzy37mEc4eQTy/jRaH2EucA =ZMId -----END PGP SIGNATURE----- . Ubuntu warns its community regarding flaws in openoffice, highlighting issues with inadequate input validation and data exposure; users are urged to perform upgrades.. xpdf exploit, Debian advisory, local security issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 10, 2000 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here