Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Version 2.10.1 - 2026-06-04 Security: Fixed shell escaping when opening an editor (#12903) Security: Verify backup phar signature before restoring it when using self- update --rollback (#12918) Fixed source-fallback also disabling fallbacks to dist install when source is. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-4308b5fc39 2026-06-14 05:02:05.956606+00:00 -------------------------------------------------------------------------------- Name : composer Product : Fedora 43 Version : 2.10.1 Release : 1.fc43 URL : https://getcomposer.org/ Summary : Dependency Manager for PHP Description : Composer helps you declare, manage and install dependencies of PHP projects, ensuring you have the right stack everywhere. Documentation: https://getcomposer.org/doc/ -------------------------------------------------------------------------------- Update Information: Version 2.10.1 - 2026-06-04 Security: Fixed shell escaping when opening an editor (#12903) Security: Verify backup phar signature before restoring it when using self- update --rollback (#12918) Fixed source-fallback also disabling fallbacks to dist install when source is the preferred install method (#12888) Fixed source -> dist package updates wiping the .git dir without checking for local changes first (#12912) Fixed GitHub token prompt happening multiple times on parallel auth failures (#12913) Fixed warnings from Composer repositories being printed twice in some cases (#12907) Version 2.10.0 Read the Composer 2.10 Release Announcement for more details on the release highlights. Full Changelog BC Break / Security: Disabled automatic fallback to source checkout if dist/zip install fails, we have introduced a new source-fallback config option as a temporary way to restore the old behavior, but if you need this talk to us as we plan to remove it entirely in 2.11 (#12885) BC Break: Minor break for audit consumers,the exit code is now always 0 (success) or 1 if anything failed the audit (#12881) Security: Added dependency policies to block package versions where malware was detected on update/install or report it with audit (#12786) Security: Hardened output filtering of URLs to reduce chances of token leaks (#12882, #12886) Security: Fixed handling of uppercase schemes in URL validation that might have allowed https requirement bypass (#12884) Security: Fixed git credentials remaining in git mirror .git/config after clone or update failed (2bcbfc3) Security: Fixed usage of insecure 3DES ciphers when ext-curl is missing (5e71d77) Security: Enforce allow-plugins even in non-interactive mode for very old pre-2.2 lock files (#12764) Added support for temporary --with constraints with wildcards in the package name for the update command (#12658) Added --strict-psr-autoloader flag to install and update commands (#12647) Added source-fallback config option to disable or enable source fallback on download failure (#12698) Added --require parameter to create-project to add new packages to the project as it gets installed (#12738) Optimized plugin autoloading by avoiding regenerating classmaps for every package per plugin (#12696) Optimized PoolOptimizer memory usage (#12783) Optimized classmap dumping performance Deprecated most of the audit config in favor of the new policy one (#12804, see #12786 for the RFC and upgrade docs) Fixed update --bump-after-update to only bump packages that actually were updated (#12733) Fixed GitHub API authentication errors not being visible to the user (#12737) Fixed error reporting for clarity when a constraint cannot be parsed (#12743) Fixed warning being shown when lock file is disabled (#12760) Fixed inconsistent treatment of SingleCommandApplication script commands wrt autoloading (#12758) Fixed some platform package parsing failing when Composer runs in web SAPIs (#12735) Fixed audit command returning a success code when the vendor dir was notpresent (#12880) -------------------------------------------------------------------------------- ChangeLog: * Thu Jun 4 2026 Remi Collet - 2.10.1-1 - update to 2.10.1 * Thu May 28 2026 Remi Collet - 2.10.0-1 - update to 2.10.0 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4308b5fc39' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
LuaTeX (TeX Live) could be made to run programs as your login if it compiled a specially crafted TeX file.. =========================================================================Ubuntu Security Notice USN-6115-1 May 30, 2023 texlive-bin vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.10 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: LuaTeX (TeX Live) could be made to run programs as your login if it compiled a specially crafted TeX file. Software Description: - texlive-bin: Binaries for TeX Live Details: Max Chernoff discovered that LuaTeX (TeX Live) did not properly disable shell escape. An attacker could possibly use this issue to execute arbitrary shell commands. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: texlive-binaries 2022.20220321.62855-5ubuntu0.1 Ubuntu 22.10: texlive-binaries 2022.20220321.62855-4ubuntu0.1 Ubuntu 22.04 LTS: texlive-binaries 2021.20210626.59705-1ubuntu0.1 Ubuntu 20.04 LTS: texlive-binaries 2019.20190605.51237-3ubuntu0.1 Ubuntu 18.04 LTS: texlive-binaries 2017.20170613.44572-8ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6115-1 CVE-2023-32700 Package Information: https://launchpad.net/ubuntu/+source/texlive-bin/2022.20220321.62855-5ubuntu0.1 https://launchpad.net/ubuntu/+source/texlive-bin/2022.20220321.62855-4ubuntu0.1 https://launchpad.net/ubuntu/+source/texlive-bin/2021.20210626.59705-1ubuntu0.1 https://launchpad.net/ubuntu/+source/texlive-bin/2019.20190605.51237-3ubuntu0.1 https://launchpad.net/ubuntu/+source/texlive-bin/2017.20170613.44572-8ubuntu0.2 . Mitigating the TeX Live security flaw in Ubuntu which permits unauthorized commandexecution through specially designed TeX documents.. LuaTeX, TeX Live, Ubuntu Security, Shell Escape, Update Instructions. . Severity: Critical. LinuxSecurity.com Team
Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3427-1
Max Chernoff discovered that improperly secured shell-escape in LuaTeX may result in arbitrary shell command execution, even with shell escape disabled, if specially crafted tex files are processed. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5406-1
An update that solves two vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for rubygem-rack ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2526-1 Rating: critical References: #1200748 #1200750 #1201588 Cross-References: CVE-2022-30122 CVE-2022-30123 CVSS scores: CVE-2022-30122 (SUSE): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVE-2022-30123 (SUSE): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud Crowbar 9 ______________________________________________________________________________ An update that solves two vulnerabilities and has one errata is now available. Description: This update for rubygem-rack fixes the following issues: - CVE-2022-30122: Fixed crafted multipart POST request may cause a DoS (bsc#1200748) - CVE-2022-30123: Fixed crafted requests can cause shell escape sequences (bsc#1200750) The following non-security bug was fixed: - Fixed a regression in CVE-2022-30122 patch (bsc#1201588). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-2526=1 - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-2526=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (x86_64): ruby2.1-rubygem-rack-1.6.13-3.13.1 - SUSE OpenStack Cloud Crowbar 8 (x86_64): ruby2.1-rubygem-rack-1.6.13-3.13.1 References: https://www.suse.com/security/cve/CVE-2022-30122.html https://www.suse.com/security/cve/CVE-2022-30123.html https://bugzilla.suse.com/1200748 https://bugzilla.suse.com/1200750 https://bugzilla.suse.com/1201588 . Important SUSE patch for rubygem-rack resolves severe vulnerabilities and provides guidance for installation.. SUSE OpenStack Security, rubygem-rack Update, Critical Security Patch. . Severity: Critical. LinuxSecurity.com Team
Crafted multipart POST request may cause a DoS (CVE-2022-30122) Crafted requests can cause shell escape sequences (CVE-2022-30123) References: - https://bugs.mageia.org/show_bug.cgi?id=30584 . MGASA-2022-0252 - Updated ruby-rack packages fix security vulnerability Publication date: 05 Jul 2022 URL: https://advisories.mageia.org/MGASA-2022-0252.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-30122, CVE-2022-30123 Crafted multipart POST request may cause a DoS (CVE-2022-30122) Crafted requests can cause shell escape sequences (CVE-2022-30123) References: - https://bugs.mageia.org/show_bug.cgi?id=30584 - - https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2022-30122.yml - https://github.com/rubysec/ruby-advisory-db/blob/master/gems/rack/CVE-2022-30123.yml - https://www.cve.org/CVERecord?id=CVE-2022-30122 - https://www.cve.org/CVERecord?id=CVE-2022-30123 SRPMS: - 8/core/ruby-rack-2.2.3.1-1.mga8 . Recent updates to the ruby-rack packages in Mageia mitigate issues related to specially designed requests that could exploit DoS conditions and facilitate shell escape vulnerabilities.. Ruby Rack Security Fix, Mageia Update, DoS Shell Escape, Software Security Advisory. . Severity: Important. LinuxSecurity.com Team
An update for patch is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: patch security update Advisory ID: RHSA-2019:4061-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:4061 Issue date: 2019-12-03 CVE Names: CVE-2018-20969 CVE-2019-13638 ==================================================================== 1. Summary: An update for patch is now available for Red Hat Enterprise Linux 7.4 Advanced Update Support, Red Hat Enterprise Linux 7.4 Telco Extended Update Support, and Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server AUS (v. 7.4) - x86_64 Red Hat Enterprise Linux Server E4S (v. 7.4) - ppc64le, x86_64 Red Hat Enterprise Linux Server TUS (v. 7.4) - x86_64 3. Description: The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Security Fix(es): * patch: do_ed_script in pch.c does not block strings beginning with a ! character (CVE-2018-20969) * patch: OS shell command injection when processing crafted patch files (CVE-2019-13638) For more details about the security issue(s), includingthe impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1733916 - CVE-2019-13638 patch: OS shell command injection when processing crafted patch files 1746672 - CVE-2018-20969 patch: do_ed_script in pch.c does not block strings beginning with a ! character 6. Package List: Red Hat Enterprise Linux Server AUS (v. 7.4): Source: patch-2.7.1-11.el7_4.src.rpm x86_64: patch-2.7.1-11.el7_4.x86_64.rpm patch-debuginfo-2.7.1-11.el7_4.x86_64.rpm Red Hat Enterprise Linux Server E4S (v. 7.4): Source: patch-2.7.1-11.el7_4.src.rpm ppc64le: patch-2.7.1-11.el7_4.ppc64le.rpm patch-debuginfo-2.7.1-11.el7_4.ppc64le.rpm x86_64: patch-2.7.1-11.el7_4.x86_64.rpm patch-debuginfo-2.7.1-11.el7_4.x86_64.rpm Red Hat Enterprise Linux Server TUS (v. 7.4): Source: patch-2.7.1-11.el7_4.src.rpm x86_64: patch-2.7.1-11.el7_4.x86_64.rpm patch-debuginfo-2.7.1-11.el7_4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-20969 https://access.redhat.com/security/cve/CVE-2019-13638 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXeZAr9zjgjWX9erEAQgSaQ/8DXzTEBiK5ZCnStrk5o83Jr7tuw2TbL0x L7ogrKW+6OK+9ca7pFAC7bMhZKIKoB00qDmwat2al08EJzBJUPdY08Ot7r6mYKI6 5UlNgET1Vjs4PIcXwqWtE2a2fr08eZ+S4zzuByDO6msGDzF6hk4r6FxpqdzWX/n2 IA1Nr1MefLRpMCHWWqS7NmXYJx0FDDhd1l7KTZB3YchIBV7E4x20Gzfp6jBx2cjS m0cStOO0WXjdMMPIcR1pLkxrzMVbsIcZV/HAxnaOkwadDfNgoeA/3fzHimiV9bk7 6G3MUTqAlJB4fz7oHlNnD1d6prfKpMhpZND4zePud0BPZ9/6oBiF0g2kXhuqvGVm hCc68r0woOfb3mOthj++/qXE17lVCBmQpxVCVNNnJ2aLhe1EaIZj++juS5v28Yw7 ST9wiMFV+giujJFYoZrvee8q9Kdqs6nH5P60g74CHGmDV0GIfGbbHSlDC65nvoua bieoR+/lNzjnpxyPm+8B24E3o2w9JVMJqQ5JNJl0cP3fmba7F4ON5/tao9aKlPA9 Z5WhvUB9DSjxPBdzhX2EgEZfFqwOiz50uhWdgfyZN1IMWK8xBRXE3Y4yjOt5RRHv 0CRttj3CMhBcE2OJn8pI84a8LbKNmywrEIrXShAullIkpUkHlAVGwDRRN9wCRQsC 0mLAthrSZao=+APm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
An update that solves one vulnerability and has three fixes is now available.. openSUSE Security Update: Security update for cobbler ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1770-1 Rating: moderate References: #1074594 #1075014 #1081714 #1090205 Cross-References: CVE-2017-1000469 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves one vulnerability and has three fixes is now available. Description: This update for cobbler fixes the following issues: The following security issue has been fixed: - CVE-2017-1000469: Escape shell parameters provided by the user for the reposync action. (bsc#1074594) Additionally, the following non-security issues have been fixed: - Fix signature for SLES15. (bsc#1075014) - Detect if there is already another instance of "cobbler sync" running and exit with failure if so. (bsc#1081714) - Add SLES 15 distro profile. (bsc#1090205) - Require tftp(server) instead of atftp. This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-655=1 Package List: - openSUSE Leap 42.3 (noarch): cobbler-2.6.6-14.1 cobbler-tests-2.6.6-14.1 cobbler-web-2.6.6-14.1 koan-2.6.6-14.1 References: https://www.suse.com/security/cve/CVE-2017-1000469.html https://bugzilla.suse.com/show_bug.cgi?id=1074594 https://bugzilla.suse.com/show_bug.cgi?id=1075014 https://bugzilla.suse.com/show_bug.cgi?id=1081714 https://bugzilla.suse.com/show_bug.cgi?id=1090205 -- . New patch released for openSUSE, resolving cobbler'svulnerabilities and boosting system performance with four improvements.. openSUSE Security,cobbler Update,moderate Severity Advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.