Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 11: DLA-4069-1 Critical: emacs code execution threats

Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4069-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sean Whitton February 27, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : emacs Version : 1:27.1+1-3.1+deb11u6 CVE ID : CVE-2023-28617 CVE-2024-53920 CVE-2025-1244 Debian Bug : 1033342 1088690 1098255 Multiple vulnerabilities were discovered in GNU Emacs, the extensible, customisable, self-documenting, real-time display editor. CVE-2023-28617 Improper handling of file or directory names containing shell metacharacters in the ob-latex Lisp library could allow the execution of attacker-controlled code. CVE-2024-53920 Several ways to trigger arbitrary code execution were discovered in Emacs's support for editing files in its own dialect of Lisp. These include arbitrary code execution upon opening an otherwise innocent-looking file, with any (or no) file extension, for editing. CVE-2025-1244 Improper handling of custom 'man' URI schemes could allow an attacker to execute arbitrary shell commands by tricking users into visiting a specially crafted website, or an HTTP URL with a redirect. For Debian 11 bullseye, these problems have been fixed in version 1:27.1+1-3.1+deb11u6. We recommend that you upgrade your emacs packages. For the detailed security status of emacs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/emacs Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest Debian LTS SecurityNotification highlights several vulnerabilities in Emacs that could lead to code execution, necessitating prompt updates to enhance system security.. GNU Emacs Security, Debian LTS Advisory, Code Execution Risk, Emacs Vulnerabilities, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 27, 2025 Critical Debian LTS
219

Rocky Linux 8 RLSA-2024:1610 Moderate: Less Utility Shell Issue

Moderate: less security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2024:1610", "synopsis": "Moderate: less security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for less.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The \"less\" utility is a text file browser that resembles \"more\", but allows users to move backwards in the file as well as forwards. Since \"less\" does not read the entire input file at startup, it also starts more quickly than ordinary text editors.\n\nSecurity Fix(es):\n\n* less: missing quoting of shell metacharacters in LESSCLOSE handling (CVE-2022-48624)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2265081", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2265081", "description": ""}], "cves": [{"name": "CVE-2022-48624", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2022-48624", "cvss3ScoringVector": "UNKNOWN", "cvss3BaseScore": "UNKNOWN", "cwe": "UNKNOWN"}], "references": [], "publishedAt": "2024-04-05T14:55:53.600745Z", "rpms": {"Rocky Linux 8": {"nvras": ["less-0:530-2.el8_9.aarch64.rpm", "less-0:530-2.el8_9.src.rpm", "less-0:530-2.el8_9.x86_64.rpm", "less-debuginfo-0:530-2.el8_9.aarch64.rpm", "less-debuginfo-0:530-2.el8_9.x86_64.rpm", "less-debugsource-0:530-2.el8_9.aarch64.rpm", "less-debugsource-0:530-2.el8_9.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The update RLSA-2024:1610 for Rocky Linux brings significant security enhancements related to the 'less' command-line tool. Explore the details.. Rocky Linux RLSA, Less Utility Update, Moderate Security Fix. .LinuxSecurity.com Team

Calendar 2 Apr 05, 2024 Rocky Linux
99

Slackware 15.0: SSA:2022-342-01 Critical: Emacs Command Execution

New emacs packages are available for Slackware 15.0 and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] emacs (SSA:2022-342-01) New emacs packages are available for Slackware 15.0 and -current to fix a security issue. Here are the details from the Slackware 15.0 ChangeLog: +--------------------------+ patches/packages/emacs-27.2-i586-2_slack15.0.txz: Rebuilt. GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input. For more information, see: https://www.cve.org/CVERecord?id=CVE-2022-45939 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 15.0: Updated package for Slackware x86_64 15.0: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 15.0 package: 97de51db765e152d32a8cf5562961f81 emacs-27.2-i586-2_slack15.0.txz Slackware x86_64 15.0 package: 91209777290bf8fd5e2ac918d72f14ba emacs-27.2-x86_64-2_slack15.0.txz Slackware -current package: 8d0bb1c76fe4e50fa33ecc6c3aaffce1 e/emacs-28.2-i586-2.txz Slackware x86_64 -current package: 3f8c307bb6e7e867cd360c4fa914a70f e/emacs-28.2-x86_64-2.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg emacs-27.2-i586-2_slack15.0.txz +-----+ . Recent Emacs updates forSlackware address an urgent security flaw in versions 15.0 and -current. Please upgrade without delay!. Emacs Security, Slackware Update, Package Upgrade, Command Execution, Shell Metacharacters. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 08, 2022 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here