Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 465
Alerts This Week
Warning Icon 1 465

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 7: MGASA-2020-0205 Critical: Samba Use-After-Free and SIGSEGV

Updated samba packages fix security vulnerabilities: A client combining the 'ASQ' and 'Paged Results' LDAP controls can cause a use-after-free in Samba's AD DC LDAP server (CVE-2020-10700). . MGASA-2020-0205 - Updated samba packages fix security vulnerabilities Publication date: 08 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0205.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10700, CVE-2020-10704 Updated samba packages fix security vulnerabilities: A client combining the 'ASQ' and 'Paged Results' LDAP controls can cause a use-after-free in Samba's AD DC LDAP server (CVE-2020-10700). A deeply nested filter in an un-authenticated LDAP search can exhaust the LDAP server's stack memory causing a SIGSEGV (CVE-2020-10704). The samba package has been updated to version 4.10.15, fixing these issues and other bugs. The ldb package has been updated to version 1.5.7. The sssd package has been rebuilt for the updated ldb. References: - https://bugs.mageia.org/show_bug.cgi?id=26566 - - - - - - https://www.cve.org/CVERecord?id=CVE-2020-10700 - https://www.cve.org/CVERecord?id=CVE-2020-10704 SRPMS: - 7/core/samba-4.10.15-1.mga7 - 7/core/sssd-1.16.3-3.2.mga7 - 7/core/ldb-1.5.7-1.mga7 . Revised Samba software for Mageia addresses significant security vulnerabilities impacting LDAP service.. Security Advisory, Samba Update, Mageia Security, LDAP Vulnerabilities, Use-after-free Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 08, 2020 Critical Mageia
89

Fedora 23: RPM Update Notification For Sigsegv And Heap Read Issues

* Fix sigsegv in stringFormat() (rhbz:1316903) * Fix reading rpmtd behind its size in formatValue() (rhbz:1316896). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-c3d9a9c0c4 2016-04-26 16:44:53.188544 -------------------------------------------------------------------------------- Name : rpm Product : Fedora 23 Version : 4.13.0 Release : 0.rc1.13.fc23 URL : http://rpm.org/ Summary : The RPM package management system Description : The RPM Package Manager (RPM) is a powerful command line driven package management system capable of installing, uninstalling, verifying, querying, and updating software packages. Each software package consists of an archive of files along with information about the package like its version, a description, etc. -------------------------------------------------------------------------------- Update Information: * Fix sigsegv in stringFormat() (rhbz:1316903) * Fix reading rpmtd behind its size in formatValue() (rhbz:1316896) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1316903 - rpm: Null pointer dereference in rstrdup https://bugzilla.redhat.com/show_bug.cgi?id=1316903 [ 2 ] Bug #1316896 - rpm: Out-of-bounds heap read triggered by crafted RPM file https://bugzilla.redhat.com/show_bug.cgi?id=1316896 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update rpm' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 24 package upgrades resolve significant concerns such as a stack overflow and an out-of-bounds stack write security flaw.. Fedora Updates, RPM Package Manager, Heap Read Issues, Security Patch, Package Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 26, 2016 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200