Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A vulnerability has been discovered in Logcheck's ebuilds which could allow for root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202209-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Logcheck: Root privilege escalation Date: September 25, 2022 Bugs: #630752 ID: 202209-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been discovered in Logcheck's ebuilds which could allow for root privilege escalation. Background ========= Logcheck mails anomalies in the system logfiles to the administrator. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/logcheck
The acroread packages as shipped in Red Hat Enterprise Linux 3 Extras contain security flaws and should not be used. This update has been rated as having critical security impact by the Red Hat Security Response Team.. ==================================================================== Red Hat Security Advisory Synopsis: Critical: acroread security update Advisory ID: RHSA-2010:0060-01 Product: Red Hat Enterprise Linux Extras Advisory URL: https://access.redhat.com/errata/RHSA-2010:0060.html Issue date: 2010-01-20 CVE Names: CVE-2009-3953 CVE-2009-3954 CVE-2009-3955 CVE-2009-3956 CVE-2009-3959 CVE-2009-4324 ==================================================================== 1. Summary: The acroread packages as shipped in Red Hat Enterprise Linux 3 Extras contain security flaws and should not be used. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Desktop version 3 Extras - i386 Red Hat Enterprise Linux AS version 3 Extras - i386 Red Hat Enterprise Linux ES version 3 Extras - i386 Red Hat Enterprise Linux WS version 3 Extras - i386 3. Description: Adobe Reader allows users to view and print documents in Portable Document Format (PDF). Adobe Reader 8.1.7 is vulnerable to critical security flaws and should no longer be used. A specially-crafted PDF file could cause Adobe Reader to crash or, potentially, execute arbitrary code as the user running Adobe Reader when opened. (CVE-2009-4324, CVE-2009-3953, CVE-2009-3954, CVE-2009-3955, CVE-2009-3959, CVE-2009-3956) Adobe have discontinued support for Adobe Reader 8 for Linux. Adobe Reader 9 for Linux is not compatible with Red Hat Enterprise Linux 3. An alternative PDF file viewer available in Red Hat Enterprise Linux 3 is xpdf. This update removes the acroread packages due to their known security vulnerabilities. 4. Solution: Before applying this update, make sure that allpreviously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 547799 - CVE-2009-4324 acroread: media.newplayer JavaScript API code execution vulnerability (APSB10-02) 554293 - CVE-2009-3953 CVE-2009-3954 CVE-2009-3955 CVE-2009-3959 acroread: multiple code execution flaws (APSB10-02) 554296 - CVE-2009-3956 acroread: script injection vulnerability (APSB10-02) 6. Package List: Red Hat Enterprise Linux AS version 3 Extras: i386: acroread-uninstall-9.3-3.i386.rpm Red Hat Desktop version 3 Extras: i386: acroread-uninstall-9.3-3.i386.rpm Red Hat Enterprise Linux ES version 3 Extras: i386: acroread-uninstall-9.3-3.i386.rpm Red Hat Enterprise Linux WS version 3 Extras: i386: acroread-uninstall-9.3-3.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2009-3953 https://access.redhat.com/security/cve/CVE-2009-3954 https://access.redhat.com/security/cve/CVE-2009-3955 https://access.redhat.com/security/cve/CVE-2009-3956 https://access.redhat.com/security/cve/CVE-2009-3959 https://access.redhat.com/security/cve/CVE-2009-4324 https://access.redhat.com/security/updates/classification#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2010 Red Hat, Inc. . Using Acrobat Reader on Red Hat Enterprise poses serious security challenges requiring attention to safely manage PDF files while preventing potential threats. acroread Security, Software Update, Red Hat Advisory. . Severity: Critical. LinuxSecurity.com Team
This is a notice that bitchx, an IRC client based on ircii-EPIC4, has been removed from Slackware -current and will not be part of future Slackware releases. Security issues and bugs have been reported, but upstream work seems to have stalled leaving bitchx in a state where there are . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] bitchx EOLed in Slackware (SSA:2009-116-02) This is a notice that bitchx, an IRC client based on ircii-EPIC4, has been removed from Slackware -current and will not be part of future Slackware releases. Security issues and bugs have been reported, but upstream work seems to have stalled leaving bitchx in a state where there are known problems without official (or in some cases any) fixes. The most secure course of action is to remove bitchx from the system and switch to using a supported IRC client. We have not compiled a complete list of open issues in BitchX, but here are a few that we know about: https://www.cve.org/CVERecord?id=CVE-2007-3360 https://www.cve.org/CVERecord?id=CVE-2007-4584 https://www.cve.org/CVERecord?id=CVE-2007-5839 Package removal instructions: +---------------------------+ Remove the package as root: # removepkg bitchx Some admins may also want to add a symlink to another console IRC client such as irssi to help users migrate: cd /usr/bin ln -sf irssi BitchX +-----+ . BitchX taken off Slackware because of vulnerabilities; transition to endorsed IRC clients to ensure safety.. BitchX, Slackware, IRC Client, Security Issues, Software Removal. . Severity: Important. LinuxSecurity.com Team
Netscape Navigator and Netscape Communicator have been removed from the RedHat Enterprise Linux 2.1 CD-ROM distribution as part of Update 5. Thesepackages were based on Netscape 4.8, which is known to be vulnerable torecent critical security issues, such as CAN-2004-0597, CAN-2004-0598, andCAN-2004-0599.. Red Hat Security Advisory Synopsis: Netscape 4.8 contains security flaws Advisory ID: RHSA-2004:429-01 Issue date: 2004-08-18 Updated on: 2004-08-18 Product: Red Hat Enterprise Linux CVE Names: CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 - --------------------------------------------------------------------- 1. Summary: Netscape Navigator and Netscape Communicator 4.8 as distributed with Red Hat Enterprise Linux 2.1 contain security flaws and should not be used. 2. Problem description: Netscape Navigator and Netscape Communicator have been removed from the Red Hat Enterprise Linux 2.1 CD-ROM distribution as part of Update 5. These packages were based on Netscape 4.8, which is known to be vulnerable to recent critical security issues, such as CAN-2004-0597, CAN-2004-0598, and CAN-2004-0599. Netscape 7.2 contains fixes for these issues and is available from AOL - News, Politics, Sports, Mail & Latest Headlines - AOL.com Netscape 4.8 packages will also remain available via Red Hat Network for those who choose to use them despite their known security vulnerabilities. Users of Netscape 4.8 are advised to switch to Mozilla, which is included and supported in Red Hat Enterprise Linux 2.1, and offers comparable functionality. 3. Solution: Red Hat Enterprise 2.1 users who do not need the functionality of Netscape 4.8 should uninstall the netscape packages. 4. References: CVE -CVE-2004-0597 CVE -CVE-2004-0598 CVE -CVE-2004-0599 5. Contact: The Red Hat security contact is . More contact details at Copyright 2004 Red Hat, Inc. . SuSE issues critical security advisory regarding vulnerabilities found inInternet Explorer 6 that may endanger users on Server 2003. Check the report for further insights.. Netscape Security,Red Hat Advisory,Linux Browser Issues. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.