Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 523
Alerts This Week
Warning Icon 1 523

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 16 articles for you...
202

openSUSE: 2023:0329-1 Important Update for SoX Security Issues

An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for sox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0329-1 Rating: important References: #1212060 #1212061 #1212062 #1212063 Cross-References: CVE-2019-13590 CVE-2021-23159 CVE-2021-33844 CVE-2021-3643 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 CVE-2023-32627 CVE-2023-34318 CVE-2023-34432 CVSS scores: CVE-2019-13590 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-33844 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-33844 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-3643 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2021-3643 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-40426 (NVD) : 10 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVE-2022-31650 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-31651 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2023-32627 (NVD) : 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2023-34318 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-34432 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for sox fixes the following issues: -Apply various fix patches taken from Debian package; it fixes also other entries (CVE-2022-31650 boo#1212060 CVE-2023-34318 boo#1212062 CVE-2023-34432 boo#1212063) - Fix floating point exception in src/voc.c (CVE-2023-32627 boo#1212061) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2023-329=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): libsox3-14.4.2-bp155.3.3.1 sox-14.4.2-bp155.3.3.1 sox-devel-14.4.2-bp155.3.3.1 References: https://www.suse.com/security/cve/CVE-2019-13590.html https://www.suse.com/security/cve/CVE-2021-23159.html https://www.suse.com/security/cve/CVE-2021-33844.html https://www.suse.com/security/cve/CVE-2021-3643.html https://www.suse.com/security/cve/CVE-2021-40426.html https://www.suse.com/security/cve/CVE-2022-31650.html https://www.suse.com/security/cve/CVE-2022-31651.html https://www.suse.com/security/cve/CVE-2023-32627.html https://www.suse.com/security/cve/CVE-2023-34318.html https://www.suse.com/security/cve/CVE-2023-34432.html https://bugzilla.suse.com/1212060 https://bugzilla.suse.com/1212061 https://bugzilla.suse.com/1212062 https://bugzilla.suse.com/1212063 . This Fedora upgrade tackles critical vulnerabilities in git to ensure user privacy is maintained securely.. openSUSE Security, sox Update, Important Patch, Security Fixes, Vulnerability Management. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 26, 2023 Important OpenSUSE
202

openSUSE: 2023:0328-1 Important: sox Security Issues Fixed

An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for sox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2023:0328-1 Rating: important References: #1212060 #1212061 #1212062 #1212063 Cross-References: CVE-2019-13590 CVE-2021-23159 CVE-2021-33844 CVE-2021-3643 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 CVE-2023-32627 CVE-2023-34318 CVE-2023-34432 CVSS scores: CVE-2019-13590 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-23159 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-33844 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2021-33844 (SUSE): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L CVE-2021-3643 (NVD) : 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVE-2021-3643 (SUSE): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L CVE-2021-40426 (NVD) : 10 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVE-2022-31650 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-31651 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2023-32627 (NVD) : 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2023-34318 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2023-34432 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for sox fixes the following issues: -Apply various fix patches taken from Debian package; it fixes also other entries (CVE-2022-31650 boo#1212060 CVE-2023-34318 boo#1212062 CVE-2023-34432 boo#1212063) - Fix floating point exception in src/voc.c (CVE-2023-32627 boo#1212061) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2023-328=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libsox3-14.4.2-bp154.2.3.1 sox-14.4.2-bp154.2.3.1 sox-devel-14.4.2-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2019-13590.html https://www.suse.com/security/cve/CVE-2021-23159.html https://www.suse.com/security/cve/CVE-2021-33844.html https://www.suse.com/security/cve/CVE-2021-3643.html https://www.suse.com/security/cve/CVE-2021-40426.html https://www.suse.com/security/cve/CVE-2022-31650.html https://www.suse.com/security/cve/CVE-2022-31651.html https://www.suse.com/security/cve/CVE-2023-32627.html https://www.suse.com/security/cve/CVE-2023-34318.html https://www.suse.com/security/cve/CVE-2023-34432.html https://bugzilla.suse.com/1212060 https://bugzilla.suse.com/1212061 https://bugzilla.suse.com/1212062 https://bugzilla.suse.com/1212063 . This Fedora update addresses 12 vulnerabilities in curl, boosting security and stability.. openSUSE Security Update, sox repair, software update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 26, 2023 Important OpenSUSE
197

Debian 10 Buster DLA-3527-1 Critical: SoX Denial Of Service Issue

SoX is a command line utility that can convert various formats of computer audio files in to other formats. It can also apply various effects to these sound files during the conversion. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3527-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès August 13, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : sox Version : 14.4.2+git20190427-1+deb10u3 CVE ID : CVE-2023-32627 Debian Bug : 1041112 SoX is a command line utility that can convert various formats of computer audio files in to other formats. It can also apply various effects to these sound files during the conversion. Sox was vulnerable to divide by zero vulnerability by reading an specialy crafted Creative Voice File (.voc) file, in the read_samples function. This flaw can lead to a denial of service. For Debian 10 buster, this problem has been fixed in version 14.4.2+git20190427-1+deb10u3. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5102-1 tackles a severe buffer overflow vulnerability in GIMP impacting image processing capabilities.. Debian LTS, SoX Denial Of Service, Critical Update, Audio File Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 13, 2023 Critical Debian LTS
197

Debian 10 Buster DLA-3315-2 Critical: Sox WAV Processing Issue

One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3315-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Helmut Grohne March 20, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sox Version : 14.4.2+git20190427-1+deb10u2 Debian Bug : 1032082 One of the security fixes released as DLA 3315 introduced a regression in the processing WAV files with variable bitrate encoding. Updated sox packages are available to correct this issue. For Debian 10 buster, this problem has been fixed in version 14.4.2+git20190427-1+deb10u2. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Confronting the regression challenge in sox related to WAV file handling within the Debian LTS Advisory DLA-3315-2. Obtain the most recent patch.. Debian LTS, Sox Update, Audio Bug Fix, Regression Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 20, 2023 Critical Debian LTS
87

Debian: DSA-5356-2 Critical: SoX Package Regression Issue Fixed

One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files. Updated sox packages are available to correct this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff March 17, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sox Debian Bug : 1032082 One of the security fixes released as DSA 5356 introduced a regression in the processing of specific WAV files. Updated sox packages are available to correct this issue. For the stable distribution (bullseye), these problems have been fixed in version 14.4.2+git20190427-2+deb11u2. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent updates to sox packages resolve a regression problem impacting WAV file handling in Debian. Installation of the latest version is advised.. Debian Security, SoX Update, Security Patch, File Processing Error. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 17, 2023 Critical Debian
203

Mageia: 2023-0059 Moderate: Sox Validation Fix for Multiple Flaws

CVE-2019-13590: sox-fmt validation CVE-2021-3643 and CVE-2021-23210: voc validation CVE-2021-23159 and CVE-2021-23172: hcom validation CVE-2021-33844: wav validation CVE-2021-40426: sphere validation . MGASA-2023-0059 - Updated sox packages fix security vulnerability Publication date: 27 Feb 2023 URL: https://advisories.mageia.org/MGASA-2023-0059.html Type: security Affected Mageia releases: 8 CVE: CVE-2019-13590, CVE-2021-23159, CVE-2021-23172, CVE-2021-23210, CVE-2021-33844, CVE-2021-3643, CVE-2021-40426, CVE-2022-3165, CVE-2022-31650 CVE-2019-13590: sox-fmt validation CVE-2021-3643 and CVE-2021-23210: voc validation CVE-2021-23159 and CVE-2021-23172: hcom validation CVE-2021-33844: wav validation CVE-2021-40426: sphere validation CVE-2022-31650: aiff validation CVE-2022-31651: reject implausible rate References: - https://bugs.mageia.org/show_bug.cgi?id=30291 - https://talosintelligence.com/vulnerability_reports/TALOS-2021-1434 - https://lists.debian.org/debian-lts-announce/2023/02/msg00009.html - https://www.cve.org/CVERecord?id=CVE-2019-13590 - https://www.cve.org/CVERecord?id=CVE-2021-23159 - https://www.cve.org/CVERecord?id=CVE-2021-23172 - https://www.cve.org/CVERecord?id=CVE-2021-23210 - https://www.cve.org/CVERecord?id=CVE-2021-33844 - https://www.cve.org/CVERecord?id=CVE-2021-3643 - https://www.cve.org/CVERecord?id=CVE-2021-40426 - https://www.cve.org/CVERecord?id=CVE-2022-3165 - https://www.cve.org/CVERecord?id=CVE-2022-31650 SRPMS: - 8/core/sox-14.4.3-0.git20200117.3.1.mga8 . Recent updates to sox packages address various validation vulnerabilities in Mageia editions, thereby enhancing overall system security.. Sox Security,Mageia Software Update,Validate Flaws. . LinuxSecurity.com Team

Calendar%202 Feb 27, 2023 Mageia
87

Debian DSA-5356-1 Severe: Sox Denial Of Service Threat Explained

Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5356-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 20, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : sox CVE ID : CVE-2021-3643 CVE-2021-23159 CVE-2021-23172 CVE-2021-23210 CVE-2021-33844 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 Debian Bug : 1010374 1012138 1012516 1021133 1021134 1021135 Multiple security issues were discovered in Sox, the Swiss Army knife of sound processing programs, which could result in denial of service or potentially the execution of arbitrary code if a malformed audio file is processed. For the stable distribution (bullseye), these problems have been fixed in version 14.4.2+git20190427-2+deb11u1. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Various vulnerabilities identified in Sox may lead to denial of service or arbitrary code execution upon processing corrupted audio files. It is advisable to implement updates.. Debian Security,Sox Update,DoS Risk. . LinuxSecurity.com Team

Calendar%202 Feb 20, 2023 Debian
197

Debian 10: DLA-3315-1 Critical: SoX Memory Access Threats

This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3315-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Helmut Grohne February 10, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : sox Version : 14.4.2+git20190427-1+deb10u1 CVE ID : CVE-2019-13590 CVE-2021-3643 CVE-2021-23159 CVE-2021-23172 CVE-2021-23210 CVE-2021-33844 CVE-2021-40426 CVE-2022-31650 CVE-2022-31651 Debian Bug : 933372 1010374 1012138 1012516 1021133 1021134 1021135 This update fixes multiple file format validation vulnerabilities that could result in memory access violations such as buffer overflows and floating point exceptions. It also fixes a regression in hcom parsing introduced when fixing CVE-2017-11358. CVE-2019-13590 In sox-fmt.h (startread function), there is an integer overflow on the result of integer addition (wraparound to 0) fed into the lsx_calloc macro that wraps malloc. When a NULL pointer is returned, it is used without a prior check that it is a valid pointer, leading to a NULL pointer dereference on lsx_readbuf in formats_i.c. CVE-2021-3643 The lsx_adpcm_init function within libsox leads to a global-buffer-overflow. This flaw allows an attacker to input a malicious file, leading to the disclosure of sensitive information. CVE-2021-23159 A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash. CVE-2021-23172 A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash. CVE-2021-23210 A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash. CVE-2021-33844 A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash. CVE-2021-40426 A heap-based buffer overflow vulnerability exists in the sphere.c start_read() functionality of Sound Exchange libsox. A specially-crafted file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability. CVE-2022-31650 There is a floating-point exception in lsx_aiffstartwrite in aiff.c. CVE-2022-31651 There is an assertion failure in rate_init in rate.c. For Debian 10 buster, these problems have been fixed in version 14.4.2+git20190427-1+deb10u1. We recommend that you upgrade your sox packages. For the detailed security status of sox please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/sox Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The latest update addresses significant vulnerabilities in SoX, improving protection against memory-related problems and ensuring proper validation of file formats.. SoX Security, Debian LTS, Memory Access Issues, File Format Validation, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2023 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200