Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
203

Mageia 8: MGASA-2022-0110 Moderate: Sphinx File Access Issue

It was found that sphinx could allow arbitrary files to be read by abusing a configuration option. (CVE-2020-29050) References: - https://bugs.mageia.org/show_bug.cgi?id=30076 . MGASA-2022-0110 - Updated sphinx packages fix security vulnerability Publication date: 23 Mar 2022 URL: https://advisories.mageia.org/MGASA-2022-0110.html Type: security Affected Mageia releases: 8 CVE: CVE-2020-29050 It was found that sphinx could allow arbitrary files to be read by abusing a configuration option. (CVE-2020-29050) References: - https://bugs.mageia.org/show_bug.cgi?id=30076 - https://lists.debian.org/debian-security-announce/2022/msg00002.html - - https://salsa.debian.org/debian/sphinxsearch/-/blob/4d6fe40644130308604845db43d3588e715ec85d/debian/patches/06-CVE-2020-29050.patch - https://www.cve.org/CVERecord?id=CVE-2020-29050 SRPMS: - 8/core/sphinx-2.3.2-0.beta.3.1.mga8 . Recent updates to sphinx libraries rectify a setup vulnerability that permits uncontrolled file access, commencing on March 23, 2022.. Mageia Sphinx Update, Security Fix, File Access Issue. . LinuxSecurity.com Team

Calendar 2 Mar 23, 2022 Mageia
202

openSUSE Leap 15.3: openSUSE-SU-2022:0054-1 moderate sphinx vulnerability

An update that solves one vulnerability and has one errata is now available. . openSUSE Security Update: Security update for sphinx ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0054-1 Rating: moderate References: #1157590 #1195227 Cross-References: CVE-2020-29050 CVSS scores: CVE-2020-29050 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.3 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for sphinx fixes the following issues: - CVE-2020-29050: SphinxSearch in Sphinx Technologies Sphinx allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). (boo#1195227) - update to 2.0.6 release Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.3: zypper in -t patch openSUSE-2022-54=1 Package List: - openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64): libsphinxclient-0_0_1-2.2.11-lp153.2.3.1 libsphinxclient-devel-2.2.11-lp153.2.3.1 sphinx-2.2.11-lp153.2.3.1 sphinx-debuginfo-2.2.11-lp153.2.3.1 sphinx-debugsource-2.2.11-lp153.2.3.1 References: https://www.suse.com/security/cve/CVE-2020-29050.html https://bugzilla.suse.com/1157590 https://bugzilla.suse.com/1195227 . A recent Sphinx enhancement addresses directory traversal vulnerabilities in openSUSE Leap 15.3. Find out the essential correction and the steps to apply it.. openSUSE updates, Sphinx security, directory traversal fix,cybersecurity patch, openSUSE vulnerability response. . LinuxSecurity.com Team

Calendar 2 Mar 01, 2022 OpenSUSE
202

openSUSE Leap 15.4: openSUSE-SU-2022:0046-1 Moderate Sphinx Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for sphinx ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:0046-1 Rating: moderate References: #1195227 Cross-References: CVE-2020-29050 CVSS scores: CVE-2020-29050 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: openSUSE Leap 15.4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: sphinx was updated to fix the following issues: - CVE-2020-29050: SphinxSearch in Sphinx Technologies Sphinx through 3.1.1 allows directory traversal (in conjunction with CVE-2019-14511) because the mysql client can be used for CALL SNIPPETS and load_file operations on a full pathname (e.g., a file in the /etc directory). (boo#1195227) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.4: zypper in -t patch openSUSE-2022-46=1 Package List: - openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64): libsphinxclient-0_0_1-2.2.11-lp154.3.3.1 libsphinxclient-devel-2.2.11-lp154.3.3.1 sphinx-2.2.11-lp154.3.3.1 sphinx-debuginfo-2.2.11-lp154.3.3.1 sphinx-debugsource-2.2.11-lp154.3.3.1 References: https://www.suse.com/security/cve/CVE-2020-29050.html https://bugzilla.suse.com/1195227 . openSUSE enhances sphinx to address directory traversal vulnerabilities classified as moderate risk. Announcement ID: openSUSE-SU-2022:0047-1. openSUSE Security, Sphinx Update, Directory Traversal Fix. . LinuxSecurity.com Team

Calendar 2 Feb 21, 2022 OpenSUSE
203

Mageia: 2020-0087 Moderate: Sphinx Authentication Issue

Updated sphinx packages fix security vulnerability: A vulnerability was found in Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet, unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only . MGASA-2020-0087 - Updated sphinx packages fix security vulnerability Publication date: 18 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0087.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-14511 Updated sphinx packages fix security vulnerability: A vulnerability was found in Sphinx Technologies Sphinx 3.1.1 by default has no authentication and listens on 0.0.0.0, making it exposed to the internet, unless filtered by a firewall or reconfigured to listen to 127.0.0.1 only (CVE-2019-14511). References: - https://bugs.mageia.org/show_bug.cgi?id=25946 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/YSLPW44RWIGHU5AG3P4U2HPSD3UBG4GJ/ - https://www.cve.org/CVERecord?id=CVE-2019-14511 SRPMS: - 7/core/sphinx-2.3.2-0.beta.1.1.mga7 . Mageia 2020-0090 resolves a significant vulnerability in Apache, enhancing system integrity through improved software components.. Sphinx 3.1.1, Mageia 7, Security Update, Internet Exposure, Authentication Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 18, 2020 Important Mageia
89

Fedora 31: FEDORA-2019-1f604fd2f2 Critical: Sphinx Information Disclosure

Security fix for CVE-2019-14511. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-1f604fd2f2 2019-09-30 00:00:36.231210 --------------------------------------------------------------------------------Name : sphinx Product : Fedora 31 Version : 2.2.11 Release : 13.fc31 URL : http://sphinxsearch.com Summary : Free open-source SQL full-text search engine Description : Sphinx is a full-text search engine, distributed under GPL version 2. Commercial licensing (e.g. for embedded use) is also available upon request. Generally, it's a standalone search engine, meant to provide fast, size-efficient and relevant full-text search functions to other applications. Sphinx was specially designed to integrate well with SQL databases and scripting languages. Currently built-in data source drivers support fetching data either via direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML format. Adding new drivers (e.g. native support other DBMSes) is designed to be as easy as possible. Search API native ported to PHP, Python, Perl, Ruby, Java, and also available as a plug-gable MySQL storage engine. API is very lightweight so porting it to new language is known to take a few hours. As for the name, Sphinx is an acronym which is officially decoded as SQL Phrase Index. Yes, I know about CMU's Sphinx project. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14511 --------------------------------------------------------------------------------References: [ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1749188 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade--advisory FEDORA-2019-1f604fd2f2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A security update for Sphinx on Fedora mitigates the CVE-2019-14511 vulnerability to safeguard against potential data exposure threats.. Fedora 31, Sphinx, SQL Full-Text Search, Information Disclosure, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 29, 2019 Critical Fedora
89

Fedora 29 Sphinx: 2019-09-14 Critical Info Leak Advisory

Security fix for CVE-2019-14511. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-bdadf4c6f5 2019-09-14 01:53:52.304211 --------------------------------------------------------------------------------Name : sphinx Product : Fedora 29 Version : 2.2.11 Release : 12.fc29 URL : http://sphinxsearch.com Summary : Free open-source SQL full-text search engine Description : Sphinx is a full-text search engine, distributed under GPL version 2. Commercial licensing (e.g. for embedded use) is also available upon request. Generally, it's a standalone search engine, meant to provide fast, size-efficient and relevant full-text search functions to other applications. Sphinx was specially designed to integrate well with SQL databases and scripting languages. Currently built-in data source drivers support fetching data either via direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML format. Adding new drivers (e.g. native support other DBMSes) is designed to be as easy as possible. Search API native ported to PHP, Python, Perl, Ruby, Java, and also available as a plug-gable MySQL storage engine. API is very lightweight so porting it to new language is known to take a few hours. As for the name, Sphinx is an acronym which is officially decoded as SQL Phrase Index. Yes, I know about CMU's Sphinx project. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14511 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 5 2019 Ben Cotton - 2.2.11-12 - Listen only on localhost (CVE-2019-14511, rhbz#1749190) * Thu Feb 14 2019 Orion Poplawski - 2.2.11-11 - Revert incorrect use of _tmpfiledir rhbx#1551735 * Sun Feb 3 2019 Fedora Release Engineering - 2.2.11-10 - Rebuilt forhttps://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1749188 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-bdadf4c6f5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . In response to CVE-2019-14511, the latest sphinx security advisory enhances Fedora's defenses and revises service set-up.. Fedora Update,Sphinx Security,Full-Text Search Engine,Information Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 13, 2019 Critical Fedora
89

Critical Info Leak in Fedora 30 Sphinx Update: FEDORA-2019-9231a18768

Security fix for CVE-2019-14511. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-9231a18768 2019-09-14 01:11:50.073054 --------------------------------------------------------------------------------Name : sphinx Product : Fedora 30 Version : 2.2.11 Release : 12.fc30 URL : http://sphinxsearch.com Summary : Free open-source SQL full-text search engine Description : Sphinx is a full-text search engine, distributed under GPL version 2. Commercial licensing (e.g. for embedded use) is also available upon request. Generally, it's a standalone search engine, meant to provide fast, size-efficient and relevant full-text search functions to other applications. Sphinx was specially designed to integrate well with SQL databases and scripting languages. Currently built-in data source drivers support fetching data either via direct connection to MySQL, or PostgreSQL, or from a pipe in a custom XML format. Adding new drivers (e.g. native support other DBMSes) is designed to be as easy as possible. Search API native ported to PHP, Python, Perl, Ruby, Java, and also available as a plug-gable MySQL storage engine. API is very lightweight so porting it to new language is known to take a few hours. As for the name, Sphinx is an acronym which is officially decoded as SQL Phrase Index. Yes, I know about CMU's Sphinx project. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14511 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 5 2019 Ben Cotton - 2.2.11-12 - Listen only on localhost (CVE-2019-14511, rhbz#1749190) --------------------------------------------------------------------------------References: [ 1 ] Bug #1749188 - CVE-2019-14511 sphinx: no authentication and listens on 0.0.0.0 leads to information disclosure https://bugzilla.redhat.com/show_bug.cgi?id=1749188 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-9231a18768' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Urgent patch released for data leak vulnerability in Sphinx on Fedora 30 tied to CVE-2019-14511. Apply this update immediately to safeguard your system!. Fedora Security Fix,Sphinx Update,Authentication Issue,Full-text Search Engine. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 13, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here