Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
PostgreSQL could allow unintended access to network services.. =========================================================================Ubuntu Security Notice USN-5145-1 November 11, 2021 postgresql-10, postgresql-12, postgresql-13 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 21.10 - Ubuntu 21.04 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: PostgreSQL could allow unintended access to network services. Software Description: - postgresql-13: Object-relational SQL database - postgresql-12: Object-relational SQL database - postgresql-10: Object-relational SQL database Details: Jacob Champion discovered that PostgreSQL incorrectly handled SSL certificate verification and encryption. A remote attacker could possibly use this issue to inject arbitrary SQL queries when a connection is first established. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: postgresql-13 13.5-0ubuntu0.21.10.1 Ubuntu 21.04: postgresql-13 13.5-0ubuntu0.21.04.1 Ubuntu 20.04 LTS: postgresql-12 12.9-0ubuntu0.20.04.1 Ubuntu 18.04 LTS: postgresql-10 10.19-0ubuntu0.18.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart PostgreSQL to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5145-1 CVE-2021-23214, CVE-2021-23222 Package Information: https://launchpad.net/ubuntu/+source/postgresql-13/13.5-0ubuntu0.21.10.1 https://launchpad.net/ubuntu/+source/postgresql-13/13.5-0ubuntu0.21.04.1 https://launchpad.net/ubuntu/+source/postgresql-12/12.9-0ubuntu0.20.04.1 https://launchpad.net/ubuntu/+source/postgresql-10/10.19-0ubuntu0.18.04.1 . Uncover how utilizing PostgreSQL on Ubuntumight unintentionally grant unauthorized network entry. Explore the risks and their remedies.. PostgreSQL vulnerabilities, Ubuntu security notice, network service access, SSL certificate issues, software updates. . Severity: Important. LinuxSecurity.com Team
Update to the latest upstream release. This release reduces dependencies considerably and tightens security. It is recommended that everyone upgrade to this release.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-19b5c9f1c6 2017-03-17 13:16:04.566682 -------------------------------------------------------------------------------- Name : sscg Product : Fedora 25 Version : 2.0.3 Release : 1.fc25 URL : https://github.com/sgallagher/sscg Summary : Simple SSL certificate generator Description : A utility to aid in the creation of more secure "self-signed" certificates. The certificates created by this tool are generated in a way so as to create a CA certificate that can be safely imported into a client machine to trust the service certificate without needing to set up a full PKI environment and without exposing the machine to a risk of false signatures from the service certificate. -------------------------------------------------------------------------------- Update Information: Update to the latest upstream release. This release reduces dependencies considerably and tightens security. It is recommended that everyone upgrade to this release. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sscg' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Scott Cantor discovered that curl, a file retrieval tool, would disable the CURLOPT_SSLVERIFYHOST check when the CURLOPT_SSL_VERIFYPEER setting was disabled. This would also disable ssl certificate host name checks when it should have only disabled verification of the certificate trust . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2798-1
Several unauthorised SSL certificates have been found in the wild issued for the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2200-1
An unauthorized SSL certificate has been found in the wild issued the DigiNotar Certificate Authority, obtained through a security compromise with said company. Debian, like other software distributors, has as a precaution decided to disable the DigiNotar . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2299-1
. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-11740 2009-11-20 04:23:22 -------------------------------------------------------------------------------- Name : wget Product : Fedora 11 Version : 1.12 Release : 2.fc11 URL : Summary : A utility for retrieving files using the HTTP or FTP protocols Description : GNU Wget is a file retrieval utility which can use either the HTTP or FTP protocols. Wget features include the ability to work in the background while you are logged out, recursive retrieval of directories, file name wildcard matching, remote file timestamp storage and comparison, use of Rest with FTP servers and Range with HTTP servers to retrieve files over slow or unstable connections, support for Proxy servers, and configurability. -------------------------------------------------------------------------------- ChangeLog: * Wed Nov 18 2009 Karsten Hopp 1.12-2 - don't provide /usr/share/info/dir * Tue Nov 17 2009 Karsten Hopp 1.12-1 - update to wget-1.12 - fixes CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name * Fri Aug 21 2009 Tomas Mraz - 1.11.4-5 - rebuilt with new openssl * Mon Jul 27 2009 Fedora Release Engineering - 1.11.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #520454 - CVE-2009-3490 wget: incorrect verification of SSL certificate with NUL in name https://bugzilla.redhat.com/show_bug.cgi?id=520454 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update wget' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
It was discovered that OpenLDAP, a free implementation of the Lightweight Directory Access Protocol, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1943
security fix for CVE-2009-2700. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-9231 2009-09-03 00:09:58 --------------------------------------------------------------------------------Name : qt Product : Fedora 11 Version : 4.5.2 Release : 3.fc11 URL : https://qtsoftware.info/?v=0b3b97fa6688 Summary : Qt toolkit Description : Qt is a software toolkit for developing applications. This package contains base tools, like string, xml, and network handling. --------------------------------------------------------------------------------Update Information: security fix for CVE-2009-2700 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2009 Than Ngo - 4.5.2-3 - fix for CVE-2009-2700 * Tue Aug 18 2009 Than Ngo - 4.5.2-2 - security fix for CVE-2009-1725 * Tue Aug 18 2009 Rex Dieter 4.5.2-1.2 - kde-qt: 287-qmenu-respect-minwidth - kde-qt: 0288-more-x-keycodes (#475247) * Wed Aug 5 2009 Rex Dieter 4.5.2-1.1 - use linker scripts for _debug targets (#510246) - apply upstream patch to fix issue in Copy and paste - optimize (icon-mostly) scriptlets - -x11: Requires(post,postun): /sbin/ldconfig * Thu Jul 2 2009 Than Ngo - 4.5.2-1 - 4.5.2 * Sat May 30 2009 Rex Dieter - 4.5.1-13 - -doc: Obsoletes: qt-doc < 1:4.5.1-4 (workaround bug #502401) * Sat May 23 2009 Rex Dieter - 4.5.1-12 - +phonon_internal macro to toggle packaging of qt's phonon (default off) * Fri May 22 2009 Rex Dieter - 4.5.1-11 - qt-copy-patches-20090522 * Wed May 20 2009 Rex Dieter - 4.5.1-10.2 - full (non-bootstrap) build * Wed May 20 2009 Rex Dieter - 4.5.1-10.1 - allow for minimal bootstrap build (*cough* arm *cough*) * Wed May 6 2009 Rex Dieter - 4.5.1-10 - improved kde4_plugins patch, skip expensive/unneeded canonicalPath * Wed May 6 2009 Rex Dieter - 4.5.1-9 - include kde4 plugin path by default (#498809) * Mon May 4 2009Rex Dieter - 4.5.1-8 - fix invalid assumptions about mysql_config --libs (bug #440673) - fix %files breakage from 4.5.1-5 * Wed Apr 29 2009 Rex Dieter - 4.5.1-7 - -devel: Provides: qt4-devel%{?_isa} ... * Mon Apr 27 2009 Than Ngo - 4.5.1-6 - drop useless hunk of qt-x11-opensource-src-4.5.1-enable_ft_lcdfilter.patch * Mon Apr 27 2009 Rex Dieter - 4.5.1-5 - -devel: Provides: *-static for libQtUiTools.a * Fri Apr 24 2009 Rex Dieter - 4.5.1-4 - qt-doc noarch - qt-demos, qt-examples (split from -doc) - (cosmetic) re-order subpkgs in alphabetical order - drop unused profile.d bits * Fri Apr 24 2009 Rex Dieter - 4.5.1-3 - enable FT_LCD_FILTER (uses freetype subpixel filters if available at runtime) * Fri Apr 24 2009 Than Ngo - 4.5.1-2 - apply upstream patch to fix the svg rendering regression * Thu Apr 23 2009 Than Ngo - 4.5.1-1 - 4.5.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #520435 - CVE-2009-2700 Qt: QSslCertificate incorrect verification of SSL certificate with NUL in subjectAltName https://bugzilla.redhat.com/show_bug.cgi?id=520435 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update qt' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list
Get the latest Linux and open source security news straight to your inbox.