Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
87

Debian Bullseye: DSA-5408-1 Moderate: Libwebp Denial Of Service Issue

Irvan Kurniawan discovered a double free in the libwebp image compression library which may result in denial of service. For the stable distribution (bullseye), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5408-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 21, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libwebp CVE ID : CVE-2023-1999 Debian Bug : 1035371 Irvan Kurniawan discovered a double free in the libwebp image compression library which may result in denial of service. For the stable distribution (bullseye), this problem has been fixed in version 0.6.1-2.1+deb11u1. We recommend that you upgrade your libwebp packages. For the detailed security status of libwebp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libwebp Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Please ensure you enhance your libwebp libraries in alignment with DSA-5408-1 to address the denial of service vulnerability revealed by Irvan Kurniawan.. libwebp, Debian, security update, denial of service, image compression. . LinuxSecurity.com Team

Calendar%202 May 21, 2023 Debian
87

Debian Bullseye: DSA-5264-1 Critical: Batik Remote Code Execution

It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5264-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Markus Koschany October 29, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : batik CVE ID : CVE-2022-41704 CVE-2022-42890 It was discovered that Apache Batik, a SVG library for Java, allowed attackers to run arbitrary Java code by processing a malicious SVG file. For the stable distribution (bullseye), these problems have been fixed in version 1.12-4+deb11u1. We recommend that you upgrade your batik packages. For the detailed security status of batik please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/batik Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian has released an update for Batik to address severe security vulnerabilities that could enable remote code execution via SVG file manipulation. Users are strongly encouraged to upgrade.. Batik Security Update, Debian Advisory, Java Library Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 29, 2022 Critical Debian
87

Debian: DSA-4916-2 Moderate: Prosody Websocket Regression Fix

The update for prosody released as DSA 4916-1 introduced a regression in websocket support. Updated prosody packages are now available to correct this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4916-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff May 21, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : prosody Debian Bug : 988756 The update for prosody released as DSA 4916-1 introduced a regression in websocket support. Updated prosody packages are now available to correct this issue. For the stable distribution (buster), these problems have been fixed in version 0.11.2-1+deb10u2. We recommend that you upgrade your prosody packages. For the detailed security status of prosody please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/prosody Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Addressing websocket issues in Prosody through update DSA-4916-2 for the current Debian stable release. Suggested patches available.. Debian Update, Prosody Regression, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 21, 2021 Important Debian
87

Debian Buster DSA-4801-1 Critical: Brotli Buffer Overflow Update

A buffer overflow was discovered in Brotli, a generic-purpose lossless compression suite. For the stable distribution (buster), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4801-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 01, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : brotli CVE ID : CVE-2020-8927 A buffer overflow was discovered in Brotli, a generic-purpose lossless compression suite. For the stable distribution (buster), this problem has been fixed in version 1.0.7-2+deb10u1. We recommend that you upgrade your brotli packages. For the detailed security status of brotli please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/brotli Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Patch addressing buffer overflow vulnerability in Brotli for Debian stable release focuses on enhancing both security measures and overall system stability.. Debian Brotli Update, Buffer Overflow Mitigation, Security Enhancement. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 01, 2020 Critical Debian
87

Debian: DSA-4471-1 Critical: Thunderbird Code Execution Threat

Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For the stable distribution (stretch), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4471-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 24, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : thunderbird CVE ID : CVE-2019-11707 CVE-2019-11708 Multiple security issues have been found in Thunderbird which may lead to the execution of arbitrary code if malformed email messages are read. For the stable distribution (stretch), these problems have been fixed in version 1:60.7.2-1~deb9u1. We recommend that you upgrade your thunderbird packages. For the detailed security status of thunderbird please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/thunderbird Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Essential security patch for Debian Firefox addresses potential threats linked to malformed web pages that may lead to unauthorized script execution.. Debian Security, Thunderbird Update, Email Vulnerability, Code Execution, Cybersecurity Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 24, 2019 Critical Debian
87

Debian Jessie DSA-4054-1 Moderate: Tor Security Fixes Implemented

Multiple vulnerabilities have been found in Tor, a connection-based low-latency anonymous communication system. For the oldstable distribution (jessie), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4054-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 03, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : tor CVE ID : CVE-2017-8819 CVE-2017-8820 CVE-2017-8821 CVE-2017-8822 CVE-2017-8823 Multiple vulnerabilities have been found in Tor, a connection-based low-latency anonymous communication system. For the oldstable distribution (jessie), these problems have been fixed in version 0.2.5.16-1. For the stable distribution (stretch), these problems have been fixed in version 0.2.9.14-1. We recommend that you upgrade your tor packages. For the detailed security status of tor please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tor Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Tor implemented important patches to address multiple vulnerabilities in Debian oldstable and stable. Upgrade advised.. Debian Security, Tor Updates, Vulnerability Management. . LinuxSecurity.com Team

Calendar%202 Dec 03, 2017 Debian
87

Debian DSA-3101-1: Moderate Impact on c-icap Remote Attacker

Several vulnerabilities were found in c-icap, an ICAP server implementation, which could allow a remote attacker to cause c-icap to crash, or have other, unspecified impacts. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3101-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso December 13, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : c-icap CVE ID : CVE-2013-7401 CVE-2013-7402 Several vulnerabilities were found in c-icap, an ICAP server implementation, which could allow a remote attacker to cause c-icap to crash, or have other, unspecified impacts. For the stable distribution (wheezy), these problems have been fixed in version 1:0.1.6-1.1+deb7u1. For the upcoming stable distribution (jessie), these problems have been fixed in version 1:0.3.1-1. For the unstable distribution (sid), these problems have been fixed in version 1:0.3.1-1. We recommend that you upgrade your c-icap packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-3102-1 outlines security patches for libjpeg addressing critical exposure risks.. Debian Security Advisory,c-icap update,remote attack,ICAP server,security fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 13, 2014 Important Debian
87

Debian DSA-2831-2 Puppet Regression Update: Affected File Mode

The fix for CVE-2013-4969 contained a regression affecting the default file mode if none is specified on a file resource. The oldstable distribution (squeeze) is not affected by this regression. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2831-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso January 17, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : puppet Vulnerability : regression Debian-specific: no Debian Bug : 734444 The fix for CVE-2013-4969 contained a regression affecting the default file mode if none is specified on a file resource. The oldstable distribution (squeeze) is not affected by this regression. For the stable distribution (wheezy), this problem has been fixed in version 2.7.23-1~deb7u3. For the testing distribution (jessie) and the unstable distribution (sid), this problem has been fixed in version 3.4.2-1. For reference, the original advisory text follows. An unsafe use of temporary files was discovered in Puppet, a tool for centralized configuration management. An attacker can exploit this vulnerability and overwrite an arbitrary file in the system. For the oldstable distribution (squeeze), this problem has been fixed in version 2.6.2-5+squeeze9. For the stable distribution (wheezy), this problem has been fixed in version 2.7.23-1~deb7u2. For the testing distribution (jessie), this problem has been fixed in version 3.4.1-1. For the unstable distribution (sid), this problem has been fixed in version 3.4.1-1. We recommend that you upgrade your puppet packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Notice DSA-2831-3 addresses a puppet issueresulting from CVE-2013-4970 and advises users to perform updates.. Debian Puppet Security, Configuration Management, Regression Fix, Security Update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 17, 2014 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200