Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 20.04 LTS: USN-4508-1 Critical: StoreBackup Race Condition

StoreBackup could be made to stop executing or generate a race condition if it received a lock file in the default location.. =========================================================================Ubuntu Security Notice USN-4508-1 September 16, 2020 storebackup vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: StoreBackup could be made to stop executing or generate a race condition if it received a lock file in the default location. Software Description: - storebackup: fancy compressing managing checksumming deduplicating hard-linkin Details: It was discovered that StoreBackup did not properly manage lock files. A local attacker could use this issue to cause a denial of service or escalate privileges and run arbitrary code. (CVE-2020-7040) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: storebackup 3.2.1-1+deb8u1build0.20.04.1 Ubuntu 18.04 LTS: storebackup 3.2.1-1+deb8u1build0.18.04.1 Ubuntu 16.04 LTS: storebackup 3.2.1-1+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4508-1 CVE-2020-7040 Package Information: https://launchpad.net/ubuntu/+source/storebackup/3.2.1-1+deb8u1build0.20.04.1 https://launchpad.net/ubuntu/+source/storebackup/3.2.1-1+deb8u1build0.18.04.1 https://launchpad.net/ubuntu/+source/storebackup/3.2.1-1+deb8u1build0.16.04.1 . To enhance the security of your Ubuntu system, please ensure you update it to mitigate the critical vulnerability in StoreBackup as described in USN-4508-1, applicable to several LTS versions.. StoreBackup Security, Ubuntu Update, Denial of Service, Exploit Fix. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Sep 16, 2020 Critical Ubuntu
197

Debian 8 Jessie DLA-2095-1 Critical: StoreBackup Symlink Attack

storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. . Package : storebackup Version : 3.2.1-1+deb8u1 CVE ID : CVE-2020-7040 Debian Bug : 949393 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. Local users can also create a plain file named /tmp/storeBackup.lock to block use of storeBackup until an admin manually deletes that file. For Debian 8 "Jessie", this problem has been fixed in version 3.2.1-1+deb8u1. We recommend that you upgrade your storebackup packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . BackupSecure Patch Release: Mitigating Symlink Vulnerabilities in Ubuntu LTS to strengthen system integrity and dependability.. Debian Security, storebackup Update, symlink Attacks, Linux Privileges. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 05, 2020 Critical Debian LTS
87

Debian 3.1 DSA 1022-1: Critical Storebackup Local Issues Resolved

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1022-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff April 4th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : storebackup Vulnerability : several Problem-Type : local Debian-specific: no CVE ID : CVE-2005-3146 CVE-2005-3147 CVE-2005-3148 Debian Bug : 332434 Several vulnerabilities have been discovered in the backup utility storebackup. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-3146 Storebackup creates a temporary file predictably, which can be exploited to overwrite arbitrary files on the system with a symlink attack. CVE-2005-3147 The backup root directory is created with world-readable permissions, which may leak sensitive data. CVE-2005-3148 The user and group rights of symlinks are set incorrectly when making or restoring a backup, which may leak sensitive data. The old stable distribution (woody) doesn't contain storebackup packages. For the stable distribution (sarge) these problems have been fixed in version 1.18.4-2sarge1. For the unstable distribution (sid) these problems have been fixed in version 1.19-2. We recommend that you upgrade your storebackup package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 aliassarge - -------------------------------- Source archives: Size/MD5 checksum: 598 94af97325a97695b0b64fd8df238b758 Size/MD5 checksum: 5963 b85a68d72314a983f898f405afa1ca95 Size/MD5 checksum: 120135 8ae9e30dfa5918ee420dc6e6ac2e184c Architecture independent components: Size/MD5 checksum: 120128 1b558238c057ed58032d16f8c51f4d52 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Multiple security flaws resolved in Debian storebackup software to enhance data integrity and adherence to security management protocols.. Debian Storebackup Update, Backup Tool Security, System Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 03, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here