Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 25: FEDORA-2017-85eb9f7a36 Critical: Supervisor Command Injection

Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-85eb9f7a36 2017-08-07 13:52:29.113257 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 25 Version : 3.2.4 Release : 1.fc25 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent update for Fedora 25 supervisor addressing command injection flaw CVE-2017-11610. Patch immediately!. Fedora Security Update, Supervisor Control, Command Injection Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 07, 2017 Critical Fedora
89

Fedora 24: FEDORA-2017-713430fb15 Critical: Command Injection in Supervisor

Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-713430fb15 2017-08-07 13:50:50.150551 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 24 Version : 3.1.4 Release : 1.fc24 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Significant Fedora 24 revision for administrator addresses a severe command execution vulnerability recognized as CVE-2017-11610.. Fedora 24 Security Update, Supervisor Command Injection, CVE-2017-11610. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Aug 07, 2017 Critical Fedora
89

Fedora 26: Critical Security Update for Supervisor Command Injection

Security fix for CVE-2017-11610. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-307eab89e1 2017-08-07 13:52:27.804029 --------------------------------------------------------------------------------Name : supervisor Product : Fedora 26 Version : 3.3.3 Release : 1.fc26 URL : https://supervisord.org/ Summary : A System for Allowing the Control of Process State on UNIX Description : The supervisor is a client/server system that allows its users to control a number of processes on UNIX-like operating systems. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-11610 --------------------------------------------------------------------------------References: [ 1 ] Bug #1476144 - CVE-2017-11610 supervisor: Command injection via malicious XML-RPC request [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1476144 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade supervisor' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 patch resolves a significant vulnerability in the supervisor component, bolstering protection for systems against potential attacks.. Fedora 26 Supervisor Update, Command Injection Fix, Process Control Security, MaliciousXML-RPC Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 07, 2017 Critical Fedora
197

Debian 7: DLA-1047-1 Critical: Supervisor Arbitrary Command Execution

A vulnerability has been found in supervisor, a system for controlling process state, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. . Hash: SHA512 Package : supervisor Version : 3.0a8-1.1+deb7u2 CVE ID : CVE-2017-11610 Debian Bug : 870187 A vulnerability has been found in supervisor, a system for controlling process state, where an authenticated client can send a malicious XML-RPC request to supervisord that will run arbitrary shell commands on the server. The commands will be run as the same user as supervisord. For Debian 7 "Wheezy", these problems have been fixed in version 3.0a8-1.1+deb7u2. We recommend that you upgrade your supervisor packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An exploit in supervisord permits unauthorized command execution through crafted XML-RPC requests on Debian 7.. supervisor security, debian update, arbitrary command execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 31, 2017 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Is continuous patching actually viable?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/156-is-continuous-patching-actually-viable?task=poll.vote&format=json
156
radio
0
[{"id":503,"title":"Delayed updates invite catastrophic breaches.","votes":1,"type":"x","order":1,"pct":50,"resources":[]},{"id":504,"title":"Automated fixes break production environments.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":505,"title":"Manual approvals cannot keep pace.","votes":0,"type":"x","order":3,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200