Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 30 Advisory FEDORA-2019-ac709da87f Critical Command Injection

- Security fix for CVE-2019-13636 - Security fix for CVE-2019-13638. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-ac709da87f 2019-08-23 01:26:06.889580 --------------------------------------------------------------------------------Name : patch Product : Fedora 30 Version : 2.7.6 Release : 11.fc30 URL : Summary : Utility for modifying/upgrading files Description : The patch program applies diff files to originals. The diff command is used to compare an original to a changed file. Diff lists the changes made to the file. A person who has the original file can then use the patch command with the diff file to add the changes to their original file (patching the file). Patch should be installed because it is a common way of upgrading applications. --------------------------------------------------------------------------------Update Information: - Security fix for CVE-2019-13636 - Security fix for CVE-2019-13638 --------------------------------------------------------------------------------ChangeLog: * Mon Jul 29 2019 Than Ngo - 2.7.6-11 - fixed #1733917, CVE-2019-13638 patch: OS shell command injection when processing crafted patch files * Wed Jul 24 2019 Than Ngo - 2.7.6-10 - backported patch, abort when cleaning up fails - backported patch, improve support for memory leak detection - backported patch, don't crash when RLIMIT_NOFILE is set to RLIM_INFINITY - backported patch, CVE-2019-13636, don't follow symlinks unless --follow-symlinks is given - backported patch, avoid invalid memory accessin context format diffs - backported patch, fix failed assertion --------------------------------------------------------------------------------References: [ 1 ] Bug #1732781 - CVE-2019-13636 patch: the following of symlinks in inp.c and util.c is mishandled in cases other than input files https://bugzilla.redhat.com/show_bug.cgi?id=1732781 [ 2 ] Bug#1733916 - CVE-2019-13638 patch: OS shell command injection when processing crafted patch files https://bugzilla.redhat.com/show_bug.cgi?id=1733916 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-ac709da87f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Updates released for Fedora 30 tackle critical security vulnerabilities with immediate patches aimed at fortifying the system against potential threats.. Fedora Patch Updates, Command Injection Fix, Critical Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 22, 2019 Critical Fedora
197

Debian 8: DLA-1856-1 Critical: Patch Symlink Handling Improvement

Handling of symlinks in patch, a tool to apply a diff file to an original, was wrong in certain cases. . Package : patch Version : 2.7.5-1+deb8u2 CVE ID : CVE-2019-13636 Handling of symlinks in patch, a tool to apply a diff file to an original, was wrong in certain cases. For Debian 8 "Jessie", this problem has been fixed in version 2.7.5-1+deb8u2. We recommend that you upgrade your patch packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your patch packages in response to symlink management concerns on Debian LTS platforms to maintain security.. Debian, patch, symlink, security update, LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 19, 2019 Critical Debian LTS
172

Ubuntu 13.10: USN-2209-1 Critical Libvirt Symlink Handling Issues

Several security issues were fixed in libvirt.. =========================================================================Ubuntu Security Notice USN-2209-1 May 07, 2014 libvirt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.10 Summary: Several security issues were fixed in libvirt. Software Description: - libvirt: Libvirt virtualization toolkit Details: It was discovered that libvirt incorrectly handled symlinks when using the LXC driver. An attacker could possibly use this issue to delete host devices, create arbitrary nodes, and shutdown or power off the host. (CVE-2013-6456) Marian Krcmarik discovered that libvirt incorrectly handled seamless SPICE migrations. An attacker could possibly use this issue to cause a denial of service. (CVE-2013-7336) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: libvirt-bin 1.1.1-0ubuntu8.11 libvirt0 1.1.1-0ubuntu8.11 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2209-1 CVE-2013-6456, CVE-2013-7336 Package Information: https://launchpad.net/ubuntu/+source/libvirt/1.1.1-0ubuntu8.11 . Address vulnerabilities in libvirt by applying recent updates for Ubuntu 13.10 to bolster defenses against potential threats.. Ubuntu Libvirt Fix, Libvirt Security Issues, Ubuntu Vulnerability Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 07, 2014 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here