Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia 7: MGASA-2020-0093 Moderate Update for GNU Patch Vulnerabilities

Updated patch package fixes security vulnerabilities: * In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. (CVE-2019-13636). . MGASA-2020-0093 - Updated patch packages fix security vulnerabilities Publication date: 21 Feb 2020 URL: https://advisories.mageia.org/MGASA-2020-0093.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-13636, CVE-2019-13638, CVE-2018-20969 Updated patch package fixes security vulnerabilities: * In GNU patch through 2.7.6, the following of symlinks is mishandled in certain cases other than input files. (CVE-2019-13636). * A vulnerability was found in GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters (CVE-2019-13638). * A vulnerability was found in do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell metacharacter (CVE-2018-20969). References: - https://bugs.mageia.org/show_bug.cgi?id=25279 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/SVWWGISFWACROJJPVJJL4UBLVZ7LPOLT/ - https://access.redhat.com/errata/RHSA-2019:2798 - https://www.cve.org/CVERecord?id=CVE-2019-13636 - https://www.cve.org/CVERecord?id=CVE-2019-13638 - https://www.cve.org/CVERecord?id=CVE-2018-20969 SRPMS: - 7/core/patch-2.7.6-4.1.mga7 . The latest Mageia update addresses vulnerabilities linked to improper symlink management and potential command injection exploits.. Mageia Patch Security Update, GNU Patch Vulnerabilities, Package Fixes, OS Command Injection. . LinuxSecurity.com Team

Calendar 2 Feb 21, 2020 Mageia
89

Fedora 30: FEDORA-2019-bf800b1c04 Moderate: Kubernetes Symlink Issue

Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-bf800b1c04 2019-06-19 22:44:22.998147 --------------------------------------------------------------------------------Name : kubernetes Product : Fedora 30 Version : 1.13.5 Release : 1.fc30 URL : https://kubernetes.io/docs/home/ Summary : Container cluster management Description : Container cluster management --------------------------------------------------------------------------------Update Information: Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`) --------------------------------------------------------------------------------ChangeLog: * Thu Apr 11 2019 Jan Chaloupka - 1.13.5-1 - Update to v1.13.5 (CVE-2019-1002101 - Mishandling of symlinks allows for arbitrary file write via `kubectl cp`) resolves: #1693884 --------------------------------------------------------------------------------References: [ 1 ] Bug #1693884 - CVE-2019-1002101 kubernetes: Mishandling of symlinks allows for arbitrary file write via `kubectl cp` [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1693884 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-bf800b1c04' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailinglist -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The upgrade to Kubernetes version v1.13.5 fixes a symlink handling vulnerability that could permit unauthorized file writing through kubectl cp in Fedora 30.. Kubernetes Update, Symlink Issue, Fedora Security Patch, File Write Vulnerability, Container Management. . LinuxSecurity.com Team

Calendar 2 Jun 19, 2019 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here