Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 15 articles for you...
172

Ubuntu 24.04 Sympa Important Path Traversal Vuln 2024-55919

Sympa could allow unintended access to network services.. ========================================================================== Ubuntu Security Notice USN-8552-1 July 15, 2026 sympa vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Sympa could allow unintended access to network services. Software Description: - sympa: mailing list management software Details: It was discovered that Sympa did not properly validate input on the generic SSO login. A remote attacker could possibly use this issue to perform a path traversal attack and gain unintended access. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS sympa 6.2.70~dfsg-2+deb12u1build0.24.04.1 Ubuntu 22.04 LTS sympa 6.2.66~dfsg-2ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS sympa 6.2.40~dfsg-4ubuntu0.20.04.1~esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS sympa 6.2.24~dfsg-1ubuntu0.1~esm2 Available with Ubuntu Pro Ubuntu 16.04 LTS sympa 6.1.24~dfsg-1ubuntu0.1~esm1 Available with Ubuntu Pro After a standard system update you need to restart sympa to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8552-1 CVE-2024-55919 Package Information: https://launchpad.net/ubuntu/+source/sympa/6.2.70~dfsg-2+deb12u1build0.24.04.1 . Unattended access to network services via Sympa on Ubuntu can be corrected by updating your system to the latest package versions.. Ubuntu security advisory, Sympa patch, network services access, remote accessvulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Ubuntu
197

Debian 12 sympa Critical Authentication Bypass Vulnerability DLA-4668-1

A flaw was found in Sympa’s web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. For Debian 12 bookworm, this problem has been fixed in version 6.2.70~dfsg-2+deb12u1.. Debian LTS Advisory DLA-4668-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta July 04, 2026 https://wiki.debian.org/LTS Package : sympa Version : 6.2.70~dfsg-2+deb12u1 CVE ID : CVE-2024-55919 Debian Bug : 1090188 A flaw was found in Sympa’s web interface, a modern mailing list manager. An attacker may bypass authentication by using an arbitrary e-mail address when the generic SSO loging feature was enabled. For Debian 12 bookworm, this problem has been fixed in version 6.2.70~dfsg-2+deb12u1. We recommend that you upgrade your sympa packages. For the detailed security status of sympa please refer to its security tracker page at: https://security-tracker.debian.org/tracker/sympa Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A flaw in Sympa's web interface allows attackers to bypass authentication in Debian LTS. Update to version 6.2.70 to fix.. Debian LTS Security, Sympa Update, Authentication Bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 04, 2026 Critical Debian LTS
89

Fedora 41: FEDORA-2024-88ad2bee84 critical: sympa remote code execution

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-88ad2bee84 2024-12-26 01:20:11.418870+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 41 Version : 6.2.74 Release : 1.fc41 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-88ad2bee84' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . The sympa update for Fedora 41 resolves critical issues like CVE-2024-55919. Find the full changelog and installation details.. Fedora 41, sympa updates, mailing list security, open source security, system update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 26, 2024 Critical Fedora
89

Fedora 40: FEDORA-2024-14c006b8bb critical: sympa denial of service

Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-14c006b8bb 2024-12-25 01:38:03.924476+00:00 -------------------------------------------------------------------------------- Name : sympa Product : Fedora 40 Version : 6.2.74 Release : 1.fc40 URL : http://www.sympa.org Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. -------------------------------------------------------------------------------- Update Information: Update to 6.2.74, fix for CVE-2024-55919 Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 16 2024 Xavier Bachelot - 6.2.74-1 - Update to 6.2.74, fix for CVE-2024-55919 - Full changelog: https://github.com/sympa-community/sympa/releases/tag/6.2.74 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-14c006b8bb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 40 users should promptly update sympa software for crucial security updates pertaining to CVE-2024-55919. Use the command: dnf update sympa to secure your system. Fedora Updates, sympa Security, Mailing List Management, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 25, 2024 Critical Fedora
203

Mageia 9: 2024-0052 Critical: Sympa CVE-2021-32850 Security Patch

Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: . MGASA-2024-0052 - Updated sympa packages fix security vulnerabilities Publication date: 29 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0052.html Type: security Affected Mageia releases: 9 CVE: CVE-2021-32850 Sympa 6.2.72 fixes many bugs, including the security one related in CVE-2021-32850 It is required to manually run sympa upgrade after get this update References: - https://bugs.mageia.org/show_bug.cgi?id=32896 - https://github.com/sympa-community/sympa/releases/tag/6.2.72 - https://www.cve.org/CVERecord?id=CVE-2021-32850 - https://www.cve.org/CVERecord?id=CVE-2021-32850 SRPMS: - 9/core/sympa-6.2.72-4.mga9 . Mageia enhances Sympa 6.2.72 for security vulnerabilities. A manual execution is necessary post-update. Essential patches implemented.. Mageia Security Update, Sympa Bug Fix, Mageia Advisory, Sympa Security, Open Source Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 29, 2024 Critical Mageia
89

Fedora 38: FEDORA-2023-271b912b2b Moderate: Sympa XSS Issue

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-271b912b2b 2023-06-11 02:01:36.946071 --------------------------------------------------------------------------------Name : sympa Product : Fedora 38 Version : 6.2.72 Release : 2.fc38 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-271b912b2b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Ubuntu 22.04 revision with nginx 1.22.1 addresses SQL injection vulnerabilities, improving safety and performance.. Fedora Security Advisory, Sympa Update, Cross-Site Scripting Fix. . LinuxSecurity.com Team

Calendar%202 Jun 11, 2023 Fedora
89

Fedora 37: FEDORA-2023-419ca55dd3 Critical: sympa XSS Security Fix

Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-419ca55dd3 2023-06-11 01:58:02.674345 --------------------------------------------------------------------------------Name : sympa Product : Fedora 37 Version : 6.2.72 Release : 2.fc37 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to sympa 6.2.72 Fixes CVE-2021-32850 For details, see: https://github.com/sympa-community/sympa/releases/tag/6.2.72 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 1 2023 Xavier Bachelot 6.2.72-1 - Update to 6.2.72 (fixes CVE-2021-4243) - Convert License: to SPDX * Sat Jan 21 2023 Fedora Release Engineering - 6.2.70-2.1 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2156473 - CVE-2021-4243 sympa: jquery-minicolors: potential XSS when using untrusted code for swatch names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2156473 [ 2 ] Bug #2171951 - CVE-2021-32850 sympa: jquery-minicolors: cross-site scripting when handling untrusted color names [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2171951 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-419ca55dd3' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Patch addressing CVE-2021-32850 in sympa version 6.2.72 has been released for Fedora 37. Implement this update to enhance your system's security.. Fedora Security Update, Sympa Mailing List, XSS Threat Mitigation, Mailing List Manager. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 11, 2023 Critical Fedora
89

Fedora 33: FEDORA-2021-11cb6626e2 Critical: Remote Access in Sympa

Update to 6.2.60 Fixes CVE-2020-29668. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-11cb6626e2 2021-01-13 01:58:21.870854 --------------------------------------------------------------------------------Name : sympa Product : Fedora 33 Version : 6.2.60 Release : 1.fc33 URL : https://www.sympa.org/ Summary : Powerful multilingual List Manager Description : Sympa is scalable and highly customizable mailing list manager. It can cope with big lists (200,000 subscribers) and comes with a complete (user and admin) Web interface. It is internationalized, and supports the us, fr, de, es, it, fi, and chinese locales. A scripting language allows you to extend the behavior of commands. Sympa can be linked to an LDAP directory or an RDBMS to create dynamic mailing lists. Sympa provides S/MIME-based authentication and encryption. --------------------------------------------------------------------------------Update Information: Update to 6.2.60 Fixes CVE-2020-29668 --------------------------------------------------------------------------------ChangeLog: * Mon Jan 4 2021 Xavier Bachelot 6.2.60-1 - Update to 6.2.60 - Fixes CVE-2020-29668 (RHBZ#1906576) * Sat Nov 7 2020 Xavier Bachelot 6.2.58-2 - Add BR: perl-Test-Net-LDAP - Remove all of EL6 thus sysvinit support --------------------------------------------------------------------------------References: [ 1 ] Bug #1906577 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1906577 [ 2 ] Bug #1906578 - CVE-2020-29668 sympa: allows remote attackers to obtain full SOAP API access via illegal cookie [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1906578 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2021-11cb6626e2' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Important notice regarding sympa for Fedora 33 addressing remote exploit risk CVE-2020-29668. Please update immediately!. Fedora Update,sympa security fix,remote access issue,mailing list manager. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 12, 2021 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200