Multiple vulnerabilities were discovered in Gentoo's systemd unit for FreeRADIUS which could lead to root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202101-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: FreeRADIUS: Root privilege escalation Date: January 26, 2021 Bugs: #630910 ID: 202101-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities were discovered in Gentoo's systemd unit for FreeRADIUS which could lead to root privilege escalation. Background ========= FreeRADIUS is a modular, high performance free RADIUS suite. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dialup/freeradius < 3.0.20-r1 > = 3.0.20-r1 Description ========== It was discovered that Gentoo’s FreeRADIUS systemd unit set permissions on an unsafe directory on start. Impact ===== A local attacker could escalate privileges. Workaround ========= There is no known workaround at this time. Resolution ========= All FreeRADIUS users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =net-dialup/freeradius-3.0.20-r1" References ========= Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202101-27 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns shouldbe addressed to
Security fix for CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395 CVE-2017-7396. Add systemd unit file for Xvnc.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-a66ca10c22 2017-04-25 12:28:36.811319 --------------------------------------------------------------------------------Name : tigervnc Product : Fedora 24 Version : 1.7.1 Release : 4.fc24 URL : https://tigervnc.org/ Summary : A TigerVNC remote display system Description : Virtual Network Computing (VNC) is a remote display system which allows you to view a computing 'desktop' environment not only on the machine where it is running, but from anywhere on the Internet and from a wide variety of machine architectures. This package contains a client which will allow you to connect to other desktops running a VNC server. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2017-7392 CVE-2017-7393 CVE-2017-7394 CVE-2017-7395 CVE-2017-7396. Add systemd unit file for Xvnc. --------------------------------------------------------------------------------References: [ 1 ] Bug #1438703 - CVE-2017-7396 tigervnc: SecurityServer and ClientServer memory leaks https://bugzilla.redhat.com/show_bug.cgi?id=1438703 [ 2 ] Bug #1438701 - CVE-2017-7395 tigervnc: Integer overflow in SMsgReader::readClientCutText https://bugzilla.redhat.com/show_bug.cgi?id=1438701 [ 3 ] Bug #1438700 - CVE-2017-7394 tigervnc: Server crash via long usernames https://bugzilla.redhat.com/show_bug.cgi?id=1438700 [ 4 ] Bug #1438697 - CVE-2017-7393 tigervnc: Double free via crafted fences https://bugzilla.redhat.com/show_bug.cgi?id=1438697 [ 5 ] Bug #1438694 - CVE-2017-7392 tigervnc: SSecurityVeNCrypt memory leak https://bugzilla.redhat.com/show_bug.cgi?id=1438694 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tigervnc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.