Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: 2024:150-1 Medium: bci/bci-sle15-application Security Enhancement

The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update:. SUSE Container Update Advisory: bci/bci-sle15-kernel-module-devel ----------------------------------------------------------------- Container Advisory ID : SUSE-CU-2024:146-1 Container Tags : bci/bci-sle15-kernel-module-devel:15.5 , bci/bci-sle15-kernel-module-devel:15.5.3.6 , bci/bci-sle15-kernel-module-devel:latest Container Release : 3.6 Severity : low Type : security References : 1217969 CVE-2023-39804 ----------------------------------------------------------------- The container bci/bci-sle15-kernel-module-devel was updated. The following patches have been included in this update: ----------------------------------------------------------------- Advisory ID: SUSE-SU-2024:70-1 Released: Tue Jan 9 18:29:39 2024 Summary: Security update for tar Type: security Severity: low References: 1217969,CVE-2023-39804 This update for tar fixes the following issues: - CVE-2023-39804: Fixed extension attributes in PAX archives incorrect hanling (bsc#1217969). The following package changes have been done: - tar-1.34-150000.3.34.1 updated - container:sles15-image-15.0.0-36.5.71 updated . Keep informed about the most recent security notifications for SUSE Container, specifically for bci/bci-sle15-kernel-module-devel, and explore their remediation strategies.. SUSE Container, bci/bci-sle15-kernel-module-devel, low severity update. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jan 10, 2024 Low SuSE
172

Ubuntu 7.10 USN-709-1 Critical: Tar Buffer Overflow Threat

Dmitry V. Levin discovered a buffer overflow in tar. If a user or automatedsystem were tricked into opening a specially crafted tar file, an attackercould crash tar or possibly execute arbitrary code with the privileges of theuser invoking the program. [More...]. ==========================================================Ubuntu Security Notice USN-709-1 January 15, 2009 tar vulnerability CVE-2007-4476 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: tar 1.15.1-2ubuntu2.3 Ubuntu 7.10: tar 1.18-2ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Dmitry V. Levin discovered a buffer overflow in tar. If a user or automated system were tricked into opening a specially crafted tar file, an attacker could crash tar or possibly execute arbitrary code with the privileges of the user invoking the program. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 31101 bd2a94f0578416e4ad7ed5d8e0eaab15 Size/MD5: 582 6395ad2276cbfb04535c8e9a760184c2 Size/MD5: 2204322 d87021366fe6488e9dc398fcdcb6ed7d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 532580 8bf4846b9b2108f42886784c794c01f6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 519940 3ddc9cb9cf77bf95d711eef4b3f7851c powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 534426 0385fa88092124b117af7cd37bc2c588 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 524246 8b1ad8790f52ca7282a76a96b6b134cc Updated packages for Ubuntu 7.10: Source archives: Size/MD5: 47111588df897391765ca5523e6ab611ed32b Size/MD5: 679 bc6cbaab0f63ef2289c49344ed88d6df Size/MD5: 2381295 c5fc59099be4419d18f59fe8a7946017 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 384512 b9f347f8bb3f1209a2f2ba6b69a06eb6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 339818 611afdfeb25440e65e3d722947408f5c lpia architecture (Low Power Intel Architecture): Size/MD5: 339942 1c900b255c7fb9d2f8f7b69a0d737d26 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 359094 b790c9aa4e73dab09ca6892456970b71 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 342586 02aa39721b80469a26062f4c86e93b08 . The tar buffer overflow vulnerability in Ubuntu introduces notable security risks, enabling arbitrary code execution and potential privilege escalation if unpatched.. Tar Exploit, Ubuntu 7.10 Security, Buffer Overflow Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 15, 2009 Critical Ubuntu
87

Debian: DSA 377-1 Moderate: Wu-ftpd Remote Execution Risk

wu-ftpd, an FTP server, implements a feature whereby multiple filescan be fetched in the form of a dynamically constructed archive file,such as a tar archive. This feature may be abused to execute arbitrary programs with the privileges of the wu-ftpd process.. -------------------------------------------------------------------------- Debian Security Advisory DSA 377-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman September 4th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : wu-ftpd Vulnerability : insecure program execution Problem-Type : remote Debian-specific: no CVE Ids : CVE-1999-0997 wu-ftpd, an FTP server, implements a feature whereby multiple files can be fetched in the form of a dynamically constructed archive file, such as a tar archive. The names of the files to be included are passed as command line arguments to tar, without protection against them being interpreted as command-line options. GNU tar supports several command line options which can be abused, by means of this vulnerability, to execute arbitrary programs with the privileges of the wu-ftpd process. Georgi Guninski pointed out that this vulnerability exists in Debian woody. For the stable distribution (woody) this problem has been fixed in version 2.6.2-3woody2. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you update your wu-ftpd package. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. DebianGNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 607 b557af23920403ce4be64670a873a1dd Size/MD5 checksum: 100389 c2e481768ed3a0d97a110bc3cd4aefa2 Size/MD5 checksum: 354784 b3c271f02aadf663b8811d1bff9da3f6 Architecture independent components: Size/MD5 checksum: 3474 ae0a727f52cf8f1488222ce2b414a29a Alpha architecture: Size/MD5 checksum: 291710 d9725bc2a271f151fc42605edd6394c6 ARM architecture: Size/MD5 checksum: 265366 d435ee1977a93705462528b23b8c9550 Intel IA-32 architecture: Size/MD5 checksum: 257060 ed807ebe3275f76a13eed4fbb2d8a7fa Intel IA-64 architecture: Size/MD5 checksum: 321256 beaa9b061436052fddf3f47e2932360a HP Precision architecture: Size/MD5 checksum: 275896 c1bea3e7f0cdbab6c7240d5b08b4b9d1 Motorola 680x0 architecture: Size/MD5 checksum: 249368 32f06b3bbe19265f749670950691c7ff Big endian MIPS architecture: Size/MD5 checksum: 272978 1ec11e5a9b53925b02fb7cfbbc3df56b Little endian MIPS architecture: Size/MD5 checksum: 273058 37140e512eaa62cfa0b99b9983e89b6f PowerPC architecture: Size/MD5 checksum: 268354 4da902291bc8bb6c5c652dfd9f7ba729 IBM S/390 architecture: Size/MD5 checksum: 263100 a89f0be201d65cff953bc496a6391af4 Sun Sparc architecture: Size/MD5 checksum: 270448 088bb0a66ee5b74ec59baff506a2be2a These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages .-------------------------------------------------------------------------- Debian Security Advisory . wu-ftpd, server, implements, feature, whereby, filescan, fetched. . LinuxSecurity.com Team

Calendar%202 Sep 05, 2003 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200