Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 9 articles for you...
203

Mageia 8 MGASA-2022-0292 Moderate: Teeworlds Code Execution Threat

Code execution via malicious map file (CVE-2021-43518) References: - https://bugs.mageia.org/show_bug.cgi?id=30717 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/JIYZ7EVY6NZBM7FQF6GVUARYO6MKSEAT/ . MGASA-2022-0292 - Updated teeworlds packages fix security vulnerability Publication date: 20 Aug 2022 URL: https://advisories.mageia.org/MGASA-2022-0292.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-43518 Code execution via malicious map file (CVE-2021-43518) References: - https://bugs.mageia.org/show_bug.cgi?id=30717 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/JIYZ7EVY6NZBM7FQF6GVUARYO6MKSEAT/ - https://www.cve.org/CVERecord?id=CVE-2021-43518 SRPMS: - 8/core/teeworlds-0.7.5-1.1.mga8 . Mageia 2022-0293 rolls out teeworlds update to address remote code execution risk from compromised map files. In-depth information accessible.. Code Execution, Mageia Security, Teeworlds Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 20, 2022 Important Mageia
89

Fedora 36 Teeworlds Critical Advisory: Fix For Malicious Code Risk

Fix for CVE-2021-43518.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-f281321e55 2022-08-06 01:52:03.199283 --------------------------------------------------------------------------------Name : teeworlds Product : Fedora 36 Version : 0.7.5 Release : 10.fc36 URL : https://www.teeworlds.com/ Summary : Online multi-player platform 2D shooter Description : The game features cartoon-themed graphics and physics, and relies heavily on classic shooter weaponry and gameplay. The controls are heavily inspired by the FPS genre of computer games. --------------------------------------------------------------------------------Update Information: Fix for CVE-2021-43518. --------------------------------------------------------------------------------ChangeLog: * Thu Jul 28 2022 Gwyn Ciesla - 0.7.5-10 - Patch for CVE-2021-43518 * Sat Jul 23 2022 Fedora Release Engineering - 0.7.5-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #2035359 - CVE-2021-43518 teeworlds: code execution via malicious map file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2035359 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-f281321e55' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 36 introduces Teeworlds 0.7.5 update, mitigating code execution vulnerabilities linked to harmful map files. Apply the update promptly.. Teeworlds Update,Fedora Security,Malware Protection,Online Game Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 05, 2022 Critical Fedora
172

Ubuntu 20.04: USN-4553-1 Critical: Teeworlds Remote Crash

Teeworlds could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4553-1 September 28, 2020 teeworlds vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Teeworlds could be made to crash if it received specially crafted network traffic. Software Description: - teeworlds: online multi-player platform 2D shooter Details: It was discovered that Teeworlds server did not properly handler certain network traffic. A remote, unauthenticated attacker could use this vulnerability to cause Teeworlds server to crash. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: teeworlds-server 0.7.2-5ubuntu1.1 In general, a standard system update will make all the necessary changes. References: CVE-2020-12066 Package Information: https://launchpad.net/ubuntu/+source/teeworlds/0.7.2-5ubuntu1.1 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . Teeworlds on Ubuntu 22.04 LTS exposes risk of remote failure through malicious packet data. Immediate patch advised.. teeworlds vulnerability, Ubuntu 20.04 LTS, network exploit, server crash. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 28, 2020 Critical Ubuntu
87

Ubuntu: USN-4763-1 Moderate: Teeworlds Service Disruption

It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4763-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff September 14, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : teeworlds CVE ID : CVE-2020-12066 It was discovered that insufficient sanitising of received network packets in the game server of Teeworlds, an online multi-player platform 2D shooter, could result in denial of service. For the stable distribution (buster), this problem has been fixed in version 0.7.2-5+deb10u1. We recommend that you upgrade your teeworlds packages. For the detailed security status of teeworlds please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/teeworlds Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Inadequate validation of incoming network data in Teeworlds poses risks for denial-of-service attacks. It's crucial to update Teeworlds to enhance its security measures.. Teeworlds Security Update, Debian Advisory, Denial Of Service. . LinuxSecurity.com Team

Calendar%202 Sep 14, 2020 Debian
89

Fedora 30: 2020-0d6b80678a Critical Teeworlds Remote Shutdown Issue

0.7.5. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-0d6b80678a 2020-05-08 03:31:40.231699 --------------------------------------------------------------------------------Name : teeworlds Product : Fedora 30 Version : 0.7.5 Release : 1.fc30 URL : https://www.teeworlds.com/ Summary : Online multi-player platform 2D shooter Description : The game features cartoon-themed graphics and physics, and relies heavily on classic shooter weaponry and gameplay. The controls are heavily inspired by the FPS genre of computer games. --------------------------------------------------------------------------------Update Information: 0.7.5 --------------------------------------------------------------------------------ChangeLog: * Mon Apr 20 2020 Gwyn Ciesla - 0.7.5-1 - 0.7.5 * Fri Jan 31 2020 Fedora Release Engineering - 0.7.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Mon Dec 30 2019 Gwyn Ciesla - 0.7.4-2 - bump EVR for koji error * Mon Dec 30 2019 Gwyn Ciesla - 0.7.4-1 - 0.7.4 * Fri Aug 9 2019 Gwyn Ciesla - 0.7.3.1-5 - Path fix. * Fri Aug 9 2019 Gwyn Ciesla - 0.7.3.1-4 - Put a copy of icon in a place flatpak will use. * Sat Jul 27 2019 Fedora Release Engineering - 0.7.3.1-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1829193 - CVE-2019-20787 teeworlds: there's an integer overflow when computing a tilemap size [fedora-30] https://bugzilla.redhat.com/show_bug.cgi?id=1829193 [ 2 ] Bug #1829537 - CVE-2020-12066 teeworlds: allows an attacker force the server to repetitively shut down [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1829537 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c'dnf upgrade --advisory FEDORA-2020-0d6b80678a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest Teeworlds update for Fedora 30, version 0.7.5, resolves a significant remote shutdown vulnerability. You can install it using the DNF package manager.. Fedora Security Update, Teeworlds Release, Online Shooter Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 07, 2020 Critical Fedora
203

Mageia: 2020-0191 Moderate: Teeworlds Integer Overflow and DoS Issue

Updated teeworlds packages fix security vulnerabilities Teeworlds before 0.7.4 is subject to an integer overflow when computing a tilemap size (CVE-2019-20787). . MGASA-2020-0191 - Updated teeworlds packages fix security vulnerabilities Publication date: 05 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0191.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-20787, CVE-2020-12066 Updated teeworlds packages fix security vulnerabilities Teeworlds before 0.7.4 is subject to an integer overflow when computing a tilemap size (CVE-2019-20787). Teeworlds before 0.7.5 is subject to a denial of service against the server (CVE-2020-12066). This update fixes both vulnerabilities by updating from Teeworlds 0.7.3.1 to 0.7.5, including additional features and bug fixes (see the referenced changelogs for details). References: - https://bugs.mageia.org/show_bug.cgi?id=26553 - - https://www.teeworlds.com/?page=journal&id=13357 - https://www.teeworlds.com/forum/viewtopic.php?id=14784 - https://www.cve.org/CVERecord?id=CVE-2019-20787 - https://www.cve.org/CVERecord?id=CVE-2020-12066 SRPMS: - 7/core/teeworlds-0.7.5-1.mga7 . Revised teeworlds distributions tackle integer overflows and DoS vulnerabilities, enhancing safety for Mageia clients.. teeworlds updates, Mageia vulnerabilities, integer overflow, denial of service. . LinuxSecurity.com Team

Calendar%202 May 05, 2020 Mageia
202

openSUSE: 2020:0563-1 Moderate: Teeworlds Denial Of Service Fix

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for teeworlds ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0563-1 Rating: moderate References: #1170252 #1170253 Cross-References: CVE-2019-20787 CVE-2020-12066 Affected Products: openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for teeworlds to version 0.7.5 fixes the following issues: Security issues fixed: - CVE-2020-12066: Fixed a denial of service against the server (boo#1170252) - CVE-2019-20787: Fixed an integer overflow when computing a tilemap size (boo#1170253) Non-security issues fixed: - multiple smaller bug fixes and improvements. This update was imported from the openSUSE:Leap:15.1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2020-563=1 Package List: - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): teeworlds-0.7.5-bp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-20787.html https://www.suse.com/security/cve/CVE-2020-12066.html https://bugzilla.suse.com/1170252 https://bugzilla.suse.com/1170253 -- . This patch mitigates various security flaws in teeworlds for openSUSE, featuring essential repairs to avert server interruptions.. openSUSE Update, teeworlds Security Fix, Denial Of Service, Integer Overflow. . LinuxSecurity.com Team

Calendar%202 Apr 29, 2020 OpenSUSE
202

openSUSE: 2020:0557-1 Moderate: teeworlds Denial of Service and Overflow

An update that fixes two vulnerabilities is now available.. openSUSE Security Update: Security update for teeworlds ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:0557-1 Rating: moderate References: #1170252 #1170253 Cross-References: CVE-2019-20787 CVE-2020-12066 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for teeworlds to version 0.7.5 fixes the following issues: Security issues fixed: - CVE-2020-12066: Fixed a denial of service against the server (boo#1170252) - CVE-2019-20787: Fixed an integer overflow when computing a tilemap size (boo#1170253) Non-security issues fixed: - multiple smaller bug fixes and improvements. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-557=1 Package List: - openSUSE Leap 15.1 (x86_64): teeworlds-0.7.5-lp151.2.6.1 teeworlds-debuginfo-0.7.5-lp151.2.6.1 teeworlds-debugsource-0.7.5-lp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-20787.html https://www.suse.com/security/cve/CVE-2020-12066.html https://bugzilla.suse.com/1170252 https://bugzilla.suse.com/1170253 -- . An openSUSE Security Update addresses two vulnerabilities identified in teeworlds: a Denial of Service (DoS) concern and a potential integer overflow flaw.. openSUSE Security, teeworlds Update, Moderate Security Fix, Software Patch. . LinuxSecurity.com Team

Calendar%202 Apr 27, 2020 OpenSUSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200