Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 11: DLA-3894-1 moderate: booth invalid HMAC acceptance

Invalid HMAC could have been accepted in the Booth Cluster Ticket Manager. For Debian 11 bullseye, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3894-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk September 24, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : booth Version : 1.0-237-gdd88847-2+deb11u2 CVE ID : CVE-2024-3049 Debian Bug : 1073249 Invalid HMAC could have been accepted in the Booth Cluster Ticket Manager. For Debian 11 bullseye, this problem has been fixed in version 1.0-237-gdd88847-2+deb11u2. We recommend that you upgrade your booth packages. For the detailed security status of booth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/booth Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-5021-1 addresses severe flaw in Libgcrypt's cryptographic functions.. Debian LTS, booth, security updates, cluster ticket manager, HMAC. . LinuxSecurity.com Team

Calendar%202 Sep 24, 2024 Debian LTS
89

Fedora 35: FEDORA-2022-e0a87993b8 moderate: booth service unit fix

Remove Alias directive from booth@.service unit file ---- Security fix for CVE-2022-2553. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-e0a87993b8 2022-10-07 13:13:03.413588 --------------------------------------------------------------------------------Name : booth Product : Fedora 35 Version : 1.0 Release : 251.4.bfb2f92.git.fc35 URL : https://github.com/ClusterLabs/booth Summary : Ticket Manager for Multi-site Clusters Description : Booth manages tickets which authorize cluster sites located in geographically dispersed locations to run resources. It facilitates support of geographically distributed clustering in Pacemaker. --------------------------------------------------------------------------------Update Information: Remove Alias directive from booth@.service unit file ---- Security fix for CVE-2022-2553 --------------------------------------------------------------------------------ChangeLog: * Thu Sep 29 2022 Jan Friesse - 1.0-251.4.bfb2f92.git - Remove Alias directive from booth@.service unit file * Thu Jul 28 2022 Jan Friesse - 1.0-251.3.bfb2f92.git - Fix authfile directive handling in booth config file (fixes CVE-2022-2553) - Add enable-authfile option --------------------------------------------------------------------------------References: [ 1 ] Bug #2109251 - CVE-2022-2553 booth: authfile directive in booth config file is completely ignored. https://bugzilla.redhat.com/show_bug.cgi?id=2109251 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-e0a87993b8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Improvement in booth@.service configuration file addresses CVE-2022-2553, bolstering security on Fedora 35 systems.. booth service unit,Fedora updates,security notifications,CVE-2022-2553,security patches. . LinuxSecurity.com Team

Calendar%202 Oct 07, 2022 Fedora
87

Debian 11: DSA-5194-1 Critical: Booth Intra-Node Security Issue

It was discovered that Booth, a cluster ticket manager, didn't correctly restrict intra-node communication when configuring the "authfile" configuration directive. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5194-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff July 29, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : booth CVE ID : CVE-2022-2553 It was discovered that Booth, a cluster ticket manager, didn't correctly restrict intra-node communication when configuring the "authfile" configuration directive. For the oldstable distribution (buster), this problem has been fixed in version 1.0-162-g27f917f-2+deb10u1. For the stable distribution (bullseye), this problem has been fixed in version 1.0-237-gdd88847-2+deb11u1. We recommend that you upgrade your booth packages. For the detailed security status of booth please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/booth Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhancing safety in your Debian setup for intra-node communication concerns in booth is crucial. Follow the corrective measures in DSA-5194-1 for system integrity. Booth Security Update, Debian Advisory DSA-5194-1, Intra-Node Security, Ticket Manager Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 29, 2022 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200