Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 6 articles for you...
197

Debian 9: DLA-2748-1 Critical: Tnef Mail Attachment Risk

An issue has been found in tnef, a tool to unpack MIME application/ms-tnef attachments. Using emails with a crafted winmail.dat application/ms-tnef attachment . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2748-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz August 23, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : tnef Version : 1.4.12-1.2+deb9u1 CVE ID : CVE-2019-18849 An issue has been found in tnef, a tool to unpack MIME application/ms-tnef attachments. Using emails with a crafted winmail.dat application/ms-tnef attachment might allow an attacker to change .ssh/authorized_keys. For Debian 9 stretch, this problem has been fixed in version 1.4.12-1.2+deb9u1. We recommend that you upgrade your tnef packages. For the detailed security status of tnef please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/tnef Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance tnef to resolve vulnerabilities linked to malicious email attachments impacting security on Debian LTS platforms.. Debian Security Update,Tnef Application Security,Debian LTS Advisory,Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 23, 2021 Critical Debian LTS
172

Ubuntu 16.04 LTS: USN-4524-1 Critical: TNEF DoS And File Write Issue

TNEF could be made to crash or write arbitrary files to the filesystem.. =========================================================================Ubuntu Security Notice USN-4524-1 September 21, 2020 tnef vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: TNEF could be made to crash or write arbitrary files to the filesystem. Software Description: - tnef: Tool to unpack MIME application/ms-tnef attachments Details: Paul Dreik discovered that TNEF incorrectly handled filenames. If a user were tricked into opening a specially crafted email attachment, an attacker could possibly use this issue to write arbitrary files to the filesystem or cause TNEF crash, resulting in a denial of service. (CVE-2019-18849) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: tnef 1.4.9-1+deb8u4build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4524-1 CVE-2019-18849 Package Information: https://launchpad.net/ubuntu/+source/tnef/1.4.9-1+deb8u4build0.16.04.1 . The recently discovered TNEF weakness permits system crashes or unauthorized file modifications on Ubuntu 16.04 LTS. Ensure you update immediately to protect your system!. tnef vulnerabilities, Ubuntu release, file writing exploit, denial of service issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2020 Critical Ubuntu
203

Mageia: 2019-0367 Moderate: tnef Buffer Over-Read Threat

Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based . MGASA-2019-0367 - Updated tnef packages fix security vulnerability Publication date: 06 Dec 2019 URL: https://advisories.mageia.org/MGASA-2019-0367.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-18849 Updated tnef package fixes security vulnerability: In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup (CVE-2019-18849). References: - https://bugs.mageia.org/show_bug.cgi?id=25785 - https://lists.debian.org/debian-lts-announce/2019/11/msg00035.html - https://www.cve.org/CVERecord?id=CVE-2019-18849 SRPMS: - 7/core/tnef-1.4.18-1.mga7 . The revised tnef software addresses a vulnerability that permitted unauthorized entry through specially designed email files.. Mageia Security Update, tnef Package Update, Email Exploit. . LinuxSecurity.com Team

Calendar%202 Dec 06, 2019 Mageia
89

Fedora 31: tnef Security Advisory FEDORA-2019-815807c020 Attack Risk

tnef release 1.4.18. [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-815807c020 2019-12-05 01:39:12.689184 --------------------------------------------------------------------------------Name : tnef Product : Fedora 31 Version : 1.4.18 Release : 1.fc31 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: tnef release 1.4.18. ==================== Security release to resolve [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 26 2019 David Timms - 1.4.18-1 - Update to release 1.4.18. Fixes CVE-2019-18849 - bug #1771891 - Add global builddolphin to enable -dolphin subpackage when available. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-815807c020' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 31 patch resolves vulnerability in tnef application that enables email exploitation through specially designed messages.. tnef Email Security Update, Fedora Software Release, Exploit Mitigation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2019 Critical Fedora
89

Fedora 30: FEDORA-2019-5f14b810f8 Critical: tnef Email Attack Fix

tnef release 1.4.18. [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-5f14b810f8 2019-12-05 01:09:44.880069 --------------------------------------------------------------------------------Name : tnef Product : Fedora 30 Version : 1.4.18 Release : 1.fc30 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: tnef release 1.4.18. ==================== Security release to resolve [CVE-2019-18849](https://www.cve.org/CVERecord?id=CVE-2019-18849) in which it may be possible to attack via a crafted email message extracted via tnef. --------------------------------------------------------------------------------ChangeLog: * Tue Nov 26 2019 David Timms - 1.4.18-1 - Update to release 1.4.18. Fixes CVE-2019-18849 - bug #1771891 - Add global builddolphin to enable -dolphin subpackage when available. * Sat Jul 27 2019 Fedora Release Engineering - 1.4.17-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1771892 - CVE-2019-18849 tnef: security bypass in .ssh/authorized_keys file via an e-mail message [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1771892 [ 2 ] Bug #1771893 - CVE-2019-18849 tnef: security bypass in.ssh/authorized_keys file via an e-mail message [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1771893 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-5f14b810f8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Security bulletin for Fedora regarding tnef upgrade to mitigate email exploitation threats. Critical for ensuring system stability.. Fedora Update, tnef Security Fix, Email Attack Mitigation, Cybersecurity Notification. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 04, 2019 Critical Fedora
197

Debian 8: DLA-2005-1 Critical: tnef Buffer Over-read Attack

In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based . Package : tnef Version : 1.4.9-1+deb8u4 CVE ID : CVE-2019-18849 Debian Bug : 944851 In tnef, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup. For Debian 8 "Jessie", this problem has been fixed in version 1.4.9-1+deb8u4. We recommend that you upgrade your tnef packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . Package : tnef Version : 1.4.9-1+deb8u4 CVE ID : CVE-2019-18849 Debian Bug : 944851 In tnef, an atta. attacker, write, victim's, ssh/authorized_keys, e-mail. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 29, 2019 Critical Debian LTS
89

Fedora 26: Security Update for Tnef - Critical Integer Underflow

Update to 1.4.15. Fixes CVE-2017-8911. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-c2882ae75b 2017-10-25 21:34:15.278209 --------------------------------------------------------------------------------Name : tnef Product : Fedora 26 Version : 1.4.15 Release : 1.fc26 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: Update to 1.4.15. Fixes CVE-2017-8911 --------------------------------------------------------------------------------References: [ 1 ] Bug #1427435 - CVE-2017-6307 CVE-2017-6308 CVE-2017-6309 CVE-2017-6310 tnef: Multiple vulnerabilities fixed in 1.4.13 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427435 [ 2 ] Bug #1451259 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451259 [ 3 ] Bug #1451258 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tnef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Addresses integer overflow weakness in tnef for Fedora 26, improving email handling protection through version enhancement.. Fedora Security,tnef Update,Integer Underflow,Email Protection,Software Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 25, 2017 Critical Fedora
89

Fedora: 2017-2b28a055f2 moderate: tnef Integer Underflow Fix

Update to 1.4.15. Fixes CVE-2017-8911. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-2b28a055f2 2017-10-25 19:26:45.871846 --------------------------------------------------------------------------------Name : tnef Product : Fedora 25 Version : 1.4.15 Release : 1.fc25 URL : https://github.com/verdammelt/tnef Summary : Extract files from email attachments like WINMAIL.DAT Description : This application provides a way to unpack Microsoft MS-TNEF MIME attachments. It operates like tar in order to unpack files of type "application/ms-tnef", which may have been placed into the MS-TNEF attachment instead of being attached separately. Such files may have attachment names similar to WINMAIL.DAT --------------------------------------------------------------------------------Update Information: Update to 1.4.15. Fixes CVE-2017-8911 --------------------------------------------------------------------------------References: [ 1 ] Bug #1427435 - CVE-2017-6307 CVE-2017-6308 CVE-2017-6309 CVE-2017-6310 tnef: Multiple vulnerabilities fixed in 1.4.13 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1427435 [ 2 ] Bug #1451259 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451259 [ 3 ] Bug #1451258 - CVE-2017-8911 tnef: Integer underflow in unicode_to_utf8 [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1451258 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade tnef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora has released a security patch for the tnef utility, targeting vulnerabilities such as integer overflow. Discover more about this update.. Fedora Security, tnef Update, Integer Underflow Fix, Email Attachment Handling. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 25, 2017 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200