Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian 4.0 etch: DSA-1639-1 Critical: Twiki Remote Command Execution

It was discovered that twiki, a web based collaboration platform, didn't properly sanitize the image parameter in its configuration script. This could allow remote users to execute arbitrary commands upon the system, or read any files which were readable by the webserver user.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1639-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp September 19, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : twiki Vulnerability : command execution Problem type : remote Debian-specific: no CVE Id(s) : CVE-2008-3195 Debian Bug : 499534 It was discovered that twiki, a web based collaboration platform, didn't properly sanitize the image parameter in its configuration script. This could allow remote users to execute arbitrary commands upon the system, or read any files which were readable by the webserver user. For the stable distribution (etch), this problem has been fixed in version 1:4.0.5-9.1etch1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your twiki package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 657 402a4ba19643a0a537c9f790bd03c9d0 Size/MD5 checksum: 4264148 d984b90886c12601b76f51419bb5352b Size/MD5checksum: 40238 265511661493e751ffce5ba2b00c1555 Architecture independent packages: Size/MD5 checksum: 4254028 cd6524136eca86aefb207cc86abce619 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-1639-1 http://www.debian.org/security/ Steve Kemp September 19, 2008 ht. twiki, based, collaboration, platform, didn', properly, sanitize, image. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 19, 2008 Critical Debian
91

Gentoo: GLSA-200411-33 High: TWiki Command Execution Risk

A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: TWiki: Arbitrary command execution Date: November 24, 2004 Bugs: #71035 ID: 200411-33 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A bug in the TWiki search function allows an attacker to execute arbitrary commands with the permissions of the user running TWiki. Background ========= TWiki is a Web-based groupware tool based around the concept of wiki pages that can be edited by anybody with a Web browser. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/twiki < 20040902 > = 20040902 Description ========== The TWiki search function, which uses a shell command executed via the Perl backtick operator, does not properly escape shell metacharactersin the user-provided search string. Impact ===== An attacker can insert malicious commands into a search request, allowing the execution of arbitrary commands with the privileges of the user running TWiki (usually the Web server user). Workaround ========= There is no known workaround at this time. Resolution ========= All TWiki users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/twiki-20040902" References ========= [ 1 ] TWiki Security Alert [ 2 ] CAN-2004-1037 https://www.cve.org/CVERecord?id=CAN-2004-1037 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200411-33 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . TWiki administrators are urged to perform upgrades in light of a critical vulnerability that enables unauthorized command execution. Prompt intervention is essential.. TWiki Security Advisory,Gentoo Security Update,Command Execution Flaw,TWiki Upgrade,Web Application Issues. . LinuxSecurity.com Team

Calendar 2 Nov 24, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here