Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 44 Pgbouncer Security Update for Untrusted Search Path Issue 2026

Update to 1.25.2.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-d3d959a176 2026-05-18 00:40:49.529053+00:00 -------------------------------------------------------------------------------- Name : pgbouncer Product : Fedora 44 Version : 1.25.2 Release : 1.fc44 URL : https://www.pgbouncer.org Summary : Lightweight connection pooler for PostgreSQL Description : pgbouncer is a lightweight connection pooler for PostgreSQL and uses libevent for low-level socket handling. -------------------------------------------------------------------------------- Update Information: Update to 1.25.2. -------------------------------------------------------------------------------- ChangeLog: * Sat May 9 2026 Simone Caronni - 1.25.2-1 - Update to 1.25.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2419513 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2419513 [ 2 ] Bug #2419514 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2419514 [ 3 ] Bug #2419515 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2419515 [ 4 ] Bug #2419516 - CVE-2025-12819 pgbouncer: Untrusted search path in auth_query connection in PgBouncer [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2419516 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-d3d959a176' at the command line. For more information, refer to the dnf documentation availableat http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Explore the details of the Fedora 44 pgbouncer update addressing the untrusted search path security issue and how to apply it.. pgbouncer connection pooling PostgreSQL Fedora update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 18, 2026 Important Fedora
87

Debian Bullseye: DSA-5395-1 Critical Node.js Untrusted Path Issue

An untrusted search path vulnerability was discovered in Node.js, which could result in unexpected searching or loading ICU data when running with elevated privileges. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5395-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu May 02, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : nodejs CVE ID : CVE-2023-23920 Debian Bug : 1031834 An untrusted search path vulnerability was discovered in Node.js, which could result in unexpected searching or loading ICU data when running with elevated privileges. For the stable distribution (bullseye), this problem has been fixed in version 12.22.12~dfsg-1~deb11u4. We recommend that you upgrade your nodejs packages. For the detailed security status of nodejs please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/nodejs Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your Node.js dependencies to rectify a significant unverified search path vulnerability in Debian Bullseye.. Debian Security, Node.js Update, Untrusted Path Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 02, 2023 Critical Debian
197

Debian LTS: DLA-3027-1 Critical: GIMP Vulnerability in Image Handling

Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory. . - -------------------------------------------------------------------------Debian LTS Advisory DLA-3026-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Andreas Rönnquist May 26, 2022 https://wiki.debian.org/LTS - -------------------------------------------------------------------------Package : filezilla Version : 3.24.0-1+deb9u1 CVE ID : CVE-2019-5429 Debian Bug : Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory. For Debian 9 stretch, this problem has been fixed in version 3.24.0-1+deb9u1. We recommend that you upgrade your filezilla packages. For the detailed security status of filezilla please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/filezilla Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance the security of FileZilla in Debian LTS by updating the packages to resolve the untrusted search path vulnerability, which could potentially lead to unauthorized privilege elevation.. FileZilla Security Update, Debian LTS Advisory, Untrusted Path Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 26, 2022 Critical Debian LTS
91

Gentoo 201009-08 High Severity: python-updater Untrusted Path Issue

An untrusted search path vulnerability in python-updater might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201009-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: python-updater: Untrusted search path Date: September 21, 2010 Bugs: #288361 ID: 201009-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in python-updater might result in the execution of arbitrary code. Background ========= python-updater is a script used to remerge python packages when changing Python version. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-admin/python-updater < 0.7-r1 > = 0.7-r1 Description ========== Robert Buchholz of the Gentoo Security Team reported that python-updater includes the current working directory and subdirectories in the Python module search path (sys.path) before calling "import". Impact ===== A local attacker could entice the root user to run "python-updater" from a directory containing a specially crafted Python module, resulting in the execution of arbitrary code with root privileges. Workaround ========= Do not run "python-updater" from untrusted working directories. Resolution ========= All python-updater users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-admin/python-updater-0.7-r1" Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/201009-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2010 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical severity Gentoo Linux Advisory GLSA 202301-05: python-manager risk linked to unauthorized execution path vulnerabilities.. Gentoo Python-Updater Risk, Untrusted Path Execution, High Severity Advisory. . LinuxSecurity.com Team

Calendar 2 Sep 21, 2010 Gentoo
87

Debian 5.0: DSA-2107-1 Moderate: CouchDB Local Code Execution Risk

Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------ Debian Security Advisory DSA-2107-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Sébastien Delafond Sep 9, 2010 http://www.debian.org/security/faq - - ------------------------------------------------------------------------ Package : couchdb Vulnerability : untrusted search path Problem type : local Debian-specific: no CVE Id : CVE-2010-2953 Debian Bug : 594412 Dan Rosenberg discovered that in couchdb, a distributed, fault-tolerant and schema-free document-oriented database, an insecure library search path is used; a local attacker could execute arbitrary code by first dumping a maliciously crafted shared library in some directory, and then having an administrator run couchdb from this same directory. For the stable distribution (lenny), this problem has been fixed in version 0.8.0-2+lenny1. We recommend that you upgrade your couchdb package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Sourcearchives: Size/MD5 checksum: 1309 2a4a53978b085f1222e75f6106f4ee4d Size/MD5 checksum: 4941 dca93014f06c7521660ebe5e2c2309da Size/MD5 checksum: 560637 0837bce26ed2ab2ce2efd65e86c85bfc alpha architecture (DEC Alpha) Size/MD5 checksum: 277348 1a038436ac64f66a2d9cc23775589b6f amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 277324 cb838abfb1b2a623a9e3457922bf1925 arm architecture (ARM) Size/MD5 checksum: 274602 2e75d6e81dbb7194d1a8f6001d37598b armel architecture (ARM EABI) Size/MD5 checksum: 275548 d5a7b1f7407269243e6c79bdf4ce50ea hppa architecture (HP PA RISC) Size/MD5 checksum: 278728 3bb4c5a7d223fae6b96437ed89575c3f i386 architecture (Intel ia32) Size/MD5 checksum: 275686 f0135ec654b502ecbcbdaa26f65542c4 ia64 architecture (Intel ia64) Size/MD5 checksum: 279586 4725662dc6d62d1d193e58eaa0c00d2f mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 276820 d2dd578ac579d20c719bfcd225265eb8 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 278256 680e03ba3bc11f30c2aa4748b3e76f31 powerpc architecture (PowerPC) Size/MD5 checksum: 281584 40fa5e635d4c0c956cee908f7cf66096 s390 architecture (IBM S/390) Size/MD5 checksum: 276302 cd6162c5068d9f2e25e0f7952d7f5df0 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 275786 5f6d4d4208838527a16cf7ce95d848c7 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu Security Notice regarding PostgreSQL highlights vulnerable modules allowing unauthorized access; users urged to upgrade.. CouchDB Risk, Debian Update, Arbitrary CodeExecution. . LinuxSecurity.com Team

Calendar 2 Sep 09, 2010 Debian
91

Gentoo: GLSA-200911-04 Normal: Dstat Untrusted Path Code Execution

An untrusted search path vulnerability in the dstat might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200911-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: dstat: Untrusted search path Date: November 25, 2009 Bugs: #293497 ID: 200911-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in the dstat might result in the execution of arbitrary code. Background ========= dstat is a versatile system resource monitor written in Python. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/dstat < 0.6.9-r1 > = 0.6.9-r1 Description ========== Robert Buchholz of the Gentoo Security Team reported that dstat includes the current working directory and subdirectories in the Python module search path (sys.path) before calling "import". Impact ===== A local attacker could entice a user to run "dstat" from a directory containing a specially crafted Python module, resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= Do not run "dstat" from untrusted working directories. Resolution ========= All dstat users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =sys-apps/dstat-0.6.9-r1" References ========= [ 1 ] CVE-2009-3894 https://www.cve.org/CVERecord?id=CVE-2009-3894 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200911-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Security Advisory GLSA 202311-05 highlights a vulnerability in the utility 'appname' which could lead to unauthorized memory access.. dstat security, untrusted path issue, code execution risk. . LinuxSecurity.com Team

Calendar 2 Nov 25, 2009 Gentoo
91

Gentoo: GLSA-200904-06 Normal: Eye of GNOME Untrusted Path Risk

An untrusted search path vulnerability in the Eye of GNOME might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Eye of GNOME: Untrusted search path Date: April 06, 2009 Bugs: #257002 ID: 200904-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in the Eye of GNOME might result in the execution of arbitrary code. Background ========= The Eye of GNOME is the official image viewer for the GNOME Desktop environment. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/eog < 2.22.3-r3 > = 2.22.3-r3 Description ========== James Vega reported an untrusted search path vulnerability in the GObject Python interpreter wrapper in the Eye of GNOME, a vulnerabiliy related to CVE-2008-5983. Impact ===== A local attacker could entice a user to run the Eye of GNOME from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= Do not run "eog" from untrusted working directories. Resolution ========= All Eye of GNOME users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/eog-2.22.3-r3" References ========= [ 1 ] CVE-2008-5983 https://www.cve.org/CVERecord?id=CVE-2008-5983 [ 2 ] CVE-2008-5987 https://www.cve.org/CVERecord?id=CVE-2008-5987 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200904-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical advisory for Gentoo users regarding a vulnerability in Eye of GNOME that facilitates an untrusted search path, thereby presenting a risk for possible code execution.. Eye of GNOME,Gentoo Advisory,Untrusted Search,Code Execution Issue. . LinuxSecurity.com Team

Calendar 2 Apr 06, 2009 Gentoo
91

Gentoo: GLSA-200904-04 Normal: Gnumeric Vulnerable Input Handling

An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Gnumeric: Untrusted search path Date: April 03, 2009 Bugs: #257012 ID: 200904-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An untrusted search path vulnerability in Gnumeric might result in the execution of arbitrary code. Background ========= The Gnumeric spreadsheet is a versatile application developed as part of the GNOME Office project. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-office/gnumeric < 1.8.4-r1 > = 1.8.4-r1 Description ========== James Vega reported an untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric. Impact ===== A local attacker could entice a user to run Gnumeric from a directory containing a specially crafted python module, resulting in the execution of arbitrary code with the privileges of the user running Gnumeric. Workaround ========= Do not run "gnumeric" from untrusted working directories. Resolution ========= All Gnumeric users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-office/gnumeric-1.8.4-r1" References ========= [ 1 ] CVE-2009-0318 https://www.cve.org/CVERecord?id=CVE-2009-0318 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/200904-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gnumeric contains a vulnerability involving an untrusted search path that may lead to arbitrary code execution. It is advised to upgrade.. Gnumeric Security Advisory, Untrusted Path Risk, Gentoo Linux Update. . LinuxSecurity.com Team

Calendar 2 Apr 03, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here