Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 34: FEDORA-2021-7a1c3e9b7e Critical: Ceph Security Fix

ceph 14.2.21 GA Security fix for CVE-2021-3524, CVE-2021-3531. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-6e540b85b9 2021-05-23 01:29:39.229346 --------------------------------------------------------------------------------Name : ceph Product : Fedora 32 Version : 14.2.21 Release : 1.fc32 URL : Summary : User space components of the Ceph file system Description : Ceph is a massively scalable, open-source, distributed storage system that runs on commodity hardware and delivers object, block and file system storage. --------------------------------------------------------------------------------Update Information: ceph 14.2.21 GA Security fix for CVE-2021-3524, CVE-2021-3531 --------------------------------------------------------------------------------ChangeLog: * Thu May 13 2021 Kaleb S. KEITHLEY - 2:14.2.21-1 - ceph 14.2.21 GA --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-6e540b85b9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply tospam on the list, report it: https://pagure.io/fedora-infrastructure . Ceph 14.2.21 on Fedora 32 receives a vital patch that resolves various security vulnerabilities, ensuring improved system protection.. Fedora Security,Cep Update,Ceph 14.2.21,Software Patch,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2021 Critical Fedora
197

Debian 9 DLA-2650-1 Critical: Exim4 Escalation and Code Execution

The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2650-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz May 05, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : exim4 Version : 4.89-2+deb9u8 CVE ID : CVE-2020-28007 CVE-2020-28008 CVE-2020-28009 CVE-2020-28011 CVE-2020-28012 CVE-2020-28013 CVE-2020-28014 CVE-2020-28015 CVE-2020-28017 CVE-2020-28019 CVE-2020-28020 CVE-2020-28021 CVE-2020-28022 CVE-2020-28023 CVE-2020-28024 CVE-2020-28025 CVE-2020-28026 The Qualys Research Labs reported several vulnerabilities in Exim, a mail transport agent, which could result in local privilege escalation and remote code execution. Details can be found in the Qualys advisory at https://https://www.qualys.com/2021/05/04/21nails/21nails.txt For Debian 9 stretch, these problems have been fixed in version 4.89-2+deb9u8. We recommend that you upgrade your exim4 packages. For the detailed security status of exim4 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/exim4 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-2651-1 addresses security vulnerabilities in Exim, aimed at resolving local privilege escalation and arbitrary code execution concerns.. Debian LTS, Exim Security, Privilege Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 05, 2021 Critical Debian LTS
99

Slackware 14.1: SSA:2016-095-01 Critical: Mozilla Thunderbird Security Fix

New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] mozilla-thunderbird (SSA:2016-095-01) New mozilla-thunderbird packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz: Upgraded. This release contains security fixes and improvements. For more information, see: https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/ (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.1 package: d60cfd10b8c26b1df43e9683a9a1f0d6 mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz Slackware x86_64 14.1 package: d4a33e4edfaaa8bebba291ac11b4d1a0 mozilla-thunderbird-38.7.2-x86_64-1_slack14.1.txz Slackware -current package: b6a3444a1ea9e91c98337001b7aa49ae xap/mozilla-thunderbird-38.7.2-i586-1.txz Slackware x86_64 -current package: 07e97d2546740c3b15cf2932ec00846d xap/mozilla-thunderbird-38.7.2-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg mozilla-thunderbird-38.7.2-i486-1_slack14.1.txz +-----+ . Recent Mozilla Thunderbird patch for Slackware 14.1 released, targeting security vulnerabilities while enhancing overall stability.. Mozilla Thunderbird, Slackware Security, Software Update. . Severity: Critical. LinuxSecurity.comTeam

Calendar%202 Apr 04, 2016 Critical Slackware
89

Fedora 20: FEDORA-2015-6862 Urgent Springframework Security Alert

Security fix for CVE-2014-0225. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6862 2015-04-26 07:27:39 -------------------------------------------------------------------------------- Name : springframework Product : Fedora 20 Version : 3.1.4 Release : 3.fc20 URL : https://spring.io Summary : Spring Java Application Framework Description : Spring is a layered Java/J2EE application framework, based on code published in Expert One-on-One J2EE Design and Development by Rod Johnson (Wrox, 2002). -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2014-0225 -------------------------------------------------------------------------------- ChangeLog: * Fri Apr 24 2015 Michal Srb - 0:3.1.4-3 - Resolves: CVE-2014-0225 * Fri Dec 6 2013 gil cattaneo 0:3.1.4-2 - fix for rhbz: 993376, 953977 - switch to XMvn - disable derby (partial), and jopt-simple support - enable castor and jruby support * Thu Dec 5 2013 Orion Poplawski - 0:3.1.4-1 - Update to 3.1.4 - Add BR xmlunit - Change wstx-asl to woodstox-core-asl * Sun Aug 4 2013 Fedora Release Engineering - 0:3.1.1-15 - Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #1110110 - CVE-2014-0225 Spring Framework: Information disclosure via SSRF https://bugzilla.redhat.com/show_bug.cgi?id=1110110 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update springframework' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important update for Spring Framework on Fedora 20 resolves a serious vulnerability that could lead to information leakage through SSRF. Protect your systems immediately!. Fedora,Spring Framework,Security Update,App Protection. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 08, 2015 Critical Fedora
89

Fedora 21: Advisory 2021-4876 Critical: php-symfony Security Update

**2.5.11** (2015-04-01) * security #14167 CVE-2015-2308 (nicolas-grekas) * security #14166 CVE-2015-2309 (neclimdul). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-5457 2015-04-04 03:51:41 -------------------------------------------------------------------------------- Name : php-symfony Product : Fedora 21 Version : 2.5.11 Release : 1.fc21 URL : https://symfony.com/ Summary : PHP framework for web projects Description : PHP framework for web projects -------------------------------------------------------------------------------- Update Information: **2.5.11** (2015-04-01) * security #14167 CVE-2015-2308 (nicolas-grekas) * security #14166 CVE-2015-2309 (neclimdul) -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 2 2015 Remi Collet - 2.5.11-1 - Update to 2.5.11 - security fix for CVE-2015-2308 and CVE-2015-2309 * Wed Mar 18 2015 Remi Collet - 2.5.10-1 - Update to 2.5.10 * Mon Dec 15 2014 Remi Collet - 2.5.8-1 - Update to 2.5.8 * Thu Nov 20 2014 Shawn Iwinski - 2.5.7-1 - Updated to 2.5.7 (BZ #1166396) - Added php-composer(egulias/email-validator) dependency -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update php-symfony' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 21 patch addresses significant php-symfony securityflaws identified in version 2.5.11. Uncover the safety enhancements today.. php-symfony Patch,Fedora 21 Update,Security Advisories. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 18, 2015 Critical Fedora
87

Debian: DSA 1182-1 Urgent Fix for Gzip Code Execution Risk

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1181-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 19th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : gzip Vulnerability : several Problem-Type : local(remote) Debian-specific: no CVE ID : CVE-2006-4334 CVE-2006-4335 CVE-2006-4336 CVE-2006-4337 CVE-2006-4338 Tavis Ormandy from the Google Security Team discovered several vulnerabilities in gzip, the GNU compression utility. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2006-4334 A null pointer dereference may lead to denial of service if gzip is used in an automated manner. CVE-2006-4335 Missing boundary checks may lead to stack modification, allowing execution of arbitrary code. CVE-2006-4336 A buffer underflow in the pack support code may lead to execution of arbitrary code. CVE-2006-4337 A buffer underflow in the LZH support code may lead to execution of arbitrary code. CVE-2006-4338 An infinite loop may lead to denial of service if gzip is used in an automated manner. For the stable distribution (sarge) these problems have been fixed in version 1.3.5-10sarge2. For the unstable distribution (sid) these problems have been fixed in version 1.3.5-15. We recommend that you upgrade your gzip package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by addingthe resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 566 b4ef2a9e595a17f8596fdefb1f4b9bf6 Size/MD5 checksum: 60478 cd1bec47a01d72c800f3bac85dfcc5f3 Size/MD5 checksum: 331550 3d6c191dfd2bf307014b421c12dc8469 Alpha architecture: Size/MD5 checksum: 83740 450c8d78aa9654ab651ac21115834432 AMD64 architecture: Size/MD5 checksum: 75370 cf8896b90d00dc8fce58ab1e88149674 ARM architecture: Size/MD5 checksum: 76472 24b1723495120c89b9a1a55712fc557d HP Precision architecture: Size/MD5 checksum: 79586 9a2d72859917de0f8b269ea95f392b2b Intel IA-32 architecture: Size/MD5 checksum: 71164 8267f1f753b0a2b380d149280b6e44bb Intel IA-64 architecture: Size/MD5 checksum: 91588 30b9aa547cfacc09cee832a9b7516b6e Motorola 680x0 architecture: Size/MD5 checksum: 69110 cf17c8d59a6204c2dce1828f2b1f24c6 Big endian MIPS architecture: Size/MD5 checksum: 79488 e2242db1fb6e1c589a67658f96ba7f27 Little endian MIPS architecture: Size/MD5 checksum: 79350 da63d665a88c29c6cf07b1ef3566ecd1 PowerPC architecture: Size/MD5 checksum: 76948 12e742fd43b8325e89f3b96e0cdd89a6 IBM S/390 architecture: Size/MD5 checksum: 77540 0e75950ede6c45a332eead6d71b7e7a2 Sun Sparc architecture: Size/MD5 checksum: 74654 471feed410766674a72327e58702febd These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . ---------------------------------------------------------------------------Debian Security Advisory. updated, package, --------------------------------------------------------------------------debian. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 19, 2006 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200