Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 38: FEDORA-2024-b5b85798cd critical: mingw-jasper memory issue

Backport fix for CVE-2023-51257.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-b5b85798cd 2024-01-24 01:32:39.687107 -------------------------------------------------------------------------------- Name : mingw-jasper Product : Fedora 38 Version : 3.0.6 Release : 5.fc38 URL : https://www.ece.uvic.ca/~frodo/jasper/ Summary : MinGW Windows Jasper library Description : MinGW Windows Jasper library. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-51257. -------------------------------------------------------------------------------- ChangeLog: * Mon Jan 15 2024 Sandro Mani - 3.0.6-5 - Backport memory fixes, incl CVE-2023-51257 * Thu Jul 20 2023 Fedora Release Engineering - 3.0.6-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258403 - TRIAGE CVE-2023-51257 mingw-jasper: . A significant announcement regarding the mingw-jasper package in Fedora 38 addresses CVE-2023-51257, which is a severe memory vulnerability.. mingw-jasper update,Fedora 38 security advisory,memory fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 24, 2024 Critical Fedora
87

Debian DSA-5563-1 Urgent Intel Microcode Update for Privilege Escalation

Benoit Morgan, Paul Grosen, Thais Moreira Hamasaki, Ke Sun, Alyssa Milburn, Hisham Shafi, Nir Shlomovich, avis Ormandy, Daniel Moghimi, Josh Eads, Salman Qazi, Alexandra Sandulescu, Andy Nguyen, Eduardo Vela, Doug Kwan, and Kostik Shtoyk discovered that some Intel processors . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5563-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 23, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : intel-microcode CVE ID : CVE-2023-23583 Debian Bug : 1055962 Benoit Morgan, Paul Grosen, Thais Moreira Hamasaki, Ke Sun, Alyssa Milburn, Hisham Shafi, Nir Shlomovich, avis Ormandy, Daniel Moghimi, Josh Eads, Salman Qazi, Alexandra Sandulescu, Andy Nguyen, Eduardo Vela, Doug Kwan, and Kostik Shtoyk discovered that some Intel processors mishandle repeated sequences of instructions leading to unexpected behavior, which may result in privilege escalation, information disclosure or denial of service. For the oldstable distribution (bullseye), this problem has been fixed in version 3.20231114.1~deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 3.20231114.1~deb12u1. We recommend that you upgrade your intel-microcode packages. For the detailed security status of intel-microcode please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/intel-microcode Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notification DSA-5564-1 addresses urgent intel-microcode patch for vulnerability exploitation risk.. Debian Security, Intel Microcode, Privilege Escalation,Information Disclosure, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 23, 2023 Critical Debian
87

Debian Bullseye: DSA-5298-1 Urgent: Cacti Command Injection and LDAP Bypass

Two security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in unauthenticated command injection or LDAP authentication bypass. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5298-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff December 09, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cacti CVE ID : CVE-2022-0730 CVE-2022-46169 Debian Bug : 1008693 1025648 Two security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in unauthenticated command injection or LDAP authentication bypass. For the stable distribution (bullseye), these problems have been fixed in version 1.2.16+ds1-2+deb11u1. We recommend that you upgrade your cacti packages. For the detailed security status of cacti please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/cacti Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The surveillance platform Nagios has been granted a vital safety enhancement addressing buffer overflow and SQL injection weaknesses.. Cacti Security Update, Debian DSA-5298-1, Command Injection, LDAP Bypass. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 09, 2022 Critical Debian
87

Debian: DSA-4611-1 Urgent OpenSMTPD Command Execution and TLS Downgrade

Qualys discovered that the OpenSMTPD SMTP server performed insufficient validation of email addresses which could result in the execution of arbitrary commands as root. In addition this update fixes a denial of service by triggering an opportunistic TLS downgrade. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4611-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff January 29, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : opensmtpd CVE ID : CVE-2020-7247 Debian Bug : 950121 Qualys discovered that the OpenSMTPD SMTP server performed insufficient validation of email addresses which could result in the execution of arbitrary commands as root. In addition this update fixes a denial of service by triggering an opportunistic TLS downgrade. For the oldstable distribution (stretch), these problems have been fixed in version 6.0.2p1-2+deb9u2. For the stable distribution (buster), these problems have been fixed in version 6.0.3p1-5+deb10u3. This update also includes non-security bugfixes which were already lined up for the Buster 10.3 point release. We recommend that you upgrade your opensmtpd packages. For the detailed security status of opensmtpd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/opensmtpd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Postfix has been patched to address vulnerabilities stemming from improper email filtering and a risk of service interruptions.. OpenSMTPD Security Update, Debian OpenSMTPD Patch, Email Address Vulnerability. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jan 29, 2020 Important Debian
89

Fedora 31: FEDORA-2019-99ff6aa32c Urgent: jackson-core Remote Exec

- Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-99ff6aa32c 2019-09-18 00:01:15.683454 --------------------------------------------------------------------------------Name : jackson-core Product : Fedora 31 Version : 2.9.9 Release : 1.fc31 URL : https://github.com/FasterXML/jackson-core/ Summary : Core part of Jackson Description : Core part of Jackson that defines Streaming API as well as basic shared abstractions. --------------------------------------------------------------------------------Update Information: - Update jackson-databind to version 2.9.9.3. - Update jackson-core to version 2.9.9. - Update jackson-annotations to version 2.9.9. - Update jackson-bom to version 2.9.9. Resolves CVE-2019-12086, CVE-2019-12384, CVE-2019-12814, CVE-2019-14379, and CVE-14439. --------------------------------------------------------------------------------References: [ 1 ] Bug #1737518 - CVE-2019-14379 jackson-databind: default typing mishandling leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1737518 [ 2 ] Bug #1725808 - CVE-2019-12384 jackson-databind: failure to block the logback-core class from polymorphic deserialization leading to remote code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725808 [ 3 ] Bug #1725796 - CVE-2019-12814 jackson-databind: polymorphic typing issue allows attacker to read arbitrary local files on the server via crafted JSON message. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725796 [ 4 ] Bug #1713469 - CVE-2019-12086 jackson-databind: polymorphic typing issue allows attacker to read arbitrarylocal files on the server. [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1713469 [ 5 ] Bug #1752964 - CVE-2019-14439 jackson-databind: Polymorphic typing issue related to logback/JNDI [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1752964 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-99ff6aa32c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . New update alert for jackson-core and related libraries addressing several critical remote code execution vulnerabilities. Users are urged to upgrade promptly.. jackson-core update,Fedora security advisory,remote execution fix,software package updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 17, 2019 Important Fedora
202

openSUSE Leap 42.2: 2017:0588-1 Important: php7 Security Update

An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available. An update that fixes 13 vulnerabilities is now available.. openSUSE Security Update: Security update for php7 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:0588-1 Rating: important References: #1008026 #1019547 #1019550 #1019568 #1019570 #1022219 #1022255 #1022257 #1022260 #1022262 #1022263 #1022264 #1022265 Cross-References: CVE-2016-10158 CVE-2016-10159 CVE-2016-10160 CVE-2016-10161 CVE-2016-10162 CVE-2016-10166 CVE-2016-10167 CVE-2016-10168 CVE-2016-7478 CVE-2016-7479 CVE-2016-7480 CVE-2016-9138 CVE-2017-5340 Affected Products: openSUSE Leap 42.2 ______________________________________________________________________________ An update that fixes 13 vulnerabilities is now available. Description: This update for php7 fixes the following security issues: - CVE-2016-7480: The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP did not verify that a key is an object, which allowed remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access) via crafted serialized data. (bsc#1019568) - CVE-2017-5340: Zend/zend_hash.c in PHP mishandled certain cases that require large array allocations, which allowed remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data. (bsc#1019570) - CVE-2016-7479: In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may have lead to use-after-free. A remote attacker may exploit this bug to gain arbitrary code execution. (bsc#1019547) - CVE-2016-7478: Zend/zend_exceptions.c in PHP allowed remote attackers to cause a denial of service (infinite loop) via a crafted Exception object in serialized data, a related issue to CVE-2015-8876. (bsc#1019550) - CVE-2016-10159: Integer overflow in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory consumption or application crash) via a truncated manifest entry in a PHAR archive. (bsc#1022255) - CVE-2016-10160: Off-by-one error in the phar_parse_pharfile function in ext/phar/phar.c in PHP allowed remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PHAR archive with an alias mismatch. (bsc#1022257) - CVE-2016-10161: The object_common1 function in ext/standard/var_unserializer.c in PHP allowed remote attackers to cause a denial of service (buffer over-read and application crash) via crafted serialized data that is mishandled in a finish_nested_data call. (bsc#1022260) - CVE-2016-10162: The php_wddx_pop_element function in ext/wddx/wddx.c in PHP 7 allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an inapplicable class name in a wddxPacket XML document, leading to mishandling in a wddx_deserialize call. (bsc#1022262) - CVE-2016-10166: A potential unsigned underflow in gd interpolation functions could lead to memory corruption in the PHP gd module (bsc#1022263) - CVE-2016-10167: A denial of service problem in gdImageCreateFromGd2Ctx() could lead to php out of memory even on small files. (bsc#1022264) - CVE-2016-10168: A signed integer overflow in the gd module could lead to memory corruption (bsc#1022265) - CVE-2016-9138: PHP mishandled property modification during __wakeup processing, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted serialized data, as demonstrated by Exception::__toString with DateInterval::__wakeup. (bsc#1008026) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patch openSUSE-2017-304=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (i586 x86_64): apache2-mod_php7-7.0.7-12.1 apache2-mod_php7-debuginfo-7.0.7-12.1 php7-7.0.7-12.1 php7-bcmath-7.0.7-12.1 php7-bcmath-debuginfo-7.0.7-12.1 php7-bz2-7.0.7-12.1 php7-bz2-debuginfo-7.0.7-12.1 php7-calendar-7.0.7-12.1 php7-calendar-debuginfo-7.0.7-12.1 php7-ctype-7.0.7-12.1 php7-ctype-debuginfo-7.0.7-12.1 php7-curl-7.0.7-12.1 php7-curl-debuginfo-7.0.7-12.1 php7-dba-7.0.7-12.1 php7-dba-debuginfo-7.0.7-12.1 php7-debuginfo-7.0.7-12.1 php7-debugsource-7.0.7-12.1 php7-devel-7.0.7-12.1 php7-dom-7.0.7-12.1 php7-dom-debuginfo-7.0.7-12.1 php7-enchant-7.0.7-12.1 php7-enchant-debuginfo-7.0.7-12.1 php7-exif-7.0.7-12.1 php7-exif-debuginfo-7.0.7-12.1 php7-fastcgi-7.0.7-12.1 php7-fastcgi-debuginfo-7.0.7-12.1 php7-fileinfo-7.0.7-12.1 php7-fileinfo-debuginfo-7.0.7-12.1 php7-firebird-7.0.7-12.1 php7-firebird-debuginfo-7.0.7-12.1 php7-fpm-7.0.7-12.1 php7-fpm-debuginfo-7.0.7-12.1 php7-ftp-7.0.7-12.1 php7-ftp-debuginfo-7.0.7-12.1 php7-gd-7.0.7-12.1 php7-gd-debuginfo-7.0.7-12.1 php7-gettext-7.0.7-12.1 php7-gettext-debuginfo-7.0.7-12.1 php7-gmp-7.0.7-12.1 php7-gmp-debuginfo-7.0.7-12.1 php7-iconv-7.0.7-12.1 php7-iconv-debuginfo-7.0.7-12.1 php7-imap-7.0.7-12.1 php7-imap-debuginfo-7.0.7-12.1 php7-intl-7.0.7-12.1 php7-intl-debuginfo-7.0.7-12.1 php7-json-7.0.7-12.1 php7-json-debuginfo-7.0.7-12.1 php7-ldap-7.0.7-12.1 php7-ldap-debuginfo-7.0.7-12.1 php7-mbstring-7.0.7-12.1 php7-mbstring-debuginfo-7.0.7-12.1 php7-mcrypt-7.0.7-12.1 php7-mcrypt-debuginfo-7.0.7-12.1 php7-mysql-7.0.7-12.1 php7-mysql-debuginfo-7.0.7-12.1 php7-odbc-7.0.7-12.1 php7-odbc-debuginfo-7.0.7-12.1 php7-opcache-7.0.7-12.1 php7-opcache-debuginfo-7.0.7-12.1 php7-openssl-7.0.7-12.1 php7-openssl-debuginfo-7.0.7-12.1 php7-pcntl-7.0.7-12.1 php7-pcntl-debuginfo-7.0.7-12.1 php7-pdo-7.0.7-12.1 php7-pdo-debuginfo-7.0.7-12.1 php7-pgsql-7.0.7-12.1 php7-pgsql-debuginfo-7.0.7-12.1 php7-phar-7.0.7-12.1 php7-phar-debuginfo-7.0.7-12.1 php7-posix-7.0.7-12.1 php7-posix-debuginfo-7.0.7-12.1 php7-pspell-7.0.7-12.1 php7-pspell-debuginfo-7.0.7-12.1 php7-readline-7.0.7-12.1 php7-readline-debuginfo-7.0.7-12.1 php7-shmop-7.0.7-12.1 php7-shmop-debuginfo-7.0.7-12.1 php7-snmp-7.0.7-12.1 php7-snmp-debuginfo-7.0.7-12.1 php7-soap-7.0.7-12.1 php7-soap-debuginfo-7.0.7-12.1 php7-sockets-7.0.7-12.1 php7-sockets-debuginfo-7.0.7-12.1 php7-sqlite-7.0.7-12.1 php7-sqlite-debuginfo-7.0.7-12.1 php7-sysvmsg-7.0.7-12.1 php7-sysvmsg-debuginfo-7.0.7-12.1 php7-sysvsem-7.0.7-12.1 php7-sysvsem-debuginfo-7.0.7-12.1 php7-sysvshm-7.0.7-12.1 php7-sysvshm-debuginfo-7.0.7-12.1 php7-tidy-7.0.7-12.1 php7-tidy-debuginfo-7.0.7-12.1 php7-tokenizer-7.0.7-12.1 php7-tokenizer-debuginfo-7.0.7-12.1 php7-wddx-7.0.7-12.1 php7-wddx-debuginfo-7.0.7-12.1 php7-xmlreader-7.0.7-12.1 php7-xmlreader-debuginfo-7.0.7-12.1 php7-xmlrpc-7.0.7-12.1 php7-xmlrpc-debuginfo-7.0.7-12.1 php7-xmlwriter-7.0.7-12.1 php7-xmlwriter-debuginfo-7.0.7-12.1 php7-xsl-7.0.7-12.1 php7-xsl-debuginfo-7.0.7-12.1 php7-zip-7.0.7-12.1 php7-zip-debuginfo-7.0.7-12.1 php7-zlib-7.0.7-12.1 php7-zlib-debuginfo-7.0.7-12.1 - openSUSE Leap 42.2 (noarch): php7-pear-7.0.7-12.1 php7-pear-Archive_Tar-7.0.7-12.1 References: https://www.suse.com/security/cve/CVE-2016-10158.html https://www.suse.com/security/cve/CVE-2016-10159.html https://www.suse.com/security/cve/CVE-2016-10160.html https://www.suse.com/security/cve/CVE-2016-10161.html https://www.suse.com/security/cve/CVE-2016-10162.html https://www.suse.com/security/cve/CVE-2016-10166.html https://www.suse.com/security/cve/CVE-2016-10167.html https://www.suse.com/security/cve/CVE-2016-10168.html https://www.suse.com/security/cve/CVE-2016-7478.html https://www.suse.com/security/cve/CVE-2016-7479.html https://www.suse.com/security/cve/CVE-2016-7480.html https://www.suse.com/security/cve/CVE-2016-9138.html https://www.suse.com/security/cve/CVE-2017-5340.html https://bugzilla.suse.com/1008026 https://bugzilla.suse.com/1019547 https://bugzilla.suse.com/1019550 https://bugzilla.suse.com/1019568 https://bugzilla.suse.com/1019570 https://bugzilla.suse.com/1022219 https://bugzilla.suse.com/1022255 https://bugzilla.suse.com/1022257 https://bugzilla.suse.com/1022260 https://bugzilla.suse.com/1022262 https://bugzilla.suse.com/1022263 https://bugzilla.suse.com/1022264 https://bugzilla.suse.com/1022265 . This critical enhancement addresses 15 vulnerabilities in php8, improving both reliability and protection for Fedora users.. openSUSE, php7, security update, code execution, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 02, 2017 Important OpenSUSE
87

Debian: DSA-2955-1 Urgent OpenSSL Patch Fixes TLS Issues

This update updates the upstream fix for CVE-2014-0224 to address problems with CCS which could result in problems with the Postgres database. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - ------------------------------------------------------------------------- Debian Security Advisory DSA-2950-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 16, 2014 http://www.debian.org/security/faq - - ------------------------------------------------------------------------- Package : openssl CVE ID : CVE-2014-0195 CVE-2014-0221 CVE-2014-0224 CVE-2014-3470 This update updates the upstream fix for CVE-2014-0224 to address problems with CCS which could result in problems with the Postgres database. In addition this update disables ZLIB compress by default. If you need to re-enable it for some reason, you can set the environment variable OPENSSL_NO_DEFAULT_ZLIB. This update also fixes a header declaration which could result in build failures in applications using OpenSSL. For the stable distribution (wheezy), these problems have been fixed in version 1.0.1e-2+deb7u11. We recommend that you upgrade your openssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Debian Security Notice DSA-2951-3 highlights a vital update for OpenSSL that mitigates vulnerabilities related to the CCS protocol and enhances ZLIB compression security mechanisms.. Debian Security Advisory, OpenSSL Update, CCS Fix, PostgreSQL Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 16, 2014 Critical Debian
87

Ubuntu: EUS-3401-2 Urgent: OpenSSH Privilege Escalation

An authentication bypass vulnerability was found in charon, the daemon handling IKEv2 in strongSwan, an IKE/IPsec suite. The state machine handling the security association (IKE_SA) handled some state transitions incorrectly. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2903-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Yves-Alexis Perez April 14, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : strongswan CVE ID : CVE-2014-2338 An authentication bypass vulnerability was found in charon, the daemon handling IKEv2 in strongSwan, an IKE/IPsec suite. The state machine handling the security association (IKE_SA) handled some state transitions incorrectly. An attacker can trigger the vulnerability by rekeying an unestablished IKE_SA during the initiation itself. This will trick the IKE_SA state to 'established' without the need to provide any valid credential. Vulnerable setups include those actively initiating IKEv2 IKE_SA (like ”clients” or “roadwarriors”) but also during re-authentication (which can be initiated by the responder). Installations using IKEv1 (pluto daemon in strongSwan 4 and earlier, and IKEv1 code in charon 5.x) is not affected. For the oldstable distribution (squeeze), this problem has been fixed in version 4.4.1-5.5. For the stable distribution (wheezy), this problem has been fixed in version 4.5.2-1.5+deb7u3. For the unstable distribution (sid), this problem has been fixed in version 5.1.2-4. We recommend that you upgrade your strongswan packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. .-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ----------------------------------------------------. authentication, bypass, vulnerability, found, charon, daemon, handling, ikev2, strongswan. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 14, 2014 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200