create a separate user for dnsmasq.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2f1f243787 2018-02-27 17:16:42.083176 --------------------------------------------------------------------------------Name : dnsmasq Product : Fedora 27 Version : 2.78 Release : 5.fc27 URL : https://thekelleys.org.uk/dnsmasq/ Summary : A lightweight DHCP/caching DNS server Description : Dnsmasq is lightweight, easy to configure DNS forwarder and DHCP server. It is designed to provide DNS and, optionally, DHCP, to a small network. It can serve the names of local machines which are not in the global DNS. The DHCP server integrates with the DNS server and allows machines with DHCP-allocated addresses to appear in the DNS with names configured either in each host or in a central configuration file. Dnsmasq supports static and dynamic DHCP leases and BOOTP for network booting of diskless machines. --------------------------------------------------------------------------------Update Information: create a separate user for dnsmasq. --------------------------------------------------------------------------------ChangeLog: --------------------------------------------------------------------------------References: [ 1 ] Bug #1548050 - dnsmasq starts dnsmasq which runs as nobody user https://bugzilla.redhat.com/show_bug.cgi?id=1548050 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade dnsmasq' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
A vulnerability in xinetd could lead to privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201611-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xinetd: Privilege escalation Date: November 15, 2016 Bugs: #488158 ID: 201611-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in xinetd could lead to privilege escalation. Background ========= xinetd is a secure replacement for inetd. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 sys-apps/xinetd < 2.3.15-r2 > = 2.3.15-r2 Description ========== Xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root. Impact ===== Attackers could escalate privileges outside of the running process. Workaround ========= There is no known workaround at this time. Resolution ========= All xinetd users should upgrade to the latest version: # emerge --sync # emerge --ask --verbose --oneshot "> =sys-apps/xinetd-2.3.15-r2" References ========= [ 1 ] CVE-2013-4342 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4342 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201611-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressedto
Get the latest Linux and open source security news straight to your inbox.