Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 28: Security Advisory - VNC Server Local Binding Update

Update to 2.14 This updates ensures that the VNC server used for debugging is bound to the local interfaces. Previously the VNC server might have been available globally depending on the system's firewall settings.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c5c870e3ab 2018-07-03 16:49:24.958505 --------------------------------------------------------------------------------Name : standard-test-roles Product : Fedora 28 Version : 2.14 Release : 1.fc28 URL : https://fedoraproject.org/wiki/Changes/InvokingTestsAnsible Summary : Standard Test Interface Ansible roles Description : Shared Ansible roles to support the Standard Test Interface as described at https://fedoraproject.org/wiki/Changes/InvokingTestsAnsible. --------------------------------------------------------------------------------Update Information: Update to 2.14 This updates ensures that the VNC server used for debugging is bound to the local interfaces. Previously the VNC server might have been available globally depending on the system's firewall settings. --------------------------------------------------------------------------------ChangeLog: * Fri Jun 29 2018 Andrei Stepanov - 2.14-1 - Build with the latest merged PRs. * Fri May 25 2018 Andrei Stepanov - 2.13-2 - Build with the latest merged PRs. * Wed May 23 2018 Andrei Stepanov - 2.12-1 - Build with the latest merged PRs. * Mon May 21 2018 Andrei Stepanov - 2.11-1 - Build with the latest merged PRs. * Mon Apr 23 2018 Andrei Stepanov - 2.10-1 - Build with the latest merged PRs. --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c5c870e3ab' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signedwith the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/TJGRJWHJ4MJDHKNH4CUJMC364HQS6KJJ/ . Take advantage of the latest Fedora patch to guarantee your VNC server is safely connected to local interfaces.. Fedora Update, VNC Server, Security Updates, Ansible Roles. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 03, 2018 Important Fedora
91

Gentoo: GLSA-202310-07 Normal: OpenSSH Security Vulnerability

A buffer overflow in TigerVNC could result in execution of arbitrary code or Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: TigerVNC: User-assisted execution of arbitrary code Date: November 05, 2014 Bugs: #505170 ID: 201411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in TigerVNC could result in execution of arbitrary code or Denial of Service. Background ========= TigerVNC is a high-performance VNC server/client. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/tigervnc < 1.3.1 > = 1.3.1 Description ========== Two boundary errors in TigerVNC could lead to a heap-based buffer overflow. Impact ===== A remote attacker could entice a user to connect to a malicious VNC server using TigerVNC, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All TigerVNC users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-misc/tigervnc-1.3.1" References ========= [ 1 ] CVE-2014-0011 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0011 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201411-03 Concerns? ======== Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA 202311-04 highlights a security flaw in OpenSSH which could lead to privilege escalation or unauthorized access.. TigerVNC, Buffer Overflow, Code Execution, Denial of Service. . LinuxSecurity.com Team

Calendar%202 Nov 06, 2014 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200