Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
198

Arch Linux: ASA-202105-16 High Risk: WebSVN Remote Command Execution

The package websvn before version 2.6.1-1 is vulnerable to arbitrary command execution. . Arch Linux Security Advisory ASA-202105-16 ========================================= Severity: High Date : 2021-05-25 CVE-ID : CVE-2021-32305 Package : websvn Type : arbitrary command execution Remote : Yes Link : https://security.archlinux.org/AVG-1969 Summary ====== The package websvn before version 2.6.1-1 is vulnerable to arbitrary command execution. Resolution ========= Upgrade to 2.6.1-1. # pacman -Syu "websvn> =2.6.1-1" The problem has been fixed upstream in version 2.6.1. Workaround ========= None. Description ========== WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter. Impact ===== A remote attacker can execute arbitrary shell commands on the server using a crafted search query. References ========= https://github.com/websvnphp/websvn/pull/142 https://github.com/websvnphp/websvn/commit/88fce56b7b9dbfc0fe2629217c3bff2c2e751920 https://security.archlinux.org/CVE-2021-32305 . Ubuntu Security Notice USN-1234-1 reveals a critical vulnerability in the XYZ application that allows unauthorized code execution. Update immediately.. websvn security advisory, arch linux command execution, high severity risks. . LinuxSecurity.com Team

Calendar%202 May 26, 2021 ArchLinux
87

Debian 8 DSA-3572-1 Critical: Websvn Cross-Site Scripting Threat

Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3572-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 09, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : websvn CVE ID : CVE-2016-1236 Nitin Venkatesh discovered that websvn, a web viewer for Subversion repositories, is susceptible to cross-site scripting attacks via specially crafted file and directory names in repositories. For the stable distribution (jessie), this problem has been fixed in version 2.3.3-1.2+deb8u2. We recommend that you upgrade your websvn packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Websvn enhancements tackle vulnerabilities linked to cross-origin scripting. Update to bolster defenses against specific threats within Debian systems.. Debian Security, Cross-Site Scripting, Websvn Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 09, 2016 Critical Debian
89

Fedora 23: 2016-657a1305aa Moderate: WebSVN Cross-Site Scripting Issue

- Fix CVE-2016-2511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-657a1305aa 2016-03-20 22:04:03.377791 -------------------------------------------------------------------------------- Name : websvn Product : Fedora 23 Version : 2.3.3 Release : 12.fc23 URL : https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&followup=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&ifkv=AdBytiOa3OwAAmtOSnC9TDUsO4xXtpIZ3cSXCpBSfErjstoPCwo3KVe-rRcHqY7fghdODcRfIJBf5Q&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S1914885879%3A1750217781873400// Summary : Online subversion repository browser Description : WebSVN offers a view onto your subversion repositories that's been designed to reflect the Subversion methodology. You can view the log of any file or directory and see a list of all the files changed, added or deleted in any given revision. You can also view the differences between two versions of a file so as to see exactly what was changed in a particular revision. -------------------------------------------------------------------------------- Update Information: - Fix CVE-2016-2511 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1310760 - CVE-2016-2511 websvn: reflected cross-site scripting [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310760 [ 2 ] Bug #1310759 - CVE-2016-2511 websvn: reflected cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310759 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update websvn' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . A recent patch for Fedora 23 fixes the vulnerability CVE-2016-2511 in websvn, reducing the risks associated with reflected cross-site scripting.. Fedora Update, WebSVN Cross-Site Scripting, Security Patch. . LinuxSecurity.com Team

Calendar%202 Mar 21, 2016 Fedora
89

Fedora 22: Critical WebSVN Security Update for CVE-2016-2511

- Fix CVE-2016-2511. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-11537160e9 2016-03-20 16:01:37.706621 -------------------------------------------------------------------------------- Name : websvn Product : Fedora 22 Version : 2.3.3 Release : 12.fc22 URL : https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&followup=https%3A%2F%2Fsites.google.com%2Fview%2Fvn88-vn88com&ifkv=AdBytiOQZ2dUdfmEMgcyNZ8idzChC8XFDbQJkfaTxrHWeF3Ya1LWEI-n97T4zfMTdoIYpA-cgv0Q1g&osid=1&passive=1209600&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S1781429062%3A1750217749713434// Summary : Online subversion repository browser Description : WebSVN offers a view onto your subversion repositories that's been designed to reflect the Subversion methodology. You can view the log of any file or directory and see a list of all the files changed, added or deleted in any given revision. You can also view the differences between two versions of a file so as to see exactly what was changed in a particular revision. -------------------------------------------------------------------------------- Update Information: - Fix CVE-2016-2511 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1310760 - CVE-2016-2511 websvn: reflected cross-site scripting [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310760 [ 2 ] Bug #1310759 - CVE-2016-2511 websvn: reflected cross-site scripting [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1310759 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update websvn' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Debian 10 security bulletin highlights important kernel patches targeting severe buffer overflow flaws.. Fedora Security, WebSVN Update, Cross-Site Scripting. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 20, 2016 Critical Fedora
87

Debian: DSA-3137-1 Moderate: Websvn Symlink Access Issue

James Clawson discovered that websvn, a web viewer for Subversion repositories, would follow symlinks in a repository when presenting a file for download. An attacker with repository write access could thereby access any file on disk readable by the user the webserver . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3137-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst January 24, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : websvn CVE ID : CVE-2013-6892 Debian Bug : 775682 James Clawson discovered that websvn, a web viewer for Subversion repositories, would follow symlinks in a repository when presenting a file for download. An attacker with repository write access could thereby access any file on disk readable by the user the webserver runs as. For the stable distribution (wheezy), this problem has been fixed in version 2.3.3-1.1+deb7u1. For the unstable distribution (sid), this problem has been fixed in version 2.3.3-1.2. We recommend that you upgrade your websvn packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-3178-1: Urgent update for dnsmasq resolves significant security vulnerability enabling unauthorized data exposure.. Websvn Security, Debian Update, Symlink Access Flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 24, 2015 Important Debian
91

Gentoo: GLSA-200903-20 Normal: WebSVN File Overwrite and Info Leak

Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebSVN: Multiple vulnerabilities Date: March 09, 2009 Bugs: #243852 ID: 200903-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in WebSVN allow for file overwrite and information disclosure. Background ========= WebSVN is a web-based browsing tool for Subversion repositories written in PHP. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/websvn < 2.1.0 > = 2.1.0 Description ========== * James Bercegay of GulfTech Security reported a Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl() function in index.php (CVE-2008-5918) and a directory traversal vulnerability in rss.php when magic_quotes_gpc is disabled (CVE-2008-5919). * Bas van Schaik reported that listing.php does not properly enforce access restrictions when using an SVN authz file to authenticate users (CVE-2009-0240). Impact ===== A remote attacker can exploit these vulnerabilities to overwrite arbitrary files, to read changelogs or diffs for restricted projects and to hijack a user's session. Workaround ========= There is no known workaround at this time. Resolution ========= All WebSVN users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=www-apps/websvn-2.1.0" References ========= [ 1 ] CVE-2008-5918 https://www.cve.org/CVERecord?id=CVE-2008-5918 [ 2 ] CVE-2008-5919 https://www.cve.org/CVERecord?id=CVE-2008-5919 [ 3 ] CVE-2009-0240 https://www.cve.org/CVERecord?id=CVE-2009-0240 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . WebSVN contains several security flaws on Gentoo Linux; an upgrade is necessary to avert data leaks and file replacement.. WebSVN, Gentoo Linux, File Overwrite, Info Leak. . LinuxSecurity.com Team

Calendar%202 Mar 09, 2009 Gentoo
87

Debian Lenny: DSA-1725-1 Critical: WebSVN Remote Access Issue

Bas van Schaik discovered that WebSVN, a tool to view Subversion repositories over the web, did not properly restrict access to private repositories, allowing a remote attacker to read significant parts of their content. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1725-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst February 15, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : websvn Vulnerability : programming error Problem type : remote Debian-specific: no CVE Id(s) : CVE-2009-0240 Debian Bug : 512191 Bas van Schaik discovered that WebSVN, a tool to view Subversion repositories over the web, did not properly restrict access to private repositories, allowing a remote attacker to read significant parts of their content. The old stable distribution (etch) is not affected by this problem. For the stable distribution (lenny), this problem has been fixed in version 2.0-4+lenny1. For the unstable distribution (sid), this problem has also been fixed in version 2.0-4+lenny1. We recommend that you upgrade your websvn package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Source archives: Size/MD5 checksum: 21217 fec9c4c9173ac5da1e6866b6afdb37ff Size/MD5 checksum: 1291 3b2910de66eb35b3650558c2a6b70d74 Size/MD5 checksum: 172005 047e02c0fa2948fdf98a3e348e3f1530 Architectureindependent packages: Size/MD5 checksum: 194618 f03bd2f1bf00ee0666368a85faf1a9ef These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian Security Advisory DSA-1725-2 deals with a vulnerability in WebSVN that causes sensitive data exposure, rectifying remote exploitation risks.. WebSVN, Information Leak, Debian Security, Remote Access, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 15, 2009 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200