Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 492
Alerts This Week
Warning Icon 1 492

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
87

Debian DSA-3485-2 Accessibility Fix for Didiwiki Package

The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose names started with non-ascii characters. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3485-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond April 12, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : didiwiki Debian Bug : 818708 The update for didiwiki issued as DSA-3485-1 introduced a regression that caused a large number of valid pages to not be accessible anymore. This occurred mostly for pages whose names started with non-ascii characters. For the oldstable distribution (wheezy), this problem has been fixed in version 0.5-11+deb7u2. For the stable distribution (jessie), this problem has been fixed in version 0.5-11+deb8u2. For the unstable distribution (sid), this problem has been fixed in version 0.5-13. We recommend that you upgrade your didiwiki packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-3485-2 tackles the problem of accessibility in didiwiki, resulting from a regression. Further details are available.. didiwiki update,dsa 3485 2,debian security advisory,package upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 12, 2016 Important Debian
87

Debian: DSA-4385-2 Critical: Exploit for MySQL Vulnerability Detected

Two vulnerabilities have been discovered in VirtualBox, an x86 virtualisation solution. For the oldstable distribution (wheezy), these problems have been fixed . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3384-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 29, 2015 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : virtualbox CVE ID : CVE-2015-4813 CVE-2015-4896 Two vulnerabilities have been discovered in VirtualBox, an x86 virtualisation solution. For the oldstable distribution (wheezy), these problems have been fixed in version 4.1.42-dfsg-1+deb7u1. For the stable distribution (jessie), these problems have been fixed in version 4.3.32-dfsg-1+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 5.0.8-dfsg-1. For the unstable distribution (sid), these problems have been fixed in version 5.0.8-dfsg-1. We recommend that you upgrade your virtualbox packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Updates released for Debian-based systems in VirtualBox have mitigated two notable vulnerabilities across different releases.. Debian Security Advisory, VirtualBox Update, Software Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 29, 2015 Critical Debian
87

Debian: DSA-3149-1 Critical: Condor Code Execution Threat

Florian Weimer, of Red Hat Product Security, discovered an issue in condor, a distributed workload management system. Upon job completion, it can optionally notify a user by sending an email; the mailx invocation used in that process allowed for any authenticated user . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3149-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Sebastien Delafond February 02, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : condor CVE ID : CVE-2014-8126 Debian Bug : 775276 Florian Weimer, of Red Hat Product Security, discovered an issue in condor, a distributed workload management system. Upon job completion, it can optionally notify a user by sending an email; the mailx invocation used in that process allowed for any authenticated user able to submit jobs, to execute arbitrary code with the privileges of the condor user. For the stable distribution (wheezy), this problem has been fixed in version 7.8.2~dfsg.1-1+deb7u3. For the upcoming stable distribution (jessie) and unstable distribution (sid), this problem has been fixed in version 8.2.3~dfsg.1-6. We recommend that you upgrade your condor packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-3150-1 addresses a vulnerability in the samba package that may permit unauthorized access to system files.. Debian Security Advisory, Condor Management System, Code Execution Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 02, 2015 Critical Debian
87

Debian: DSA-3116-1 Moderate: Polarssl Memory Leak DoS Issue

It was discovered that a memory leak in parsing X.509 certificates may result in denial of service. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3116-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff December 30, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : polarssl CVE ID : CVE-2014-8628 It was discovered that a memory leak in parsing X.509 certificates may result in denial of service. For the stable distribution (wheezy), this problem has been fixed in version 1.2.9-1~deb7u4. For the upcoming stable distribution (jessie), this problem has been fixed in version 1.3.9-1. For the unstable distribution (sid), this problem has been fixed in version 1.3.9-1. We recommend that you upgrade your polarssl packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A vulnerability in polarssl may result in unhandled memory consumption, causing service outages. Ensure to update your software packages to maintain the security of your Debian system.. polarssl update, Denial of Service Fix, Debian Security Management. . LinuxSecurity.com Team

Calendar%202 Dec 30, 2014 Debian
87

Debian Wheezy: DSA-3110-1 Moderate XSS Threat in Mediawiki Update

A flaw was discovered in mediawiki, a wiki engine: thumb.php outputs wikitext messages as raw HTML, potentially leading to cross-site scripting (XSS). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3110-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Sebastien Delafond December 23, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mediawiki Debian Bug : 773654 A flaw was discovered in mediawiki, a wiki engine: thumb.php outputs wikitext messages as raw HTML, potentially leading to cross-site scripting (XSS). For the stable distribution (wheezy), this problem has been fixed in version 1.19.20+dfsg-0+deb7u3; this version additionally fixes a regression introduced in the previous release, DSA-3100-1. For the upcoming stable distribution (jessie) and unstable distribution (sid), this problem has been fixed in version 1:1.19.20+dfsg-2.2. We recommend that you upgrade your mediawiki packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Bulletin DSA-3110-2 concerns a mediawiki vulnerability impacting thumb.php; update strongly advised.. Debian Security, Mediawiki Update, XSS Flaw, Security Patch. . LinuxSecurity.com Team

Calendar%202 Dec 23, 2014 Debian
87

Debian 3.2: DSA-3094-1 Critical: Linux Kernel Service Denial Exploit

Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation: CVE-2014-7841 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3093-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso December 08, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : linux CVE ID : CVE-2014-7841 CVE-2014-8369 CVE-2014-8884 CVE-2014-9090 Several vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or privilege escalation: CVE-2014-7841 Liu Wei of Red Hat discovered that a SCTP server doing ASCONF will panic on malformed INIT chunks by triggering a NULL pointer dereference. CVE-2014-8369 A flaw was discovered in the way iommu mapping failures were handled in the kvm_iommu_map_pages() function in the Linux kernel. A guest OS user could exploit this flaw to cause a denial of service (host OS memory corruption) or possibly have other unspecified impact on the host OS. CVE-2014-8884 A stack-based buffer overflow flaw was discovered in the TechnoTrend/Hauppauge DEC USB driver. A local user with write access to the corresponding device could use this flaw to crash the kernel or, potentially, elevate their privileges. CVE-2014-9090 Andy Lutomirski discovered that the do_double_fault function in arch/x86/kernel/traps.c in the Linux kernel did not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to cause a denial of service (panic). For the stable distribution (wheezy), these problems have been fixed in version 3.2.63-2+deb7u2. This update also includes fixes for regressions introduced by previous updates. For the unstable distribution (sid), these problems will be fixed soon inversion 3.16.7-ckt2-1. We recommend that you upgrade your linux packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . On January 15, 2015, Ubuntu addressed multiple security flaws in the kernel that posed risks of service interruption and unauthorized privilege elevation.. Debian Kernel Update, Denial of Service, Security Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 2014 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200