Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
198

Arch Linux: 202009-14 High: Yaws Command Execution and Disclosure

The package yaws before version 2.0.8-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure. . Arch Linux Security Advisory ASA-202009-14 ========================================= Severity: High Date : 2020-09-26 CVE-ID : CVE-2020-12872 CVE-2020-24379 CVE-2020-24916 Package : yaws Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-1228 Summary ====== The package yaws before version 2.0.8-1 is vulnerable to multiple issues including arbitrary command execution and information disclosure. Resolution ========= Upgrade to 2.0.8-1. # pacman -Syu "yaws> =2.0.8-1" The problems have been fixed upstream in version 2.0.8. Workaround ========= None. Description ========== - CVE-2020-12872 (information disclosure) yaws_config.erl in Yaws through 2.0.7 loads obsolete TLS ciphers, as demonstrated by ones that allow Sweet32 attacks. - CVE-2020-24379 (information disclosure) WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection. - CVE-2020-24916 (arbitrary command execution) CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection. Impact ===== A remote attacker might be able to execute arbitrary commands, downgrade TLS ciphers, or load foreign entities via craftedcontent. References ========= https://github.com/erlyaws/yaws/releases/tag/yaws-2.0.8 https://vulnbe.github.io/post/yaws-xxe-and-shell-injections/ https://sweet32.info/ https://medium.com/@charlielabs101/cve-2020-12872-df315411aa70 https://packetstorm.news/tos/aHR0cHM6Ly9wYWNrZXRzdG9ybS5uZXdzL2ZpbGVzL2lkLzE1OTEwNiAxNzM0NDg2NjIyIDY0MTE5NWMwNmJmMWU3MDdiYTYzYzIzNjE1NGQ1MmNlMWEyZWFiMjUzZjBlYTBjNjBkMGU0ODdmMDYyN2QwZTk= https://github.com/erlyaws/yaws/commit/05a06345012598f5da55dbb4d041c8dc26e88e6c https://github.com/vulnbe/poc-yaws-dav-xxe https://github.com/erlyaws/yaws/commit/799b3b526d15b7a9bc43ae97165aeb085f18fac1 https://github.com/vulnbe/poc-yaws-cgi-shell-injection https://security.archlinux.org/CVE-2020-12872 https://security.archlinux.org/CVE-2020-24379 https://security.archlinux.org/CVE-2020-24916 . The Arch Linux Security Bulletin regarding yaws draws attention to critical vulnerabilities, such as the potential for unauthorized remote command execution and sensitive information exposure.. yaws security, Arch Linux advisory, command execution risk, information disclosure issue. . LinuxSecurity.com Team

Calendar 2 Oct 06, 2020 ArchLinux
197

Debian LTS DLA-2384-1 Critical: Yaws Command Injection and XML Attacks

Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2384-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz September 26, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : yaws Version : 2.0.4+dfsg-1+deb9u1 CVE ID : CVE-2020-24379 CVE-2020-24916 Two issues have been found in yaws, a high performance HTTP 1.1 webserver written in Erlang. CVE-2020-24379 Reject external resource requests in DAV in order to avoid XML External Entity (XXE) attackes. CVE-2020-24916 Sanitize CGI executable in order to avoid command injection via CGI requests. For Debian 9 stretch, these problems have been fixed in version 2.0.4+dfsg-1+deb9u1. We recommend that you upgrade your yaws packages. For the detailed security status of yaws please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/yaws Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2384-1 highlights crucial security vulnerabilities in yaws, notably command injection and XML-related exploits.. Debian LTS, Yaws Update, Security Patch, XML External Entity, Command Injection. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 26, 2020 Critical Debian LTS
89

Fedora 30: Yaws Security Update - Critical Enhancements and Fixes

* Yaws ver. 2.0.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-aa7f37cd4d 2019-04-14 00:01:14.812568 --------------------------------------------------------------------------------Name : yaws Product : Fedora 30 Version : 2.0.6 Release : 1.fc30 URL : Summary : Web server for dynamic content written in Erlang Description : HTTP 1.0 and HTTP 1.1 web server capable of both static content page delivery and dynamic content generation using embedded Erlang code in the HTML pages. It provides virtual hosting capabilities and implements HTTP tracing and other debugging functionality such as interactive interpreter environment. Performance can be boosted with built-in support for RAM caching and streaming capabilities of dynamically generated content. Among security features are SSL and support for WWW-Authenticated pages. --------------------------------------------------------------------------------Update Information: * Yaws ver. 2.0.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1606767 - yaws: FTBFS in Fedora rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1606767 [ 2 ] Bug #1357922 - CVE-2016-1000108 yaws: sets environmental variable based on user supplied Proxy request header [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1357922 [ 3 ] Bug #1676256 - yaws: FTBFS in Fedora rawhide/f30 https://bugzilla.redhat.com/show_bug.cgi?id=1676256 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-aa7f37cd4d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by theFedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . --------------------------------------------------------------------------------Fedora Update Notifi. --------------------------------------------------------------------------------fe. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 13, 2019 Critical Fedora
87

Debian 5.0: DSA-1740-1 Critical: Yaws Remote Denial Of Service

It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1740-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steffen Joeris March 14, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : yaws Vulnerability : denial of service Problem type : remote Debian-specific: no CVE Id : CVE-2009-0751 It was discovered that yaws, a high performance HTTP 1.1 webserver, is prone to a denial of service attack via a request with a large HTTP header. For the stable distribution (lenny), this problem has been fixed in version 1.77-3+lenny1. For the oldstable distribution (etch), this problem has been fixed in version 1.65-4etch1. For the testing distribution (squeeze) and the unstable distribution (sid), this problem has been fixed in version 1.80-1. We recommend that you upgrade your yaws package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Debian (oldstable) - ------------------ Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 15050 de600331ea301eb9a8cd82987bbecac1 Size/MD5 checksum: 742 5ff0d18eaf5b0982cab087a0da30546b Size/MD5 checksum: 7759784c08ba6abb40e41a49066a4c35d66102 alpha architecture (DEC Alpha) Size/MD5 checksum: 920326 bcdde19abfa0509a7fec5980ae4c6977 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 922808 f69d7ec4e1082067e8ce2c5b35088ed7 arm architecture (ARM) Size/MD5 checksum: 921284 74360fb5c5ace09cde4a0afe9612b35e i386 architecture (Intel ia32) Size/MD5 checksum: 923758 b6f68cab4953d114197eecef7e89a5d7 ia64 architecture (Intel ia64) Size/MD5 checksum: 921190 be465d69af82a67b1d0a5e4bf6e21984 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 923582 fa6d77670fee39cfc6bd1cd0c5532786 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 919572 a235d55de32b60a838b0ca92fa2e5308 powerpc architecture (PowerPC) Size/MD5 checksum: 920814 23d52c172afae1269fccc7a536418fbe s390 architecture (IBM S/390) Size/MD5 checksum: 919460 39fca419254eaca0a843e4d5a8abfd5e sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 784600 ab81930fb47510802e13cd26cad09c73 Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 838170 7e01d9e8f4fe12895c76081ee4cf7754 Size/MD5 checksum: 1206 6b5844871553c42a824f401586aa46a1 Size/MD5 checksum: 19814 253cfc5da27428df313c4e8b4dfbf93a Architecture independent packages: Size/MD5 checksum: 200784 8731c7f94f6f3550f142f21d225d918d Size/MD5 checksum: 65076 65681b94bf96027c0684bb2d29db00e8 Size/MD5 checksum: 160840 efdcebae480d452dc628eb715e7f8b22 Size/MD5 checksum: 66196 b281bb1587101a3e83d50ffe1e92f6fd alpha architecture (DEC Alpha) Size/MD5 checksum: 652508 3e474dff842f080a6897958243c6c0d8 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 652258 03053ee15e1b92456785a08e91e5d7e5 arm architecture (ARM) Size/MD5 checksum: 651702 06e61922443dc30ab4c0b144c34a7a2e armel architecture (ARM EABI) Size/MD5 checksum: 649654 d752e8341ad8797bd0fb5879e53f07dd hppa architecture (HP PA RISC) Size/MD5 checksum: 652286 a87d4e8c7ed413812f8b59311c55a689 i386 architecture (Intel ia32) Size/MD5 checksum: 652642 de9b389be1cb7842b0d8584e0d0a1b18 ia64 architecture (Intel ia64) Size/MD5 checksum: 653308 f9b75201e1191fb8dd7cf158631a9c89 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 653008 874547bac10ca979bfeeb065ed895bff mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 651392 37c53dd40471f02f2dfea75c788ea5f5 powerpc architecture (PowerPC) Size/MD5 checksum: 654140 c90a7a7f66fd0e2093d502a5893d9e08 s390 architecture (IBM S/390) Size/MD5 checksum: 651624 e7ecaf982f7f027475b3c8275e63c8c8 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 651006 6fbb95dace09ead71d6f335322de5171 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian has issued an update for yaws to fix a vulnerability that may enable denial of service attacks through oversized HTTP headers. Upgrading is highly recommended for optimal security. Debian Security,Yaws Denial Fix,System Security Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2009 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here