Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

CentOS 8: 2021-8194acdeab Define: BIND DNS Server Misconfiguration

- Update to 4.6.2 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.2 ---- - Update to 4.6.1 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.1. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-8367cefdea 2022-04-20 19:09:32.222133 --------------------------------------------------------------------------------Name : pdns Product : Fedora 35 Version : 4.6.2 Release : 1.fc35 URL : https://www.powerdns.com/ Summary : A modern, advanced and high performance authoritative-only nameserver Description : The PowerDNS Nameserver is a modern, advanced and high performance authoritative-only nameserver. It is written from scratch and conforms to all relevant DNS standards documents. Furthermore, PowerDNS interfaces with almost any database. --------------------------------------------------------------------------------Update Information: - Update to 4.6.2 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.2 ---- -Update to 4.6.1 Release notes: https://doc.powerdns.com/authoritative/changelog/4.6.html#change-4.6.1 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 12 2022 Morten Stevens - 4.6.2-1 - Update to 4.6.2 * Sun Apr 10 2022 Morten Stevens - 4.6.1-1 - Update to 4.6.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #2069400 - CVE-2022-27227 pdns: pdns,pdns-recursor: Incomplete zone transfers handled as successful [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2069400 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-8367cefdea' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Upgrade to PowerDNS 4.6.2 to address crucial zone transfer vulnerabilities for Fedora 35. Make sure your nameserver is both secure and current.. PowerDNS Update, Fedora Advisory, Nameserver Security, Authority Nameserver, Zone Transfer Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 20, 2022 Critical Fedora
202

openSUSE: 2019:1533-1 Important: Bind Denial of Service Issues

An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for bind ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1533-1 Rating: important References: #1104129 #1126068 #1126069 #1133185 Cross-References: CVE-2018-5740 CVE-2018-5743 CVE-2018-5745 CVE-2019-6465 Affected Products: openSUSE Leap 15.1 openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for bind fixes the following issues: Security issues fixed: - CVE-2019-6465: Fixed an issue where controls for zone transfers may not be properly applied to Dynamically Loadable Zones (bsc#1126069). - CVE-2018-5745: Fixed a denial of service vulnerability if a trust anchor rolls over to an unsupported key algorithm when using managed-keys (bsc#1126068). - CVE-2018-5743: Fixed a denial of service vulnerability which could be caused by to many simultaneous TCP connections (bsc#1133185). - CVE-2018-5740: Fixed a denial of service vulnerability in the "deny-answer-aliases" feature (bsc#1104129). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1533=1 - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1533=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): bind-9.11.2-lp151.11.3.1 bind-chrootenv-9.11.2-lp151.11.3.1 bind-debuginfo-9.11.2-lp151.11.3.1 bind-debugsource-9.11.2-lp151.11.3.1 bind-devel-9.11.2-lp151.11.3.1 bind-lwresd-9.11.2-lp151.11.3.1 bind-lwresd-debuginfo-9.11.2-lp151.11.3.1 bind-utils-9.11.2-lp151.11.3.1 bind-utils-debuginfo-9.11.2-lp151.11.3.1 libbind9-160-9.11.2-lp151.11.3.1 libbind9-160-debuginfo-9.11.2-lp151.11.3.1 libdns169-9.11.2-lp151.11.3.1 libdns169-debuginfo-9.11.2-lp151.11.3.1 libirs-devel-9.11.2-lp151.11.3.1 libirs160-9.11.2-lp151.11.3.1 libirs160-debuginfo-9.11.2-lp151.11.3.1 libisc166-9.11.2-lp151.11.3.1 libisc166-debuginfo-9.11.2-lp151.11.3.1 libisccc160-9.11.2-lp151.11.3.1 libisccc160-debuginfo-9.11.2-lp151.11.3.1 libisccfg160-9.11.2-lp151.11.3.1 libisccfg160-debuginfo-9.11.2-lp151.11.3.1 liblwres160-9.11.2-lp151.11.3.1 liblwres160-debuginfo-9.11.2-lp151.11.3.1 - openSUSE Leap 15.1 (x86_64): bind-devel-32bit-9.11.2-lp151.11.3.1 libbind9-160-32bit-9.11.2-lp151.11.3.1 libbind9-160-32bit-debuginfo-9.11.2-lp151.11.3.1 libdns169-32bit-9.11.2-lp151.11.3.1 libdns169-32bit-debuginfo-9.11.2-lp151.11.3.1 libirs160-32bit-9.11.2-lp151.11.3.1 libirs160-32bit-debuginfo-9.11.2-lp151.11.3.1 libisc166-32bit-9.11.2-lp151.11.3.1 libisc166-32bit-debuginfo-9.11.2-lp151.11.3.1 libisccc160-32bit-9.11.2-lp151.11.3.1 libisccc160-32bit-debuginfo-9.11.2-lp151.11.3.1 libisccfg160-32bit-9.11.2-lp151.11.3.1 libisccfg160-32bit-debuginfo-9.11.2-lp151.11.3.1 liblwres160-32bit-9.11.2-lp151.11.3.1 liblwres160-32bit-debuginfo-9.11.2-lp151.11.3.1 - openSUSE Leap 15.1 (noarch): bind-doc-9.11.2-lp151.11.3.1 python3-bind-9.11.2-lp151.11.3.1 - openSUSE Leap 15.0 (i586 x86_64): bind-9.11.2-lp150.8.13.1 bind-chrootenv-9.11.2-lp150.8.13.1 bind-debuginfo-9.11.2-lp150.8.13.1 bind-debugsource-9.11.2-lp150.8.13.1 bind-devel-9.11.2-lp150.8.13.1 bind-lwresd-9.11.2-lp150.8.13.1 bind-lwresd-debuginfo-9.11.2-lp150.8.13.1 bind-utils-9.11.2-lp150.8.13.1 bind-utils-debuginfo-9.11.2-lp150.8.13.1 libbind9-160-9.11.2-lp150.8.13.1 libbind9-160-debuginfo-9.11.2-lp150.8.13.1 libdns169-9.11.2-lp150.8.13.1 libdns169-debuginfo-9.11.2-lp150.8.13.1 libirs-devel-9.11.2-lp150.8.13.1 libirs160-9.11.2-lp150.8.13.1 libirs160-debuginfo-9.11.2-lp150.8.13.1 libisc166-9.11.2-lp150.8.13.1 libisc166-debuginfo-9.11.2-lp150.8.13.1 libisccc160-9.11.2-lp150.8.13.1 libisccc160-debuginfo-9.11.2-lp150.8.13.1 libisccfg160-9.11.2-lp150.8.13.1 libisccfg160-debuginfo-9.11.2-lp150.8.13.1 liblwres160-9.11.2-lp150.8.13.1 liblwres160-debuginfo-9.11.2-lp150.8.13.1 - openSUSE Leap 15.0 (noarch): bind-doc-9.11.2-lp150.8.13.1 python3-bind-9.11.2-lp150.8.13.1 - openSUSE Leap 15.0 (x86_64): bind-devel-32bit-9.11.2-lp150.8.13.1 libbind9-160-32bit-9.11.2-lp150.8.13.1 libbind9-160-32bit-debuginfo-9.11.2-lp150.8.13.1 libdns169-32bit-9.11.2-lp150.8.13.1 libdns169-32bit-debuginfo-9.11.2-lp150.8.13.1 libirs160-32bit-9.11.2-lp150.8.13.1 libirs160-32bit-debuginfo-9.11.2-lp150.8.13.1 libisc166-32bit-9.11.2-lp150.8.13.1 libisc166-32bit-debuginfo-9.11.2-lp150.8.13.1 libisccc160-32bit-9.11.2-lp150.8.13.1 libisccc160-32bit-debuginfo-9.11.2-lp150.8.13.1 libisccfg160-32bit-9.11.2-lp150.8.13.1 libisccfg160-32bit-debuginfo-9.11.2-lp150.8.13.1 liblwres160-32bit-9.11.2-lp150.8.13.1 liblwres160-32bit-debuginfo-9.11.2-lp150.8.13.1 References: https://www.suse.com/security/cve/CVE-2018-5740.html https://www.suse.com/security/cve/CVE-2018-5743.html https://www.suse.com/security/cve/CVE-2018-5745.html https://www.suse.com/security/cve/CVE-2019-6465.html https://bugzilla.suse.com/1104129 https://bugzilla.suse.com/1126068 https://bugzilla.suse.com/1126069 https://bugzilla.suse.com/1133185 -- . Crucial openSUSE security patch for bind addresses multiple significant vulnerabilities. Discover thespecifics of the issues and resolutions available now.. openSUSE Security, bind update, denial of service, security fix, system vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 10, 2019 Important OpenSUSE
197

Debian: DLA-1697-1 Critical: Bind9 Zone Transfer Vulnerability Alert

Two issues have been found in bind9, the Internet Domain Name Server. CVE-2019-6465 . Package : bind9 Version : 1:9.9.5.dfsg-9+deb8u17 CVE ID : CVE-2018-5745 CVE-2019-6465 Two issues have been found in bind9, the Internet Domain Name Server. CVE-2019-6465 Zone transfer for DLZs are executed though not permitted by ACLs. CVE-2018-5745 Avoid assertion and thus causing named to deliberately exit when a trust anchor's key is replaced with a key which uses an unsupported algorithm. For Debian 8 "Jessie", these problems have been fixed in version 1:9.9.5.dfsg-9+deb8u17. We recommend that you upgrade your bind9 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : bind9 Version : 1:9.9.5.dfsg-9+deb8u17 CVE ID : CVE-2018-5745 CVE-2019-6465 Two issues hav. bind9, found, internet, domain, server, cve-2019-6465, package. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 28, 2019 Critical Debian LTS
172

Ubuntu 12.04 ESM USN-3346-3 Critical: Bind Zone Transfer Threat

Bind could be made to serve incorrect information or expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-3346-3 November 08, 2017 bind9 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Bind could be made to serve incorrect information or expose sensitive information over the network. Software Description: - bind9: Internet Domain Name Server Details: USN-3346-1 and USN-3346-2 fixed two vulnerabilities in Bind and a regression, respectively. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone update requests. An attacker could use this to improperly perform zone updates. (CVE-2017-3143) Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone transfer requests. An attacker could use this to improperly transfer entire zones. (CVE-2017-3142) In addition, this update adds the new root zone key signing key (KSK). Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: bind9 1:9.8.1.dfsg.P1-4ubuntu0.23 After a standard system update you need to restart Bind to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3346-1 CVE-2017-3142, CVE-2017-3143 . Exploitable flaws in Ubuntu systems can result in data breaches or misrouted information. It is recommended to apply updates.. Bind9 Threats, Ubuntu Security Update, Zone Transfer Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 08, 2017 Critical Ubuntu
89

Fedora 24: FEDORA-2017-001f135337 Moderate: bind-dyndb-ldap Security Update

Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-001f135337 2017-07-11 18:56:33.196447 --------------------------------------------------------------------------------Name : bind-dyndb-ldap Product : Fedora 24 Version : 10.1 Release : 2.fc24 URL : https://pagure.io/bind-dyndb-ldap Summary : LDAP back-end plug-in for BIND Description : This package provides an LDAP back-end plug-in for BIND. It features support for dynamic updates and internal caching, to lift the load off of your LDAP server. --------------------------------------------------------------------------------Update Information: Update back to ISC supported version. Security fix for CVE-2017-3143, CVE-2017-3142, CVE-2017-3140 --------------------------------------------------------------------------------References: [ 1 ] Bug #1466193 - CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates https://bugzilla.redhat.com/show_bug.cgi?id=1466193 [ 2 ] Bug #1461302 - CVE-2017-3140 bind: Error processing RPZ rules leads to endless loop while handling query https://bugzilla.redhat.com/show_bug.cgi?id=1461302 [ 3 ] Bug #1466189 - CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers https://bugzilla.redhat.com/show_bug.cgi?id=1466189 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind-dyndb-ldap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent security patch for bind-dyndb-ldap in Fedora 24 resolves several vulnerabilities concerning dynamic updates and zone transfers.. bind-dyndb-ldap Security Update,Fedora 24 Update,Dyamic Updates Security,Zone Transfer Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 12, 2017 Important Fedora
89

Fedora 27: 2018-4dca7je64b Minor: BIND Authorization Vulnerabilities

Update to last supported version, fixes CVE-2017-3142 and CVE-2017-3143. Includes minor fix of missing dependencies.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-30f678e62a 2017-07-07 22:40:59.830090 --------------------------------------------------------------------------------Name : bind Product : Fedora 26 Version : 9.11.1 Release : 2.P2.fc26 URL : Summary : The Berkeley Internet Name Domain (BIND) DNS (Domain Name System) server Description : BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. BIND includes a DNS server (named), which resolves host names to IP addresses; a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating properly. --------------------------------------------------------------------------------Update Information: Update to last supported version, fixes CVE-2017-3142 and CVE-2017-3143. Includes minor fix of missing dependencies. --------------------------------------------------------------------------------References: [ 1 ] Bug #1466189 - CVE-2017-3142 bind: An error in TSIG authentication can permit unauthorized zone transfers https://bugzilla.redhat.com/show_bug.cgi?id=1466189 [ 2 ] Bug #1466193 - CVE-2017-3143 bind: An error in TSIG authentication can permit unauthorized dynamic updates https://bugzilla.redhat.com/show_bug.cgi?id=1466193 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade bind' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 bind security patch addresses various vulnerabilities and enhances dependency management for improved efficiency.. bind Security Update,Fedora 26,DNS Server,Authentication Flaw. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 07, 2017 Important Fedora
172

Ubuntu 17.04: USN-3346-1 Moderate: bind9 Zone Transfer Threat

Bind could be made to serve incorrect information or expose sensitive information over the network.. =========================================================================Ubuntu Security Notice USN-3346-1 June 29, 2017 bind9 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Bind could be made to serve incorrect information or expose sensitive information over the network. Software Description: - bind9: Internet Domain Name Server Details: Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone update requests. An attacker could use this to improperly perform zone updates. (CVE-2017-3143) Clément Berthaux discovered that Bind did not correctly check TSIG authentication for zone transfer requests. An attacker could use this to improperly transfer entire zones. (CVE-2017-3142) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: bind9 1:9.10.3.dfsg.P4-10.1ubuntu5.1 Ubuntu 16.10: bind9 1:9.10.3.dfsg.P4-10.1ubuntu1.7 Ubuntu 16.04 LTS: bind9 1:9.10.3.dfsg.P4-8ubuntu1.7 Ubuntu 14.04 LTS: bind9 1:9.9.5.dfsg-3ubuntu0.15 After a standard system update you need to restart Bind to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3346-1 CVE-2017-3142, CVE-2017-3143 Package Information: https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu5.1 https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-10.1ubuntu1.7 https://launchpad.net/ubuntu/+source/bind9/1:9.10.3.dfsg.P4-8ubuntu1.7 https://launchpad.net/ubuntu/+source/bind9/1:9.9.5.dfsg-3ubuntu0.15 . Urgent update for Ubuntuusers regarding Bind9 security vulnerabilities that may expose sensitive data. Apply the recommended updates to protect your system. bind9 Updates, Ubuntu Security Notices, Network Risks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 29, 2017 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200