Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Ubuntu Security: USN-1234-1 Severe Data Exposure in Zoneminder

Multiple vulnerabilities have been found in zoneminder. This update fixes only a serious file disclosure vulnerability (CVE-2017-5595). The application has been found to suffer from many other problems . Hash: SHA512 Package : zoneminder Version : 1.25.0-4+deb7u2 CVE ID : CVE-2017-5595 Multiple vulnerabilities have been found in zoneminder. This update fixes only a serious file disclosure vulnerability (CVE-2017-5595). The application has been found to suffer from many other problems such as SQL injection vulnerabilities, cross-site scripting issues, cross-site request forgery, session fixation vulnerability. Due to the amount of issues and to the relative invasiveness of the relevant patches, those issues will not be fixed in Wheezy. We thus advise you to restrict access to zoneminder to trusted users only. If you want to review the list of ignored issues, you can check the security tracker: https://security-tracker.debian.org/tracker/source-package/zoneminder We recommend that you upgrade your zoneminder packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: https://www.freexian.com/lts/debian/ Learn to master Debian: https://debian-handbook.info/get/ . Various vulnerabilities in zoneminder resolved: limit access, enhance packages for security.. Zoneminder Security Update, File Disclosure, Debian LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 26, 2017 Critical Debian LTS
89

Fedora 24 Update: 2017-d5fb74cd2e Critical File Disclosure in Zoneminder

Security fix for CVE-2017-5595. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-d5fb74cd2e 2017-02-18 15:07:31.990596 -------------------------------------------------------------------------------- Name : zoneminder Product : Fedora 24 Version : 1.28.1 Release : 8.fc24 URL : https://zoneminder.com/ Summary : A camera monitoring and analysis tool Description : ZoneMinder is a set of applications which is intended to provide a complete solution allowing you to capture, analyse, record and monitor any cameras you have attached to a Linux based machine. It is designed to run on kernels which support the Video For Linux (V4L) interface and has been tested with cameras attached to BTTV cards, various USB cameras and IP network cameras. It is designed to support as many cameras as you can attach to your computer without too much degradation of performance. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-5595 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1419507 - CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input https://bugzilla.redhat.com/show_bug.cgi?id=1419507 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade zoneminder' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. Tounsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent security update for Information Exposure in ZoneMinder on Fedora 24 related to CVE-2017-5595. Please update immediately!. zoneminder Security,Fedora Update,File Disclosure,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 18, 2017 Critical Fedora
89

Fedora 26: FEDORA-2017-3cc284bc4d High: Nginx Path Traversal Vulnerability

Security fix for CVE-2017-5595. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-2bb174ae3c 2017-02-18 15:07:53.157167 -------------------------------------------------------------------------------- Name : zoneminder Product : Fedora 25 Version : 1.28.1 Release : 8.fc25 URL : https://zoneminder.com/ Summary : A camera monitoring and analysis tool Description : ZoneMinder is a set of applications which is intended to provide a complete solution allowing you to capture, analyse, record and monitor any cameras you have attached to a Linux based machine. It is designed to run on kernels which support the Video For Linux (V4L) interface and has been tested with cameras attached to BTTV cards, various USB cameras and IP network cameras. It is designed to support as many cameras as you can attach to your computer without too much degradation of performance. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-5595 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1419507 - CVE-2017-5595 zoneminder: File disclosure due to unfiltered user-input https://bugzilla.redhat.com/show_bug.cgi?id=1419507 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade zoneminder' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. . Important zoneminder patch for Fedora 25 tackling file exposure vulnerability, boosting protection for surveillance systems.. zoneminder Security, Fedora 25 Update, Camera Monitoring Security, File Disclosure Fix, Security Patch. . LinuxSecurity.com Team

Calendar 2 Feb 18, 2017 Fedora
87

Debian DSA-2640-1 Critical: Zoneminder Remote Code Exec & File Inclusion

Multiple vulnerabilities were discovered in zoneminder, a Linux video camera security and surveillance solution. The Common Vulnerabilities and Exposures project identifies the following problems: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2640-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso March 14, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zoneminder Vulnerability : several issues Problem type : remote Debian-specific: no CVE ID : CVE-2013-0232 CVE-2013-0332 Debian Bug : 698910 700912 Multiple vulnerabilities were discovered in zoneminder, a Linux video camera security and surveillance solution. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2013-0232 Brendan Coles discovered that zoneminder is prone to an arbitrary command execution vulnerability. Remote (authenticated) attackers could execute arbitrary commands as the web server user. CVE-2013-0332 zoneminder is prone to a local file inclusion vulnerability. Remote attackers could examine files on the system running zoneminder. For the stable distribution (squeeze), these problems have been fixed in version 1.24.2-8+squeeze1. For the testing distribution (wheezy), these problems have been fixed in version 1.25.0-4. For the unstable distribution (sid), these problems have been fixed in version 1.25.0-4. We recommend that you upgrade your zoneminder packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Important announcement concerning zoneminder to tackle vulnerabilities related to remote codeexecution and file inclusion on Debian systems. Immediate upgrade is advised.. Zoneminder Vulnerabilities, Debian Security Advisory, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 14, 2013 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here