Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 499
Alerts This Week
Warning Icon 1 499

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
87

Debian 11 and 12: DSA-5544-1 Moderate: Zookeeper Authentication Issue

Damien Diederen discovered that SASL quorum peer authentication within Zookeeper, a service for maintaining configuration information, was insufficiently enforced in some configurations. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5544-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff October 31, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zookeeper CVE ID : CVE-2023-44981 Damien Diederen discovered that SASL quorum peer authentication within Zookeeper, a service for maintaining configuration information, was insufficiently enforced in some configurations. For the oldstable distribution (bullseye), this problem has been fixed in version 3.4.13-6+deb11u1. For the stable distribution (bookworm), this problem has been fixed in version 3.8.0-11+deb12u1. We recommend that you upgrade your zookeeper packages. For the detailed security status of zookeeper please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zookeeper Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . SASL cluster integrity validation resolved in Zookeeper for Ubuntu. Update advised for improved safety.. Debian Security,Zookeeper SASL,Security Advisory DSA-5544-1,Authentication Issues. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2023 Debian
197

Debian 10: DLA-3624-1 Critical: Zookeeper Authentication Bypass

It was discovered that there was a potential authorisation bypass vulnerability in Apache Zookeeper, a co-ordination service for reliable distributed applications. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3624-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Chris Lamb October 20, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : zookeeper Version : 3.4.13-2+deb10u1 CVE ID : CVE-2023-44981 Debian Bug : 1054224 It was discovered that there was a potential authorisation bypass vulnerability in Apache Zookeeper, a co-ordination service for reliable distributed applications. Specifically, if SASL Quorum Peer authentication was enabled via quorum.auth.enableSasl, authorisation was performed by verifying that the instance part in the SASL authentication ID was listed in the zoo.cfg server list. However, this value is optional, and, if missing (such as in This email address is being protected from spambots. You need JavaScript enabled to view it.'), the authorisation check will be skipped. As a result, an arbitrary endpoint could join the cluster and begin propagating counterfeit changes to the leader, essentially giving it complete read-write access to the data tree. For Debian 10 buster, this problem has been fixed in version 3.4.13-2+deb10u1. We recommend that you upgrade your zookeeper packages. For the detailed security status of zookeeper please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zookeeper Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A recent security alert for Debian LTS updates the Postfix mail server to address a vulnerability related to email spoofing in version 3.4.14-1+deb10u2.. Debian LTS,Zookeeper Update,Authorization Bypass. .Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 21, 2023 Critical Debian LTS
100

SUSE: 2022:0133-1 Important: OpenStack Monasca Agent Security Fix

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openstack-monasca-agent, spark, spark-kit, zookeeper ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0133-1 Rating: important References: #1193662 Cross-References: CVE-2021-4104 CVSS scores: CVE-2021-4104 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 9 SUSE OpenStack Cloud 9 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openstack-monasca-agent, spark, spark-kit, zookeeper fixes the following issues: - CVE-2021-4104: Remove JMSAppender from log4j jars (bsc#1193662) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 9: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-9-2022-133=1 - SUSE OpenStack Cloud 9: zypper in -t patch SUSE-OpenStack-Cloud-9-2022-133=1 Package List: - SUSE OpenStack Cloud Crowbar 9 (noarch): openstack-monasca-agent-2.8.2~dev5-3.15.1 python-monasca-agent-2.8.2~dev5-3.15.1 spark-2.2.3-5.6.1 zookeeper-server-3.4.13-3.9.1 - SUSE OpenStack Cloud 9 (noarch): openstack-monasca-agent-2.8.2~dev5-3.15.1 python-monasca-agent-2.8.2~dev5-3.15.1 spark-2.2.3-5.6.1 venv-openstack-monasca-x86_64-2.7.1~dev10-3.29.1 zookeeper-server-3.4.13-3.9.1 References: https://www.suse.com/security/cve/CVE-2021-4104.html https://bugzilla.suse.com/1193662 . SUSE Security Bulletin: Mitigating significant vulnerabilities in openstack-monasca-collector and associated components.. SUSEOpenStack Security, Security Patch, OpenStack Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 20, 2022 Important SuSE
100

SUSE: 2022:0126-1 Important Update For OpenStack, Spark, Zookeeper

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for openstack-monasca-agent, spark, spark-kit, zookeeper ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:0126-1 Rating: important References: #1193662 Cross-References: CVE-2021-4104 CVSS scores: CVE-2021-4104 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 HPE Helion Openstack 8 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for openstack-monasca-agent, spark, spark-kit, zookeeper fixes the following issues: - CVE-2021-4104: Remove JMSAppender from log4j jars (bsc#1193662) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2022-126=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2022-126=1 - HPE Helion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2022-126=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 zookeeper-server-3.4.10-3.12.1 - SUSE OpenStack Cloud 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 venv-openstack-monasca-x86_64-2.2.2~dev1-11.37.1 zookeeper-server-3.4.10-3.12.1 - HPE Helion Openstack 8 (noarch): openstack-monasca-agent-2.2.6~dev4-3.24.1 python-monasca-agent-2.2.6~dev4-3.24.1 spark-1.6.3-8.9.2 venv-openstack-monasca-x86_64-2.2.2~dev1-11.37.1 zookeeper-server-3.4.10-3.12.1 References: https://www.suse.com/security/cve/CVE-2021-4104.html https://bugzilla.suse.com/1193662 . SUSE has issued a critical security patch that resolves an issue found in openstack-monasca-agent as well as various other modules.. SUSE Security Update, OpenStack Patch, Log4j Issue, Spark Security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jan 19, 2022 Important SuSE
87

Debian: DSA-4461-1 Moderate: Zookeeper Information Disclosure

Harrison Neil discovered that the getACL() command in Zookeeper, a service for maintaining configuration information, did not validate permissions, which could result in information disclosure. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4461-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 12, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zookeeper CVE ID : CVE-2019-0201 Harrison Neil discovered that the getACL() command in Zookeeper, a service for maintaining configuration information, did not validate permissions, which could result in information disclosure. For the stable distribution (stretch), this problem has been fixed in version 3.4.9-3+deb9u2. We recommend that you upgrade your zookeeper packages. For the detailed security status of zookeeper please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zookeeper Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your Zookeeper installations by updating the packages to resolve the ACL permission checks, ensuring improved security protocols.. zookeeper security update, debian advisory dsa-4461-1, acl permission issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2019 Important Debian
197

Debian 8 Jessie: DLA-1801-1 Critical: Zookeeper Access Control Issue

It was discovered that there was an information disclosure vulnerability in zookeeper, a distributed co-ordination server. Users who were not authorised to read data were able to view the access control list. . Package : zookeeper Version : 3.4.9-3+deb8u2 CVE ID : CVE-2019-0201 Debian Bug : #929283 It was discovered that there was an information disclosure vulnerability in zookeeper, a distributed co-ordination server. Users who were not authorised to read data were able to view the access control list. For Debian 8 "Jessie", this issue has been fixed in zookeeper version 3.4.9-3+deb8u2. We recommend that you upgrade your zookeeper packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Package : zookeeper Version : 3.4.9-3+deb8u2 CVE ID : CVE-2019-0201 Debian Bug : #929283 It was disc. there, information, disclosure, vulnerability, zookeeper, distributed. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 24, 2019 Critical Debian LTS
87

Debian: DSA-4214-1 Moderate: Zookeeper Access Control Flaw

It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4214-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 01, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : zookeeper CVE ID : CVE-2018-8012 It was discovered that Zookeeper, a service for maintaining configuration information, enforced no authentication/authorisation when a server attempts to join a Zookeeper quorum. This update backports authentication support. Additional configuration steps are needed, please see https://cwiki.apache.org/confluence/display/ZOOKEEPER/Server-Server+mutual+authentication for additional information. For the oldstable distribution (jessie), this problem has been fixed in version 3.4.9-3+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 3.4.9-3+deb9u1. We recommend that you upgrade your zookeeper packages. For the detailed security status of zookeeper please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/zookeeper Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Database managers rectify access authentication errors during quorum integration. Update for improved safety.. Zookeeper Security, Debian Advisory, Configuration Management, Authentication Control, Server Security. . LinuxSecurity.com Team

Calendar%202 Jun 01, 2018 Debian
197

Debian 7 Wheezy: DLA-986-1 Moderate: Zookeeper DoS Mitigation

It was discovered that Zookeeper, a service for maintaining configuration information, didn't restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption. . Hash: SHA512 Package : zookeeper Version : 3.4.5+dfsg-2+deb7u1 CVE ID : CVE-2017-5637 Debian Bug : 863811 It was discovered that Zookeeper, a service for maintaining configuration information, didn't restrict access to the computationally expensive wchp/wchc commands which could result in denial of service by elevated CPU consumption. This update disables those two commands by default. The new configuration option "4lw.commands.whitelist" can be used to whitelist commands selectively (and the full set of commands can be restored with '*') For Debian 7 "Wheezy", these problems have been fixed in version 3.4.5+dfsg-2+deb7u1. We recommend that you upgrade your zookeeper packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The configuration adjustment in the database management utility limits command access to mitigate risks of service unavailability and CPU overload scenarios.. Zookeeper Update, Debian Security, Service Hardening. . LinuxSecurity.com Team

Calendar%202 Jun 15, 2017 Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200