Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 5 articles for you...
81

SUSE Linux: Mozilla VPN Client Security Advisory for Integrity Breach

A cybersecurity researcher from SUSE, a Linux distribution manufacturer, has made public a serious security flaw in the Mozilla VPN client for Linux. . Mozilla has been slow to correct it. Yet this vulnerability could enable malicious actors to commit a host of integrity violations. In an article published on Openwall, Matthias Gerstner mentions a faulty authentication check in the Mozilla VPN Client v2.14.1. This vulnerability was discovered when, as part of a standard procedure, SUSE engineers analyzed the Mozilla VPN client before adding it to openSUSE Tumbleweed, a Linux distribution. The analysis showed that the VPN software “contains a privileged D-Bus service running as root and a Polkit policy”, which basically means that the D-Bus call will work for any user account, regardless of privileges. . A critical vulnerability in the Mozilla VPN application for Linux has been discovered, potentially resulting in various integrity violations. Explore further insights here.. Mozilla VPN, Integrity Breach, SUSE Linux, D-Bus Service, Cybersecurity Issue. . LinuxSecurity.com Team

Calendar 2 Aug 21, 2023 User Avatar LinuxSecurity.com Team Privacy
67

SUSE: Mozilla VPN Authentication Flaw Advisory - Critical Exploit Risk

A security engineer at Linux distro maker SUSE has published an advisory for a flaw in the Mozilla VPN client for Linux that has yet to be addressed in a publicly released fix because the disclosure process went off the rails. . In a post to the Openwall security mailing list, Matthias Gerstner describes a broken authentication check in Mozilla VPN client v2.14.1 , released on May 30. Essentially, the client can be exploited by any user on a system to, among other things, configure their own arbitrary VPN setup, redirect network traffic to outside parties, and break existing VPN setups. That's no good on shared computers with multiple users. The issue was identified, says Gerstner, when an openSUSE community manager wanted to add the Mozilla VPN client to openSUSE Tumbleweed , a Linux distribution. The software was reviewed by the SUSE security team, a standard procedure, and they found the VPN software "contains a privileged D-Bus service running as root and a Polkit policy." . Lena Schmidt uncovers vulnerabilities within the Telegram Messenger app, exposing risks of unauthorized data access.. Mozilla VPN,SUSE Security,Auth Exploit,Linux Security Advisory. . LinuxSecurity.com Team

Calendar 2 Aug 07, 2023 User Avatar LinuxSecurity.com Team Cryptography
77

Linux Kernel: Critical Zero Day Flaw Allows Dos via KSMBD

This flaw , which has been identified that affects the ksmbd NTLMv2 authentication in the Linux kernel, is known to quickly cause the operating system on Linux-based computers to crash. Namjae Jeon is the developer of KSMBD, which is an open-source In-kernel CIFS/SMB3 server designed for the Linux Kernel. . It is an implementation of the SMB/CIFS protocol in the kernel space that allows for the sharing of IPC services and files over a network. In order to take advantage of the vulnerability, you will need to transmit corrupted packets to the server, personal computer, tablet, or smartphone that you are targeting. The attack causes what is known as “a memory overflow flaw in ksmbd decodentlmssp auth blob,” which states that nt len may be less than CIFS ENCPWD SIZE in some circumstances. Because of this, the blen parameter that is sent to ksmbd authntlmv2, which runs memcpy using blen on memory that was allocated by kmalloc(blen + CIFS CRYPTO KEY SIZE), is now negative. It is important to take note that the CIFS ENCPWD SIZE value is 16, and the CIFS CRYPTO KEY SIZE value is 8. As the heap overflow happens when blen is in the range [-8, -1], we think that the only possible outcome of this problem is a remote denial of service and not a privilege escalation or a remote code execution. . A serious vulnerability in the Linux kernel's ksmbd enables attackers to execute remote denial of service through malicious packets. Prompt remediation is recommended.. Linux Kernel,kSMBD,DoS Attack,Authentication Flaw. . LinuxSecurity.com Team

Calendar 2 Jan 15, 2023 User Avatar LinuxSecurity.com Team Server Security
210

Sudo: Local User Root Access Advisory with Important Security Fix

A dangerous (but now-fixed) Sudo vulnerability allowed any local user to gain root privileges on Linux systems without requiring authentication. . Sudo is a Unix program that enables system admins to provide limited root privileges to normal users listed in the sudoers file, while at the same time keeping a log of their activity. It works on the Principle of Least Privilege where the program gives people just enough permissions to get their work done without compromising the system's overall security. . Sudo is a command-line utility in Unix-like systems that allows system administrators to grant specified users elevated access to run commands as the superuser or another user.. Sudo Vulnerability, Root Access, Linux Security, User Privileges. . Brittany Day

Calendar 2 Jan 27, 2021 User Avatar Brittany Day Security Vulnerabilities
81

Exposed iSCSI Storage Clusters Present Major Data Breach Threats

Over 13,000 iSCSI storage clusters are currently accessible via the internet after their respective owners forgot to enable authentication. . This misconfiguration has the risk of causing serious harm to devices' owners, as cyber-criminal groups could access these internet-accessible hard drives (storage disk arrays and NAS devices) to replace legitimate files with malware, insert backdoors inside backups, or steal company information stored on the unprotected devices. The link for this article located at ZDNet is no longer available. . More than 12,000 open SMB file shares can be found on the internet, posing a threat of unapproved access and possible information leaks.. iSCSI Access Risk, Storage Cluster Security, Internet Vulnerability. . LinuxSecurity.com Team

Calendar 2 Apr 02, 2019 User Avatar LinuxSecurity.com Team Privacy
83

Nikon: Security Flaw in Image Authentication Allows Forged Images

Russian encryption specialist ElcomSoft has discovered flaws in Nikon's systems for ensuring that images have not been tampered with.. The flaw in Nikon's Image Authentication System creates a means to produce forged pictures that would successfully pass validation checks. The security weakness uncovered by ElcomSoft revolves around cryptographic shortcomings in how the secure image signing key is handled by Nikon digital cameras. The shortcoming created a means for researchers to extract the original signing key from a Nikon camera. This, in turn, facilitated the creating of manipulated images with a fully valid authentication signature, as explained in greater detail here. The link for this article located at The Register UK is no longer available. . Canon's Photo Verification vulnerability enables counterfeit photos to be validated, threatening digital authenticity.. Nikon Image Security, Authentication Flaws, Tampering Risks, Cryptographic Weaknesses. . LinuxSecurity.com Team

Calendar 2 May 05, 2011 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

University of Michigan: RSA Authentication Flaw and Voltage Attack

Three University of Michigan computer scientists say they have found a way to exploit a weakness in RSA security technology used to protect everything from media players to smartphones and e-commerce servers. . RSA authentication is susceptible, they say, to changes in the voltage supplied to a private key holder. The researchers The link for this article located at Network World is no longer available. . Scientists reveal a power manipulation method targeting DSA verification, jeopardizing credential owners' protection and affecting technology broadly.. RSA Authentication, Authentication Flaws, Voltage Attack, Cryptography Research. . LinuxSecurity.com Team

Calendar 2 Mar 04, 2010 User Avatar LinuxSecurity.com Team Hacks/Cracks
67

IETF Security Advisory: SSL Protocol Fix for MITM Attack Severity Critical

The Internet Engineering Task Force (IETF) has completed a security extension to the Secure Sockets Layer (SSL) protocol that fixes a flaw affecting browsers, servers, smart cards, and VPN products, as well as many lower-profile devices, such as Webcams, that contain the protocol embedded in their firmware.. Members of the IETF, the Industry Consortium for the Advancement of Security on the Internet, and several vendors, including Google, Microsoft, and PhoneFactor, have been working on a fix since October for the bug, which is basically a gap in the authentication process that lets an attacker execute a man-in-the-middle (MITM) attack and inject his own text into the encrypted SSL connection. The gap occurs in the renegotiation process of the session, when some applications require the encryption process be refreshed at a certain point. Marsh Ray, a senior software development engineer for PhoneFactor who first discovered the SSL bug in August, says the IETF's extension to SSL, which is the Transport Layer Security (TLS) protocol in IETF parlance, secures the renegotiation process. "This is a short extension to the handshake protocol of TLS," Ray says. "Some identifiers from the previous session are carried over to the handshake in the subsequent session." The link for this article located at Dark Reading is no longer available. . Members of the IETF, the Industry Consortium for the Advancement of Security on the Internet, and se. internet, engineering, force, (ietf), completed, security, extension, secure, sockets. . LinuxSecurity.com Team

Calendar 2 Jan 13, 2010 User Avatar LinuxSecurity.com Team Cryptography
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here