Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Stay Ahead With Linux Security News

Filter%20icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -2 articles for you...
78

Libssh: Major Advisory on Authentication Bypass for Key Products

Products from major vendors such as F5 and Red Hat are affected by a major vulnerability that came to light this week and which resides in the libssh library.. The vulnerability, which is tracked in infosec circles as CVE-2018-10933, is an authentication bypass in the libssh code that handles server-side login procedures. The link for this article located at ZDNet is no longer available. . A significant vulnerability in libssh allows for authentication circumvention, affecting numerous vendor solutions.. libssh Security, Authentication Bypass, Vendor Impact, Software Flaw, Security Alert. . LinuxSecurity.com Team

Calendar%202 Oct 21, 2018 User Avatar LinuxSecurity.com Team Vendors/Products
77

LibSSH Critical Advisory: Bypass Password Protection for Server Access

A four-year-old severe vulnerability has been discovered in the Secure Shell (SSH) implementation library known as Libssh that could allow anyone to completely bypass authentication and gain unfettered administrative control over a vulnerable server without requiring a password.. The security vulnerability, tracked as CVE-2018-10933, is an authentication-bypass issue that was introduced in Libssh version 0.6 released earlier 2014, leaving thousands of enterprise servers open to hackers for the last four years. The link for this article located at The Hacker News is no longer available. . A critical vulnerability in OpenSSH allows cybercriminals to gain full access to systems, circumventing all security measures.. LibSSH, Authentication Bypass, Remote Exploitation. . LinuxSecurity.com Team

Calendar%202 Oct 17, 2018 User Avatar LinuxSecurity.com Team Server Security
79

Libssh 0.5.0 Enhances Asynchronous Functionality and Server Support

The developers of the multi-platform LGPLv2.1-licensed C library libssh, which implements SSHv2 (and SSHv1) on client and server side, have announced the release of version 0.5.0. According to the developers, there has been a rewrite of "huge parts of the libssh internals" to allow the library to be completely asynchronous in the future.. This involved moving from a synchronous to an event-based network design. Other changes in 0.5.0 include prefixing all public functions with ssh_, completing Windows support, improved server support, additional unit tests and the addition of an asynchronous service request and a multi-platform ssh_getpass() function. The developers have also added a tutorial and other documentation, fixed a number of bugs and reduced memory leaks. The improvements in libssh reduce the differences between it and libssh2, a BSD-licensed library with similar goals. The link for this article located at H Security is no longer available. . Release 0.5.0 of libssh brings enhanced asynchronous capabilities and expanded features for network architecture and server compatibility.. libssh, Asynchronous Support, Multi-Platform Library, SSH Protocol. . LinuxSecurity.com Team

Calendar%202 Jun 02, 2011 User Avatar LinuxSecurity.com Team Security Projects
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200