Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found -3 articles for you...
210

Red Hat: CVE-2024-9050 Important: NetworkManager-libreswan Flaw

Red Hat recently discovered a severe flaw in the NetworkManager-libreswan plugin, allowing local attackers to escalate privileges and gain root access to impacted Linux systems. Tracked as CVE-2024-9050 , this vulnerability has received a Common Vulnerability Scoring System (CVSS) base score of 7.8, underscoring its high severity. . To help you understand this critical bug and measures you can take to practively secure your systems, I'll explain how it works, who is affected, and practical mitigation strategies we admins can implement to reduce risk. Let's begin by understanding the nature of this flaw. Understanding The Nature of This NetworkManager Flaw This vulnerability lies within the NetworkManager-libreswan plugin. It specifically involves its failure to properly sanitize VPN configurations from unprivileged users. The plugin utilizes an executable command, accepting a parameter known as leftupdown, which links NetworkManager-libreswan and NetworkManager for callback functions. The heart of the problem lies in the improper handling of special characters in key-value format configuration, which allows attackers to manipulate values so they are mistakenly taken as keys. Since NetworkManager uses Polkit for unprivileged users to manage network configurations, this vulnerability provides a possible route for local privilege escalation, leading to root-level code execution. What Is the Impact of This Bug on Affected Systems? This flaw affects multiple versions and platforms of Red Hat Enterprise Linux (RHEL), such as RHEL 9.0 Update Services for SAP Solutions and Red Hat Enterprise Linux Server AUS 7.7. Additionally, various architectures may be affected, such as x86_64, ppc64le, aarch64, and s390x. Red Hat has classified this security issue as "Important" and issued patches via multiple security advisories ( RHSA-2024:8312 and RHSA-2024:8338 ). Furthermore, NetworkManager-libreswan packages that address this vulnerability across platforms are now available. Systemadministrators should immediately upgrade affected systems to the latest versions despite available patches. Delaying updates leaves systems vulnerable to exploitation. Who Is at Risk? This vulnerability poses the greatest danger in environments where local users possess network configuration privileges. Server environments typically face lower risks because their local users usually don't have the permissions necessary to exploit this flaw. Still, their risk is higher when local users possess such privileges. Practical Mitigation Strategies for Red Hat Sysadmins System administrators can take various practical steps to mitigate vulnerabilities such as this flaw and secure their systems more effectively. Admins should update NetworkManager-libreswan packages immediately, thus mitigating any identified vulnerabilities and preventing exploitation. Admins must also restrict local user privileges when patch applications cannot be applied to prevent unintended changes to network configuration. Polkit can help administrators do this. However, restricting local user control may have detrimental effects on devices that rely on this mechanism for network administration, such as laptops. Auditing and monitoring network configurations are also integral in detecting unauthorized changes or suspicious activities that could compromise network security. Any anomalies should be promptly investigated to ensure they do not constitute exploits of newly discovered vulnerabilities. User education and upholding the principle of least privilege are equally vital components. Informing local users about potential security threats associated with network configurations and only providing necessary permissions will limit unapproved access and exploitative efforts. Deploying security tools is also vital to increasing system protection. Intrusion Detection Systems (IDS) and Intrusion Prevention Systems (IPS) provide extra layers of defense against malicious activities by detecting privilege escalationattempts and warning of suspicious activities. Regularly reviewing and strengthening security policies is crucial to protecting systems against emerging threats and vulnerabilities. Adopting best practices and adhering to security standards are effective strategies for increasing systems' protection. Network segmentation can decrease risks by isolating critical systems and data from other network parts. Access should only be granted to individuals who require it, thus minimizing attack surfaces and potential exploits. Finally, maintaining regular backups of critical data and pre-tested disaster recovery plans helps ensure rapid recovery during a security breach or exploit. These comprehensive mitigation strategies will increase system resilience against flaws like this NetworkManager-libreswan bug. Our Final Thoughts on Addressing This Severe Vulnerability The NetworkManager-libreswan flaw in Red Hat systems is an urgent security threat, highlighting the importance of input sanitization and privilege management within networking-related software components. While Red Hat has provided patches to address this vulnerability, system administrators must act swiftly to update affected systems with these patches as soon as they become available while taking additional preventive steps against potential exploits. By taking proactive measures such as applying patches , restricting local user privileges, auditing network configurations, educating users about security policies and tools deployed, segmenting networks for maximum protection, maintaining backup plans, and maintaining robust disaster recovery plans, organizations can significantly bolster their security posture against vulnerabilities such as this flaw. Employing an all-encompassing security strategy will address this particular vulnerability and build resilience against future threats and attacks. . Address the NetworkManager-libreswan flaw in Red Hat systems with proactive measures to enhance your security posture..NetworkManager-libreswan flaw, Red Hat security measures, privilege escalation mitigation, security updates. . Brittany Day

Calendar 2 Oct 24, 2024 User Avatar Brittany Day Security Vulnerabilities
78

Cisco: Critical Flaw In IOS Software Requires Immediate Patching

Cisco has released patches for 34 vulnerabilities mostly affecting its IOS and IOS XE networking software, including three critical remote code execution security bugs. Perhaps the most serious issue Cisco has released a patch for is critical bug CVE-2018-0171 affecting Smart Install, a Cisco client for quickly deploying new switches for Cisco IOS Software and Cisco IOS XE Software.. . Cisco released updates addressing 34 security flaws, mainly affecting its IOS and IOS XE routing software, which are crucial to mitigate.. Cisco Networking Software,Patches for Vulnerabilities,Remote Code Execution. . LinuxSecurity.com Team

Calendar 2 Mar 29, 2018 User Avatar LinuxSecurity.com Team Vendors/Products
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here