Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The OpenSSL Project team has announced that, on November 1, 2022, they will release OpenSSL version 3.0.7, which will fix a critical vulnerability in the popular open-source cryptographic library (but does not affect OpenSSL versions before 3.0). . According to the team’s own risk classification, critical vulnerabilities in OpenSSL are those that affect common configurations and are likely to be exploitable. “Examples include significant disclosure of the contents of server memory (potentially revealing user details), vulnerabilities which can be easily exploited remotely to compromise server private keys or where remote code execution is considered likely in common situations,” they say . . Anticipate the important OpenSSL 3.0.7 patch targeting significant flaws that may jeopardize safety.. OpenSSL Update,Critical Security Fix,Cryptographic Vulnerability,Remote Code Execution. . LinuxSecurity.com Team
The Python Software Foundation (PSF) has rushed out Python 3.9.2 and 3.8.8 to address two notable security flaws, including one that is remotely exploitable- but in practical terms can only be used to knock a machine offline. Upgrade now! . PSF is urging its legion of Python users to upgrade systems to Python 3.8.8 or 3.9.2 , in particular to address the remote code execution (RCE) vulnerability that's tracked as CVE-2021-3177. The project expedited the release after receiving unexpected pressure from some users who were concerned over the security flaw. . The PSF recommends that all Python developers move to version 3.8.8 or 3.9.2 urgently, as they resolve a significant remote execution vulnerability.. Python 3.8.8 Update, Remote Code Threat, PSF Urgent Patch. . Brittany Day
A high-risk RCE bug impacting PHP-based websites running a vulnerable version of the web-app creation tool Zend Framework and some Laminas Project releases has been discovered and disputed by Zend. Regardless of the dispute, Zend has issued a patch addressing this vulnerability which "provides type checking of the $streamName property before performing a cleanup operation (which results in an unlink() operation, which, previously, could have resulted in an implied call to an an object’s __toString() method) in the Laminas\Http\Response\Stream destructor". . Versions of the popular developer tool Zend Framework and its successor Laminas Project can be abused by an attacker to execute remote code on PHP-based websites, if they are running web-based applications that are vulnerable to attack. However, those that maintain Zend Framework emphasize that the conditions under which a web app can be abused first require the application author to write code that is “inherently insecure.” For that reason, the current maintainers of Zend Framework are contesting whether or not the vulnerability classification is correct. “We are contesting the vulnerability, and consider our patch a security tightening patch, and not a vulnerability patch,” said Matthew Weier O’Phinney, Zend product owner and principal engineer in an email-based interview with Threatpost. The link for this article located at ThreatPost is no longer available. . Critical vulnerability detected in Zend Framework and Laminas Project, demanding urgent updates to protect PHP applications.. remote Code Execution,Zend Framework,Laminas Project,PHP Security,Web Application Threat. . Brittany Day
Get the latest Linux and open source security news straight to your inbox.