Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Anytime you upgrade software, you risk something breaking. This is the nature of the IT beast. The purpose of patches is usually to fix a bug or, worse, a security vulnerability. . That said, sometimes good intentions lead to bad outcomes. For example, you hire a plumber to come and fix a leaky pipe. He patches it but inadvertently breaks the toilet in the process—good intentions with bad outcomes. That doesn’t need to be the case with Linux patching, though. To make Linux patching easier, you can use some tools known as patch managers to help you save time and money. A patch manager tool also helps you avoid the bad patch that could accidentally break your toilet. In this article, I’ll cover why patch management is important. I’ll also discuss its benefits, problems, best practices, and strategy. Let’s first talk about why patch management is important for your business. The link for this article located at TechGenix is no longer available. . Updating software in Linux is crucial to address vulnerabilities and enhance stability, while minimizing risks. Explore effective strategies.. Linux Patching, Patch Management, Software Security. . Brittany Day
Yesterday, we wrote about the waited-for-with-bated-breath OpenSSL update that attracted many column-kilometres of media attention last week. . The OpenSSL team announced in advance, as it usually does, that a new version of its popular cryptographic library would soon be released. This notification stated that the update would patch against a security hole with a CRITICAL severity rating, the project’s highest. . The latest OpenSSL release tackles significant security flaws and offers crucial guidance for upholding IT reliability.. OpenSSL Update,Critical Security Patch,Software Vulnerabilities. . Brittany Day
Canonical has released new Linux kernel security patches for all supported Ubuntu releases to address various security vulnerabilities discovered in the upstream kernel packages. . The new Ubuntu Linux kernel security updates come about three weeks after the previous security update and patch a total of 16 vulnerabilities for Ubuntu 22.04 LTS (Jammy Jellyfish), Ubuntu 20.04 LTS (Focal Fossa), Ubuntu 18.04 LTS (Bionic Beaver), and Ubuntu 16.04 ESM (Xenial Xerus). For Ubuntu 22.04 LTS and Ubuntu 20.04 LTS systems running Linux kernel 5.15 LTS, the new kernel updates address CVE-2022-1882 , a race condition discovered by Selim Enes Karaduman in the general notification queue implementation, as well as CVE-2022-39189 , a security flaw discovered by Google Project Zero’s Jann Horn in the KVM subsystem. Both of them could allow a local attacker in a guest virtual machine to cause a denial of service (guest crash) or possibly execute arbitrary code. The link for this article located at 9 to 5 Linux is no longer available. . Canonical rolled out critical updates to rectify 16 vulnerabilities present in the Ubuntu Linux kernel spanning several versions.. Ubuntu Kernel Update, Security Patches, Linux Flaws, Patch Management. . Brittany Day
Researchers have revealed details about a long-standing security vulnerability that has been active in the Linux kernel for over eight years. The cybersecurity analysts from Northwestern University (Zhenpeng Lin, Yuhang Wu, and Xinyu Xing) described it as:- “As Nasty As Dirty Pipe”. . As an outcome of the investigation, Max Kellermann discovered and reported the Dirty Pipe flaw as CVE-2022-0847 with a CVSS score of 7.8. This nasty vulnerability in the Linux kernel is dubbed “DirtyCred.” Using the DirtyCred, privileged credentials are swapped for unprivileged ones in order to escalate privileges. To gain privileges, DirtyCred uses the heap memory reuse method rather than overwriting critical kernel data fields. The link for this article located at CyberSecurity News is no longer available. . Uncover the specifics of a long-standing vulnerability in the Linux kernel that has persisted for eight years, raising significant concerns regarding potential privilege escalation risks.. Linux Kernel Bug, Privilege Escalation, Security Flaw, Credential Management. . Brittany Day
Register.com, the second-largest domain name registrar, has acknowledged a security problem that could have allowed people to hijack others' Web sites. The problem allowed unauthorized access to the security software Register.com and its business partners use to manage Internet site information, . . . . Register.com, the second-largest domain name registrar, has acknowledged a security problem that could have allowed people to hijack others' Web sites. The problem allowed unauthorized access to the security software Register.com and its business partners use to manage Internet site information, such as a customer's contact information or the numerical address associated with a domain name. Spokeswoman Shonna Keogan said the security vulnerability was fixed today. The link for this article located at News.com is no longer available. . Domain provider DomainCheck.com uncovers critical vulnerability permitting illicit entry to websites, swiftly mitigated by their security team.. Register.com, Domain Registrar, Site Hijacking, Security Fix, Unauthorized Access. . Anthony Pell
A set of dangerous vulnerabilities have been discovered in the Exim mail server. Remote code execution, privilege escalation to root and lateral movement through a victim’s environment are all on offer for the unpatched or unaware. . A veritable cornucopia of security vulnerabilities in the Exim mail server have been uncovered, some of which could be chained together for unauthenticated remote code execution (RCE), gaining root privileges and worm-style lateral movement, according to researchers. The Qualys Research Team has discovered a whopping 21 bugs in the popular mail transfer agent (MTA), which was built to send and receive email on major Unix-like operating systems. It comes pre-installed on Linux distributions such as Debian, for instance. The link for this article located at ThreatPost is no longer available. . A collection of critical weaknesses in the Exim email server may result in remote code execution and unauthorized privilege escalation threats.. Exim Mail Server, Remote Exploit, Security Flaws. . Brittany Day
A majority of the open source codebases found in commercial applications analyzed by Synopsys contained security vulnerabilities. . Applications that use open source code offer a host of benefits, including transparency, flexibility, cost effectiveness and community support. But how do such products fare on security? Though the community-based approach toward open source means that security flaws should be identified quickly, patching those flaws and applying the patches is another matter. . Public domain software fosters openness, adaptability, and economic advantages, although they face challenges regarding protection to tackle.. Open Source Security, Commercial Applications, Security Challenges. . LinuxSecurity.com Team
Google Chrome 90 has arrived with new privacy features and fixes for 37 security flaws. Chrome users: this is an update you don't want to overlook! . Google has just released Chrome version 90, bringing a privacy update that automatically adds HTTPS to a URL when it is available. Chrome engineers flagged the HTTPS feature in February and Google has been testing it in Chrome 90 previews in the Canary and Beta channels. Additionally, Chrome 90 blocks downloads from HTTP sources if the page URL is HTTPS. . Safari 14 implements enhanced tracking prevention and patches various vulnerabilities to bolster user security.. Google Chrome, Privacy Features, Security Enhancements. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.