Security Information
Experience has shown that security through obscurity
never works. Therefore, public disclosure allows for quicker and better solutions of security problems. In that respect, this page addresses Debian's status regarding various known security holes, which could potentially affect the Debian operating system.
The Debian project coordinates many security advisories with other free software vendors, and as a result, these advisories are published the same day a vulnerability is made public. In order to receive the latest Debian security advisories, please subscribe to the debian-security-announce mailing list.
Debian also participates in security standardization efforts:
- The Debian Security Advisories are CVE-Compatible
- Debian publishes its security information using the Open Vulnerability Assessment Language (OVAL)
Keeping your Debian System secure
The packages unattended-upgrades can be installed to keep the computer current with the latest security (and other) updates automatically. The wiki entry has more detailed information how to manually set up unattended-upgrades.
For more information about security issues in Debian, please refer to our FAQ and our documentation:
Recent Advisories RSS
These are the recent Debian Security Advisories (DSA) posted to the debian-security-announce list.
T is the link to the Debian Security Tracker information, the DSA number links to the announcement mail.
Sources of Security Information
- Debian Security Tracker primary source for all security related information, search options
- JSON list contains CVE description, package name, Debian bug number, package versions with fix, no DSA included
- DSA list contains DSA including date, related CVE's numbers, package versions with fix
- DLA list contains DLA including date, related CVE's numbers, package versions with fix
- DSA announcements (Debian Security Advisories)
- DLA announcements (Debian Security Advisories of Debian LTS)
- RSS of the DSA or RSS long version including the text of the advisory
- RSS of the DLA or RSS long version including the text of the advisory
- Oval files
- Lookup a DSA (uppercase is important)
e.g. https://security-tracker.debian.org/tracker/DSA-3814 - Lookup a DLA ( -1 is important)
e.g. https://security-tracker.debian.org/tracker/DLA-867-1 - Lookup a CVE
e.g. https://security-tracker.debian.org/tracker/CVE-2017-6827
