Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
200

Scientific Linux: Important Update on abrt and libreport Security Issues

Important: abrt and libreport security update. Date: Fri, 1 Feb 2013 09:47:42 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Important: abrt and libreport on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: abrt and libreport security update Issue Date: 2013-01-31 CVE Numbers: CVE-2012-5659 CVE-2012-5660 -- It was found that the /usr/libexec/abrt-action-install-debuginfo-to-abrt-cache tool did not sufficiently sanitize its environment variables. This could lead to Python modules being loaded and run from non-standard directories (such as /tmp/). A local attacker could use this flaw to escalate their privileges to that of the abrt user. (CVE-2012-5659) A race condition was found in the way ABRT handled the directories used to store information about crashes. A local attacker with the privileges of the abrt user could use this flaw to perform a symbolic link attack, possibly allowing them to escalate their privileges to root. (CVE-2012-5660) -- SL6 x86_64 abrt-2.0.8-6.el6_3.2.x86_64.rpm abrt-addon-ccpp-2.0.8-6.el6_3.2.x86_64.rpm abrt-addon-kerneloops-2.0.8-6.el6_3.2.x86_64.rpm abrt-addon-python-2.0.8-6.el6_3.2.x86_64.rpm abrt-cli-2.0.8-6.el6_3.2.x86_64.rpm abrt-debuginfo-2.0.8-6.el6_3.2.i686.rpm abrt-debuginfo-2.0.8-6.el6_3.2.x86_64.rpm abrt-desktop-2.0.8-6.el6_3.2.x86_64.rpm abrt-gui-2.0.8-6.el6_3.2.x86_64.rpm abrt-libs-2.0.8-6.el6_3.2.i686.rpm abrt-libs-2.0.8-6.el6_3.2.x86_64.rpm abrt-tui-2.0.8-6.el6_3.2.x86_64.rpm libreport-2.0.9-5.el6_3.2.i686.rpm libreport-2.0.9-5.el6_3.2.x86_64.rpm libreport-cli-2.0.9-5.el6_3.2.x86_64.rpm libreport-debuginfo-2.0.9-5.el6_3.2.i686.rpm libreport-debuginfo-2.0.9-5.el6_3.2.x86_64.rpm libreport-gtk-2.0.9-5.el6_3.2.i686.rpm libreport-gtk-2.0.9-5.el6_3.2.x86_64.rpm libreport-newt-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-kerneloops-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-logger-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-mailx-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-reportuploader-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-rhtsupport-2.0.9-5.el6_3.2.x86_64.rpm libreport-python-2.0.9-5.el6_3.2.x86_64.rpm abrt-addon-vmcore-2.0.8-6.el6_3.2.x86_64.rpm abrt-devel-2.0.8-6.el6_3.2.i686.rpm abrt-devel-2.0.8-6.el6_3.2.x86_64.rpm libreport-devel-2.0.9-5.el6_3.2.i686.rpm libreport-devel-2.0.9-5.el6_3.2.x86_64.rpm libreport-gtk-devel-2.0.9-5.el6_3.2.i686.rpm libreport-gtk-devel-2.0.9-5.el6_3.2.x86_64.rpm libreport-plugin-bugzilla-2.0.9-5.el6_3.2.x86_64.rpm i386 abrt-2.0.8-6.el6_3.2.i686.rpm abrt-addon-ccpp-2.0.8-6.el6_3.2.i686.rpm abrt-addon-kerneloops-2.0.8-6.el6_3.2.i686.rpm abrt-addon-python-2.0.8-6.el6_3.2.i686.rpm abrt-cli-2.0.8-6.el6_3.2.i686.rpm abrt-debuginfo-2.0.8-6.el6_3.2.i686.rpm abrt-desktop-2.0.8-6.el6_3.2.i686.rpm abrt-gui-2.0.8-6.el6_3.2.i686.rpm abrt-libs-2.0.8-6.el6_3.2.i686.rpm abrt-tui-2.0.8-6.el6_3.2.i686.rpm libreport-2.0.9-5.el6_3.2.i686.rpm libreport-cli-2.0.9-5.el6_3.2.i686.rpm libreport-debuginfo-2.0.9-5.el6_3.2.i686.rpm libreport-gtk-2.0.9-5.el6_3.2.i686.rpm libreport-newt-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-kerneloops-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-logger-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-mailx-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-reportuploader-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-rhtsupport-2.0.9-5.el6_3.2.i686.rpm libreport-python-2.0.9-5.el6_3.2.i686.rpm abrt-addon-vmcore-2.0.8-6.el6_3.2.i686.rpm abrt-devel-2.0.8-6.el6_3.2.i686.rpm libreport-devel-2.0.9-5.el6_3.2.i686.rpm libreport-gtk-devel-2.0.9-5.el6_3.2.i686.rpm libreport-plugin-bugzilla-2.0.9-5.el6_3.2.i686.rpm - Scientific Linux Development Team . A vital security patch for abrt and libreport in Scientific Linux resolves privilege escalation vulnerabilities and additional concerns.. abrt update, libreport security, Scientific Linux, security patch, privilege escalation. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 01, 2013 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here