Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 7: MGASA-2020-0001 Moderate: apache-commons-compress Resource Flaw

pdated apache-commons-compress packages fix security vulnerability: A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the . MGASA-2020-0001 - Updated apache-commons-compress- packages fix security vulnerability Publication date: 05 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0001.html Type: security Affected Mageia releases: 7 CVE: CVE-2019-12402 pdated apache-commons-compress packages fix security vulnerability: A resource consumption vulnerability was discovered in apache-commons- compress in the way NioZipEncoding encodes filenames. Applications that use Compress to create archives, with one of the filenames within the archive being controlled by the user, may be vulnerable to this flaw. A remote attacker could exploit this flaw to cause an infinite loop during the archive creation, thus leading to a denial of service (CVE-2019-12402). References: - https://bugs.mageia.org/show_bug.cgi?id=25365 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/QLJIK2AUOZOWXR3S5XXBUNMOF3RTHTI7/ - https://www.cve.org/CVERecord?id=CVE-2019-12402 SRPMS: - 7/core/apache-commons-compress-1.19-1.mga7 . Security bulletin MGASA-2020-0002 addresses a critical vulnerability in the jQuery library that can result in XSS attacks.. apache commons compress, mageia security, resource consumption vulnerability. . LinuxSecurity.com Team

Calendar 2 Jan 05, 2020 Mageia
89

Fedora 27: 2018-03-06 Severe Heap Overflow In Sharutils Unshar

This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8f4b3fa844 2018-03-06 17:17:51.856083 --------------------------------------------------------------------------------Name : sharutils Product : Fedora 27 Version : 4.15.2 Release : 8.fc27 URL : http://www.gnu.org/software/sharutils/ Summary : The GNU shar utilities for packaging and unpackaging shell archives Description : The sharutils package contains the GNU shar utilities, a set of tools for encoding and decoding packages of files (in binary or text format) in a special plain text format called shell archives (shar). This format can be sent through e-mail (which can be problematic for regular binary files). The shar utility supports a wide range of capabilities (compressing, uuencoding, splitting long files for multi-part mailings, providing check-sums), which make it very flexible at creating shar files. After the files have been sent, the unshar tool scans mail messages looking for shar files. Unshar automatically strips off mail headers and introductory text and then unpacks the shar files. --------------------------------------------------------------------------------Update Information: This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines. --------------------------------------------------------------------------------References: [ 1 ] Bug #1548018 - sharutils: heap-buffer-overflow in find_archive in unshar.c https://bugzilla.redhat.com/show_bug.cgi?id=1548018 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sharutils' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 27 issued a sharutils patch to address a potential heap buffer overflow vulnerability in unshar, triggered by handling excessively lengthy lines in compression archives.. Fedora Updates, Security Notifications, Sharutils Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 06, 2018 Critical Fedora
89

Fedora 27: 2018-8f4b3fa844 Critical: Sharutils Heap Overflow

This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-8f4b3fa844 2018-03-06 17:17:51.856083 --------------------------------------------------------------------------------Name : sharutils Product : Fedora 27 Version : 4.15.2 Release : 8.fc27 URL : http://www.gnu.org/software/sharutils/ Summary : The GNU shar utilities for packaging and unpackaging shell archives Description : The sharutils package contains the GNU shar utilities, a set of tools for encoding and decoding packages of files (in binary or text format) in a special plain text format called shell archives (shar). This format can be sent through e-mail (which can be problematic for regular binary files). The shar utility supports a wide range of capabilities (compressing, uuencoding, splitting long files for multi-part mailings, providing check-sums), which make it very flexible at creating shar files. After the files have been sent, the unshar tool scans mail messages looking for shar files. Unshar automatically strips off mail headers and introductory text and then unpacks the shar files. --------------------------------------------------------------------------------Update Information: This release fixes a heap buffer overflow when processing a shar archive by unshar tool if the arhive contains overlong lines. --------------------------------------------------------------------------------References: [ 1 ] Bug #1548018 - sharutils: heap-buffer-overflow in find_archive in unshar.c https://bugzilla.redhat.com/show_bug.cgi?id=1548018 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade sharutils' at the command line. For more information, refer to the dnf documentationavailable at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This patch resolves a critical memory corruption in libarchive for Ubuntu 20.04, improving file extraction capabilities.. Fedora Security Update, Heap Overflow Fix, Sharutils Critical Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 06, 2018 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here