Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
91

Gentoo: GLSA-202303-12 Normal: OpenSSL Vulnerability Exploitation Risk

Multiple integer overflow vulnerabilities have been found in ArgyllCMS which could allow attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201402-29 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ArgyllCMS: User-assisted execution of arbitrary code Date: February 28, 2014 Bugs: #437652 ID: 201402-29 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple integer overflow vulnerabilities have been found in ArgyllCMS which could allow attackers to execute arbitrary code. Background ========= ArgyllCMS is an ICC compatible color management system that supports accurate ICC profile creation for scanners, cameras and film recorders. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/argyllcms < 1.4.0-r1 > = 1.4.0-r1 Description ========== Multiple integer overflow vulnerabilities have been discovered in the ICC Format Library in ArgyllCMS. Impact ===== A remote attacker could entice a user to open a specially crafted image file using ArgyllCMS, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All ArgyllCMS users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/argyllcms-1.4.0-r1" References ========= [ 1 ] CVE-2012-4405 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4405 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201402-29 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several integer overflows in ArgyllCMS may enable the execution of unauthorized code, posing risks to Gentoo users.. ArgyllCMS, Integer Overflow, Gentoo Linux, Execution Threat, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Feb 28, 2014 Gentoo
91

Gentoo GLSA-201206-04 Normal: ArgyllCMS Code Execution Risk

A vulnerability has been found in ArgyllCMS which could allow attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201206-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ArgyllCMS: User-assisted execution of arbitrary code Date: June 18, 2012 Bugs: #416781 ID: 201206-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in ArgyllCMS which could allow attackersto execute arbitrary code. Background ========= ArgyllCMS is an ICC compatible color management system that supports accurate ICC profile creation for scanners, cameras and film recorders. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/argyllcms < 1.4.0 > = 1.4.0 Description ========== ArgyllCMS does not properly handle ICC profiles causing a use-after-free vulnerability. Impact ===== A remote attacker could entice a user to open a specially crafted image file using ArgyllCMS, possibly resulting in execution of arbitrary code with the privileges of the process, or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All argyllcms users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/argyllcms-1.4.0" References ========= [ 1 ] CVE-2012-1616 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-1616 Availability =========== This GLSA and any updates to it are available forviewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201206-04 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A standardized alert regarding ArgyllCMS security flaw enables potential code execution through image formats. Users are urged to update for enhanced safety.. ArgyllCMS Vulnerability,Gentoo Advisory,Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 Jun 18, 2012 Gentoo
89

Fedora 9: 2009-3430 High: ArgyllCMS Integer Overflow Update

Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found, the original patch, addressing this issue was incomplete.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3430 2009-04-09 15:24:29 --------------------------------------------------------------------------------Name : argyllcms Product : Fedora 9 Version : 1.0.3 Release : 4.fc9 URL : http://www.argyllcms.com/ Summary : ICC compatible color management system Description : The Argyll color management system supports accurate ICC profile creation for scanners, CMYK printers, film recorders and calibration and profiling of displays. Spectral sample data is supported, allowing a selection of illuminants observer types, and paper fluorescent whitener additive compensation. Profiles can also incorporate source specific gamut mappings for perceptual and saturation intents. Gamut mapping and profile linking uses the CIECAM02 appearance model, a unique gamut mapping algorithm, and a wide selection of rendering intents. It also includes code for the fastest portable 8 bit raster color conversion engine available anywhere, as well as support for fast, fully accurate 16 bit conversion. Device color gamuts can also be viewed and compared using a VRML viewer. --------------------------------------------------------------------------------Update Information: Multiple integer overflows and multiple insufficient upper-bounds checks on certain variable sizes were originally discovered in the Ghostscript's International Color Consortium Format Library (icclib). It was found, the original patch, addressing this issue was incomplete. --------------------------------------------------------------------------------ChangeLog: * Wed Apr 8 2009 Jon Ciesla - 1.0.3-4 - Patch forICC library CVE-2009-0792. * Mon Mar 23 2009 Jon Ciesla - 1.0.3-3 - Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh. * Mon Feb 23 2009 Fedora Release Engineering - 1.0.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Wed Sep 3 2008 Nicolas Mailhot - 1.0.3-1 ⌨ Bugfix release * Mon Sep 1 2008 Nicolas Mailhot - 1.0.2-1 ᾢ Bugfix release * Sun Jul 27 2008 Nicolas Mailhot - 1.0.1-1 ☻ Lots of workarounds dropped — Argyll continues progressing towards “normal package” state ☺ No more jam hell ☡, autotooling patch by Alastair M. Robinson ♥♥♥ ♿ New workaround added for private libusb check ⚔ We build againt system libusb, and will fix ⚕ any problem people care to report ⁜ Re-applied some patches still not merged upstream, including the legal ⚖ one ⚙ It builds, what can go wrong⁉ ⁂ Changed Huey policy file. Huey users, please test --------------------------------------------------------------------------------References: [ 1 ] Bug #491853 - CVE-2009-0792 ghostscript, argyllcms: Incomplete fix for CVE-2009-0583 https://bugzilla.redhat.com/show_bug.cgi?id=491853 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update argyllcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Resolving several integer overflow issues in Fedora argyllcms alongside essential enhancements for colormanagement frameworks.. ArgyllCMS, Integer Overflow, Fedora Updates, Software Patch. . LinuxSecurity.com Team

Calendar 2 Apr 09, 2009 Fedora
89

Fedora 10: FEDORA-2009-3011 Critical: Integer Overflow in Argyllcms

Multiple integer overflows were found in the International Color Consortium Format Library (icclib). An attacker could use this flaw to potentially execute arbitrary code by requesting to translate a specially- crafted image file created on one device into another's device native color space via a device file.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3011 2009-03-25 15:23:17 --------------------------------------------------------------------------------Name : argyllcms Product : Fedora 10 Version : 1.0.3 Release : 3.fc10 URL : Summary : ICC compatible color management system Description : The Argyll color management system supports accurate ICC profile creation for scanners, CMYK printers, film recorders and calibration and profiling of displays. Spectral sample data is supported, allowing a selection of illuminants observer types, and paper fluorescent whitener additive compensation. Profiles can also incorporate source specific gamut mappings for perceptual and saturation intents. Gamut mapping and profile linking uses the CIECAM02 appearance model, a unique gamut mapping algorithm, and a wide selection of rendering intents. It also includes code for the fastest portable 8 bit raster color conversion engine available anywhere, as well as support for fast, fully accurate 16 bit conversion. Device color gamuts can also be viewed and compared using a VRML viewer. --------------------------------------------------------------------------------Update Information: Multiple integer overflows were found in the International Color Consortium Format Library (icclib). An attacker could use this flaw to potentially execute arbitrary code by requesting to translate a specially- crafted image file created on one device into another's device native color space via adevice file. --------------------------------------------------------------------------------ChangeLog: * Mon Mar 23 2009 Jon Ciesla - 1.0.3-3 - Patch for ICC library CVE-2009-{0583, 0584} by Tim Waugh. * Mon Feb 23 2009 Fedora Release Engineering - 1.0.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #487742 - CVE-2009-0583 ghostscript: Multiple integer overflows in the International Color Consortium Format Library https://bugzilla.redhat.com/show_bug.cgi?id=487742 [ 2 ] Bug #487744 - CVE-2009-0584 ghostscript: Multiple insufficient upper-bounds checks on certain sizes in the International Color Consortium Format Library https://bugzilla.redhat.com/show_bug.cgi?id=487744 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update argyllcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A vulnerability identified in the Argyll content management system may enable arbitrary code execution via manipulated image uploads, necessitating urgent remediation.. ArgyllCMS Update, Integer Overflow Risk, Fedora 10, Security Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 25, 2009 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here