Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
200

Scientific Linux 6/7: SLSA-2014:2024-1 Important: ntp Buffer Overflow

Important: ntp security update. Date: Sat, 20 Dec 2014 19:22:14 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: ntp on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: ntp security update Advisory ID: SLSA-2014:2024-1 Issue Date: 2014-12-20 CVE Numbers: CVE-2014-9293 CVE-2014-9294 CVE-2014-9295 CVE-2014-9296 -- Multiple buffer overflow flaws were discovered in ntpd's crypto_recv(), ctl_putdata(), and configure() functions. A remote attacker could use either of these flaws to send a specially crafted request packet that could crash ntpd or, potentially, execute arbitrary code with the privileges of the ntp user. Note: the crypto_recv() flaw requires non- default configurations to be active, while the ctl_putdata() flaw, by default, can only be exploited via local attackers, and the configure() flaw requires additional authentication to exploit. (CVE-2014-9295) It was found that ntpd automatically generated weak keys for its internal use if no ntpdc request authentication key was specified in the ntp.conf configuration file. A remote attacker able to match the configured IP restrictions could guess the generated key, and possibly use it to send ntpdc query or configuration requests. (CVE-2014-9293) It was found that ntp-keygen used a weak method for generating MD5 keys. This could possibly allow an attacker to guess generated MD5 keys that could then be used to spoof an NTP client or server. Note: it is recommended to regenerate any MD5 keys that had explicitly been generated with ntp-keygen; the default installation does not contain such keys). (CVE-2014-9294) A missing return statement in the receive() function could potentially allow a remote attacker to bypass NTP's authentication mechanism. (CVE-2014-9296) After installing the update, the ntpd daemon will restart automatically. -- SL6 x86_64 ntp-4.2.6p5-2.el6_6.x86_64.rpm ntp-debuginfo-4.2.6p5-2.el6_6.x86_64.rpm ntpdate-4.2.6p5-2.el6_6.x86_64.rpm ntp-perl-4.2.6p5-2.el6_6.x86_64.rpm i386 ntp-4.2.6p5-2.el6_6.i686.rpm ntp-debuginfo-4.2.6p5-2.el6_6.i686.rpm ntpdate-4.2.6p5-2.el6_6.i686.rpm ntp-perl-4.2.6p5-2.el6_6.i686.rpm noarch ntp-doc-4.2.6p5-2.el6_6.noarch.rpm SL7 x86_64 ntp-4.2.6p5-19.el7_0.x86_64.rpm ntp-debuginfo-4.2.6p5-19.el7_0.x86_64.rpm ntpdate-4.2.6p5-19.el7_0.x86_64.rpm sntp-4.2.6p5-19.el7_0.x86_64.rpm noarch ntp-doc-4.2.6p5-19.el7_0.noarch.rpm ntp-perl-4.2.6p5-19.el7_0.noarch.rpm - Scientific Linux Development Team . Urgent security patch released for ntpd on Scientific Linux rectifying several buffer overflow vulnerabilities and authentication flaws.. ntp Security Update, Scientific Linux Advisories, Buffer Overflow Risks. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 20, 2014 Important Scientific Linux
172

Ubuntu 11.10 USN-1233-1 Critical: Kerberos Denial Of Service Issue

Several denial of service issues were fixed in the Kerberos KeyDistribution Center (KDC).. =========================================================================Ubuntu Security Notice USN-1233-1 October 18, 2011 krb5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 11.10 - Ubuntu 11.04 - Ubuntu 10.10 - Ubuntu 10.04 LTS Summary: Several denial of service issues were fixed in the Kerberos Key Distribution Center (KDC). Software Description: - krb5: MIT Kerberos Network Authentication Protocol Details: Nalin Dahyabhai, Andrej Ota and Kyle Moffett discovered a NULL pointer dereference in the KDC LDAP backend. An unauthenticated remote attacker could use this to cause a denial of service. This issue affected Ubuntu 11.10. (CVE-2011-1527) Mark Deneen discovered that an assert() could be triggered in the krb5_ldap_lockout_audit() function in the KDC LDAP backend and the krb5_db2_lockout_audit() function in the KDC DB2 backend. An unauthenticated remote attacker could use this to cause a denial of service. (CVE-2011-1528) It was discovered that a NULL pointer dereference could occur in the lookup_lockout_policy() function in the KDC LDAP and DB2 backends. An unauthenticated remote attacker could use this to cause a denial of service. (CVE-2011-1529) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 11.10: krb5-kdc 1.9.1+dfsg-1ubuntu1.1 krb5-kdc-ldap 1.9.1+dfsg-1ubuntu1.1 Ubuntu 11.04: krb5-kdc 1.8.3+dfsg-5ubuntu2.2 krb5-kdc-ldap 1.8.3+dfsg-5ubuntu2.2 Ubuntu 10.10: krb5-kdc 1.8.1+dfsg-5ubuntu0.8 krb5-kdc-ldap 1.8.1+dfsg-5ubuntu0.8 Ubuntu 10.04 LTS: krb5-kdc 1.8.1+dfsg-2ubuntu0.10 krb5-kdc-ldap 1.8.1+dfsg-2ubuntu0.10 In general, a standardsystem update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1233-1 CVE-2011-1527, CVE-2011-1528, CVE-2011-1529 Package Information: https://launchpad.net/ubuntu/+source/krb5/1.9.1+dfsg-1ubuntu1.1 https://launchpad.net/ubuntu/+source/krb5/1.8.3+dfsg-5ubuntu2.2 https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-5ubuntu0.8 https://launchpad.net/ubuntu/+source/krb5/1.8.1+dfsg-2ubuntu0.10 . Multiple denial of service vulnerabilities resolved in Kerberos KDC, impacting Ubuntu 10.04 LTS and newer releases. Upgrade promptly.. Denial Of Service, Kerberos KDC, Ubuntu Update, Security Patch, Remote Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 18, 2011 Critical Ubuntu
200

Scientific Linux SL5.x: CVE-2008-0887 Moderate Gnome-Screensaver Threat

Moderate: gnome-screensaver security update. Date: Wed, 2 Apr 2008 15:50:43 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for gnome-screensaver on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: gnome-screensaver security update Issue date: 2008-04-02 CVE Names: CVE-2008-0887 A flaw was found in the way gnome-screensaver verified user passwords. When a system used a remote directory service for login credentials, a local attacker able to cause a network outage could cause gnome-screensaver to crash, unlocking the screen. (CVE-2008-0887) SL 5.x SRPMS: gnome-screensaver-2.16.1-5.el5_1.1.src.rpm i386: gnome-screensaver-2.16.1-5.el5_1.1.i386.rpm x86_64: gnome-screensaver-2.16.1-5.el5_1.1.x86_64.rpm -Connie Sieh -Troy Dawson . Critical gnome-screensaver patch released for Scientific Linux SL5.x mitigating a local exploit risk.. gnome-screensaver update, scientific linux security, password authentication. . LinuxSecurity.com Team

Calendar 2 Apr 02, 2008 Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here