Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
100

SUSE: 2019:0002-1 Moderate: Libraw Buffer Overflow Security Advisory

An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for libraw ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:0002-1 Rating: moderate References: #1097973 #1097974 #1118894 Cross-References: CVE-2018-5805 CVE-2018-5806 CVE-2018-5808 Affected Products: SUSE Linux Enterprise Workstation Extension 12-SP4 SUSE Linux Enterprise Workstation Extension 12-SP3 SUSE Linux Enterprise Software Development Kit 12-SP4 SUSE Linux Enterprise Software Development Kit 12-SP3 SUSE Linux Enterprise Desktop 12-SP4 SUSE Linux Enterprise Desktop 12-SP3 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libraw fixes the following issues: Security issues fixed: - CVE-2018-5808: Fixed a stack-based buffer overflow and code execution vulnerability in find_green() function internal/dcraw_common.cpp (bsc#1118894). - CVE-2018-5805: Fixed a boundary error within the quicktake_100_load_raw function (bsc#1097973) - CVE-2018-5806: Fixed a a NULL pointer dereference in the leaf_hdr_load_raw function (bsc#1097974) Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP4: zypper in -t patch SUSE-SLE-WE-12-SP4-2019-2=1 - SUSE Linux Enterprise Workstation Extension 12-SP3: zypper in -t patch SUSE-SLE-WE-12-SP3-2019-2=1 - SUSE Linux Enterprise Software Development Kit 12-SP4: zypper in -t patch SUSE-SLE-SDK-12-SP4-2019-2=1 - SUSE Linux Enterprise SoftwareDevelopment Kit 12-SP3: zypper in -t patch SUSE-SLE-SDK-12-SP3-2019-2=1 - SUSE Linux Enterprise Desktop 12-SP4: zypper in -t patch SUSE-SLE-DESKTOP-12-SP4-2019-2=1 - SUSE Linux Enterprise Desktop 12-SP3: zypper in -t patch SUSE-SLE-DESKTOP-12-SP3-2019-2=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP4 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Workstation Extension 12-SP3 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Software Development Kit 12-SP4 (aarch64 ppc64le s390x x86_64): libraw-debugsource-0.15.4-27.1 libraw-devel-0.15.4-27.1 libraw-devel-static-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Software Development Kit 12-SP3 (aarch64 ppc64le s390x x86_64): libraw-debugsource-0.15.4-27.1 libraw-devel-0.15.4-27.1 libraw-devel-static-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Desktop 12-SP4 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 - SUSE Linux Enterprise Desktop 12-SP3 (x86_64): libraw-debugsource-0.15.4-27.1 libraw9-0.15.4-27.1 libraw9-debuginfo-0.15.4-27.1 References: https://www.suse.com/security/cve/CVE-2018-5805.html https://www.suse.com/security/cve/CVE-2018-5806.html https://www.suse.com/security/cve/CVE-2018-5808.html https://bugzilla.suse.com/1097973 https://bugzilla.suse.com/1097974 https://bugzilla.suse.com/1118894 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Advisory: Critical patch for libraw. Tackles various vulnerabilities of moderate risk..libraw security advisory, SUSE update, buffer overflow fix, null pointer issue. . LinuxSecurity.com Team

Calendar 2 Jan 02, 2019 SuSE
200

Scientific Linux 4: Important GStreamer-Plugins Security Update

Important: gstreamer-plugins security update. Date: Thu, 8 Sep 2011 09:56:50 -0500 Reply-To: "Tyler L. Parsons" Sender: Security Errata for Scientific Linux From: "Tyler L. Parsons" Subject: Security ERRATA Important: gstreamer-plugins on SL4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." MIME-Version: 1.0 Synopsis: Important: gstreamer-plugins security update Issue Date: 2011-09-06 CVE Numbers: CVE-2011-2911 The gstreamer-plugins packages contain plug-ins used by the GStreamer streaming-media framework to support a wide variety of media formats. An integer overflow flaw, a boundary error, and multiple off-by-one flaws were found in various ModPlug music file format library (libmodplug) modules, embedded in GStreamer. An attacker could create specially-crafted music files that, when played by a victim, would cause applications using GStreamer to crash or, potentially, execute arbitrary code. (CVE-2011-2911, CVE-2011-2912, CVE-2011-2913, CVE-2011-2914, CVE-2011-2915) All users of gstreamer-plugins are advised to upgrade to these updated packages, which contain backported patches to correct these issues. After installing the update, all applications using GStreamer (such as Rhythmbox) must be restarted for the changes to take effect. SL4: i386 gstreamer-plugins-0.8.5-1.EL.4.i386.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.4.i386.rpm gstreamer-plugins-devel-0.8.5-1.EL.4.i386.rpm x86_64 gstreamer-plugins-0.8.5-1.EL.4.x86_64.rpm gstreamer-plugins-debuginfo-0.8.5-1.EL.4.x86_64.rpm gstreamer-plugins-devel-0.8.5-1.EL.4.x86_64.rpm - Scientific Linux Development Team . Important security patch for gstreamer-plugins on Scientific Linux resolves buffer overflow vulnerabilities.. GStreamer Plugins, Scientific Linux, Security Updates, Media Formats. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 08, 2011 Important Scientific Linux
91

Gentoo: GLSA-202310-05 Normal: VLC Media Player Vulnerability Expose

A boundary error in Audacity allows for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Audacity: User-assisted execution of arbitrary code Date: March 06, 2009 Bugs: #253493 ID: 200903-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A boundary error in Audacity allows for the execution of arbitrary code. Background ========= Audacity is a free cross-platform audio editor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/audacity < 1.3.6 > = 1.3.6 Description ========== Houssamix discovered a boundary error in the String_parse::get_nonspace_quoted() function in lib-src/allegro/strparse.cpp. Impact ===== A remote attacker could entice a user into importing a specially crafted *.gro file, resulting in the execution of arbitrary code or a Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All Audacity users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/audacity-1.3.6" References ========= [ 1 ] CVE-2009-0490 https://www.cve.org/CVERecord?id=CVE-2009-0490 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A buffer overflow vulnerability in Audacity enables threat actors to run unauthorized commands, creating a security concern within Debian Linux distributions.. Audacity Security,Gentoo Advisory,Code Execution Risk,Boundary Error,User-Assisted Threats. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here