Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 14.04 LTS: USN-2549-1 Moderate: libarchive Crash and Overwrite

libarchive could be made to crash or overwrite files.. =========================================================================Ubuntu Security Notice USN-2549-1 March 25, 2015 libarchive vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: libarchive could be made to crash or overwrite files. Software Description: - libarchive: Library to read/write archive files Details: It was discovered that the libarchive bsdcpio utility extracted absolute paths by default without using the --insecure flag, contrary to expectations. If a user or automated system were tricked into extracting cpio archives containing absolute paths, a remote attacker may be able to write to arbitrary files. (CVE-2015-2304) Fabian Yamaguchi discovered that libarchive incorrectly handled certain type conversions. A remote attacker could possibly use this issue to cause libarchive to crash, resulting in a denial of service. This issue only affected Ubuntu 12.04 LTS. (CVE-2013-0211) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: bsdcpio 3.1.2-9ubuntu0.1 libarchive13 3.1.2-9ubuntu0.1 Ubuntu 14.04 LTS: bsdcpio 3.1.2-7ubuntu2.1 libarchive13 3.1.2-7ubuntu2.1 Ubuntu 12.04 LTS: bsdcpio 3.0.3-6ubuntu1.1 libarchive12 3.0.3-6ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2549-1 CVE-2013-0211, CVE-2015-2304 Package Information: https://launchpad.net/ubuntu/+source/libarchive/3.1.2-9ubuntu0.1 https://launchpad.net/ubuntu/+source/libarchive/3.1.2-7ubuntu2.1 https://launchpad.net/ubuntu/+source/libarchive/3.0.3-6ubuntu1.1 . Ubuntu security advisory regarding libarchive flaws leading to system instabilities and data loss across multiple versions.. libarchive Issues, Ubuntu Updates, File Security Risks. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 25, 2015 Important Ubuntu
87

Debian DSA-3180-1 Directory Traversal in Libarchive - Critical Threat

Alexander Cherepanov discovered that bsdcpio, an implementation of the 'cpio' program part of the libarchive project, is susceptible to a directory traversal vulnerability via absolute paths. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3180-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Alessandro Ghedini March 05, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libarchive CVE ID : no yet available Debian Bug : 778266 Alexander Cherepanov discovered that bsdcpio, an implementation of the 'cpio' program part of the libarchive project, is susceptible to a directory traversal vulnerability via absolute paths. For the stable distribution (wheezy), this problem has been fixed in version 3.0.4-3+wheezy1. For the upcoming stable distribution (jessie), this problem has been fixed in version 3.1.2-11. For the unstable distribution (sid), this problem has been fixed in version 3.1.2-11. We recommend that you upgrade your libarchive packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Libarchive encounters a path traversal vulnerability; timely patching is critical for safe functionality.. libarchive security update,directory traversal,bsdcpio exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 05, 2015 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here