Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
100

SUSE: 2025:01882-1 important: Tomcat URL Handling Issue

* bsc#1242009 Cross-References: * CVE-2025-31651 . # Security update for tomcat Announcement ID: SUSE-SU-2025:01882-1 Release Date: 2025-06-11T05:42:17Z Rating: important References: * bsc#1242009 Cross-References: * CVE-2025-31651 CVSS scores: * CVE-2025-31651 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-31651 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-31651 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-31651 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2025-31651: Better handling of URLs with literal ';' and '?' (bsc#1242009). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2025-1882=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * tomcat-lib-9.0.36-3.142.1 * tomcat-docs-webapp-9.0.36-3.142.1 * tomcat-jsp-2_3-api-9.0.36-3.142.1 * tomcat-servlet-4_0-api-9.0.36-3.142.1 * tomcat-webapps-9.0.36-3.142.1 * tomcat-9.0.36-3.142.1 * tomcat-javadoc-9.0.36-3.142.1 * tomcat-admin-webapps-9.0.36-3.142.1 * tomcat-el-3_0-api-9.0.36-3.142.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31651.html * https://bugzilla.suse.com/show_bug.cgi?id=1242009 . This bulletin outlines a significant patch for SUSE's tomcat, addressing vulnerabilities in URL managementand associated concerns.. SUSE, tomcat, security patch, important update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 11, 2025 Important SuSE
203

Mageia 2025-0096: opensc Security Advisory Updates

Heap buffer overflow in openpgp driver when generating key. (CVE-2024-8443) Usage of uninitialized values in libopensc and pkcs15init. (CVE-2024-45615) Uninitialized values after incorrect check or usage of apdu response . MGASA-2025-0096 - Updated opensc packages fix security vulnerabilities Publication date: 13 Mar 2025 URL: https://advisories.mageia.org/MGASA-2025-0096.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-8443, CVE-2024-45615, CVE-2024-45616, CVE-2024-45617, CVE-2024-45618, CVE-2024-45619, CVE-2024-45620 Heap buffer overflow in openpgp driver when generating key. (CVE-2024-8443) Usage of uninitialized values in libopensc and pkcs15init. (CVE-2024-45615) Uninitialized values after incorrect check or usage of apdu response values in libopensc. (CVE-2024-45616) Uninitialized values after incorrect or missing checking return values of functions in libopensc. (CVE-2024-45617) Uninitialized values after incorrect or missing checking return values of functions in pkcs15init. (CVE-2024-45618) Incorrect handling length of buffers or files in libopensc. (CVE-2024-45619) Incorrect handling of the length of buffers or files in pkcs15init. (CVE-2024-45620) References: - https://bugs.mageia.org/show_bug.cgi?id=34087 - https://ubuntu.com/security/notices/USN-7346-1 - https://www.cve.org/CVERecord?id=CVE-2024-8443 - https://www.cve.org/CVERecord?id=CVE-2024-45615 - https://www.cve.org/CVERecord?id=CVE-2024-45616 - https://www.cve.org/CVERecord?id=CVE-2024-45617 - https://www.cve.org/CVERecord?id=CVE-2024-45618 - https://www.cve.org/CVERecord?id=CVE-2024-45619 - https://www.cve.org/CVERecord?id=CVE-2024-45620 SRPMS: - 9/core/opensc-0.25.0-1.1.mga9 . Critical updates for Mageia address buffer overflow and uninitialized values in opensc packages to protect systems.. buffer, overflow, openpgp, driver, generating, (cve-2024-8443), usage, uninitialized. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 13, 2025 Important Mageia
203

Mageia: 2023-0083 Moderate: DCMTK Denial Of Service Threats

Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2015-8979) . MGASA-2023-0083 - Updated dcmtk packages fix security vulnerability Publication date: 11 Mar 2023 URL: https://advisories.mageia.org/MGASA-2023-0083.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, CVE-2021-41690, CVE-2022-2119, CVE-2022-2120, CVE-2022-2121, CVE-2022-43272 Gjoko Krstic discovered that DCMTK incorrectly handled buffers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2015-8979) Omar Ganiev discovered that DCMTK incorrectly handled buffers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2019-1010228) Jinsheng Ba discovered that DCMTK incorrectly handled certain requests. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2021-41687, CVE-2021-41688, CVE-2021-41689, and CVE-2021-41690) Sharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled certain inputs. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2022-2119 and CVE-2022-2120) Sharon Brizinov and Noam Moshe discovered that DCMTK incorrectly handled pointers. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-2121) It wasdiscovered that DCMTK incorrectly handled certain inputs. If a user or an automated system were tricked into opening a certain specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2022-43272) References: - https://bugs.mageia.org/show_bug.cgi?id=30790 - https://dicom.offis.de/download/dcmtk/dcmtk367/ANNOUNCE - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/2Z7WVDK43MKWOS23BIN4VCQRQRXHGSDB/ - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/WF2FCZOYXVZ4ETCHO62JWUP4D55UWJCV/ - https://ubuntu.com/security/notices/USN-5882-1 - https://www.cve.org/CVERecord?id=CVE-2021-41687 - https://www.cve.org/CVERecord?id=CVE-2021-41688 - https://www.cve.org/CVERecord?id=CVE-2021-41689 - https://www.cve.org/CVERecord?id=CVE-2021-41690 - https://www.cve.org/CVERecord?id=CVE-2022-2119 - https://www.cve.org/CVERecord?id=CVE-2022-2120 - https://www.cve.org/CVERecord?id=CVE-2022-2121 - https://www.cve.org/CVERecord?id=CVE-2022-43272 SRPMS: - 8/core/dcmtk-3.6.5-3.1.mga8 . Revised DCMTK distributions for Mageia address possible denial of service vulnerabilities and code execution threats identified on 11 Mar 2023.. Mageia Security, DCMTK Update, Denial Of Service, Buffer Issues. . LinuxSecurity.com Team

Calendar%202 Mar 11, 2023 Mageia
200

Scientific Linux: SLSA-2016:2779-1 Moderate: nss Util Flaws

Moderate: nss and nss-util security update. Date: Thu, 10 Nov 2016 10:20:59 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Discontinuing Software Collections for Scientific Linux Comments: To: scientific-linux-announce@ MIME-Version: 1.0 Message-ID: When Scientific Linux started building the Software Collection Library and Developer Toolset, these packages were not freely distributed. The upstream packages and more can now be obtained from softwarecollections.org. With this in mind, we will be discontinuing the Scientific Linux Software Collections. As a part of this process we will: - archive the existing RPMS - provide a new yum-conf-softwarecollections which points to the SoftwareCollections.org repo The new yum-conf-softwarecollections rpms are available now. Users of the yum-conf-softwarecollections rpms can upgrade to the latest version by running 'yum update yum-conf-softwarecollections'. Archiving the Scientific Linux Software Collections is scheduled for Nov 28 2016. Date: Mon, 21 Nov 2016 18:19:39 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: nss and nss-util on SL5.x, SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: nss and nss-util security update Advisory ID: SLSA-2016:2779-1 Issue Date: 2016-11-16 CVE Numbers: CVE-2016-2834 CVE-2016-5285 CVE-2016-8635 -- The nss-util packages provide utilities for use with the Network Security Services (NSS) libraries. The following packages have been upgraded to a newer upstream version: nss (3.12.3), nss-util (3.12.3). Security Fix(es): * Multiple buffer handling flaws were found in the way NSS handled cryptographic data from the network. A remote attacker could use these flaws to crash an application using NSS or, possibly, execute arbitrary code with the permission of the user running the application. (CVE-2016-2834) * A NULL pointer dereference flaw wasfound in the way NSS handled invalid Diffie-Hellman keys. A remote client could use this flaw to crash a TLS/SSL server using NSS. (CVE-2016-5285) * It was found that Diffie Hellman Client key exchange handling in NSS was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of the desired group. (CVE-2016-8635) -- SL5 x86_64 nss-3.21.3-2.el5_11.i386.rpm nss-3.21.3-2.el5_11.x86_64.rpm nss-debuginfo-3.21.3-2.el5_11.i386.rpm nss-debuginfo-3.21.3-2.el5_11.x86_64.rpm nss-tools-3.21.3-2.el5_11.x86_64.rpm nss-devel-3.21.3-2.el5_11.i386.rpm nss-devel-3.21.3-2.el5_11.x86_64.rpm nss-pkcs11-devel-3.21.3-2.el5_11.i386.rpm nss-pkcs11-devel-3.21.3-2.el5_11.x86_64.rpm i386 nss-3.21.3-2.el5_11.i386.rpm nss-debuginfo-3.21.3-2.el5_11.i386.rpm nss-tools-3.21.3-2.el5_11.i386.rpm nss-devel-3.21.3-2.el5_11.i386.rpm nss-pkcs11-devel-3.21.3-2.el5_11.i386.rpm SL6 x86_64 nss-3.21.3-2.el6_8.i686.rpm nss-3.21.3-2.el6_8.x86_64.rpm nss-debuginfo-3.21.3-2.el6_8.i686.rpm nss-debuginfo-3.21.3-2.el6_8.x86_64.rpm nss-sysinit-3.21.3-2.el6_8.x86_64.rpm nss-tools-3.21.3-2.el6_8.x86_64.rpm nss-util-3.21.3-1.el6_8.i686.rpm nss-util-3.21.3-1.el6_8.x86_64.rpm nss-util-debuginfo-3.21.3-1.el6_8.i686.rpm nss-util-debuginfo-3.21.3-1.el6_8.x86_64.rpm nss-devel-3.21.3-2.el6_8.i686.rpm nss-devel-3.21.3-2.el6_8.x86_64.rpm nss-pkcs11-devel-3.21.3-2.el6_8.i686.rpm nss-pkcs11-devel-3.21.3-2.el6_8.x86_64.rpm nss-util-devel-3.21.3-1.el6_8.i686.rpm nss-util-devel-3.21.3-1.el6_8.x86_64.rpm i386 nss-3.21.3-2.el6_8.i686.rpm nss-debuginfo-3.21.3-2.el6_8.i686.rpm nss-sysinit-3.21.3-2.el6_8.i686.rpm nss-tools-3.21.3-2.el6_8.i686.rpm nss-util-3.21.3-1.el6_8.i686.rpm nss-util-debuginfo-3.21.3-1.el6_8.i686.rpm nss-devel-3.21.3-2.el6_8.i686.rpm nss-pkcs11-devel-3.21.3-2.el6_8.i686.rpm nss-util-devel-3.21.3-1.el6_8.i686.rpm SL7 x86_64 nss-3.21.3-2.el7_3.i686.rpm nss-3.21.3-2.el7_3.x86_64.rpm nss-debuginfo-3.21.3-2.el7_3.i686.rpm nss-debuginfo-3.21.3-2.el7_3.x86_64.rpm nss-sysinit-3.21.3-2.el7_3.x86_64.rpm nss-tools-3.21.3-2.el7_3.x86_64.rpm nss-util-3.21.3-1.1.el7_3.i686.rpm nss-util-3.21.3-1.1.el7_3.x86_64.rpm nss-util-debuginfo-3.21.3-1.1.el7_3.i686.rpm nss-util-debuginfo-3.21.3-1.1.el7_3.x86_64.rpm nss-devel-3.21.3-2.el7_3.i686.rpm nss-devel-3.21.3-2.el7_3.x86_64.rpm nss-pkcs11-devel-3.21.3-2.el7_3.i686.rpm nss-pkcs11-devel-3.21.3-2.el7_3.x86_64.rpm nss-util-devel-3.21.3-1.1.el7_3.i686.rpm nss-util-devel-3.21.3-1.1.el7_3.x86_64.rpm - Scientific Linux Development Team . Important security enhancement for nss and nss-util mitigating various vulnerabilities on Scientific Linux systems.. Scientific Linux nss update, nss-util security patch, Moderate nss vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 21, 2016 Important Scientific Linux
89

Fedora 20: FEDORA-2015-6712 Moderate: Curl Buffer Handling Issues

- require credentials to match for NTLM re-use (CVE-2015-3143) - fix invalid write in cookie path sanitization code (CVE-2015-3145) - close Negotiate connections when done (CVE-2015-3148). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-6712 2015-04-23 11:30:46 -------------------------------------------------------------------------------- Name : curl Product : Fedora 20 Version : 7.32.0 Release : 20.fc20 URL : https://curl.se/ Summary : A utility for getting files from remote servers (FTP, HTTP, and others) Description : curl is a command line tool for transferring data with URL syntax, supporting FTP, FTPS, HTTP, HTTPS, SCP, SFTP, TFTP, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3 and RTSP. curl supports SSL certificates, HTTP POST, HTTP PUT, FTP uploading, HTTP form based upload, proxies, cookies, user+password authentication (Basic, Digest, NTLM, Negotiate, kerberos...), file transfer resume, proxy tunneling and a busload of other useful tricks. -------------------------------------------------------------------------------- Update Information: - require credentials to match for NTLM re-use (CVE-2015-3143) - fix invalid write in cookie path sanitization code (CVE-2015-3145) - close Negotiate connections when done (CVE-2015-3148) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 22 2015 Kamil Dudka 7.32.0-20 - require credentials to match for NTLM re-use (CVE-2015-3143) - fix invalid write in cookie path sanitization code (CVE-2015-3145) - close Negotiate connections when done (CVE-2015-3148) * Mon Feb 23 2015 Kamil Dudka 7.32.0-19 - make ConnectionExists() re-use connections better (#1194603) * Thu Jan 8 2015 Kamil Dudka 7.32.0-18 - reject CRLFs in URLs passed to proxy (CVE-2014-8150) * Wed Dec 10 2014 Kamil Dudka 7.32.0-17 - make CURLOPT_LOW_SPEED_LIMIT work again with threaded resolver (#1172572) * Mon Nov 24 2014 Kamil Dudka 7.32.0-16 - allow to use TLS 1.1 and TLS 1.2 (#1153814) - disable libcurl-level downgrade to SSLv3 (#1166567) - low-speed-limit: avoid timeout flood (#1166239) * Wed Nov 5 2014 Kamil Dudka 7.32.0-15 - fix handling of CURLOPT_COPYPOSTFIELDS in curl_easy_duphandle (CVE-2014-3707) * Tue Oct 21 2014 Kamil Dudka 7.32.0-14 - fix a connection failure when FTPS handle is reused * Wed Sep 10 2014 Kamil Dudka 7.32.0-13 - use only full matches for hosts used as IP address in cookies (CVE-2014-3613) - reject incoming cookies set for top level domains (CVE-2014-3620) * Wed Jul 30 2014 Kamil Dudka 7.32.0-12 - fix endless loop with GSSAPI proxy auth (patches by David Woodhouse, #1118751) * Mon Jun 2 2014 Kamil Dudka 7.32.0-11 - acknowledge the --no-sessionid/CURLOPT_SSL_SESSIONID_CACHE option (#1098711) * Sat May 10 2014 Kamil Dudka 7.32.0-10 - extend URL parser to support IPv6 zone identifiers (#680996) - auth failure on duplicated 'WWW-Authenticate: Negotiate' header (#1093348) * Fri Apr 25 2014 Kamil Dudka 7.32.0-9 - nss: implement non-blocking SSL handshake * Wed Mar 26 2014 Kamil Dudka 7.32.0-8 - fix connection re-use when using different log-in credentials (CVE-2014-0138) * Mon Mar 17 2014 Paul Howarth 7.32.0-7 - add all perl build requirements for the test suite, in a portable way * Wed Mar 5 2014 Kamil Dudka 7.32.0-6 - avoid spurious failure of test1086 on s390(x) koji builders (#1072273) * Tue Feb 25 2014 Kamil Dudka 7.32.0-5 - refresh expired cookie in test172 from upstream test-suite (#1068967) - use proxy name in error messages when proxy is used (#1066484) * Fri Jan 31 2014 Kamil Dudka 7.32.0-4 - re-use of wrong HTTP NTLM connection in libcurl (CVE-2014-0015) -------------------------------------------------------------------------------- References: [ 1 ] Bug #1213351 - CVE-2015-3148 curl: Negotiate not treated as connection-oriented https://bugzilla.redhat.com/show_bug.cgi?id=1213351 [ 2 ] Bug #1213306 - CVE-2015-3143 curl: re-using authenticated connection whenunauthenticated https://bugzilla.redhat.com/show_bug.cgi?id=1213306 [ 3 ] Bug #1213347 - CVE-2015-3145 curl: cookie parser out of boundary memory access https://bugzilla.redhat.com/show_bug.cgi?id=1213347 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update curl' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Critical curl enhancements for Fedora 20 tackle vulnerabilities, focusing on cookie paths and authentication redundancy.. curl Update,Fedora Security Patch,Authentication Reuse,Buffer Handling Issues. . LinuxSecurity.com Team

Calendar%202 Apr 28, 2015 Fedora
87

Debian: DSA-383-2 Critical: OpenSSH Buffer Handling Issue Fix

This advisory is an addition to the earlier DSA-383-1 advisory: SolarDesigner found four more bugs in OpenSSH that may be exploitable.. - ------------------------------------------------------------------------ Debian Security Advisory DSA-383-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman September 21, 2003 - ------------------------------------------------------------------------ Package : ssh-krb5 Vulnerability : buffer handling Problem type : possible remote Debian-specific: no CVE references : CAN-2003-0693 CAN-2003-0695 CAN-2003-0682 This advisory is an addition to the earlier DSA-383-1 advisory: Solar Designer found four more bugs in OpenSSH that may be exploitable. For the Debian stable distribution these bugs have been fixed in version 1:3.4p1-0woody4 . Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 1357 d7f2f4b66a60aec2636aaa131a04ea86 Size/MD5 checksum: 837668 459c1d0262e939d6432f193c7a4ba8a8 Size/MD5 checksum: 120639 8c57caab816733519f2e764ff824ea2d alpha architecture (DEC Alpha) Size/MD5 checksum: 888572 addc35a6bc52711c42ae8a1e3cf86577 arm architecture (ARM) Size/MD5 checksum: 687794 c1143d02c214f8cfe4bd60ef6b8aaac5 hppa architecture (HP PA RISC) Size/MD5 checksum: 789374 2bdbe110e4df220c91c927b06116c8ea i386 architecture (Intel ia32) Size/MD5 checksum: 671778a4fe8e3f4de7c6a8048ec123f637838f ia64 architecture (Intel ia64) Size/MD5 checksum: 1049908 c420b72bc0c9a5f6c6d9b658291b7dc5 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 640920 b1df32262d6fb5cd7a1eca52c66e412f mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 762850 211c9d9c0385314d49039ce8e651ea61 powerpc architecture (PowerPC) Size/MD5 checksum: 711568 83acd76f1dd01ad7bba04f83e84e7b0e s390 architecture (IBM S/390) Size/MD5 checksum: 749104 e88e2b9601a057e9f45c6517b77701f7 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 694636 9cf84d70e306be2f4f94a86b8d41c857 - -- - ---------------------------------------------------------------------------- Debian Security team Debian -- Security Information Mailing-List: This email address is being protected from spambots. You need JavaScript enabled to view it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/bfZrPLiSUC+jvC0RAjcUAKCDoLyZ7u5kzPDbKcyDR/Ic7XVKaQCgl9qQ CBxj8Nr6AgjdI0pW0CoDM18=YvpS -----END PGP SIGNATURE----- . The latest Ubuntu advisory points to critical flaws within the OpenSSL framework, stressing the urgency for prompt upgrades to enhance protection and avert possible breaches.. OpenSSH Security, Debian Update, Remote Fix, Buffer Handling Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2003 Critical Debian
87

Debian 3.0: DSA-382-3 Critical: OpenSSH Remote Access Issues

This advisory is an addition to the earlier DSA-382-1 and DSA-382-3advisories: Solar Designer found four more bugs in OpenSSH that may beexploitable.. - ------------------------------------------------------------------------ Debian Security Advisory DSA-382-3 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman September 21, 2003 - ------------------------------------------------------------------------ Package : ssh Vulnerability : buffer handling Problem type : possible remote Debian-specific: no CVE references : CAN-2003-0693 CAN-2003-0695 CAN-2003-0682 This advisory is an addition to the earlier DSA-382-1 and DSA-382-3 advisories: Solar Designer found four more bugs in OpenSSH that may be exploitable. For the Debian stable distribution these bugs have been fixed in version 1:3.4p1-1.woody.3 . Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 837668 459c1d0262e939d6432f193c7a4ba8a8 Size/MD5 checksum: 36523 b264717da79efedfbaaecfede3ec5934 Size/MD5 checksum: 1350 bf5970e940e1d5bf7345a1d9e778d7f4 alpha architecture (DEC Alpha) Size/MD5 checksum: 35900 634340333420155ddaf6f70fab3fbd59 Size/MD5 checksum: 850196 c9e82af3e9f16941c64d0ae478e1f184 arm architecture (ARM) Size/MD5 checksum: 35132 b7c3431b949c24cf1c040be28e06fbbf Size/MD5 checksum: 658324 5ac2853c07e93bc498aadcc63565bb82 hppa architecture (HPPA RISC) Size/MD5 checksum: 755910 14d426db61713617a1e914bd1c675b07 Size/MD5 checksum: 35494 714c4e74169c5985ad745f8928d1e831 i386 architecture (Intel ia32) Size/MD5 checksum: 35414 ab621997a28bc30c928c2d317ae0c3a9 Size/MD5 checksum: 642624 a4293645b075984afa600f8094395c2d ia64 architecture (Intel ia64) Size/MD5 checksum: 1002720 ac989f421d1de08ce6487060ce231968 Size/MD5 checksum: 36906 45b3a0b3f0564cc6688fab9bc2bceee1 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 727514 4b667b3d8306af3eb8073e66932c853d Size/MD5 checksum: 35384 2395ff7a07f5d4e255844d0f608a8161 powerpc architecture (PowerPC) Size/MD5 checksum: 681524 f8f9c03826fce1dccc16c7d47b93a376 Size/MD5 checksum: 35150 b6a0d8c9edf371d118dd32d503102c6c s390 architecture (IBM S/390) Size/MD5 checksum: 718140 97e5e2e22860eb74d336e2938286d7a7 Size/MD5 checksum: 35786 97f0c72c5d72b61b5fe9c0c2a1d278be sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 686130 d44dec2bc9161419f71f769fff78f95b Size/MD5 checksum: 35202 1b2eb82ad15a4209237a61000dc63c3c - -- - ---------------------------------------------------------------------------- Debian Security team Debian -- Security Information Mailing-List: This email address is being protected from spambots. You need JavaScript enabled to view it. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQE/bfZaPLiSUC+jvC0RAm/eAJoCBZEgxQNjwmUPF/X5nDmzSwdYrwCfQAjQ 9EzuhfWxLhqW/yZ7Vd1fcjc=DXMK -----END PGP SIGNATURE----- . Critical advisory for Debian regarding vulnerabilities in OpenSSH requiring immediate patching and resolution.. Debian Security Advisory, OpenSSH Bug Fixes, Remote Access Threats. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 21, 2003 Critical Debian
87

Debian: DSA-382-2 Critical: OpenSSH Buffer Handling Remote Issue

This advisory is an addition to the earlier DSA-382-1 advisory: two morebuffer handling problems have been found in addition to the onedescribed in DSA-382-1. - ------------------------------------------------------------------------ Debian Security Advisory DSA-382-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman September 17, 2003 - ------------------------------------------------------------------------ Package : ssh Vulnerability : buffer handling Problem type : possible remote Debian-specific: no CVS references : CAN-2003-0693 CAN-2003-0695 This advisory is an addition to the earlier DSA-382-1 advisory: two more buffer handling problems have been found in addition to the one described in DSA-382-1. It is not known if these bugs are exploitable, but as a precaution an upgrade is advised. For the Debian stable distribution these bugs have been fixed in version 1:3.4p1-1.woody.2 . Please note that if a machine is setup to install packages from proposed-updates it will not automatically install this update. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 837668 459c1d0262e939d6432f193c7a4ba8a8 Size/MD5 checksum: 815 99e4e39a5347fe8e5619761060bf9d2b Size/MD5 checksum: 35975 8c6a44e3c8cbfd5dccb010be5cdf564d alpha architecture (DEC Alpha) Size/MD5 checksum: 35840 77fcccedb2ac13fd027abba4c8656e38 Size/MD5 checksum: 85008652c511f04447dc6d3bbc3fff19c6f0fd arm architecture (ARM) Size/MD5 checksum: 35074 f42db667b183a1551544ec0ac05bc0ba Size/MD5 checksum: 658234 94b2f66ad21fca6acd61cdffebb5af35 hppa architecture (HP PA RISC) Size/MD5 checksum: 35432 d6b3856b13d7ea28ea87cf158074b247 Size/MD5 checksum: 755812 0d98e1f72ae21c92a45c81f08ac55ea5 i386 architecture (Intel ia32) Size/MD5 checksum: 642524 88ca624e0b28087e918e3e7ee5b1e75f Size/MD5 checksum: 35346 b6a6e4cbc599a4ff13918bf41b1f24c7 ia64 architecture (Intel ia64) Size/MD5 checksum: 36838 75534178ba2118d8cd2bcbb15966c8bb Size/MD5 checksum: 1002662 1633a52473a4dedd0aed1d606c91f45a mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 35366 7a9b4c554c46e70d91e545a352be3fe1 Size/MD5 checksum: 729978 245ad86a030f8abe236ee7e79c0a7eb6 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 35326 4f6d478143b4d0775a70639efcbf349a Size/MD5 checksum: 727424 e0fd2c4d7ce937f33071aaa9505e5f5e powerpc architecture (PowerPC) Size/MD5 checksum: 681518 71f51665606d40f711a5f726b961dcb0 Size/MD5 checksum: 35088 0e9e0faa18c89a1851b7c47dc609bb71 s390 architecture (IBM S/390) Size/MD5 checksum: 35726 3fd0240ab71a05f7b5ca5f68f695ee72 Size/MD5 checksum: 718054 660d30ccc42e85ab02f3c19b7dca8ee8 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 686044 de5978b63c24074f28935c73d143e8fd Size/MD5 checksum: 35146 a3c936f9274de7182f8b00616f67249e - -- - ---------------------------------------------------------------------------- Debian Security team Debian -- Security Information Mailing-List: This email address is being protected from spambots. You need JavaScript enabled to view it. . The notice issued by Ubuntu draws attention to new security flaws identified in OpenSSH's memory handling and advises users to promptlyrefresh their systems.. Debian Security, OpenSSH Update, Critical Threats, Buffer Management Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 17, 2003 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200