Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 10: DLA-3516-1 Critical: Burp JSON Parser Memory Issues

Multiple vulnerabilities have been found in the version of yajl bundled with burp, a simple cross-platform network BackUp and Restore Program. yajl is a JSON parser and small validating JSON generator. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3516-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Sean Whitton August 05, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : burp Version : 2.1.32-2+deb10u1 CVE ID : CVE-2017-16516 CVE-2022-24795 CVE-2023-33460 Debian Bug : 1040036 Multiple vulnerabilities have been found in the version of yajl bundled with burp, a simple cross-platform network BackUp and Restore Program. yajl is a JSON parser and small validating JSON generator. CVE-2017-16516 When a crafted JSON file is supplied to yajl, the process might crash with a SIGABRT in the yajl_string_decode function in yajl_encode.c. This potentially results in a denial of service. CVE-2022-24795 The 1.x branch and the 2.x branch of `yajl` contain an integer overflow which leads to subsequent heap memory corruption when dealing with large (~2GB) inputs. CVE-2023-33460 There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function, which potentially cause the server to run out of memory and crash. For Debian 10 buster, this problem has been fixed in version 2.1.32-2+deb10u1. We recommend that you upgrade your burp packages. For the detailed security status of burp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/burp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3517-2 warns of vulnerabilities in OpenSSL. Prompt upgrades are stronglyadvised.. Burp Security Update, Debian LTS, JSON Parser Issues, Memory Leak, Denial Of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 05, 2023 Critical Debian LTS
91

Gentoo: GLSA 201904-05 Normal: BURP Root Privilege Escalation

A vulnerability was discovered in Gentoo's ebuild for BURP which could lead to root privilege escalation.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201904-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: BURP: Root privilege escalation Date: April 02, 2019 Bugs: #641842 ID: 201904-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability was discovered in Gentoo's ebuild for BURP which could lead to root privilege escalation. Background ========= A network backup and restore program. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-backup/burp < 2.1.32-r1 > = 2.1.32-r1 Description ========== It was discovered that Gentoo’s BURP ebuild does not properly set permissions or place the pid file in a safe directory. Additionally, the first set of patches did not completely address this. As such, a revision has been made available that addresses all concerns of the initial report. Impact ===== A local attacker could escalate privileges. Workaround ========= Users should ensure the proper permissions are set as discussed in the referenced bugs. Resolution ========= All BURP users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-backup/burp-2.1.32-r1" References ========= [ 1 ] CVE-2017-18285 https://nvd.nist.gov/vuln/detail/CVE-2017-18285 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201904-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2019 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Linux Security Advisory GLSA 202110-08 discusses vulnerabilities in SYSTEM-X that could lead to unauthorized access. It is crucial to apply patches to maintain system integrity.. Gentoo Security, BURP Upgrade, Privilege Escalation. . LinuxSecurity.com Team

Calendar%202 Apr 02, 2019 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here