Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 816-1 Moderate: Fetchmail Man In The Middle Attack Alert

Moxie Marlinspike discovered that fetchmail did not properly handlecertificates with NULL characters in the certificate name. A remoteattacker could exploit this to perform a man in the middle attack toview sensitive information or alter encrypted communications. [More...]. ==========================================================Ubuntu Security Notice USN-816-1 August 12, 2009 fetchmail vulnerability CVE-2009-2666 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: fetchmail 6.3.2-2ubuntu2.3 Ubuntu 8.04 LTS: fetchmail 6.3.8-10ubuntu1.1 Ubuntu 8.10: fetchmail 6.3.8-11ubuntu3.1 Ubuntu 9.04: fetchmail 6.3.9~rc2-4ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Moxie Marlinspike discovered that fetchmail did not properly handle certificates with NULL characters in the certificate name. A remote attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 191107 9d0c089074ea79db248cca36714e56cd Size/MD5: 812 68c7ce726e683390daf0199b2b646865 Size/MD5: 1522264 a661735496077232acedb82a901fa499 Architecture independent packages: Size/MD5: 114946 01a751405f08024ed08e0ec1b06b6213 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 347012 32a3fff1c437774c2480646536b9e716 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 333650 0eed4e07d723dba7ca14210e80e59c7a powerpc architecture (AppleMacintosh G3/G4/G5): Size/MD5: 345698 ee714084a44f35a1c7bc9916691ccea2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 339820 47b3f94dc05000e46489fddd30eea5be Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 63885 e305fcae9eb86e0fce57c1e0467db13e Size/MD5: 1080 49e91c3a8ed18d928a3002279ac61caa Size/MD5: 1691723 1b84621072b4f906b5686a4fbae0b1d7 Architecture independent packages: Size/MD5: 63906 e40223bb9b433719091d0d9de835cc1e amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 385906 154e459bf59e28a44750bd392ddd2ca9 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 373120 dcb601f22e56bf36f2104b359fbc1c9d lpia architecture (Low Power Intel Architecture): Size/MD5: 373342 f1a37e39a5dc46fdeb25ece934faff56 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 388680 2f669c26bd5093201815241caae577a0 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 377326 b8f0ba3a4ac9513ff931cb9e9ddeed0c Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 65008 ae5fa277a18f59b0e2af5119b21cc962 Size/MD5: 1488 c2dbe38ccbcdcb60260fefd9fcc47608 Size/MD5: 1691723 1b84621072b4f906b5686a4fbae0b1d7 Architecture independent packages: Size/MD5: 64354 2b0529ffa107f1622b7b559dbcea19f3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 387888 93842d6ea6f4544b58976d6b7329b65c i386 architecture (x86 compatible Intel/AMD): Size/MD5: 373930 968ae9e9dac23d81c6d63eac91590a49 lpia architecture (Low Power Intel Architecture): Size/MD5: 373726 a12e3bf5a1b691e2435f8b91b028b3d2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 388470 d7da47c31d27d3edbb5c8e2b0b308909 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 380018 b4015f4a8b8e67c1b62231033b736bba Updated packages forUbuntu 9.04: Source archives: Size/MD5: 49605 3bbf57ecf060a6254b71bc73b46c429e Size/MD5: 1505 3d4d55b89631a10be608739db0488d00 Size/MD5: 1711087 200ece6f73ac28ccda7aea42ea4e492d Architecture independent packages: Size/MD5: 64940 68cf588634d7ab15120f0fc73f8cbb73 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 391020 40816e1ae515f598756b55ec23c38cf6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 377636 70682ec1fbf0fc1692f83c15bdf593e7 lpia architecture (Low Power Intel Architecture): Size/MD5: 377928 986f144b2162feb7664b9f5c39047035 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 391402 d69de1a36758e6b35d46e7283f555b61 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 384332 eabd08fec6c574ad615e0dd38c0961e6 . Ubuntu security alert regarding fetchmail vulnerability using NULL characters in certificates; update is advised.. fetchmail Exploit, Ubuntu Security Update, Certificate Handling Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 12, 2009 Important Ubuntu
172

Ubuntu 8.10: USN-810-1 Critical: NSS Denial Of Service Issues

Moxie Marlinspike discovered that NSS did not properly handle regularexpressions in certificate names. A remote attacker could create aspecially crafted certificate to cause a denial of service (via applicationcrash) or execute arbitrary code as the user invoking the program.(CVE-2009-2404) [More...]. ==========================================================Ubuntu Security Notice USN-810-1 August 04, 2009 nss vulnerabilities CVE-2009-2404, CVE-2009-2408, CVE-2009-2409 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libnss3-1d 3.12.3.1-0ubuntu0.8.04.1 Ubuntu 8.10: libnss3-1d 3.12.3.1-0ubuntu0.8.10.1 Ubuntu 9.04: libnss3-1d 3.12.3.1-0ubuntu0.9.04.1 After a standard system upgrade you need to restart an applications that use NSS, such as Firefox, to effect the necessary changes. Details follow: Moxie Marlinspike discovered that NSS did not properly handle regular expressions in certificate names. A remote attacker could create a specially crafted certificate to cause a denial of service (via application crash) or execute arbitrary code as the user invoking the program. (CVE-2009-2404) Moxie Marlinspike and Dan Kaminsky independently discovered that NSS did not properly handle certificates with NULL characters in the certificate name. An attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. (CVE-2009-2408) Dan Kaminsky discovered NSS would still accept certificates with MD2 hash signatures. As a result, an attacker could potentially create a malicious trusted certificate to impersonate another site. (CVE-2009-2409) Updated packages for Ubuntu 8.04LTS: Source archives: Size/MD5: 37286 f4041d128d758f5506197b1cf0f1214f Size/MD5: 2012 401475ce9f7efa228d7b61671aa69c11 Size/MD5: 5316068 cc5607243fdfdbc80ebbbf6dbb33f784 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 18232 49a5581a19be7771ecdc65fb943e86d7 Size/MD5: 3166090 074734f6e0fd51257999bdc0e38010f3 Size/MD5: 1147016 ddc8dfd4f0cc77c129c5bb4b18b6612c Size/MD5: 257780 f6d735c7c95478fe2992178e0d7781d4 Size/MD5: 312528 05d78cad52b8c5464350c9b191528e0e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 18200 2c088a165372b431416a5b6d9f54b80b Size/MD5: 3012554 50978f6f10b9f4c3918822d864d41aed Size/MD5: 1040016 f0a52f96bd4f7bb7d8001b7ca5ace8d0 Size/MD5: 254880 c2151ff8a86f4119fcefa1f6c9ee7add Size/MD5: 295096 f6fde2292ca35df9e6cac822d158e512 lpia architecture (Low Power Intel Architecture): Size/MD5: 18190 cbc624cedbae82a39d3c47aaa8ffee38 Size/MD5: 3041822 533fda14ea785417cababc58419a8fec Size/MD5: 1016224 1ed477ec2ffe3ac642cb7c29413842ab Size/MD5: 253574 b9756509dcdeea8433a0f6bbe2dc27b7 Size/MD5: 292466 55f2cf8c33f19f17cae613aca3ce71c1 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 20678 a26907dda711e1d13e8d597bee4689e0 Size/MD5: 3125800 102117180150342cecff38e653963f66 Size/MD5: 1143852 f96cab41f4bf24cf4fa4686b3a963464 Size/MD5: 256600 e19a891112bea8df4f27fe569da9c951 Size/MD5: 324934 9aaac74bc3f6ec7f990f78d556c5ec09 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 18292 7e17d87ea08f93759ed7784705d82453 Size/MD5: 2834720 02b6284e651dcf2e6556378dcb730689 Size/MD5: 1019944 ee1829f9195609b3912994fc76788243 Size/MD5: 251578 09583a51b0814b53959af6d79a1b4f8c Size/MD5: 299484 0d12ed86aae10c56300bd7cefb2884ef Updated packages forUbuntu 8.10: Source archives: Size/MD5: 32769 d4e1fb5ca38687ad1e7532c457febc11 Size/MD5: 2012 f98ccd513ae480ac7b56d7a4793758d3 Size/MD5: 5316068 cc5607243fdfdbc80ebbbf6dbb33f784 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 3310610 9f8e4b95d1019e3956a88745ce3888c4 Size/MD5: 1195070 21daa67a1f51cc4a942e41beb2da001f Size/MD5: 257586 89d972c2b67679eca265abac76d0687d Size/MD5: 18296 8c1d95902c4f0e85c47a3ca941f0b48a Size/MD5: 317026 11f10cc940951638cf5cac0e6e2f7ded i386 architecture (x86 compatible Intel/AMD): Size/MD5: 3137262 2ae6e2fa5e934a5fa27e14cedcdc74b6 Size/MD5: 1076898 59318f3e92b12686695704ef33074dc0 Size/MD5: 254686 b0dc3ec378ea87afff4a6d46fafca34f Size/MD5: 18248 7a86d451f0cc722f66ca51f9894c81e2 Size/MD5: 300214 88f4442427f4ad5b1e507f24a872d7d5 lpia architecture (Low Power Intel Architecture): Size/MD5: 3173686 65714f22fc4908727cd58fa917cff249 Size/MD5: 1050748 c55a36fa65b311364ddfc5f9bcacc3e9 Size/MD5: 253226 0b49775e55163a5c6fa22fba288eded7 Size/MD5: 18220 8fd881d7744299014a919437d9edaf87 Size/MD5: 296154 fce2927b08d43ba6d2188bf927dfb4d6 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 3284430 e411ebc5e3848a9a28fdb7bcf55af833 Size/MD5: 1165792 f6a9ba644f3fb0cd888bf4b425522633 Size/MD5: 256434 19a95ab61e462058ecaf05cbebd11c8a Size/MD5: 20666 abe014ba1940180af1051006e4d293fd Size/MD5: 320710 0f3c730279a7e731e72986d15fa2fcc2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 2942578 3d396922de5283db749fd41036403ead Size/MD5: 1038356 9d291947a8ef7d02c8c1a9746c1309d4 Size/MD5: 251226 c09de8036a434e93488b5c1b77108246 Size/MD5: 18380 0d18623f50973af22fd4e44e0d042bf4 Size/MD5: 301438 430f4a9aef7a540fac80629656572ea9 Updated packagesfor Ubuntu 9.04: Source archives: Size/MD5: 35980 b64ec10add3d7fbbc7335b0f85b9fb00 Size/MD5: 2012 a889688996d5530e8bf1eb181683137e Size/MD5: 5316068 cc5607243fdfdbc80ebbbf6dbb33f784 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 3309788 d48afcfa4139fe94b4c0af67c8d9c850 Size/MD5: 1196740 7ace44202680241529edaeb226d0dec1 Size/MD5: 258240 54d581c61ba7608526790263545e1b1c Size/MD5: 17404 bfbb39c275bb15dcef644991c6af7e7b Size/MD5: 317668 9d55ed9607359667cf963e04ccb834d5 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 3137602 af5d5d420c440bf53de79f8952ee17d0 Size/MD5: 1078336 706162a5436e733e4ce57d51baf163fb Size/MD5: 255338 140b54235689f93baa3971add5401a42 Size/MD5: 17412 fb6ca266988f45378c41455fa5207a85 Size/MD5: 300808 7b06b74c327641634d4f8f1f61b7d432 lpia architecture (Low Power Intel Architecture): Size/MD5: 3171676 ad44dc80ef0066d3da2edede234b0210 Size/MD5: 1052136 727ab68dd03bec2ae01b4611c5f98309 Size/MD5: 253840 15198ca066b229b42ced8cb5f4307a53 Size/MD5: 17408 fdf85ab9c62a3d3999d4f49bf0172243 Size/MD5: 296796 ecc392b5e6b2b2b5b5ef6d9f93f3ad30 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 3282216 5399927c4f40c9369fcb58d3038cc3ec Size/MD5: 1167866 477cd3a3cb2ec7c5cf791208e096de93 Size/MD5: 257080 85844f856588609fba74ec37044f9c35 Size/MD5: 17410 98059af1adbd24026a4dab4faa27ddd1 Size/MD5: 321372 b7afef4b3c7dc27dceb12668458629d8 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 2942004 2e8c7c62ef1119b9326564fe50389b8d Size/MD5: 1039416 ad6d7c7f3a2301c7e46a1102098fdbaf Size/MD5: 251874 4a70da68d8ae2e444b7aaf6836d50eba Size/MD5: 17410 9921067423eeb95bea428bf9f471559c Size/MD5: 301814 302527f9bbcb164d12b13d25719a9ab9 . Identifycritical NSS security flaws in Ubuntu versions 8.04, 8.10, and 9.04 that can lead to Denial of Service threats. Immediate updates required.. NSS Threats, Ubuntu Security Risks, Denial Of Service Flaws, Arbitrary Code Risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 04, 2009 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here