Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
87

Debian: DSA-2635-1 Critical: Cfingerd Buffer Overflow Remote Exploit

Malcolm Scott discovered a remote-exploitable buffer overflow in the rfc1413 (ident) client of cfingerd, a configurable finger daemon. This vulnerability was introduced in a previously applied patch to the cfingerd package in 1.4.3-3. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2635-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso March 1, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : cfingerd Vulnerability : buffer overflow Problem type : remote Debian-specific: yes CVE ID : CVE-2013-1049 Debian Bug : 700098 Malcolm Scott discovered a remote-exploitable buffer overflow in the rfc1413 (ident) client of cfingerd, a configurable finger daemon. This vulnerability was introduced in a previously applied patch to the cfingerd package in 1.4.3-3. For the stable distribution (squeeze), this problem has been fixed in version 1.4.3-3+squeeze1. For the testing distribution (wheezy), this problem has been fixed in version 1.4.3-3.1. For the unstable distribution (sid), this problem has been fixed in version 1.4.3-3.1. We recommend that you upgrade your cfingerd packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The advisory DSA-2635-1 from Debian outlines severe security vulnerabilities present in cfingerd, specifically highlighting a critical buffer overflow issue and the corresponding remedies.. Debian Security, Buffer Overflow, Cfingerd Patch, Remote Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 01, 2013 Critical Debian
87

Debian 2.2 DSA-066-1 Critical: Cfingerd Remote Exploit Fix

Buffer overflow and format string attack vulnerabilities exist in previous versions of cfingerd.. ------------------------------------------------------------------------ Debian Security Advisory DSA-066-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman July 11, 2001 ------------------------------------------------------------------------ Package : cfingerd Problem type : remote exploit Debian-specific: no Steven van Acker reported on bugtraq that the version of cfingerd (a configurable finger daemon) as distributed in Debian GNU/Linux 2.2 suffers from two problems: 1. The code that reads configuration files (files in which $ commands are expanded) copied its input to a buffer without checking for a buffer overflow. When the ALLOW_LINE_PARSING feature is enabled that code is used for reading users files as well, so local users could exploit this. 2. There also was a printf call in the same routine that did not protect against printf format attacks. Since ALLOW_LINE_PARSING is enabled in the default /etc/cfingerd.conf local users could use this to gain root access. This has been fixed in version 1.4.1-1.2, and we recommend that you upgrade your cfingerd package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: e1e5ed3fe85f2af5304b9f0d3d236a91 MD5 checksum: 966e205737bcd43182d01114694ed52a MD5 checksum: 0461179bca7bb9b00fb23c0886666cb0 Alpha architecture: MD5 checksum: 9c43dd39460c58ed6a0134333349e2f9 ARM architecture: MD5 checksum: 70da6073d42fbbdd29a025517127ebb0 Intel IA-32 architecture: MD5 checksum: 2281e1aa8dc439680b1df546a5139aae Motorola 680x0 architecture: MD5checksum: 19bf9fbcf1d2e1d7d38ff5bd00c6dc0a PowerPC architecture: MD5 checksum: 383389307d0ebd11b3f8a20abe1395a9 Sun Sparc architecture: MD5 checksum: 1e734a8573e1c05d8e07ffcc8543c4e9 These packages will be moved into the stable distribution on its next revision. For not yet released architectures please refer to the appropriate directory . -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Reassess cfingerd to mitigate risks linked to buffer overflow and format string security flaws that may enable remote attacks. Immediate action recommended.. Cfingerd Exploit Fix, Debian Security Update, Remote Exploit, Buffer Overflow, Format String Attack. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 11, 2001 Critical Debian
87

Debian: DSA-048-1 Critical: Cfingerd Remote Access Privilege Escalation

Megyer Laszlo report on Bugtraq that the cfingerd Debian as distributed with Debian GNU/Linux 2.2 was not careful in its logging code.. ------------------------------------------------------------------------ Debian Security Advisory DSA-048-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman April 19, 2001 ------------------------------------------------------------------------ Package : cfingerd Problem type : remote printf format attack Debian-specific: no Megyer Laszlo report on Bugtraq that the cfingerd Debian as distributed with Debian GNU/Linux 2.2 was not careful in its logging code. By combining this with an off-by-one error in the code that copied the username from an ident response cfingerd could exploited by a remote user. Since cfingerd does not drop its root privileges until after it has determined which user to finger an attacker can gain root privileges. This has been fixed in version 1.4.1-1.1, and we recommend that you upgrade your cfingerd package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 9ea177fd9f986c75da499c52c15d9dbe MD5 checksum: c9b3a1bc6bd2cb2dad3916da82df917c MD5 checksum: 0461179bca7bb9b00fb23c0886666cb0 Alpha architecture: MD5 checksum: 55eebf918692fb12bbcefb512ae9cfad ARM architecture: MD5 checksum: 41089c6e44cd1a91beb769070720c597 Intel ia32 architecture: MD5 checksum: 6ef1f240c9ab6fa1e94143d020bd782e Motorola 680x0 architecture: MD5 checksum: 670ed451481a4ade769c3128a95d20f2 PowerPC architecture: MD5 checksum: 9ca4d42c82f49974de09711f9d146c14 Sun Sparc architecture: MD5 checksum: 898af9044c308cc217cc9d3b0050c34e Thesepackages will be moved into the stable distribution on its next revision. For not yet released architectures please refer to the appropriate directory . -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . An urgent vulnerability found in cfingerd for Debian GNU/Linux. Promptly upgrade your software to safeguard administrative access.. debian cfingerd remote access upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 19, 2001 Critical Debian
87

Debian 1.4.0 Urgent: Update on cfingerd Root Vulnerability Fix

We have received a report that the all versions of cfingerd prior to 1.4.0 and 1.3.2-18.1 are vulnerable to a root exploit - as posted on bugtraq. . We have received a report that the all versions of cfingerd prior to 1.4.0 and 1.3.2-18.1 are vulnerable to a root exploit - as posted on bugtraq. We recommend you upgrade your cfingerd package immediately or disable ALLOW_EXECUTION. The latter is turned off in the default Debian configuration. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink ------------------------------- Source archives: MD5 checksum: 01f1f08cb22716f3188370bb827557e4 MD5 checksum: 8fd375da499ec3e0198981a97c11d5fe Sun Sparc architecture: MD5 checksum: 7edc36abd55c18c0c8f9e90837ab15cb Intel architecture: MD5 checksum: 515bdcc9e579ce8b886341658bacaefd Motorola 680x0 architecture: MD5 checksum: ec6f1388f5a7b407637aabc4de29a0c5 Alpha architecture: MD5 checksum: 97123d5b5eed85c74788d0c35c20b03b Debian GNU/Linux unstable alias potato -------------------------------------- Source archives: .4.0-1.diff.gz MD5 checksum: ad4cf97b7c3f679e3b4133320cac769c -1.dsc MD5 checksum: c5b5448968db444ee70075087e35a294 Sun Sparc architecture: MD5 checksum: 8aa7fd61b8db6f76cb8120df3082a54e Intel ia32 architecture: MD5 checksum: a33ea81eb429c7b734a2769685c1131a Motorola 680x0 architecture: MD5 checksum: 09b035f723bb9dd831e7d3a23f80f2f7 Alpha architecture: MD5 checksum: a3ecf841a966487fa888a6b4e9f92bc7 PowerPC architecture: MD5 checksum: 011da6d4cacaaf78304559606ff2f05e For not yet released architectures please refer to the appropriate directory . -- Debian GNU/Linux . Security Managers . This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it. Christian Hudon . Wichert Akkerman . Martin Schulze . . . Older cfingerd releases before 1.4.0 and 1.3.2-18.1 contain a severe root vulnerability; update immediately!. cfingerd Fix, Root Exploit, Debian Package, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 13, 1999 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200