Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA-2158-1 Urgent: Warning Regarding Cgiirc XSS Vulnerability

Michael Brooks (Sitewatch) discovered a reflective XSS flaw in cgiirc, a web based IRC client, which could lead to the execution of arbitrary javascript. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2158-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp February 9, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : cgiirc Vulnerability : cross-site scripting Problem type : local Debian-specific: no CVE ID : CVE-2011-0050 Michael Brooks (Sitewatch) discovered a reflective XSS flaw in cgiirc, a web based IRC client, which could lead to the execution of arbitrary javascript. For the old-stable distribution (lenny), this problem has been fixed in version 0.5.9-3lenny1. For the stable distribution (squeeze), and unstable distribution (sid), this problem will be fixed shortly. We recommend that you upgrade your cgiirc packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . New vulnerability found in cgiirc may permit unauthorized script execution. Debian users should upgrade as a precaution.. Cgiirc Security, Debian Advisory, XSS Threat. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 09, 2011 Important Debian
87

Debian: DSA 1053-2 Severe: OpenSSL Buffer Overflow Remote Risk

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1052-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze May 8th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : cgiirc Vulnerability : buffer overflows Problem type : remote Debian-specific: no CVE ID : CVE-2006-2148 Debian Bug : 365680 Several buffer overflows have been discovered in cgiirc, a web-based IRC client, which could be exploited to execute arbitrary code. The old stable distribution (woody) does not contain cgiirc packages. For the stable distribution (sarge) these problems have been fixed in version 0.5.4-6sarge1. For the unstable distribution (sid) these problems have been fixed in version 0.5.4-6sarge1. We recommend that you upgrade your cgiirc package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 590 daed94ad35a0ac4935086bfd1379c20f Size/MD5 checksum: 13507 a885a3704d8313920548f156d764dec6 Size/MD5 checksum: 127545 c32ce6514626729ef8cf30cf7bd1a51e Alpha architecture: Size/MD5 checksum: 122974 55a573eb356b35cb32b651ca570d76f6 AMD64 architecture: Size/MD5 checksum: 122526 25977ad46ac501c8c81de1347dac8cc9 ARM architecture: Size/MD5 checksum: 122004 594434fc3222bd093b4b202e2e9df1ec Intel IA-32 architecture: Size/MD5 checksum: 122082 e5d18578977303524a6d9c92a314b0cf Intel IA-64 architecture: Size/MD5 checksum: 123546 b91e34892993e4d176d3fa8ff970f123 HP Precision architecture: Size/MD5 checksum: 122868 96f3c61fa95509d03277209d5549a037 Motorola 680x0 architecture: Size/MD5 checksum: 121960 e6a1341cee535289a78ef0e2ca33badd Big endian MIPS architecture: Size/MD5 checksum: 123686 ebebe98b959b9985581338ffa5f60857 Little endian MIPS architecture: Size/MD5 checksum: 123688 0004985ff0018cad8ff54630b4b96e7d PowerPC architecture: Size/MD5 checksum: 122502 d2b6b1cbd8d05baebdbd7febd16edc39 IBM S/390 architecture: Size/MD5 checksum: 122504 833f9eb5d35ec6baac52ceec8193422d Sun Sparc architecture: Size/MD5 checksum: 122060 e611d3c02896f065d3989a3182cd4fd7 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Upgrade cgiirc on your Debian system to enhance security against remote code execution vulnerabilities from buffer overflows. Follow the steps to upgrade:. Debian Security Advisory, cgiirc buffer overflow, security patch, remote code execution, Debian upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 08, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200