Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo GLSA-201709-05 High: Chkrootkit Local Privilege Escalation

A vulnerability in chkrootkit may allow local users to gain root privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: chkrootkit: Local privilege escalation Date: September 17, 2017 Bugs: #512356 ID: 201709-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in chkrootkit may allow local users to gain root privileges. Background ========= chkrootkit is a tool to locally check for signs of a rootkit. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-forensics/chkrootkit < 0.50 > = 0.50 Description ========== When /tmp is mounted without the noexec option chkrootkit will execute files in /tmp with root privileges. Impact ===== A local attacker could possibly execute arbitrary code with root privileges. Workaround ========= Users should mount /tmp with noexec option. Resolution ========= All chkrootkit users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-forensics/chkrootkit-0.50" References ========= [ 1 ] CVE-2014-0476 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0476 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is ofutmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Local attackers may obtain administrative rights through a chkrootkit flaw; it is recommended that users update promptly to reduce exposure.. Chkrootkit, Local Escalation, Gentoo Security Advisory, Root Privileges, Software Upgrade. . LinuxSecurity.com Team

Calendar 2 Sep 17, 2017 Gentoo
172

Ubuntu 14.04 LTS: USN-2230-1 Critical Chkrootkit Admin Access Risk

chkrootkit could be made to run programs as an administrator.. =========================================================================Ubuntu Security Notice USN-2230-1 June 04, 2014 chkrootkit vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: chkrootkit could be made to run programs as an administrator. Software Description: - chkrootkit: rootkit detector Details: Thomas Stangner discovered that chkrootkit incorrectly quoted certain values. A local attacker could use this issue to execute arbitrary code when chkrootkit is run and gain root privileges. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: chkrootkit 0.49-4.1ubuntu1.14.04.1 Ubuntu 13.10: chkrootkit 0.49-4.1ubuntu1.13.10.1 Ubuntu 12.04 LTS: chkrootkit 0.49-4ubuntu1.1 Ubuntu 10.04 LTS: chkrootkit 0.49-3ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2230-1 CVE-2014-0476 Package Information: https://launchpad.net/ubuntu/+source/chkrootkit/0.49-4.1ubuntu1.14.04.1 https://launchpad.net/ubuntu/+source/chkrootkit/0.49-4.1ubuntu1.13.10.1 https://launchpad.net/ubuntu/+source/chkrootkit/0.49-4ubuntu1.1 https://launchpad.net/ubuntu/+source/chkrootkit/0.49-3ubuntu0.1 . Ubuntu Security Advisory USN-2265-1 highlights an issue in the sudo package that permits unauthorized privilege escalation for local users through a vulnerability.. chkrootkit, rootkit detection, admin access risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 04, 2014 Critical Ubuntu
87

Debian: DSA-2945-1 Moderate: Chkrootkit Local Access Threat

Thomas Stangner discovered a vulnerability in chkrootkit, a rootkit detector, which may allow local attackers to gain root access when /tmp is mounted without the noexec option. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2945-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano June 03, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chkrootkit CVE ID : CVE-2014-0476 Thomas Stangner discovered a vulnerability in chkrootkit, a rootkit detector, which may allow local attackers to gain root access when /tmp is mounted without the noexec option. For the stable distribution (wheezy), this problem has been fixed in version 0.49-4.1+deb7u2. For the unstable distribution (sid), this problem has been fixed in version 0.49-5. We recommend that you upgrade your chkrootkit packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A recent Chkrootkit patch mitigates local vulnerability issues in Debian systems. Safeguard your environment immediately.. Chkrootkit Update, Debian Security Advisory, Local Access Threat. . LinuxSecurity.com Team

Calendar 2 Jun 03, 2014 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here