Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora 9 FEDORA-2008-9458 Moderate: rgmanager Buffer Overflow Threat

A major code audit did show several unsecure use of /tmp. This update addresses those issues across the whole code.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-9458 2008-11-07 01:35:31 --------------------------------------------------------------------------------Name : rgmanager Product : Fedora 9 Version : 2.03.09 Release : 1.fc9 URL : Summary : Open Source HA Resource Group Failover for Red Hat Enterprise Linux Description : Red Hat Resource Group Manager provides high availability of critical server applications in the event of planned or unplanned system downtime. --------------------------------------------------------------------------------Update Information: A major code audit did show several unsecure use of /tmp. This update addresses those issues across the whole code. --------------------------------------------------------------------------------ChangeLog: * Fri Oct 31 2008 Fabio M. Di Nitto - 2.03.09-1 - New upstream release Fix rhbz#468966 Addresses several security issues similar to CVE-2008-4192 and CVE-2008-4579 after deep code audit from upstream - cleanup patches to match 2.6.26 kernel in F-9 * Tue Oct 21 2008 Fabio M. Di Nitto - 2.03.08-1 - New upstream release Fix rhbz#460376 CVE-2008-4192 Fix rhbz#467386 CVE-2008-4579 - cleanup/update patches to match 2.6.26 kernel in F-9 * Thu Aug 14 2008 Fabio M. Di Nitto - 2.03.07-1 - New upstream release - Fix rgmanager startup locking issues - Apply patch to include kernel headers from 2.6.26 required to build userland. Userland will run in 2.6.25 compatibility mode - Apply patch to keep kernel modules at 2.6.25 (upstream is at 2.6.26) (this patch is purely cosmetic since we don't build kernel modules but keep the source in sync is Good (tm)) - Cleanup packaging for installed docs and file permissions * Mon Jul 14 2008 Fabio M. Di Nitto - 2.03.05-1 - New upstreamrelease - Cleanup installed doc after upstream * Wed Jun 11 2008 Fabio M. Di Nitto 2.03.04-1 - New upstream release - Resolves: #446995 #318271 #447378 #445662 - Update license tags after major upstream cleanup - Include COPYRIGHT file * Fri May 30 2008 Fabio M. Di Nitto - 2.03.03-1 - New upstream release - Cleanup spec file - Update Requires to use packages rather than pointing at files - Update licence tag - Drop local patches that are now upstream - Update build section to use standard macros and remove need of kernel heaeders - Cleanup install target and remove local hacks - Fix preun section to stop rgmanager - Cleanup files section to use macros --------------------------------------------------------------------------------References: [ 1 ] Bug #468966 - Possible buffer overflow in cman config loader can lead to memory corruption https://bugzilla.redhat.com/show_bug.cgi?id=468966 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update rgmanager' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Upgrade rgmanager on Fedora 9 to enhance security against identified vulnerabilities related to /tmp directory usage by following these essential steps. rgmanager update,Fedora security,high availability,code audit,server applications. . LinuxSecurity.com Team

Calendar 2 Nov 06, 2008 Fedora
87

Debian: DSA-520-1 Critical: Multiple CVS Security Issues

Sebastian Krahmer and Stefan Esser discovered several vulnerabilities in the CVS server during a code audit.. Debian Security Advisory DSA 519-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze June 15th, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : cvs Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0416 CAN-2004-0417 CAN-2004-0418 Sebastian Krahmer and Stefan Esser discovered several vulnerabilities in the CVS server, which serves the popular Concurrent Versions System. The Common Vulnerability and Exposures project identifies the following problems: CAN-2004-0416: double-free() in error_prog_name CAN-2004-0417: argument integer overflow CAN-2004-0418: out of bound writes in serve_notify() For the stable distribution (woody) this problem has been fixed in version 1.11.1p1debian-9woody7. For the unstable distribution (sid) this problem has been fixed in version 1.12.9-1. We recommend that you upgrade your cvs package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 693 808c55e071608254b399c5cf8288c478 Size/MD5 checksum: 55929 5c87146893651805658b497c8d2164f3 Size/MD5 checksum: 2621658 500965ab9702b31605f8c58aa21a6205 Alpha architecture: Size/MD5 checksum: 1178992d411cdd545809660443ff35d49c6e105 ARM architecture: Size/MD5 checksum: 1106154 5839fcf6673e32d51fc8814591cb49d1 Intel IA-32 architecture: Size/MD5 checksum: 1086800 1283329c4e9337eb1308945ab77738a7 Intel IA-64 architecture: Size/MD5 checksum: 1272232 e71070f4b415c03b996fbc5e14006094 HP Precision architecture: Size/MD5 checksum: 1148086 8e70b23bba46da919774913f5b3d3b83 Motorola 680x0 architecture: Size/MD5 checksum: 1066546 e7f59327f9afdeeec311178839c6997e Big endian MIPS architecture: Size/MD5 checksum: 1130478 08811baa91dabf7619b2ca9bb3c84fe6 Little endian MIPS architecture: Size/MD5 checksum: 1131936 6f51edb9c8f078f8c37ffeb87db686e7 PowerPC architecture: Size/MD5 checksum: 1116890 c50418a92b897b0bd698a389a3dd5ba5 IBM S/390 architecture: Size/MD5 checksum: 1097614 1e967b9a0ea2f2feaf4f83b4fb082750 Sun Sparc architecture: Size/MD5 checksum: 1107928 49e348f931f71a861140995edb0fcd30 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Investigate the security alerts related to multiple CVE vulnerabilities affecting Debian servers and the associated remediation steps.. Debian Advisory, CVS Remote Threats, Software Update, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 17, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here