Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

RedHat: RHSA-2019-4785 Critical: ImageMagick Security Flaw Detected

An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ghostscript security update Advisory ID: RHSA-2018:3760-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:3760 Issue date: 2018-12-03 CVE Names: CVE-2018-16509 ==================================================================== 1. Summary: An update for ghostscript is now available for Red Hat Enterprise Linux 6. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 6) - i386, x86_64 3. Description: The Ghostscript suite contains utilities for rendering PostScript and PDF documents. Ghostscript translates PostScript code to common bitmap formats so that the code can be displayed or printed. Security Fix(es): * It was discovered that the ghostscript /invalidaccess checks fail under certain conditions. An attacker couldpossibly exploit this to bypass the - -dSAFER protection and, for example, execute arbitrary shell commands via a specially crafted PostScript document. (CVE-2018-16509) Red Hat would like to thank Tavis Ormandy (Google Project Zero) for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1619748 - CVE-2018-16509 ghostscript: /invalidaccess bypass after failed restore (699654) 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: ghostscript-8.70-24.el6_10.2.src.rpm i386: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm x86_64: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): i386: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-doc-8.70-24.el6_10.2.i686.rpm ghostscript-gtk-8.70-24.el6_10.2.i686.rpm x86_64: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.x86_64.rpm ghostscript-doc-8.70-24.el6_10.2.x86_64.rpm ghostscript-gtk-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: ghostscript-8.70-24.el6_10.2.src.rpm x86_64: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v.6): x86_64: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.x86_64.rpm ghostscript-doc-8.70-24.el6_10.2.x86_64.rpm ghostscript-gtk-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: ghostscript-8.70-24.el6_10.2.src.rpm i386: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ppc64: ghostscript-8.70-24.el6_10.2.ppc.rpm ghostscript-8.70-24.el6_10.2.ppc64.rpm ghostscript-debuginfo-8.70-24.el6_10.2.ppc.rpm ghostscript-debuginfo-8.70-24.el6_10.2.ppc64.rpm s390x: ghostscript-8.70-24.el6_10.2.s390.rpm ghostscript-8.70-24.el6_10.2.s390x.rpm ghostscript-debuginfo-8.70-24.el6_10.2.s390.rpm ghostscript-debuginfo-8.70-24.el6_10.2.s390x.rpm x86_64: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.6): i386: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-doc-8.70-24.el6_10.2.i686.rpm ghostscript-gtk-8.70-24.el6_10.2.i686.rpm ppc64: ghostscript-debuginfo-8.70-24.el6_10.2.ppc.rpm ghostscript-debuginfo-8.70-24.el6_10.2.ppc64.rpm ghostscript-devel-8.70-24.el6_10.2.ppc.rpm ghostscript-devel-8.70-24.el6_10.2.ppc64.rpm ghostscript-doc-8.70-24.el6_10.2.ppc64.rpm ghostscript-gtk-8.70-24.el6_10.2.ppc64.rpm s390x: ghostscript-debuginfo-8.70-24.el6_10.2.s390.rpm ghostscript-debuginfo-8.70-24.el6_10.2.s390x.rpm ghostscript-devel-8.70-24.el6_10.2.s390.rpm ghostscript-devel-8.70-24.el6_10.2.s390x.rpm ghostscript-doc-8.70-24.el6_10.2.s390x.rpm ghostscript-gtk-8.70-24.el6_10.2.s390x.rpm x86_64: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.x86_64.rpm ghostscript-doc-8.70-24.el6_10.2.x86_64.rpm ghostscript-gtk-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: ghostscript-8.70-24.el6_10.2.src.rpm i386: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm x86_64: ghostscript-8.70-24.el6_10.2.i686.rpm ghostscript-8.70-24.el6_10.2.x86_64.rpm ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 6): i386: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-doc-8.70-24.el6_10.2.i686.rpm ghostscript-gtk-8.70-24.el6_10.2.i686.rpm x86_64: ghostscript-debuginfo-8.70-24.el6_10.2.i686.rpm ghostscript-debuginfo-8.70-24.el6_10.2.x86_64.rpm ghostscript-devel-8.70-24.el6_10.2.i686.rpm ghostscript-devel-8.70-24.el6_10.2.x86_64.rpm ghostscript-doc-8.70-24.el6_10.2.x86_64.rpm ghostscript-gtk-8.70-24.el6_10.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are availablefrom https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2018-16509 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXAXB8NzjgjWX9erEAQgceg/+Nlzzkc5UFF6a7W7IBrRCV11QM0BSqeAA I3fM6YxGHGTiQz2qmGJIcDwno932WD3M4jhFk488dxDY0qctI3al+0MaV3gJ4L/s VkSRaKh8ENHh6lh5RGJuP6zEPDat5KNc962CB87qmbxr22N2+6nXouwVwjTKYB04 VnqdQP/E834rerwFQOIZBrH1sYuRUfDGcN7B/uGQ5CzniqSwjSgs+wy2IKb3BKcb k/KRjxfNOBUJQXzypl/H4r38GUNODShBXiYTdIKu9aVOIEI0z5SMsYGGJ6DH/k4r R5Bb4uPPww3iXWhaDMn5ymmb5BcEXi3kboPq/6W5Oic1fKWYvL8WLSnyv2QjjxdP bxHvAfEp2fJZODvpUQUhZVN0wgLXGFmSGz3iUZhv/GQJJIIbyj/HG1NLh/6B5BQV l8drkB1zPJ2AtWp8R+UMWBPFXPeXcyj0mAlHZAgHp19EEgVcLaLznVuRph/ETE1W aXQ9rsgCG6s5wHWaMq9Ys6bglpVWtlFUNlk8XOJHGBclAZCHf0gmvJzbs4oR0zNY IKoEl2yNZaTarRZHwBOhynARij8JEN8NiZ5g6I8rrgQGetYWHCtgKeBIFJdq4qHv KLzwlDD33TjRTN25lm4YS6FWuUI+d8cFNXkbaQwENrc04q+2a/oHSph17KQslOYB wsMm9yDireI=MpjT -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Ghostscript update for Red Hat Enterprise Linux has been classified as Critical, focusing on resolving significant security vulnerabilities and potential risks.. Ghostscript Update, Red Hat Security, Linux Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 03, 2018 Important Red Hat
98

Red Hat Linux 7: RHSA-2001:154-06 Critical: OpenSSH Command Bypass

These updates fix a bug in handling of restricted keys which mayallow users to bypass command restrictions by using subsystems and a subtlebug which might aid a passive analysis attack.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated OpenSSH packages available Advisory ID: RHSA-2001:154-06 Issue date: 2001-11-13 Updated on: 2001-11-30 Product: Red Hat Linux Keywords: openssh restricted commands echo Cross references: Obsoletes: RHSA-2001:114 --------------------------------------------------------------------- 1. Topic: Updated OpenSSH packages are now available for Red Hat Linux 7, 7.1, and 7.2. These updates fix a bug in handling of restricted keys which may allow users to bypass command restrictions by using subsystems and a subtle bug which might aid a passive analysis attack. 2. Relevant releases/architectures: Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 Red Hat Linux 7.2 - i386 3. Problem description: OpenSSH versions prior to 2.9.9, when configured to provide sftp access using the subsystem feature, allows remote authenticated users to bypass authorized_keys2 "command=" restrictions by using sftp commands. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2001-0816 to this issue. OpenSSH 2.9 also contained a subtle bug in the routines which attempt to confound an attacker using passive analysis, which would cause it to send two confounding packets instead of one when a client finished sending it a password. Red Hat would like to thank Solar Designer and Markus Friedl for assisting with the patches. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: Red Hat Linux 7.2: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 6aaf629a210dea1988e7631e60072681 7.0/en/os/SRPMS/openssh-2.9p2-10.7.src.rpm 340e97c4aa1b88cb83b29929d2031a8b 7.0/en/os/alpha/openssh-2.9p2-10.7.alpha.rpm 833c1efcc3f0b501b2f95dc0225a1110 7.0/en/os/alpha/openssh-askpass-2.9p2-10.7.alpha.rpm 6afbdb015d3ae72cf34c5005212ce14d 7.0/en/os/alpha/openssh-askpass-gnome-2.9p2-10.7.alpha.rpm 890b6a4623bd251cbb509e0f52976aa8 7.0/en/os/alpha/openssh-clients-2.9p2-10.7.alpha.rpm 38dcfb8105a2585eb66166509ffb8ec3 7.0/en/os/alpha/openssh-server-2.9p2-10.7.alpha.rpm 206678dd9fed4e895282fdf944026fd5 7.0/en/os/i386/openssh-2.9p2-10.7.i386.rpm 932b8383849cd3c72575026873e04b2a 7.0/en/os/i386/openssh-askpass-2.9p2-10.7.i386.rpm 451ad9f475a4816b7def9f4737a2910f 7.0/en/os/i386/openssh-askpass-gnome-2.9p2-10.7.i386.rpm e6aaa5454932133eb5140d5aa8694c23 7.0/en/os/i386/openssh-clients-2.9p2-10.7.i386.rpm 2e2c50953866c77510e320587b2b763a 7.0/en/os/i386/openssh-server-2.9p2-10.7.i386.rpm 6aaf629a210dea1988e7631e60072681 7.1/en/os/SRPMS/openssh-2.9p2-10.7.src.rpm 340e97c4aa1b88cb83b29929d2031a8b7.1/en/os/alpha/openssh-2.9p2-10.7.alpha.rpm 833c1efcc3f0b501b2f95dc0225a1110 7.1/en/os/alpha/openssh-askpass-2.9p2-10.7.alpha.rpm 6afbdb015d3ae72cf34c5005212ce14d 7.1/en/os/alpha/openssh-askpass-gnome-2.9p2-10.7.alpha.rpm 890b6a4623bd251cbb509e0f52976aa8 7.1/en/os/alpha/openssh-clients-2.9p2-10.7.alpha.rpm 38dcfb8105a2585eb66166509ffb8ec3 7.1/en/os/alpha/openssh-server-2.9p2-10.7.alpha.rpm 206678dd9fed4e895282fdf944026fd5 7.1/en/os/i386/openssh-2.9p2-10.7.i386.rpm 932b8383849cd3c72575026873e04b2a 7.1/en/os/i386/openssh-askpass-2.9p2-10.7.i386.rpm 451ad9f475a4816b7def9f4737a2910f 7.1/en/os/i386/openssh-askpass-gnome-2.9p2-10.7.i386.rpm e6aaa5454932133eb5140d5aa8694c23 7.1/en/os/i386/openssh-clients-2.9p2-10.7.i386.rpm 2e2c50953866c77510e320587b2b763a 7.1/en/os/i386/openssh-server-2.9p2-10.7.i386.rpm 40f477635b6440dfd46afe59e28bf8f9 7.1/en/os/ia64/openssh-2.9p2-10.7.ia64.rpm 702b0a6703da90a7cca6037f6947794f 7.1/en/os/ia64/openssh-askpass-2.9p2-10.7.ia64.rpm 60f72ff95c7c3d41b56b3cb969e6494e 7.1/en/os/ia64/openssh-askpass-gnome-2.9p2-10.7.ia64.rpm 5c4e3ae0ce17e742b8dc3acd807246ec 7.1/en/os/ia64/openssh-clients-2.9p2-10.7.ia64.rpm 3400b7fb0337971f652a1e6403fb234d 7.1/en/os/ia64/openssh-server-2.9p2-10.7.ia64.rpm 90ce862375e8410ed5c5a29d9f23ed63 7.2/en/os/SRPMS/openssh-2.9p2-11.src.rpm ee061bdb5d9907ae65259c60823545db 7.2/en/os/i386/openssh-2.9p2-11.i386.rpm 8f589e90d818865053666bcfeed32bdb 7.2/en/os/i386/openssh-askpass-2.9p2-11.i386.rpm 3233cdafc1f62b926414b05445415548 7.2/en/os/i386/openssh-askpass-gnome-2.9p2-11.i386.rpm 3b7ef488182ae3afbd639e74e7eed8cc 7.2/en/os/i386/openssh-clients-2.9p2-11.i386.rpm 3358900ffa3d3327c9cfe79b365c1464 7.2/en/os/i386/openssh-server-2.9p2-11.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm--checksig --nogpg 8. References: CVE -CVE-2001-0816 http://marc.theaimsgroup.com/?l=openssh-unix-dev&m=100156674610824&w=2 Copyright(c) 2000, 2001 Red Hat, Inc. `. The latest patches for OpenSSH tackle security flaws that might allow unauthorized command execution and facilitate silent monitoring assaults on Fedora systems.. OpenSSH Update, Red Hat Security, Command Restrictions, Passive Analysis. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 30, 2001 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here