Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu 12.10, 12.04 LTS USN-2048-2 Critical Curl Regression

USN-2048-1 introduced a regression in curl.. =========================================================================Ubuntu Security Notice USN-2048-2 December 06, 2013 curl regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: USN-2048-1 introduced a regression in curl. Software Description: - curl: HTTP, HTTPS, and FTP client and client libraries Details: USN-2048-1 fixed a vulnerability in curl. The security fix uncovered a bug in the curl command line tool which resulted in the --insecure (-k) option not working as intended. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Scott Cantor discovered that libcurl incorrectly verified CN and SAN name fields when digital signature verification was disabled. When libcurl is being used in this uncommon way by specific applications, an attacker could exploit this to perform a man in the middle attack to view sensitive information or alter encrypted communications. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: libcurl3 7.27.0-1ubuntu1.6 Ubuntu 12.04 LTS: libcurl3 7.22.0-3ubuntu4.5 Ubuntu 10.04 LTS: libcurl3 7.19.7-1ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2048-2 https://ubuntu.com/security/notices/USN-2048-1 https://bugs.launchpad.net/ubuntu/+source/curl/+bug/1258366 Package Information: https://launchpad.net/ubuntu/+source/curl/7.27.0-1ubuntu1.6 https://launchpad.net/ubuntu/+source/curl/7.22.0-3ubuntu4.5 https://launchpad.net/ubuntu/+source/curl/7.19.7-1ubuntu1.5 . A new update for multiple LTS versions of Ubuntu hasbeen issued to rectify a regression in the curl utility, enhancing security against man-in-the-middle attacks. Ubuntu Curl Update, Regression Issue, System Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 06, 2013 Critical Ubuntu
172

Ubuntu 8.10: USN-726-2 Moderate: Curl Regression Issue Fix

USN-726-1 fixed a vulnerability in curl. Due to an incomplete fix, a regression was introduced in Ubuntu 8.10 that caused certain types of URLs to fail. This update fixes the problem. We apologize for the inconvenience. [More...]. ==========================================================Ubuntu Security Notice USN-726-2 March 04, 2009 curl regression https://bugs.launchpad.net/ubuntu/+source/curl/+bug/337501 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: libcurl3 7.18.2-1ubuntu4.3 libcurl3-gnutls 7.18.2-1ubuntu4.3 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-726-1 fixed a vulnerability in curl. Due to an incomplete fix, a regression was introduced in Ubuntu 8.10 that caused certain types of URLs to fail. This update fixes the problem. We apologize for the inconvenience. Original advisory details: It was discovered that curl did not enforce any restrictions when following URL redirects. If a user or automated system were tricked into opening a URL to an untrusted server, an attacker could use redirects to gain access to abitrary files. This update changes curl behavior to prevent following "file" URLs after a redirect. Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 22444 f03a34d199a3dfe6862d4f93b6704e10 Size/MD5: 1491 906af0232a5e1c0a02e921eb508eff57 Size/MD5: 2273077 4fe99398a64a34613c9db7bd61bf6e3c amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 210392 605f35f7ab21dc4ed16205f73f5ce335 Size/MD5: 1124818 52b6531b8d0ba56e47844b90faaa7d88 Size/MD5: 216220700b648d0e4b4346da9dd4ba9421962f Size/MD5: 223312 58580fc77cdd1a93439ee92875aee1fc Size/MD5: 926208 16822154e80a941fd4305169d7979379 Size/MD5: 933192 ae5cc0e338e4f2d9f43ceac6c92303f0 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 209182 e34d8187746e820d6328fdc4540e7e73 Size/MD5: 1092044 3d9e9bf04f0dd77c09ff967ce0822011 Size/MD5: 212674 bdad3624169c184cdee7153dfdc61a16 Size/MD5: 219586 e9b3008f8cb5047b326b4d3f1f6e0323 Size/MD5: 899702 6dd63d112bdc8055636b2c8edfdd24a2 Size/MD5: 905420 ff0b8f23fd90555ffe215698ac644cdf lpia architecture (Low Power Intel Architecture): Size/MD5: 208850 1c452ad9122b12518bf1b5c8b3996c3b Size/MD5: 1099132 7735bb7e7c240be1a5f9ee749a67eb6e Size/MD5: 210934 5f3eea9bf9eece8f91200332c6f41b6a Size/MD5: 217456 eebef9ad6914c70cb38b0fa08875233c Size/MD5: 898570 21805c5b24e9477670aad07d167d56ab Size/MD5: 903918 90628d272b4301c968ef5cf446c778fe powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 212598 4003e25fccb2f67b75f451e60d7e9362 Size/MD5: 1130394 f755328b6c0df8b6963ea39255594cfb Size/MD5: 223766 b72e7008472791b08bba97fc57857f1b Size/MD5: 229632 d891ef64864441ba7f2496c29b57d49a Size/MD5: 925530 35c2284ab719cb773592ea4bc8679af6 Size/MD5: 931828 f29cf3a604d660801e1b011fa409af90 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 209654 b25b0908a500fb1c6ba5e9af876249ac Size/MD5: 1072608 7c3c67a9fcd09e1807a22d6ba110790e Size/MD5: 209368 cb36362b891401548905671dee5057db Size/MD5: 214076 49e05a9531109bcc7cbbce75adb29681 Size/MD5: 904932 56300cb1c407a1b90d23b72a22df0b56 Size/MD5: 909964 92dc9ddcf638da3dcac80c7f90373b10 . Ubuntu has resolved the curl regression noted in USN-726-2 to enhance URL managementwhile preventing unauthorized redirects. Users must update their systems for better security and stability. Ubuntu Security Update,Curl Security Fix,Remote Code Execution,Network Exploit. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 04, 2009 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here