Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 32: 2020-aa51efe207 moderate: radare2 Shell Injection Risk

- Rebase radare2 to upstream version 4.5.0 - Rebase cutter to upstream version 1.11.0 - Provide cutter translation - Provide -devel sub package of cutter-re. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-aa51efe207 2020-08-07 01:18:08.804645 --------------------------------------------------------------------------------Name : radare2 Product : Fedora 32 Version : 4.5.0 Release : 2.fc32 URL : https://radare.org/ Summary : The reverse engineering framework Description : The radare2 is a reverse-engineering framework that is multi-architecture, multi-platform, and highly scriptable. Radare2 provides a hexadecimal editor, wrapped I/O, file system support, debugger support, diffing between two functions or binaries, and code analysis at opcode, basic block, and function levels. --------------------------------------------------------------------------------Update Information: - Rebase radare2 to upstream version 4.5.0 - Rebase cutter to upstream version 1.11.0 - Provide cutter translation - Provide -devel sub package of cutter-re --------------------------------------------------------------------------------ChangeLog: * Mon Jul 20 2020 Riccardo Schirone - 4.5.0-2 - Remove the .1 from the version signature * Mon Jul 20 2020 Riccardo Schirone - 4.5.0-1 - Rebase to upstream version 4.5.0 --------------------------------------------------------------------------------References: [ 1 ] Bug #1859143 - CVE-2020-15121 radare2: malformed PDB file names in the PDB server path cause shell injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1859143 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-aa51efe207' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Enhance radare2 to edition 4.5.0 while resolving shell injection vulnerabilities within Fedora 32 through this advisory announcement.. radare2 Update, Fedora 32 Advisory, Reverse Engineering Security. . LinuxSecurity.com Team

Calendar 2 Aug 06, 2020 Fedora
89

Fedora: FEDORA-2020-aa51efe207 moderate: cutter-re shell injection

- Rebase radare2 to upstream version 4.5.0 - Rebase cutter to upstream version 1.11.0 - Provide cutter translation - Provide -devel sub package of cutter-re. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-aa51efe207 2020-08-07 01:18:08.804645 --------------------------------------------------------------------------------Name : cutter-re Product : Fedora 32 Version : 1.11.0 Release : 1.fc32 URL : https://cutter.re/ Summary : GUI for radare2 reverse engineering framework Description : Cutter is a Qt and C++ GUI for radare2. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. --------------------------------------------------------------------------------Update Information: - Rebase radare2 to upstream version 4.5.0 - Rebase cutter to upstream version 1.11.0 - Provide cutter translation - Provide -devel sub package of cutter-re --------------------------------------------------------------------------------ChangeLog: * Mon Jul 27 2020 Riccardo Schirone - 1.11.0-1 - Bump to upstream version 1.11.0-1 (Thanks to Michal Ambroz, changes mostly taken from https://src.fedoraproject.org/rpms/cutter-re/pull-request/2#request_diff) - Add cutter translations - Provide -devel sub package to allow compilation of cutter plugins --------------------------------------------------------------------------------References: [ 1 ] Bug #1859143 - CVE-2020-15121 radare2: malformed PDB file names in the PDB server path cause shell injection [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1859143 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-aa51efe207' at the command line. For more information, refer tothe dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Debian Upgrade Alert DEBIAN-2023-bc67def654 brings important enhancements in gedit and improvements to libgtk.. Cutter Update, Radare2 Rebase, Fedora Security, GUI Reverse Engineering. . LinuxSecurity.com Team

Calendar 2 Aug 06, 2020 Fedora
89

Fedora 30: FEDORA-2019-2a16e1ab93 critical: cutter radare2 Security Fixes

Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and CVE-2019-12865 and rebase cutter to 1.8.3.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2a16e1ab93 2019-07-30 01:13:56.894668 --------------------------------------------------------------------------------Name : cutter-re Product : Fedora 30 Version : 1.8.3 Release : 1.fc30 URL : https://cutter.re/ Summary : GUI for radare2 reverse engineering framework Description : Cutter is a Qt and C++ GUI for radare2. Its goal is making an advanced, customizable and FOSS reverse-engineering platform while keeping the user experience at mind. Cutter is created by reverse engineers for reverse engineers. --------------------------------------------------------------------------------Update Information: Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and CVE-2019-12865 and rebase cutter to 1.8.3. --------------------------------------------------------------------------------ChangeLog: * Mon Jul 15 2019 Riccardo Schirone - 1.8.3-1 - rebase to cutter 1.8.3 * Wed Jun 26 2019 Riccardo Schirone - 1.8.0-4 - recompile for radare2 3.6.0 * Mon Apr 15 2019 Riccardo Schirone - 1.8.0-3 - recompile for radare2 3.4.1 * Tue Apr 9 2019 Lubomir Rintel - 1.8.0-2 - Update to radare2 3.4.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1725676 - CVE-2019-12865 radare2: double free in cmd_mount in libr/core/cmd_mount.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725676 [ 2 ] Bug #1722733 - CVE-2019-12802 radare2: denial of service in function rcc_context in /libr/egg/egg_lang.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1722733 [ 3 ] Bug #1723354 - CVE-2019-12790 radare2: heap-based buffer over-read in function r_egg_lang_parsechar in egg_lang.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1723354 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2a16e1ab93' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Fedora 30's new update tackles vulnerabilities in cutter, effectively patching significant security weaknesses linked to radare2.. Fedora Cutter Update, Security Fixes, Radare2 Issues, Application Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2019 Critical Fedora
89

Fedora: 2019-2a16e1ab93 Critical: radare2 Double Free And DoS Issues

Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and CVE-2019-12865 and rebase cutter to 1.8.3.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-2a16e1ab93 2019-07-30 01:13:56.894668 --------------------------------------------------------------------------------Name : radare2 Product : Fedora 30 Version : 3.6.0 Release : 1.fc30 URL : https://radare.org/ Summary : The reverse engineering framework Description : The radare2 is a reverse-engineering framework that is multi-architecture, multi-platform, and highly scriptable. Radare2 provides a hexadecimal editor, wrapped I/O, file system support, debugger support, diffing between two functions or binaries, and code analysis at opcode, basic block, and function levels. --------------------------------------------------------------------------------Update Information: Rebase to radare2 3.6.0 and fix CVE-2019-12790, CVE-2019-12802 and CVE-2019-12865 and rebase cutter to 1.8.3. --------------------------------------------------------------------------------ChangeLog: * Wed Jun 26 2019 Riccardo Schirone - 3.6.0 - rebase to upstream version 3.6.0 * Tue Apr 16 2019 Adam Williamson - 3.4.1-2 - Rebuild with Meson fix for #1699099 - Fix versioning * Mon Apr 8 2019 Riccardo Schirone - 3.4.1-1 - rebase to upstream version 3.4.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1725676 - CVE-2019-12865 radare2: double free in cmd_mount in libr/core/cmd_mount.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1725676 [ 2 ] Bug #1722733 - CVE-2019-12802 radare2: denial of service in function rcc_context in /libr/egg/egg_lang.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1722733 [ 3 ] Bug #1723354 - CVE-2019-12790 radare2: heap-based buffer over-read in function r_egg_lang_parsechar in egg_lang.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1723354 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-2a16e1ab93' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . CentOS System Alert for radare2 brings vital patches and improves functionalities for fortified security performance.. radare2 Framework, Fedora Update, Denial of Service, Buffer Over-read. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 29, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here