Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
172

Ubuntu 10.10: USN-1108-2 Moderate: DHCP Client Privilege Escalation Risk

An attacker's DHCP server could send crafted responses to your computer and cause it to run programs as root.. =========================================================================Ubuntu Security Notice USN-1108-2 April 19, 2011 dhcp3 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 10.10 - Ubuntu 10.04 LTS - Ubuntu 9.10 Summary: An attacker's DHCP server could send crafted responses to your computer and cause it to run programs as root. Software Description: - dhcp3: DHCP Client Details: USN-1108-1 fixed vulnerabilities in DHCP. Due to an error, the patch to fix the vulnerability was not properly applied on Ubuntu 9.10 and higher. This update fixes the problem. Original advisory details: Sebastian Krahmer discovered that the dhclient utility incorrectly filtered crafted responses. An attacker could use this flaw with a malicious DHCP server to execute arbitrary code, resulting in root privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 10.10: dhcp3-client 3.1.3-2ubuntu6.2 Ubuntu 10.04 LTS: dhcp3-client 3.1.3-2ubuntu3.2 Ubuntu 9.10: dhcp3-client 3.1.2-1ubuntu7.3 In general, a standard system update will make all the necessary changes. References: CVE-2011-0997 Package Information: https://launchpad.net/ubuntu/+source/dhcp3/3.1.3-2ubuntu6.2 https://launchpad.net/ubuntu/+source/dhcp3/3.1.3-2ubuntu3.2 https://launchpad.net/ubuntu/+source/dhcp3/3.1.2-1ubuntu7.3 . Fedora Security Advisory FSA-1234-5 addresses a vulnerability in the FTP service that could lead to unauthorized data exposure. Immediate action is recommended.. Ubuntu DHCP Update, Security Notice, System Update Instructions. . LinuxSecurity.com Team

Calendar 2 Apr 19, 2011 Ubuntu
87

Debian: DSA 245-1 Critical: DHCP3 Packet Storm Remote Exploit

There is a bug in the dhcrelay causing it to send a continuing packet storm towards the configured DHCP server(s) in case of a malicious BOOTP packet.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 245-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze January 28th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : dhcp3 Vulnerability : ignored counter boundary Problem-Type : remote Debian-specific: no CVE Id : CAN-2003-0039 Florian Lohoff discovered a bug in the dhcrelay causing it to send a continuing packet storm towards the configured DHCP server(s) in case of a malicious BOOTP packet, such as sent from buggy Cisco switches. When the dhcp-relay receives a BOOTP request it forwards the request to the DHCP server using the broadcast MAC address ff:ff:ff:ff:ff:ff which causes the network interface to reflect the packet back into the socket. To prevent loops the dhcrelay checks whether the relay-address is its own, in which case the packet would be dropped. In combination with a missing upper boundary for the hop counter an attacker can force the dhcp-relay to send a continuing packet storm towards the configured dhcp server(s). This patch introduces a new commandline switch ``-c maxcount' and people are advised to start the dhcp-relay with ``dhcrelay -c 10' or a smaller number, which will only create that many packets. The dhcrelay program from the ``dhcp' package does not seem to be affected since DHCP packets are dropped if they were apparently relayed already. For the stable distribution (woody) this problem has been fixed in version 3.0+3.0.1rc9-2.2. The old stable distribution (potato) does not contain dhcp3 packages. For the unstable distribution (sid) this problem has been fixed in version 1.1.2-1. We recommend that you upgrade your dhcp3 packagewhen you are using the dhcrelay server. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 730 24c46bc59c7b7fbf5af839b1896073cf Size/MD5 checksum: 24457 9d555df929ea70ef2b36f7455298a79f Size/MD5 checksum: 809803 3cc4758e5a59362315393a1874dfcb21 Alpha architecture: Size/MD5 checksum: 416630 397a678e504608e82480b70da257e3de Size/MD5 checksum: 216102 393965c956aa0c61b87830ade40927ef Size/MD5 checksum: 106904 787c1f7ef446485f153fdb5985f57669 Size/MD5 checksum: 287256 9157faf5d681794429640f3c77ef2ae3 Size/MD5 checksum: 526892 48d538b72ff214a8ec5b224f9e4716da ARM architecture: Size/MD5 checksum: 386896 f4f9769ef04b52227b0b1134824a8f58 Size/MD5 checksum: 188652 b82228305af807ba3588ab0aad6d55aa Size/MD5 checksum: 93386 4990ce79c724969a518c8203398c6a36 Size/MD5 checksum: 273362 16e0bd4a19aaabf42f91d62cde3c806f Size/MD5 checksum: 484526 d597e37691b5aba8599fc654354436df Intel IA-32 architecture: Size/MD5 checksum: 375346 27d1ad0d2b6cfbbdebfcdf034edfef0b Size/MD5 checksum: 178596 955644258c1c3447c440ea68240c5595 Size/MD5 checksum: 82090 88d318c70305922de31c6f0eab7db3e6 Size/MD5 checksum: 269360 e87afd18b990a9c16e8768152b05fb11 Size/MD5 checksum: 465170 2bf1b093963bcd214e1edd9a078b7446 Intel IA-64 architecture: Size/MD5 checksum: 550076 a46f9f25e3567e22a55df624559f346e Size/MD5 checksum: 339224 d91056b8739382c06dcad9ed9fdce54d Size/MD5 checksum: 134254 11d223ea9054ad0b19d55add7083c21d Size/MD5 checksum: 348766 e546dac3162fee5eab1328c120bc51c4 Size/MD5 checksum: 701484 80aa1015319366aa8f6fa6c3e7daa088 HP Precision architecture: Size/MD5 checksum: 384876 e971b851045b3399b3280789bfb10dd8 Size/MD5 checksum: 188182 13442ca2429b42ef3aa007e84cb686bd Size/MD5 checksum: 93040 37c5a4ea972f80fc4aae1fa18cce870d Size/MD5 checksum: 274828 4ee56537ce01864eff25c04bf8cbc7cc Size/MD5 checksum: 478030 f5aa250b35b7aba6236e243f81a40571 Motorola 680x0 architecture: Size/MD5 checksum: 364618 a1fc0175cae39bb4b6f8366104cdd027 Size/MD5 checksum: 168548 e619f627bf4dc3502237445b170b9b10 Size/MD5 checksum: 79262 70957f418a8be321b6cd8ed681392daf Size/MD5 checksum: 264246 527734c5a0815888385c8030a0ab8d11 Size/MD5 checksum: 451098 b7a114770edf4846bcc122fa91802a87 Big endian MIPS architecture: Size/MD5 checksum: 397654 5dd77052a1bf96a6919b42abb7d1993d Size/MD5 checksum: 198506 29532f0c0c25cc74db482956a2e17767 Size/MD5 checksum: 94724 9be76951eec5cb400b91b6d2aa3afbc4 Size/MD5 checksum: 281616 d487fea11aa26522ca13252d5a1143f1 Size/MD5 checksum: 496364 ae74e80436ac5a5639d25c813937be4c Little endian MIPS architecture: Size/MD5 checksum: 397210 af17a66c93142f3b37f3ff54a70de6ce Size/MD5 checksum: 197808 f64f4c1cbe51b41a46105fb96afac7f2 Size/MD5 checksum: 94864 2cd66c4b1fad6f8cf76d88fb3d32b64e Size/MD5 checksum: 281570 1913fcf10728ea03dd914aef054b062a Size/MD5 checksum: 496042 9396140993730275d6b8de6e34675f54 PowerPC architecture: Size/MD5 checksum: 375068666bbe22fd67328d8992facd41d1896b Size/MD5 checksum: 178500 ae76150c581357a02d9b7bb8ced0dbdc Size/MD5 checksum: 91100 9a647196076ff0ca93f1972be8e06c96 Size/MD5 checksum: 269858 c7c3f542facc9f807dbbd1a8452cd732 Size/MD5 checksum: 466862 5e4a8282b7befb8471bcaa48d7f7e578 IBM S/390 architecture: Size/MD5 checksum: 374846 b2479d34b339e43b754f856d04fe7c18 Size/MD5 checksum: 177838 29fb48bb7d7df2abf795ba8d18d54dba Size/MD5 checksum: 83068 c693a61e70c3551ff06ebbe3902d77da Size/MD5 checksum: 270776 e518ea7234a90f9ad6775402bd1ebed9 Size/MD5 checksum: 465362 2e5c9c19eec1b2da7723ec841066d91d Sun Sparc architecture: Size/MD5 checksum: 375452 c9bd70d1b1fdf3d46d2d0c3d90afdabe Size/MD5 checksum: 178438 fc7418c8bdc8191c9068544c09095ac0 Size/MD5 checksum: 87346 dc9d3fedf805cb854e883ad054325380 Size/MD5 checksum: 271280 5a063042a2f5700ebd15c86459192761 Size/MD5 checksum: 465524 c7a808f387b4c4c488cba086145d272a These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and . Debian Security Advisory DSA 245-1 Debian Security Information Martin Schulze January 28th, 2003 Deb. there, dhcrelay, causing, continuing, packet, storm, towards, configured. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 28, 2003 Critical Debian
87

Debian DSA 231-1 Critical: Dhcp3 Remote Code Execution Threat

The Internet Software Consortium discoverd several vulnerabilities during an audit of the ISC DHCP Daemon.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 231-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze January 17th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : dhcp3 Vulnerability : stack overflows Problem-Type : remote Debian-specific: no CVE Id : CAN-2003-0026 CERT advisory : VU#284857 CA-2003-01 The Internet Software Consortium discoverd several vulnerabilities during an audit of the ISC DHCP Daemon. The vulnerabilities exist in error handling routines within the minires library and may be exploitable as stack overflows. This could allow a remote attacker to execute arbitrary code under the user id the dhcpd runs under, usually root. Other DHCP servers than dhcp3 doesn't seem to be affected. For the stable distribution (woody) this problem has been fixed in version 3.0+3.0.1rc9-2.1. The old stable distribution (potato) does not contain dhcp3 packages. For the unstable distribution (sid) this problem has been fixed in version 3.0+3.0.1rc11-1. We recommend that you upgrade your dhcp3-server package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 730 37209f2e8ff29f9d38e4f812183a8321 Size/MD5 checksum: 23781 d6b2e0bcf1b32d52423202ae5f988cf6 Size/MD5 checksum: 809803 3cc4758e5a59362315393a1874dfcb21 Alpha architecture: Size/MD5 checksum: 416508 773f104e93a351675621d4b812dedb0d Size/MD5 checksum: 216042 2a7c64e688ca68bf0b227334ba2d7833 Size/MD5 checksum: 106842 9020774e6cdc310a3a3cf2a42ba58d63 Size/MD5 checksum: 287082 189f63d99acb438981c10800d7783d44 Size/MD5 checksum: 526816 08d076cefd29fa5e0055fda006cac383 ARM architecture: Size/MD5 checksum: 386804 842b5eb5de805516022bada7f0094822 Size/MD5 checksum: 188558 5dbbd9b9ab025f52024b19627bfbdc72 Size/MD5 checksum: 93316 57bfc9321b7d10ae70ec6214d59bcb2f Size/MD5 checksum: 273220 6a99a3da6a633477ae430d92f68f2184 Size/MD5 checksum: 484438 677cd67a76fc9814fe2a7c3ca4a1a492 Intel IA-32 architecture: Size/MD5 checksum: 375234 eadc1375ff236a3f6fd831340fa23bb2 Size/MD5 checksum: 178496 afd9dda61da369a5ff76b15803fd4136 Size/MD5 checksum: 82020 6137706b46e9b5d0f8d85bf0188f2050 Size/MD5 checksum: 269162 289c850ffa01157b09537ec57bf25d0c Size/MD5 checksum: 465074 fae064fc37dede8a61bf836248e97e34 Intel IA-64 architecture: Size/MD5 checksum: 549968 cf516c3021a7a9467d0bd5e8bc5467c4 Size/MD5 checksum: 339122 abfcc44debcca325e01b76031536bacd Size/MD5 checksum: 134170 d2683f5f882b01422dab6ee93983c0a5 Size/MD5 checksum: 348612 97101d3f841d5509f61664e27158cf23 Size/MD5 checksum: 701398 5bc9980f56c7830a04f21bfedb228959 HP Precision architecture: Size/MD5 checksum: 384788 f733a3a7db9c641cff4594212f275984 Size/MD5 checksum: 188118 5928747afeb44dfd8cfd8e02c332068f Size/MD5 checksum: 92962 2044c3e40799aeb2d328b6084d611016 Size/MD5 checksum: 274626 cba0f35f3a64f21ee4f6d913bb3fa293 Size/MD5 checksum: 477908 58ca5c2bc695aaccfea6052e37767dec Motorola 680x0 architecture: Size/MD5 checksum: 364506 a78a9398f67bbf9083958cc98b2298a5 Size/MD5 checksum: 168460 9ca486cd937a27d066fd33af2fa448c9 Size/MD5 checksum: 79196 fce453cdd71d77bbb8a69af8e03fe24b Size/MD5 checksum: 264088 6b2a21514111f691e382711a488c2121 Size/MD5 checksum: 451034 c26bf487dec970ea2eb77d7420574b31 Big endian MIPS architecture: Size/MD5 checksum: 397524 fda141ea4a15b1ac3bd556d182cc77f2 Size/MD5 checksum: 198432 c44d48cb08d6645f4d371575e0c65497 Size/MD5 checksum: 94642 0a0b958f68e4e1c476db1c5cd71ff84e Size/MD5 checksum: 281424 f01760c830e76d99c0d3dff61f41474c Size/MD5 checksum: 496270 84398a69046aad6340b0235fffae8f64 Little endian MIPS architecture: Size/MD5 checksum: 397100 1cf221ff34d407a50ff39947578141b4 Size/MD5 checksum: 197736 eb08eba8000fba3315df4e940f520e40 Size/MD5 checksum: 94786 99c4b8f8cc0d9849bf72e3d43b5e4f87 Size/MD5 checksum: 281390 96e869af7f9d8e008fcde2269d676f45 Size/MD5 checksum: 495938 d3c899c409c26461e80c85aff382d3e4 PowerPC architecture: Size/MD5 checksum: 374958 6f37a18a820304e9ef9ed120b14e69c6 Size/MD5 checksum: 178404 502b47d01b6ad7d1c74aa9080edf1f8f Size/MD5 checksum: 91016 1970d5daa075c804d17c39ae6e376255 Size/MD5 checksum: 269668 494ebd8a9950a30ac5e013d41e6a0457 Size/MD5 checksum: 466796 3588ff1f5d220f236323aaebb61988b2 IBM S/390 architecture: Size/MD5 checksum: 374752 f1a1624c38f20ace387730b3cdb71257 Size/MD5 checksum: 177730 00faaea3e1a30546324b248b92980857 Size/MD5 checksum: 82992 9c1b2a9abadce85355d43e9a6cd1d0bb Size/MD5 checksum: 270624 03c36acf2b87cab9fcea4a39f0ec329f Size/MD5 checksum: 4652882937d4f9c371bd72409e8c9216d145e9 Sun Sparc architecture: Size/MD5 checksum: 375362 69a5e5399e2a980e182405c63525c792 Size/MD5 checksum: 178340 fd6d34c44429e67dd1661ee5f3563748 Size/MD5 checksum: 87262 77c318418e23c496bfbeb351075a8909 Size/MD5 checksum: 271132 c95e510874e1b1de7d3cec63c2a43887 Size/MD5 checksum: 465422 7d42532c3ecc241a5ec81215f3ad22d6 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical vulnerabilities in dhcp3 could allow remote code execution. Immediate update recommended.. dhcp3 vulnerabilities,Debian update,remote code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 17, 2003 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here