Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
91

Gentoo: 200303-29 Critical Integer Overflow in dietlibc Exploit

The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-29 - - --------------------------------------------------------------------- PACKAGE : dietlibc SUMMARY : integer overflow DATE : 2003-03-31 12:35 UTC EXPLOIT : remote VERSIONS AFFECTED : =0.22-r1 CVE : CAN-2003-0028 - - --------------------------------------------------------------------- - From advisory: "The xdrmem_getbytes() function in the XDR library provided by Sun Microsystems contains an integer overflow. Depending on the location and use of the vulnerable xdrmem_getbytes() routine, various conditions may be presented that can permit an attacker to remotely exploit a service using this vulnerable routine." Read the full advisory at: Privileged Access Management, Cyber Security, and… | BeyondTrust SOLUTION It is recommended that all Gentoo Linux users who are running dev-libs/dietlibc upgrade to dietlibc-0.22-r1 as follows: emerge sync emerge dietlibc emerge clean - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - - --------------------------------------------------------------------- . GENTOO LINUX SECURITY UPDATE 202303-45 addressing a severe buffer overflow flaw in libcurl impacting network communication functionalities.. Dietlibc, Integer Overflow, Remote Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 31, 2003 Critical Gentoo
87

Debian 3.0 DSA-272-1 Critical: Integer Overflow In Dietlibc

There is an integer overflow in the xdrmem_getbytes() function of glibc, that is also present in dietlibc.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 272-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 28th, 2003 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : dietlibc Vulnerability : integer overflow Problem-Type : remote Debian-specific: no CVE Id : CAN-2003-0028 CERT advisory : VU#516825 CA-2003-10 eEye Digital Security discovered an integer overflow in the xdrmem_getbytes() function of glibc, that is also present in dietlibc, a small libc useful especially for small and embedded systems. This function is part of the XDR encoder/decoder derived from Sun's RPC implementation. Depending upon the application, this vulnerability can cause buffer overflows and could possibly be exploited to execute arbitray code. For the stable distribution (woody) this problem has been fixed in version 0.12-2.5. The old stable distribution (potato) does not contain dietlibc packages. For the unstable distribution (sid) this problem has been fixed in version 0.22-2. We recommend that you upgrade your dietlibc packages. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 581 2b472a6986de2fe5e3561d7932ccb5bc Size/MD5 checksum: 9040 e49f1c3c007033258fcc8d171f3c42f6 Size/MD5 checksum: 415823 1b9019cc4e717470603d2716a602ec51 Architecture independent components: Size/MD5 checksum: 19032 2289d430c97d33c0a12a5eeff11fd945 Alpha architecture: Size/MD5 checksum: 264314 279ee6b13535b8500877abf35cd616f4 ARM architecture: Size/MD5 checksum: 239226 59571adaf2d6981176f87d256d633e6e Intel IA-32 architecture: Size/MD5 checksum: 230736 d6766661ce15e7d0bb981dd4283af35c Big endian MIPS architecture: Size/MD5 checksum: 252976 3c99fd2d77addfb7a67fc60e9a6018d6 Little endian MIPS architecture: Size/MD5 checksum: 251836 0e41a80c3ba91df8c6e3c79de5461953 PowerPC architecture: Size/MD5 checksum: 246132 b519307b907470bea80fcfc7176473a5 Sun Sparc architecture: Size/MD5 checksum: 239174 cecf12ea63e4c51684c4dea394a5f8ed These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . The Debian Security Advisory DSA-274-1 highlights a major vulnerability in the socket_sendmsg() method of libnetwork, risking critical data leaks from poor message length validation. Dietlibc Security Advisory, Debian Integer Overflow Threat, Buffer Overflow Exploit, Remote Vulnerability Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 28, 2003 Critical Debian
87

Debian: DSA 146-2 Critical Integer Overflow Remote Exploit in Dietlibc

The upstream author of dietlibc, Felix von Leitner, discovered a potential division by zero chance in the fwrite and calloc integer overflow checks.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 146-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 8th, 2002 - -------------------------------------------------------------------------- Package : dietlibc Vulnerability : integer overflow Problem-Type : remote Debian-specific: no CVE Id : CAN-2002-0391 CERT advisory : VU#192995 The upstream author of dietlibc, Felix von Leitner, discovered a potential division by zero chance in the fwrite and calloc integer overflow checks, which are fixed in the version below. The new version includes fixes from DSA 146-1. For completness we enclose the text of the other advisory: An integer overflow bug has been discovered in the RPC library used by dietlibc, a libc optimized for small size, which is derived from the SunRPC library. This bug could be exploited to gain unauthorized root access to software linking to this code. The packages below also fix integer overflows in the calloc, fread and fwrite code. They are also more strict regarding hostile DNS packets that could lead to a vulnerability otherwise. This problem has been fixed in version 0.12-2.4 for the current stable distribution (woody) and in version 0.20-0cvs20020808 for the unstable distribution (sid). Debian 2.2 (potato) is not affected since it doesn't contain dietlibc packages. We recommend that you upgrade your dietlibc packages immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may usean automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- The dietlibc packages are only available for the following architectures: alpha arm i386 mips mipsel powerpc sparc Source archives: Size/MD5 checksum: 581 5b35d65f52bad60c25ed4fc38171a13a Size/MD5 checksum: 7943 dc4943d8ad22321ce57a2c8109e16eee Size/MD5 checksum: 415823 1b9019cc4e717470603d2716a602ec51 Architecture independent components: Size/MD5 checksum: 18956 8677ee59b39720edb9860bed12926ac7 Alpha architecture: Size/MD5 checksum: 264232 be91b0b9c13396a26c29b44d8aee4cc7 ARM architecture: Size/MD5 checksum: 239160 3e1b0b54441a9d05d4b4f18f7bed5daf Intel IA-32 architecture: Size/MD5 checksum: 230704 705f8d03822326256e8e11e4b49b4398 Big endian MIPS architecture: Size/MD5 checksum: 252890 d962f7770928ba2acef49da1bd085850 Little endian MIPS architecture: Size/MD5 checksum: 251724 d85e74c9bbf7355d68d776fdc3cecf9e PowerPC architecture: Size/MD5 checksum: 246014 969782849549a59b0cc746bdb1482b5f Sun Sparc architecture: Size/MD5 checksum: 239082 5d2e235422c3fa8a8b8621997ae685e3 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu Security Notice USN-1543-1 addresses a critical buffer overflow issue in libxml2, which may lead to unauthorized access and compromise system integrity.. Debian Security,Dietlibc Update,Integer Overflow,Remote Exploit,Security Patch. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Aug 08, 2002 Critical Debian
87

Debian 3.0: DSA 146-1 Critical: Dietlibc Integer Overflow Threat

An integer overflow bug has been discovered in the RPC library used bydietlibc, which could be exploited to gain unauthorized root access to software linking to this code.. - -------------------------------------------------------------------------- Debian Security Advisory DSA 146-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 8th, 2002 - -------------------------------------------------------------------------- Package : dietlibc Vulnerability : integer overflow Problem-Type : remote Debian-specific: no CVE Id : CAN-2002-0391 CERT advisory : VU#192995 An integer overflow bug has been discovered in the RPC library used by dietlibc, a libc optimized for small size, which is derived from the SunRPC library. This bug could be exploited to gain unauthorized root access to software linking to this code. The packages below also fix integer overflows in the calloc, fread and fwrite code. They are also more strict regarding hostile DNS packets that could lead to a vulnerability otherwise. These problems have been fixed in version 0.12-2.2 for the current stable distribution (woody) and in version 0.20-0cvs20020806 for the unstable distribution (sid). Debian 2.2 (potato) is not affected since it doesn't contain dietlibc packages. We recommend that you upgrade your dietlibc packages immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- The dietlibc packages are only available for the following architectures: alpha arm i386 mips mipsel powerpc sparc Source archives: Size/MD5 checksum: 581 15d5d5021f626d40b662b37bf56892e8 Size/MD5 checksum: 7815 572e4c0686879b6d042ca79d3aa9acd3 Size/MD5 checksum: 415823 1b9019cc4e717470603d2716a602ec51 Architecture independent components: Size/MD5 checksum: 18852 5348058e8565523e724fa8a64b5f568c Alpha architecture: Size/MD5 checksum: 264130 7a4bc7087bd34bda37c4e4709e0b52e9 ARM architecture: Size/MD5 checksum: 239022 99d6743d6d009433fa0754867ae67aa4 Intel IA-32 architecture: Size/MD5 checksum: 230532 f671532aae3e1d70726ebd9109e7a1a4 Big endian MIPS architecture: Size/MD5 checksum: 252756 3cad479c099819721d25f78f3ab6038e Little endian MIPS architecture: Size/MD5 checksum: 251582 75ff00f46d2d83d22cec2a0fdefaa390 PowerPC architecture: Size/MD5 checksum: 245870 7b18af0fc30e37bc7a4d2b4bdd2aead5 Sun Sparc architecture: Size/MD5 checksum: 238992 bc69f78304de16347a4f0d1c7de3728c These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Tackling a buffer overflow flaw in dietlibc might lead to unapproved superuser access on Debian systems. It is vital to execute an update without delay.. Dietlibc Vulnerability, Debian Integer Overflow, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 08, 2002 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here