Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

Exploring Research System Operating Systems: May 15, 2022 Highlights

Moderate: ed security update. Date: Tue, 14 Oct 2008 16:16:19 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Re: Security ERRATA for thunderbird on SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" In-Reply-To: We had a compiling problem on the SL4 x86_64 rpms. The compiling problem has been fixed and is working now. Both the x86_64 and i386 rpm's have been rebuilt with the new name to keep consistency. No code has been changed. The rpm's were only recompiled. SL 4.x SRPMS: thunderbird-1.5.0.12-16.el4.sl.src.rpm i386: thunderbird-1.5.0.12-16.el4.sl.i386.rpm x86_64: thunderbird-1.5.0.12-16.el4.sl.x86_64.rpm Troy Dawson Troy J Dawson wrote: > Synopsis: Moderate: thunderbird security update > Issue date: 2008-10-01 > CVE Names: CVE-2008-0016 CVE-2008-3835 CVE-2008-4058 > CVE-2008-4059 CVE-2008-4060 CVE-2008-4061 > CVE-2008-4062 CVE-2008-4065 CVE-2008-4066 > CVE-2008-4067 CVE-2008-4068 CVE-2008-4070 > > > Several flaws were found in the processing of malformed HTML mail content. > An HTML mail message containing malicious content could cause Thunderbird > to crash or, potentially, execute arbitrary code as the user running > Thunderbird. (CVE-2008-0016, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, > CVE-2008-4061, CVE-2008-4062) > > Several flaws were found in the way malformed HTML mail content was > displayed. An HTML mail message containing specially crafted content could > potentially trick a Thunderbird user into surrendering sensitive > information. (CVE-2008-3835, CVE-2008-4067, CVE-2008-4068) > > A flaw was found in Thunderbird that caused certain characters to be > stripped from JavaScript code. This flaw could allow malicious JavaScript > to bypass or evade script filters. (CVE-2008-4065, CVE-2008-4066) > > Note: JavaScript support is disabled by default in Thunderbird; the above > issue is not exploitable unless JavaScript is enabled. > > A heap based buffer overflow flaw was foundin the handling of cancelled > newsgroup messages. If the user cancels a specially crafted newsgroup > message it could cause Thunderbird to crash or, potentially, execute > arbitrary code as the user running Thunderbird. (CVE-2008-4070) > > Note2: On SL4 this updates fixes the bug that when a URL link is clicked, > firefox wouldn't start. Firefox now starts when a URL link is clicked. > > SL 4.x > > SRPMS: > thunderbird-1.5.0.12-16.el4.src.rpm > i386: > thunderbird-1.5.0.12-16.el4.i386.rpm > x86_64: > thunderbird-1.5.0.12-16.el4.x86_64.rpm > > SL 5.x > > SRPMS: > thunderbird-2.0.0.17-1.el5.src.rpm > i386: > thunderbird-2.0.0.17-1.el5.i386.rpm > x86_64: > thunderbird-2.0.0.17-1.el5.x86_64.rpm > > -Connie Sieh > -Troy Dawson > > > -- __________________________________________________ Troy Dawson dawson@fnal.gov (630)840-6468 Fermilab ComputingDivision/LCSI/CSI DSS Group __________________________________________________ Date: Tue, 14 Oct 2008 16:16:21 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Re: Security ERRATA for cups on SL3.x, SL4.x, SL5.x i386/x86_64 Comments: To: "scientific-linux-errata@fnal.gov" In-Reply-To: We had a compiling problem on the SL4 x86_64 rpms. The compiling problem has been fixed and is working now. Both the x86_64 and i386 rpm's have been rebuilt with the new name to keep consistency. No code has been changed. The rpm's were only recompiled. SL 4.x SRPMS: cups-1.1.22-0.rc1.9.27.el4_7.1.sl.src.rpm i386: cups-1.1.22-0.rc1.9.27.el4_7.1.sl.i386.rpm cups-devel-1.1.22-0.rc1.9.27.el4_7.1.sl.i386.rpm cups-libs-1.1.22-0.rc1.9.27.el4_7.1.sl.i386.rpm x86_64: cups-1.1.22-0.rc1.9.27.el4_7.1.sl.x86_64.rpm cups-devel-1.1.22-0.rc1.9.27.el4_7.1.sl.x86_64.rpm cups-libs-1.1.22-0.rc1.9.27.el4_7.1.sl.i386.rpm cups-libs-1.1.22-0.rc1.9.27.el4_7.1.sl.x86_64.rpm Troy Dawson Troy J Dawson wrote: > Synopsis: Important: cups security update > Issue date: 2008-10-10 > CVE Names: CVE-2008-3639 CVE-2008-3640CVE-2008-3641 > > A buffer overflow flaw was discovered in the SGI image format decoding > routines used by the CUPS image converting filter "imagetops". An attacker > could create a malicious SGI image file that could, possibly, execute > arbitrary code as the "lp" user if the file was printed. (CVE-2008-3639) > > An integer overflow flaw leading to a heap buffer overflow was discovered > in the Text-to-PostScript "texttops" filter. An attacker could create a > malicious text file that could, possibly, execute arbitrary code as the > "lp" user if the file was printed. (CVE-2008-3640) > > An insufficient buffer bounds checking flaw was discovered in the > HP-GL/2-to-PostScript "hpgltops" filter. An attacker could create a > malicious HP-GL/2 file that could, possibly, execute arbitrary code as the > "lp" user if the file was printed. (CVE-2008-3641) > > SL 3.0.x > > SRPMS: > cups-1.1.17-13.3.54.src.rpm > i386: > cups-1.1.17-13.3.54.i386.rpm > cups-devel-1.1.17-13.3.54.i386.rpm > cups-libs-1.1.17-13.3.54.i386.rpm > x86_64: > cups-1.1.17-13.3.54.x86_64.rpm > cups-devel-1.1.17-13.3.54.x86_64.rpm > cups-libs-1.1.17-13.3.54.i386.rpm > cups-libs-1.1.17-13.3.54.x86_64.rpm > > SL 4.x > > SRPMS: > cups-1.1.22-0.rc1.9.27.el4_7.1.src.rpm > i386: > cups-1.1.22-0.rc1.9.27.el4_7.1.i386.rpm > cups-devel-1.1.22-0.rc1.9.27.el4_7.1.i386.rpm > cups-libs-1.1.22-0.rc1.9.27.el4_7.1.i386.rpm > x86_64: > cups-1.1.22-0.rc1.9.27.el4_7.1.x86_64.rpm > cups-devel-1.1.22-0.rc1.9.27.el4_7.1.x86_64.rpm > cups-libs-1.1.22-0.rc1.9.27.el4_7.1.i386.rpm > cups-libs-1.1.22-0.rc1.9.27.el4_7.1.x86_64.rpm > > SL 5.x > > SRPMS: > cups-1.2.4-11.18.el5_2.2.src.rpm > i386: > cups-1.2.4-11.18.el5_2.2.i386.rpm > cups-devel-1.2.4-11.18.el5_2.2.i386.rpm > cups-libs-1.2.4-11.18.el5_2.2.i386.rpm > cups-lpd-1.2.4-11.18.el5_2.2.i386.rpm > x86_64: > cups-1.2.4-11.18.el5_2.2.x86_64.rpm > cups-devel-1.2.4-11.18.el5_2.2.i386.rpm > cups-devel-1.2.4-11.18.el5_2.2.x86_64.rpm > cups-libs-1.2.4-11.18.el5_2.2.i386.rpm > cups-libs-1.2.4-11.18.el5_2.2.x86_64.rpm > cups-lpd-1.2.4-11.18.el5_2.2.x86_64.rpm > > -Connie Sieh > -Troy Dawson > > > -- __________________________________________________ Troy Dawson This email address is being protected from spambots. You need JavaScript enabled to view it. (630)840-6468 Fermilab ComputingDivision/LCSI/CSI DSS Group __________________________________________________ Date: Wed, 15 Oct 2008 14:01:54 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: FASTBUGS for SL 4.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." The following FASTBUGS have been uploaded to i386: bash-3.0-19.7.el4_7.1.x86_64.rpm net-snmp-5.1.2-13.el4_7.1.i386.rpm net-snmp-devel-5.1.2-13.el4_7.1.i386.rpm net-snmp-libs-5.1.2-13.el4_7.1.i386.rpm net-snmp-perl-5.1.2-13.el4_7.1.i386.rpm net-snmp-utils-5.1.2-13.el4_7.1.i386.rpm net-tools-1.60-40.el4.i386.rpm nspr-4.7.1-1.el4.i386.rpm nspr-4.7.1-1.el4.x86_64.rpm nspr-devel-4.7.1-1.el4.x86_64.rpm nss-3.12.1.1-1.el4.i386.rpm nss-3.12.1.1-1.el4.x86_64.rpm nss-devel-3.12.1.1-1.el4.x86_64.rpm x86_64: bash-3.0-19.7.el4_7.1.x86_64.rpm net-snmp-5.1.2-13.el4_7.1.x86_64.rpm net-snmp-devel-5.1.2-13.el4_7.1.x86_64.rpm net-snmp-libs-5.1.2-13.el4_7.1.i386.rpm net-snmp-libs-5.1.2-13.el4_7.1.x86_64.rpm net-snmp-perl-5.1.2-13.el4_7.1.x86_64.rpm net-snmp-utils-5.1.2-13.el4_7.1.x86_64.rpm net-tools-1.60-40.el4.x86_64.rpm nspr-4.7.1-1.el4.i386.rpm nspr-4.7.1-1.el4.x86_64.rpm nspr-devel-4.7.1-1.el4.x86_64.rpm nss-3.12.1.1-1.el4.i386.rpm nss-3.12.1.1-1.el4.x86_64.rpm nss-devel-3.12.1.1-1.el4.x86_64.rpm -Connie Sieh -Troy Dawson Date: Wed, 15 Oct 2008 14:03:23 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: FASTBUGS for SL 5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." The following FASTBUGS have been uploaded to i386: cdda2wav-2.01-10.7.el5.x86_64.rpm cdrecord-2.01-10.7.el5.x86_64.rpm cdrecord-devel-2.01-10.7.el5.i386.rpm cdrecord-devel-2.01-10.7.el5.x86_64.rpm freeradius-1.1.3-1.4.el5.x86_64.rpm freeradius-mysql-1.1.3-1.4.el5.x86_64.rpm freeradius-postgresql-1.1.3-1.4.el5.x86_64.rpm freeradius-unixODBC-1.1.3-1.4.el5.x86_64.rpm inews-2.4.3-8.el5.x86_64.rpm inn-2.4.3-8.el5.x86_64.rpm inn-devel-2.4.3-8.el5.i386.rpm inn-devel-2.4.3-8.el5.x86_64.rpm libdhcp-1.20-5.el5_2.1.i386.rpm libdhcp-devel-1.20-5.el5_2.1.i386.rpm mkisofs-2.01-10.7.el5.x86_64.rpm OpenIPMI-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-devel-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-libs-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-perl-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-python-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-tools-2.0.6-6.el5_2.2.i386.rpm sabayon-2.12.4-6.el5.x86_64.rpm sabayon-apply-2.12.4-6.el5.x86_64.rpm xfig-3.2.4-21.3.el5.x86_64.rpm x86_64: cdda2wav-2.01-10.7.el5.i386.rpm cdrecord-2.01-10.7.el5.i386.rpm cdrecord-devel-2.01-10.7.el5.i386.rpm freeradius-1.1.3-1.4.el5.i386.rpm freeradius-mysql-1.1.3-1.4.el5.i386.rpm freeradius-postgresql-1.1.3-1.4.el5.i386.rpm freeradius-unixODBC-1.1.3-1.4.el5.i386.rpm inews-2.4.3-8.el5.i386.rpm inn-2.4.3-8.el5.i386.rpm inn-devel-2.4.3-8.el5.i386.rpm libdhcp-1.20-5.el5_2.1.i386.rpm libdhcp-1.20-5.el5_2.1.x86_64.rpm libdhcp-devel-1.20-5.el5_2.1.i386.rpm libdhcp-devel-1.20-5.el5_2.1.x86_64.rpm mkisofs-2.01-10.7.el5.i386.rpm OpenIPMI-2.0.6-6.el5_2.2.x86_64.rpm OpenIPMI-devel-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-devel-2.0.6-6.el5_2.2.x86_64.rpm OpenIPMI-libs-2.0.6-6.el5_2.2.i386.rpm OpenIPMI-libs-2.0.6-6.el5_2.2.x86_64.rpm OpenIPMI-perl-2.0.6-6.el5_2.2.x86_64.rpm OpenIPMI-python-2.0.6-6.el5_2.2.x86_64.rpm OpenIPMI-tools-2.0.6-6.el5_2.2.x86_64.rpm sabayon-2.12.4-6.el5.i386.rpm sabayon-apply-2.12.4-6.el5.i386.rpm xfig-3.2.4-21.3.el5.i386.rpm -Connie Sieh -Troy Dawson Date: Wed, 22 Oct 2008 18:58:19 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for ed on SL3.x, SL4.x, SL5.xi386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: ed security update Issue date: 2008-10-21 CVE Names: CVE-2008-3916 A heap-based buffer overflow was discovered in the way ed, the GNU line editor, processed long file names. An attacker could create a file with a specially-crafted name that could possibly execute an arbitrary code when opened in the ed editor. (CVE-2008-3916) SL 3.0.x SRPMS: ed-0.2-33.30E.1.src.rpm i386: ed-0.2-33.30E.1.i386.rpm x86_64: ed-0.2-33.30E.1.x86_64.rpm SL 4.x SRPMS: ed-0.2-36.el4_7.1.src.rpm i386: ed-0.2-36.el4_7.1.i386.rpm x86_64: ed-0.2-36.el4_7.1.x86_64.rpm SL 5.x SRPMS: ed-0.2-39.el5_2.src.rpm i386: ed-0.2-39.el5_2.i386.rpm x86_64: ed-0.2-39.el5_2.x86_64.rpm -Connie Sieh -Troy Dawson . A critical security update for Scientific Linux is now available to fix a buffer overflow vulnerability in the ed text editor that could let attackers execute harmful code. Scientific Linux Security, ed Update, Buffer Overflow, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Oct 22, 2008 Scientific Linux
87

Debian 2.2: 001-1 Moderate Advisory: Ed Symlink Attack Resolved

Alan Cox discovered that GNU ed (a classed line editor tool)created temporary files unsafely.. - ------------------------------------------------------------------------ Debian Security Advisory 001-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman November 29, 2000 - ------------------------------------------------------------------------ Package : ed Problem type : symlink attack Debian-specific: no Alan Cox discovered that GNU ed (a classed line editor tool) created temporary files unsafely. This has been fixed in version 0.2-18.1. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 8f5e75fa0f1a8bcb5b2543aae5959701 MD5 checksum: 311df85a3e80149b92f9070301eae1b9 MD5 checksum: ddd57463774cae9b50e70cd51221281b Alpha architecture: MD5 checksum: 36c073a80dd76df83d340208eaf890bf ARM architecture: MD5 checksum: 73ffc5a13a0bc48f1a323cf84311caeb Intel ia32 architecture: MD5 checksum: bb6dbb9648a71c56d2cf1eb353407acf Motorola 680x0 architecture: MD5 checksum: 5bc6b3054a5c995656153aa1b9e5509b PowerPC architecture: MD5 checksum: caf9df91afac75c11264d1ebb70e56cb Sun Sparc architecture: MD5 checksum: a940e903a4e3ae47dfbe5e5bc953e423 These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - -- - ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . GNU ed tool faced a moderate symlink attack, now resolved in Debianadvisory 001-1. Update to secure system.. GNU Ed,Symlink Attack,Debian Advisory. . LinuxSecurity.com Team

Calendar 2 Nov 28, 2000 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here