Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 25: FEDORA-2017-8722576148 Moderate: Ettercap Buffer Overflow

FIx for CVE-2017-8366. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-8722576148 2017-06-15 02:57:02.424849 --------------------------------------------------------------------------------Name : ettercap Product : Fedora 25 Version : 0.8.2 Release : 4.2.fc25 URL : Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. --------------------------------------------------------------------------------Update Information: FIx for CVE-2017-8366 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447318 - CVE-2017-8366 ettercap: Heap-based buffer overflow in strescape function in ec_strings.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent Fedora release for Wireshark tackles severe CVE-2019-XXXX stack overflowvulnerability safeguarding data security.. Ettercap Update,Fedora Security,Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 15, 2017 Important Fedora
89

Fedora 24: Critical Security Update FEDORA-2017-36c7e7ef06 for ettercap

FIx for CVE-2017-8366. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-36c7e7ef06 2017-06-15 02:56:58.020983 --------------------------------------------------------------------------------Name : ettercap Product : Fedora 24 Version : 0.8.2 Release : 4.2.fc24 URL : https://www.ettercap-project.org/ Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. --------------------------------------------------------------------------------Update Information: FIx for CVE-2017-8366 --------------------------------------------------------------------------------References: [ 1 ] Bug #1447318 - CVE-2017-8366 ettercap: Heap-based buffer overflow in strescape function in ec_strings.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1447318 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An upgrade for Ettercap on Fedora 24 addressesCVE-2017-8366. Guidelines for installation are provided.. Fedora Security Update, Ettercap CVE Fix, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 15, 2017 Critical Fedora
87

Debian: DSA-3874-1 Critical: Ettercap Denial Of Service Issue

Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3874-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond June 09, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : ettercap CVE ID : CVE-2017-6430 CVE-2017-8366 Debian Bug : 857035 861604 Agostino Sarubbo and AromalUllas discovered that ettercap, a network security tool for traffic interception, contains vulnerabilities that allowed an attacker able to provide maliciously crafted filters to cause a denial-of-service via application crash. For the stable distribution (jessie), these problems have been fixed in version 1:0.8.1-3+deb8u1. For the upcoming stable (stretch) and unstable (sid) distributions, these problems have been fixed in version 1:0.8.2-4. We recommend that you upgrade your ettercap packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep your infrastructure fortified by applying the Debian DSA-3890-1: essential nmap patches to rectify vulnerabilities.. Denial of Service, Ettercap, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 09, 2017 Critical Debian
89

Fedora 26: 2017-07345abcdef High: Nmap Heap Corruption Vulnerability

Fix for CVE-2017-6430. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-06365bdcfd 2017-03-14 12:25:18.834506 -------------------------------------------------------------------------------- Name : ettercap Product : Fedora 25 Version : 0.8.2 Release : 4.1.fc25 URL : https://www.ettercap-project.org/ Summary : Network traffic sniffer/analyser, NCURSES interface version Description : Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis. -------------------------------------------------------------------------------- Update Information: Fix for CVE-2017-6430 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1429571 - CVE-2017-6430 ettercap: Out-of-bounds read in etterfilter utility https://bugzilla.redhat.com/show_bug.cgi?id=1429571 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ettercap' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 issues security notice for tcpdump to address a buffer overflow weakness, bolstering overall systemintegrity.. Fedora 25 Update, Ettercap Security, Network Traffic Safety. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2017 Important Fedora
91

Gentoo: GLSA-201505-01 Moderate: Ettercap Code Execution Threat

Multiple vulnerabilities have been found in Ettercap, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201505-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ettercap: Multiple vulnerabilities Date: May 13, 2015 Bugs: #532764 ID: 201505-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Ettercap, the worst of which allows remote attackers to execute arbitrary code. Background ========= Ettercap is a comprehensive suite for man in the middle attacks. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/ettercap < 0.8.2 > = 0.8.2 Description ========== Multiple vulnerabilities have been discovered in Ettercap. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Ettercap users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/ettercap-0.8.2" References ========= [ 1 ] CVE-2014-6395 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6395 [ 2 ] CVE-2014-6396 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6396 [ 3 ] CVE-2014-9376 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9376 [ 4 ] CVE-2014-9377 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9377 [ 5 ] CVE-2014-9378 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9378 [ 6 ] CVE-2014-9379 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9379 [ 7 ] CVE-2014-9380 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9380 [ 8 ] CVE-2014-9381 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-9381 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201505-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2015 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Recent holes in Ettercap may enable distant adversaries to execute arbitrary code or trigger a Denial of Service. Immediate updates recommended.. Ettercap Code Execution, Gentoo Security Advisory, Remote Attack Risks. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 13, 2015 Important Gentoo
91

Gentoo GLSA-201405-12 Normal: Risks of Ettercap Execution Vulnerability

Multiple vulnerabilities have been found in Ettercap, the worst of which may allow execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ettercap: Multiple vulnerabilities Date: May 17, 2014 Bugs: #340897, #451198 ID: 201405-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Ettercap, the worst of which may allow execution of arbitrary code. Background ========= Ettercap is a suite of tools for content filtering, sniffing and man in the middle attacks on a LAN. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/ettercap < 0.7.5.2 > = 0.7.5.2 Description ========== Multiple vulnerabilities have been discovered in Ettercap: * Ettercap does not handle temporary files securely (CVE-2010-3843). * A format string flaw in Ettercap could cause a buffer overflow (CVE-2010-3844). * A stack-based buffer overflow exists in Ettercap (CVE-2013-0722). Impact ===== A remote attacker could entice a user to load a specially crafted configuration file using Ettercap, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. A local attacker could perform symlink attacks to overwrite arbitrary files with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All Ettercap usersshould upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/ettercap-0.7.5.2" References ========= [ 1 ] CVE-2010-3843 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3843 [ 2 ] CVE-2010-3844 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3844 [ 3 ] CVE-2013-0722 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0722 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201405-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo Security Advisory GLSA 202103-15 addresses vulnerabilities in Nginx that could lead to unauthorized access or potential denial of service.. Gentoo Security Advisory, Ettercap Errors, Arbitrary Code Execution, System Security Issues, Linux Vulnerability Management. . LinuxSecurity.com Team

Calendar%202 May 17, 2014 Gentoo
87

Debian: DSA 750-1 Moderate: Nmap Vulnerability Mitigation

A vulnerability was discovered in the ettercap package which could allow a remote attacker to execute arbitrary code on the system running ettercap.. - ------------------------------------------------------------------------Debian Security Advisory DSA 749-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Stone July 10, 2005 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : ettercap Vulnerability : arbitrary code execution Problem type : format string error Debian-specific: no CVE Id(s) : CAN-2005-1796 A vulnerability was discovered in the ettercap package which could allow a remote attacker to execute arbitrary code on the system running ettercap. The old stable distribution (woody) did not include ettercap. For the stable distribution (sarge), this problem has been fixed in version 0.7.1-1sarge1. For the unstable distribution (sid), this problem has been fixed in version 0.7.3-1. We recommend that you upgrade your ettercap package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (sarge) - ------------------ sarge was released for alpha, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1121758 f769039e0e967e9e09d0365fe358d683 Size/MD5 checksum: 4027 409603f119d07401bf7671b317e8ccef Size/MD5 checksum: 746 12b96cbc18bdb3bd7b431efbbfa73c34 alpha architecture (DEC Alpha) Size/MD5 checksum: 262674 3360122f7ee141aa6f2d410f4f834933 Size/MD5 checksum: 318266 4b09b93eba161a30b2f6cd28c33d0f1d Size/MD5 checksum: 221836 dbe0a871072bcd8d90318b271af1952b arm architecture (ARM) Size/MD5 checksum: 202390 6feb651f0b27a18e36612804388356e8 Size/MD5 checksum: 288022 062a0e8b4fdc2985a5bf9f5a0bc14fc4 Size/MD5 checksum: 169426 b08226c852071b61b66c16fd012412ec hppa architecture (HP PA RISC) Size/MD5 checksum: 304744 59be8a0479f3b0c9512e5193865c6bc2 Size/MD5 checksum: 227462 c364ecfec15360338b93176d45d759f3 Size/MD5 checksum: 190422 abbb689c039c829ab4358c4983c96c96 i386 architecture (Intel ia32) Size/MD5 checksum: 208398 91059e61c393851e8edb3b841450b46d Size/MD5 checksum: 286292 be3fff62821300e02ee004deb7a3bf91 Size/MD5 checksum: 173010 cba1a300d2d2add3c7c8720c287a7d10 ia64 architecture (Intel ia64) Size/MD5 checksum: 331966 f316f4df7dfc6ea666288f7aa1ef955b Size/MD5 checksum: 256862 64f34b09f95832daa6de66f4e5a9be0b Size/MD5 checksum: 304328 6781371e63adcedd74db7a9435f77a64 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 153950 310081b9ca119d2ce58c4cc779ea93c9 Size/MD5 checksum: 182234 6cea01aa78d8ab57b7365bcf1977f26a Size/MD5 checksum: 284704 9fb2cbc636754bc116bb92136cd662c2 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 180014 430dad7d762ab3d21ffdf5452d038a6f Size/MD5 checksum: 296628 9dceaed8c2623ddb45a82b95f3c44480 Size/MD5 checksum: 210476 53c398ef40193a1fc5eede9f8b6d5e76 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 298032 f599e9ca6ecf52622ccfcb3ac6f20bf3 Size/MD5 checksum: 182216 1ea0f7044b6b65c56b0d7ebd23842705 Size/MD5 checksum: 212338 c8e0734ab8090a77c84d63b57086dc06 powerpc architecture (PowerPC) Size/MD5 checksum: 322336 e7ab6f5e567b2cc271f180cb16f70476 Size/MD5 checksum: 179370 b1f750e38e742030932ab076d4e62eac Size/MD5 checksum: 212186 96860165bf4e4e796eeaaea7d8ea4e51 s390 architecture (IBM S/390) Size/MD5 checksum: 296358 e2d6fac489aaca1da105b103dcf3c84c Size/MD5 checksum: 183506 d181a9d198e471ad6634c9b7b3fb6b18 Size/MD5 checksum: 216164 f480772db37197c2ed364b61185e90f6 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 289156 f3de4592a6ec6678c36499fe6ed59915 Size/MD5 checksum: 169062 880af57dc7c562dbd0a668878115b5f4 Size/MD5 checksum: 201582 08f5653424161a44534bb0c5346cab53 - -------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical vulnerability allowing remote code execution in the ettercap software for Debian has been resolved. Users are advised to update to enhance security.. Debian Security, Ettercap Code Fix, Update Instructions. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2005 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here