Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 18.04 LTS: USN-4357-1 Moderate: IPRoute Arbitrary Code Execution

IPRoute could be made to execute arbitrary code if it received a specially crafted input.. =========================================================================Ubuntu Security Notice USN-4357-1 May 13, 2020 iproute2 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: IPRoute could be made to execute arbitrary code if it received a specially crafted input. Software Description: - iproute2: networking and traffic control tools Details: It was discovered that IPRoute incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: iproute2 4.15.0-2ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4357-1 CVE-2019-20795 Package Information: https://launchpad.net/ubuntu/+source/iproute2/4.15.0-2ubuntu1.1 . The IPRoute flaw permits attackers to execute arbitrary code through specially designed input. It is recommended to upgrade Ubuntu 18.04 LTS to protect your system.. IPRoute, Arbitrary Code, Ubuntu Update, Security Patch, System Vulnerability. . LinuxSecurity.com Team

Calendar 2 May 13, 2020 Ubuntu
91

Gentoo: GLSA-201805-10 Moderate: Zsh Local Code Execution Risk

Multiple vulnerabilities have been found in Zsh, the worst of which could allow local attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201805-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Zsh: Multiple vulnerabilities Date: May 26, 2018 Bugs: #649614, #651860, #655708 ID: 201805-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in Zsh, the worst of which could allow local attackers to execute arbitrary code. Background ========= A shell designed for interactive use, although it is also a powerful scripting language. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-shells/zsh < 5.5 > = 5.5 Description ========== Multiple vulnerabilities have been discovered in Zsh. Please review the CVE identifiers referenced below for details. Impact ===== A local attacker could execute arbitrary code, escalate privileges, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All Zsh users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-shells/zsh-5.5" References ========= [ 1 ] CVE-2017-18205 https://nvd.nist.gov/vuln/detail/CVE-2017-18205 [ 2 ] CVE-2017-18206 https://nvd.nist.gov/vuln/detail/CVE-2017-18206 [ 3 ] CVE-2018-1071 https://nvd.nist.gov/vuln/detail/CVE-2018-1071 [ 4 ] CVE-2018-1083 https://nvd.nist.gov/vuln/detail/CVE-2018-1083 [ 5 ] CVE-2018-1100 https://nvd.nist.gov/vuln/detail/CVE-2018-1100 [ 6 ] CVE-2018-7548 https://nvd.nist.gov/vuln/detail/CVE-2018-7548 [ 7 ] CVE-2018-7549 https://nvd.nist.gov/vuln/detail/CVE-2018-7549 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201805-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Bash weaknesses allow for unauthorized code execution; update promptly to enhance safety measures. Refer to Gentoo notice for further information.. Gentoo Linux,Zsh Security Update,Local Attack Mitigation. . LinuxSecurity.com Team

Calendar 2 May 26, 2018 Gentoo
98

Red Hat Enterprise: RHSA-2016-0999-01 Important: QEMU-KVM-RHEV Access Flaw

An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: qemu-kvm-rhev security update Advisory ID: RHSA-2016:0999-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2016:0999.html Issue date: 2016-05-10 CVE Names: CVE-2016-3710 ==================================================================== 1. Summary: An update for qemu-kvm-rhev is now available for Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7 - x86_64 3. Description: KVM (Kernel-based Virtual Machine) is a full virtualization solution for Linux on AMD64 and Intel 64 systems. The qemu-kvm-rhev package provides the user-space component for running virtual machines using KVM in environments managed by Red Hat Enterprise Virtualization Manager. Security Fix(es): * An out-of-bounds read/write access flaw was found in the way QEMU's VGA emulation with VESA BIOS Extensions (VBE) support performed read/write operations via I/O port methods. A privileged guest user could use this flaw to execute arbitrary code on the host with the privileges of the host's QEMU process. (CVE-2016-3710) Red Hat would like to thank Wei Xiao (360 Marvel Team) and Qinghao Tang (360 Marvel Team)for reporting this issue. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect. 5. Bugs fixed (https://bugzilla.redhat.com/): 1331401 - CVE-2016-3710 qemu: incorrect banked access bounds checking in vga module 6. Package List: Red Hat Enterprise Linux OpenStack Platform 5.0 (Icehouse) for RHEL 7: Source: qemu-kvm-rhev-2.3.0-31.el7_2.13.src.rpm x86_64: libcacard-devel-rhev-2.3.0-31.el7_2.13.x86_64.rpm libcacard-rhev-2.3.0-31.el7_2.13.x86_64.rpm libcacard-tools-rhev-2.3.0-31.el7_2.13.x86_64.rpm qemu-img-rhev-2.3.0-31.el7_2.13.x86_64.rpm qemu-kvm-common-rhev-2.3.0-31.el7_2.13.x86_64.rpm qemu-kvm-rhev-2.3.0-31.el7_2.13.x86_64.rpm qemu-kvm-rhev-debuginfo-2.3.0-31.el7_2.13.x86_64.rpm qemu-kvm-tools-rhev-2.3.0-31.el7_2.13.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2016-3710 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2016 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFXMXBUXlSAg2UNWIIRAlO8AKCyAlE6sWMkWo0/E7lQz64g2Kp+WwCggF68 BP+dYgUdnmWTqbMbQyRTa/A=fi5T -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Canonical provides a significant patch for libvirt addressing high vulnerabilities in cloud infrastructure setups.. Red Hat Enterprise Linux,qemu update,virtualization security,OpenStack platforms. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 10, 2016 Important Red Hat
87

Debian 3.1 DSA 1186-1 Critical: Cscope Buffer Overflow Issue

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1186-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 30th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : cscope Vulnerability : buffer overflows Problem-Type : local(remote) Debian-specific: no CVE ID : CVE-2006-4262 Debian Bug : 385893 Will Drewry of the Google Security Team discovered several buffer overflows in cscope, a source browsing tool, which might lead to the execution of arbitrary code. For the stable distribution (sarge) this problem has been fixed in version cscope_15.5-1.1sarge2. For the unstable distribution (sid) this problem has been fixed in version 15.5+cvs20060902-1. We recommend that you upgrade your cscope package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 597 288d126f1a8e75401bec5758d21fca6e Size/MD5 checksum: 22685 efce07e2dbfdba7329ec88a143c811ad Size/MD5 checksum: 243793 beb6032a301bb11524aec74bfb5e4840 Alpha architecture: Size/MD5 checksum: 164514 0a49e059085c6b7935d19ade91441abf AMD64 architecture: Size/MD5 checksum: 152934 a10ede3f65739ef21806fd2eb139c572 ARM architecture: Size/MD5 checksum: 14722405f695127f6fcc7a934a4835c18d215c HP Precision architecture: Size/MD5 checksum: 158482 faf5225195dcb6b89fb22711ff45547e Intel IA-32 architecture: Size/MD5 checksum: 143350 94dda40490e976fb3ba9a7aac7ea92d7 Intel IA-64 architecture: Size/MD5 checksum: 181116 52a1b55bcaa05bfe5731e53c14316620 Motorola 680x0 architecture: Size/MD5 checksum: 140118 762aebb7ffbdee7c6787c750b53cd02e Big endian MIPS architecture: Size/MD5 checksum: 157354 87e2ffcf7dc6ebc10523391b29e1ab27 Little endian MIPS architecture: Size/MD5 checksum: 155750 a566cbfcd6689dca81b8730148f59965 PowerPC architecture: Size/MD5 checksum: 154680 2a959a398cff553b7a7c51ce554b516e IBM S/390 architecture: Size/MD5 checksum: 154500 6dd06b7d5ba9b119a1daf0f23fc65d79 Sun Sparc architecture: Size/MD5 checksum: 148314 585ad5bb0f6e591e7f54ce8c147d1cfb These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian advisory DSA 1204-2 highlights security enhancements in vim that address command injection vulnerabilities. Update promptly!. Debian Security,Cscope Patch,Code Execution Risk,Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 30, 2006 Critical Debian
91

Gentoo 200503-05 Normal: xli, xloadimage Execute Code Risk

xli and xloadimage are vulnerable to multiple issues, potentially leading to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200503-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xli, xloadimage: Multiple vulnerabilities Date: March 02, 2005 Bugs: #79762 ID: 200503-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= xli and xloadimage are vulnerable to multiple issues, potentially leading to the execution of arbitrary code. Background ========= xli and xloadimage are X11 utilities for displaying and manipulating a wide range of image formats. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/xloadimage < 4.1-r2 > = 4.1-r2 2 media-gfx/xli < 1.17.0-r1 > = 1.17.0-r1 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Tavis Ormandy of the Gentoo Linux Security Audit Team has reported that xli and xloadimage contain a flaw in the handling of compressed images, where shell meta-characters are not adequately escaped. Rob Holland of the Gentoo Linux Security Audit Team has reported that an xloadimage vulnerability in the handling of Faces Project images discovered by zen-parse in 2001 remained unpatched in xli. Additionally, it has been reported that insufficient validation of imageproperties in xli could potentially result in buffer management errors. Impact ===== Successful exploitation would permit a remote attacker to execute arbitrary shell commands, or arbitrary code with the privileges of the xloadimage or xli user. Workaround ========= There is no known workaround at this time. Resolution ========= All xli users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/xli-1.17.0-r1" All xloadimage users should also upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/xloadimage-4.1-r2" References ========= [ 1 ] CAN-2001-0775 https://www.cve.org/CVERecord?id=CAN-2001-0775 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200503-05 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Several vulnerabilities in xli and xloadimage on Gentoo may allow for the execution of arbitrary code. Please ensure you update your systems immediately.. xli Execute Code Threat, xloadimage Security Issues, Gentoo Vulnerability Fixes. . LinuxSecurity.com Team

Calendar 2 Mar 02, 2005 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here