Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
89

Fedora 39: FEDORA-2024-900dc7f6ff Critical: runc File Descriptor Leak

security fix for CVE-2024-21626. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-900dc7f6ff 2024-02-06 01:17:01.499262 -------------------------------------------------------------------------------- Name : runc Product : Fedora 39 Version : 1.1.12 Release : 1.fc39 URL : https://github.com/opencontainers/runc Summary : CLI for running Open Containers Description : The runc command can be used to start containers which are packaged in accordance with the Open Container Initiative's specifications, and to manage containers running under runc. -------------------------------------------------------------------------------- Update Information: security fix for CVE-2024-21626 -------------------------------------------------------------------------------- ChangeLog: * Thu Feb 1 2024 Lokesh Mandvekar - 2:1.1.12-1 - bump to v1.1.12 * Thu Feb 1 2024 Davanum Srinivas - 2:1.1.9-1 - Update to runc 1.1.9 version -------------------------------------------------------------------------------- References: [ 1 ] Bug #2258725 - CVE-2024-21626 runc: file descriptor leak https://bugzilla.redhat.com/show_bug.cgi?id=2258725 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-900dc7f6ff' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Fedora 39 has released an update to runc, tackling the CVE-2024-21626 vulnerability. This patch resolves file descriptor leaks, boosting system stability and security. Fedora Update, runc Fix, Container Management, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 06, 2024 Critical Fedora
87

Debian DSA-5615-1 Critical: Runc Container Breakout Issue Remediated

It was discovered that runc, a command line client for running applications packaged according to the Open Container Format (OCF), was suspectible to multiple container breakouts due to an internal file descriptor leak. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5615-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff February 04, 2024 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : runc CVE ID : CVE-2024-21626 It was discovered that runc, a command line client for running applications packaged according to the Open Container Format (OCF), was suspectible to multiple container breakouts due to an internal file descriptor leak. For the oldstable distribution (bullseye), this problem has been fixed in version 1.0.0~rc93+ds1-5+deb11u3. For the stable distribution (bookworm), this problem has been fixed in version 1.1.5+ds1-1+deb12u1. We recommend that you upgrade your runc packages. For the detailed security status of runc please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/runc Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance runc to mitigate severe vulnerabilities and avert container escapes in Debian environments.. Debian Security,Runc Update,Container Security,System Vulnerabilities,OCF Applications. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 04, 2024 Critical Debian
89

Fedora 34 FEDORA-2022-5e6d5fe680 Moderate Polkit File Leak

Security fix for CVE-2021-4115. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-5e6d5fe680 2022-03-03 15:50:19.518051 --------------------------------------------------------------------------------Name : polkit Product : Fedora 34 Version : 0.117 Release : 3.fc34.3 URL : https://gitlab.freedesktop.org/polkit/polkit/ Summary : An authorization framework Description : polkit is a toolkit for defining and handling authorizations. It is used for allowing unprivileged processes to speak to privileged processes. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-4115 --------------------------------------------------------------------------------ChangeLog: * Wed Feb 16 2022 Jan Rybar - 0.117-3.3 - file descriptor exhaustion (GHSL-2021-077) - Resolves: CVE-2021-4115 --------------------------------------------------------------------------------References: [ 1 ] Bug #2007534 - CVE-2021-4115 polkit: file descriptor leak allows an unprivileged user to cause a crash https://bugzilla.redhat.com/show_bug.cgi?id=2007534 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-5e6d5fe680' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important update for Fedora 34 users: Address the CVE-2021-4115 polkit vulnerability to prevent unauthorized privilege escalation on your system. Fedora 34 Security Update,polkit Security Issue,system authorization fix. . LinuxSecurity.com Team

Calendar 2 Mar 03, 2022 Fedora
203

Mageia 8: 2022-0080 Critical: Polkit File Descriptor Leak Issue

There is a file descriptor leak in polkit, which can enable an unprivileged user to cause polkit to crash, due to file descriptor exhaustion. (CVE-2021-4115) References: . MGASA-2022-0080 - Updated polkit packages fix security vulnerability Publication date: 22 Feb 2022 URL: https://advisories.mageia.org/MGASA-2022-0080.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-4115 There is a file descriptor leak in polkit, which can enable an unprivileged user to cause polkit to crash, due to file descriptor exhaustion. (CVE-2021-4115) References: - https://bugs.mageia.org/show_bug.cgi?id=30066 - https://www.openwall.com/lists/oss-security/2022/02/18/1 - https://bugzilla.redhat.com/show_bug.cgi?id=2007534 - https://securitylab.github.com/advisories/GHSL-2021-077-polkit/ - - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/KLISGPPFV5UH2W72SRUBNVWZWI7CWAAY/ - https://www.cve.org/CVERecord?id=CVE-2021-4115 SRPMS: - 8/core/polkit-0.118-1.3.mga8 . MGASA-2022-0081 resolves a vulnerability in networkd, addressing a serious flaw identified on March 15, 2022.. Polkit Update, File Descriptor Leak, Mageia Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 22, 2022 Critical Mageia
89

Fedora 30: FEDORA-2019-b6d3c8b0a8 critical: pam-u2f file leak

New upstream release Fixes Debug file descriptor leak CVE-2019-1221 Fixes insecure debug file handling CVE-2019-1220. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-b6d3c8b0a8 2019-06-19 22:44:22.998271 --------------------------------------------------------------------------------Name : pam-u2f Product : Fedora 30 Version : 1.0.8 Release : 1.fc30 URL : https://developers.yubico.com/pam-u2f/ Summary : Implements PAM authentication over U2F Description : The PAM U2F module provides an easy way to integrate the Yubikey (or other U2F-compliant authenticators) into your existing user authentication infrastructure. --------------------------------------------------------------------------------Update Information: New upstream release Fixes Debug file descriptor leak CVE-2019-1221 Fixes insecure debug file handling CVE-2019-1220 --------------------------------------------------------------------------------ChangeLog: * Wed Jun 5 2019 Seth Jennings - 1.0.8-1 - New upstream release - Fixes Debug file descriptor leak CVE-2019-1221 - Fixes insecure debug file handling CVE-2019-1220 - resolves: #1717326 --------------------------------------------------------------------------------References: [ 1 ] Bug #1717326 - Debug file descriptor leak CVE-2019-1221 and insecure debug file handling CVE-2019-12209 https://bugzilla.redhat.com/show_bug.cgi?id=1717326 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-b6d3c8b0a8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Unveil the new pam-u2f security patch for Fedora 30 resolving pivotal file management vulnerabilities and data leaks.. Fedora Security, pam-u2f Update, Authentication Module, Debug Leak Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 19, 2019 Critical Fedora
89

Fedora 29: 2018-061502de84 High: libc Memory Corruption Vulnerability

This update for the `glibc` package addresses one moderate security vulnerability and several defects. * CVE-2018-19591: A file descriptor leak in `if_nametoindex` can lead to a denial of service due to resource exhaustion when processing `getaddrinfo` calls with crafted host names. Reported by Guido Vranken. (RHBZ#1654000) * Failure to create the helper thread for. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-060302dc83 2018-12-04 02:22:12.111599 --------------------------------------------------------------------------------Name : glibc Product : Fedora 28 Version : 2.27 Release : 35.fc28 URL : https://www.gnu.org/software/libc/ Summary : The GNU libc libraries Description : The glibc package contains standard libraries which are used by multiple programs on the system. In order to save disk space and memory, as well as to make upgrading easier, common system code is kept in one place and shared between programs. This particular package contains the most important sets of shared libraries: the standard C library and the standard math library. Without these two libraries, a Linux system will not function. --------------------------------------------------------------------------------Update Information: This update for the `glibc` package addresses one moderate security vulnerability and several defects. * CVE-2018-19591: A file descriptor leak in `if_nametoindex` can lead to a denial of service due to resource exhaustion when processing `getaddrinfo` calls with crafted host names. Reported by Guido Vranken. (RHBZ#1654000) * Failure to create the helper thread for `getaddrinfo_a`/`libanl` could result in a crash. (RHBZ#1646381) * On certain Haswell-class Intel CPUs, string function feature flags could be set incorrectly, leading to a suboptimal choice of string functions. (RHBZ#1641980) * Parallel building of locales led to nondeterminism in the RPM buildprocess. (RHBZ#1652228) * Various minor bug fixes from the upstream 2.27 release branch were imported as part of this update ([swbz#17630](https://sourceware.org/bugzilla/show_bug.cgi?id=17630), [swbz#22753](https://sourceware.org/bugzilla/show_bug.cgi?id=22753), [swbz#23275](https://sourceware.org/bugzilla/show_bug.cgi?id=23275), [swbz#23562](https://sourceware.org/bugzilla/show_bug.cgi?id=23562), [swbz#23579](https://sourceware.org/bugzilla/show_bug.cgi?id=23579), [swbz#23822](https://sourceware.org/bugzilla/show_bug.cgi?id=23822)). --------------------------------------------------------------------------------ChangeLog: * Wed Nov 28 2018 Florian Weimer - 2.27-35 - Auto-sync with upstream branch release/2.27/master, commit 9f433fc791ca4f9d678903ff45b504b524c886fb: - CVE-2018-19591: if_nametoindex: Fix descriptor leak (#1654000) - libanl: proper cleanup if first helper thread creation failed (#1646381) - x86: Fix Haswell CPU string flags (#1641980) - resolv/tst-resolv-network.c: Additional test case (swbz#17630) - ia64: fix missing exp2f, log2f and powf symbols in libm.a (swbz#23822) - conform: XFAIL siginfo_t si_band test on sparc64 - signal: Use correct type for si_band in siginfo_t (swbz#23562) - pthread_mutex_lock: Fix race while promoting to PTHREAD_MUTEX_ELISION_NP (swbz#23275) - preadv2/pwritev2: Fix misreported errno (swbz#23579) - preadv2/pwritev2: Handle offset == -1 (swbz#22753) - posix_spawn: Fix potential segmentation fault * Mon Nov 26 2018 Florian Weimer - 2.27-34 - Do not use parallel make for building locales (#1652228) * Thu Aug 30 2018 Florian Weimer - 2.27-33 - Revert glibc_make_flags setting which is not needed in Fedora 28 (#1600034) * Wed Aug 29 2018 Florian Weimer - 2.27-32 - Auto-sync with upstream branch release/2.27/master, commit 2b47bb9cba048e778a7d832f284feccb14a40483: - nptl: Fix waiters-after-spinning case in pthread_cond_broadcast (#1622669) - x86: Correct index_cpu_LZCNT (swbz#23456) - x86: Populate COMMON_CPUID_INDEX_80000001for Intel CPUs (swbz#23459) * Mon Aug 13 2018 Carlos O'Donell - 2.27-31 - Remove abort() warning in manual (#1615608) * Wed Jul 11 2018 Florian Weimer - 2.27-30 - Auto-sync with upstream branch release/2.27/master, commit 68c1bf80978594388157c62fd2edd467d4e8dfb2: - regexec: Fix off-by-one bug in weight comparison (#1582229) - es_BO locale: Change LC_PAPER to en_US (swbz#22996) - conform/conformtest.pl: Escape literal braces in regular expressions * Wed Jul 11 2018 Florian Weimer - 2.27-29 - Add POWER9 multilib (downstream only) * Wed Jul 11 2018 Florian Weimer - 2.27-28 - Work around valgrind issue on i686 (#1600034) * Fri Jul 6 2018 Florian Weimer - 2.27-27 - Build additional files with stack protector * Fri Jul 6 2018 Florian Weimer - 2.27-26 - Enable build flags inheritance for nonshared flags * Fri Jul 6 2018 Florian Weimer - 2.27-25 - Inherit further build flags (downstream only) * Wed Jul 4 2018 Florian Weimer - 2.27-24 - Add annobin annotations to assembler code (downstream only) (#1548438) * Wed Jul 4 2018 Florian Weimer - 2.27-23 - Enable -D_FORTIFY_SOURCE=2 for nonshared code * Wed Jul 4 2018 Florian Weimer - 2.27-22 - Auto-sync with upstream branch release/2.27/master, commit 5fab7fe1dc9cab9a46cf5c8840aa9b7ea3a26296: - math: Set 387 and SSE2 rounding mode for tgamma on i386 (swbz#23253) * Wed Jul 4 2018 Florian Weimer - 2.27-21 - Switch to upstream implementation of --disable-crypt (#1566464) * Tue Jul 3 2018 Florian Weimer - 2.27-20 - Auto-sync with upstream branch release/2.27/master, commit 7602b9e48c30c146d52df91dd83e518b8d0d343b: - math: Fix parameter type in C++ version of iseqsig (swbz#23171) - Use _STRUCT_TIMESPEC as guard in (swbz#23349) - getifaddrs: Don't return ifa entries with NULL names (swbz#21812) - libio: Disable vtable validation in case of interposition (swbz#23313) - stdio-common/tst-printf.c: Remove part under a non-free license (swbz#23363) * Wed Jun 20 2018 Florian Weimer - 2.27-19 - Modernisensswitch.conf defaults (#1581809) * Mon Jun 18 2018 Florian Weimer - 2.27-18 - iconv: Make IBM273 equivalent to ISO-8859-1 (#1592270) * Mon Jun 18 2018 Florian Weimer - 2.27-17 - Align build flags inheritance with master (downstream only) * Mon Jun 18 2018 Florian Weimer - 2.27-16 - Auto-sync with upstream branch release/2.27/master, commit 80c83e91140d429c73f79092fdb75eed0fb71da0: - libio: Avoid _allocate_buffer, _free_buffer function pointers (swbz#23236) - posix: Fix posix_spawnp to not execute invalid binaries in non compat mode (swbz#23264) - elf: Improve DST handling (swbz#23102, swbz#21942, swbz#18018, swbz#23259) * Thu May 24 2018 Florian Weimer - 2.27-15 - Rebuild to add back .symtab section in ld.so (#1570246) - Switch to upstream version of libidn2 removal (#1452750) - Auto-sync with upstream branch release/2.27/master, commit 50df56ca86a281c8fd99a8100aac75539813788d: - CVE-2018-11237: Buffer overflow in mempcpy for Xeon Phi (#1581275) * Thu May 17 2018 Florian Weimer - 2.27-14 - Do not run telinit u on upgrades (#1579225) * Tue May 15 2018 Florian Weimer - 2.27-13 - Auto-sync with upstream branch release/2.27/master, commit 0cd4a5e87f6885a2f15fe8e7eb7378d010cdb606: - sunrpc: Remove stray exports (#1577210) - gd_GB: Fix typo in abbreviated "May" (swbz#23152) - CVE-2018-11236: realpath: Fix path length overflow (#1581270, swbz#22786) - elf: Fix stack overflow with huge PT_NOTE segment (swbz#20419) - resolv: Fully initialize struct mmsghdr in send_dg (swbz#23037) - manual: Various fixes to the mbstouwcs example, and mbrtowc update - getlogin_r: return early when linux sentinel value is set - resolv: Fix crash in resolver on memory allocation failure (swbz#23005) - Fix signed integer overflow in random_r (swbz#17343) - RISC-V: fix struct kernel_sigaction to match the kernel version (swbz#23069) * Fri May 11 2018 Florian Weimer - 2.27-12 - Unconditionally build downstream with -mstackrealign for now * Fri May 11 2018 Florian Weimer - 2.27-11 -Inherit compiler flags in the original order * Fri May 11 2018 Florian Weimer - 2.27-10 - Inherit the -mstackrealign flag if it is set * Fri May 11 2018 Florian Weimer - 2.27-9 - Use /usr/bin/python3 for benchmarks scripts (#1577223) --------------------------------------------------------------------------------References: [ 1 ] Bug #1653993 - CVE-2018-19591 glibc: file descriptor leak in if_nametoindex() in sysdeps/unix/sysv/linux/if_index.c https://bugzilla.redhat.com/show_bug.cgi?id=1653993 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-060302dc83' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Incremental glibc upgrade for Fedora 28 aimed at resolving file descriptor issues and rectifying several bugs from upstream sources.. Fedora Update, glibc Security Fix, Resource Exhaustion, Denial of Service Threat. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Dec 04, 2018 Medium Fedora
200

Scientific Linux: SLSA-2013:0831-1 Moderate: Libvirt File Descriptor Leak

Moderate: libvirt security and bug fix update. Date: Thu, 16 May 2013 18:05:25 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: libvirt on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: libvirt security and bug fix update Advisory ID: SLSA-2013:0831-1 Issue Date: 2013-05-16 CVE Numbers: CVE-2013-1962 -- It was found that libvirtd leaked file descriptors when listing all volumes for a particular pool. A remote attacker able to establish a read- only connection to libvirtd could use this flaw to cause libvirtd to consume all available file descriptors, preventing other users from using libvirtd services (such as starting a new guest) until libvirtd is restarted. (CVE-2013-1962) This update also fixes the following bugs: * Previously, libvirt made control group (cgroup) requests on files that it should not have. With older kernels, such nonsensical cgroup requests were ignored; however, newer kernels are stricter, resulting in libvirt logging spurious warnings and failures to the libvirtd and audit logs. The audit log failures displayed by the ausearch tool were similar to the following: root [date] - failed cgroup allow path rw /dev/kqemu With this update, libvirt no longer attempts the nonsensical cgroup actions, leaving only valid attempts in the libvirtd and audit logs (making it easier to search for real cases of failure). * Previously, libvirt used the wrong variable when constructing audit messages. This led to invalid audit messages, causing ausearch to format certain entries as having "path=(null)" instead of the correct path. This could prevent ausearch from locating events related to cgroup device ACL modifications for guests managed by libvirt. With this update, the audit messages are generated correctly, preventing loss of audit coverage. After installing the updated packages, libvirtd will be restarted automatically. -- SL6 x86_64 libvirt-0.10.2-18.el6_4.5.x86_64.rpm libvirt-client-0.10.2-18.el6_4.5.i686.rpm libvirt-client-0.10.2-18.el6_4.5.x86_64.rpm libvirt-debuginfo-0.10.2-18.el6_4.5.i686.rpm libvirt-debuginfo-0.10.2-18.el6_4.5.x86_64.rpm libvirt-python-0.10.2-18.el6_4.5.x86_64.rpm libvirt-devel-0.10.2-18.el6_4.5.i686.rpm libvirt-devel-0.10.2-18.el6_4.5.x86_64.rpm libvirt-lock-sanlock-0.10.2-18.el6_4.5.x86_64.rpm i386 libvirt-0.10.2-18.el6_4.5.i686.rpm libvirt-client-0.10.2-18.el6_4.5.i686.rpm libvirt-debuginfo-0.10.2-18.el6_4.5.i686.rpm libvirt-python-0.10.2-18.el6_4.5.i686.rpm libvirt-devel-0.10.2-18.el6_4.5.i686.rpm - Scientific Linux Development Team . A recent libvirt update for Scientific Linux has rectified a file descriptor leakage and resolved audit messaging concerns, thereby improving overall security.. Scientific Linux, libvirt, bug fixes, security updates, file descriptor leak. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 16, 2013 Important Scientific Linux
87

Debian: DSA-1282-1 Critical: OpenSSL Memory Management Vulnerability Fix

On 25 April, the Debian Security Team released clamav 0.90.1-3etch1, an update to the Clam anti-virus toolkit, to address several vulnerabilities. Unfortunately, there was an error in the updated packages and CVE-2007-2029, a file descriptor leak in the PDF document handler, was not properly fixed in Debian 4.0 (etch) or the Debian testing distribution (lenny). This problem has been fixed in version 0.90.1-3etch2 for Debian 4.0 (etch). . - ------------------------------------------------------------------------Debian Security Advisory DSA-1281-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Noah Meyerhans May 21, 2007 - ------------------------------------------------------------------------Package : clamav Vulnerability : file descriptor leak Problem type : remote Debian-specific: no CVE Id(s) : CVE-2007-2029 BugTraq ID : 23656 On 25 April, the Debian Security Team released clamav 0.90.1-3etch1, an update to the Clam anti-virus toolkit, to address several vulnerabilities. Unfortunately, there was an error in the updated packages and CVE-2007-2029, a file descriptor leak in the PDF document handler, was not properly fixed in Debian 4.0 (etch) or the Debian testing distribution (lenny). This problem has been fixed in version 0.90.1-3etch2 for Debian 4.0 (etch). The problem will be fixed in testing (lenny) in version clamav_0.90.1-3.1lenny2, to be released via the testing-security channel, as soon as possible. Other versions of Debian are not affected. We recommend that you upgrade your clamav packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding theresources from the footer to the proper configuration. Debian (stable) - ---------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 11643310 cd11c05b5476262eaea4fa3bd7dc25bf Size/MD5 checksum: 202678 b69d5dd04efa34a1b5d754d00d02325a Size/MD5 checksum: 886 8ea6dec6430464f80367174cbf1522ee Architecture independent packages: Size/MD5 checksum: 200024 399e614261bcf6fc11f9d8cb1f31aa36 Size/MD5 checksum: 1005888 07cf61246264a02b5f3f75b712dc352f Size/MD5 checksum: 157450 84cfbe25cbb8f43f84d3e7608dd1ff00 alpha architecture (DEC Alpha) Size/MD5 checksum: 405598 e89e635ca763a960a2b9641034cffe1f Size/MD5 checksum: 863126 be2975967f9abcad74ac30ad1a7b4ecc Size/MD5 checksum: 509806 596fb241736d8336811f5631ef922937 Size/MD5 checksum: 184282 678347363c2723c9562aa7e5edda23fe Size/MD5 checksum: 643780 d44e46beb7ed21b5f423cc40d93feae9 Size/MD5 checksum: 9303354 954ef0ff1af4fbafdf32d0230edf6d79 Size/MD5 checksum: 179444 d066c1c6f9d1b738abba4150ecfbe3ef amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 176536 3b19c1bfabe694d90a047232a3cb21ea Size/MD5 checksum: 178048 1d2d279449991d196c0444502fd05e7a Size/MD5 checksum: 637530 8914446075225de9dc8c97dd16b83acd Size/MD5 checksum: 856120 96322f73a53bc97b115ee7fcbfb3560e Size/MD5 checksum: 366656 ff2956673dbbb4a62e5ab9153a80a9cf Size/MD5 checksum: 385832 56bd5d5f8a4b2a1241c109d88d3b4279 Size/MD5 checksum: 9301488 175ff062a9408489ec8c185124e209a4 arm architecture (ARM) Size/MD5 checksum: 362196 50bfa1d26925ac85140583fce13b3909 Size/MD5 checksum: 173260 8e65843c91e2a1fe5446cb540445556a Size/MD5 checksum: 9299326 4a9c05ea0f08fbca693f1884f116b0f8 Size/MD5 checksum: 366018 d07ef427cb65e5839f0b523c08d55c1c Size/MD5 checksum: 17436274669807f901a4b8a3ce125b3ad333c9 Size/MD5 checksum: 596846 c1ac53e1501d73611556ffc547496f3b Size/MD5 checksum: 851644 952a117428093c42dd281b5c695832e0 hppa architecture (HP PA RISC) Size/MD5 checksum: 176618 89bf2c97a2690eecccebe60e3a7cd55f Size/MD5 checksum: 404346 22abe6d6d95e7933d38969fabc552253 Size/MD5 checksum: 9302836 78c95396f0971eef4c1b8f73809b74a6 Size/MD5 checksum: 617610 b0b2c5131ae5c8ebbbc049a0a204ffd4 Size/MD5 checksum: 856878 b085a2d8317bce6476d6129df8962e38 Size/MD5 checksum: 177774 0a2a82b14cdcf0cabd566e8ed8c74e9c Size/MD5 checksum: 432198 c4ad61a24a60b73528db102363af6d00 i386 architecture (Intel ia32) Size/MD5 checksum: 367872 4a4c2d68de04892779fa2ee18d454af1 Size/MD5 checksum: 9299034 a57a8dabcbfdb1ca948c7807e2b161d5 Size/MD5 checksum: 173352 1effd13aca20fd86e8b00d1a0a21e842 Size/MD5 checksum: 365298 a188cff902e8d3642e376a2185f48209 Size/MD5 checksum: 604376 3f2b2b9b7019c4b0ec612acab2de915b Size/MD5 checksum: 174936 ac2c9892b4ba30ecae20c35597b8fcc9 Size/MD5 checksum: 854652 8a44c143be20d81e88ac3500ef387df6 ia64 architecture (Intel ia64) Size/MD5 checksum: 9314878 52935be009b4a84223a81151df5ddbba Size/MD5 checksum: 474192 c31fc49ca7bdd22488a15b99357b5d76 Size/MD5 checksum: 201282 f1fe669400c25fab7b39c54ef4eaecda Size/MD5 checksum: 878096 fcdac4ab11700a235d4d39ebdbeb27c5 Size/MD5 checksum: 190928 62d04383c37b80857a93467913a1c14c Size/MD5 checksum: 656284 de83f9db8dfdf447752093747bd2a2d9 Size/MD5 checksum: 520668 edc7f091eb3cc1186839384bfef06d21 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 371698 fc79ffd010ad11bfa3160cf6ea3ce707 Size/MD5 checksum: 179500 911eb19759eaf1cf427542dae6f28406 Size/MD5 checksum: 174912 cf528b98d0097a8eb48f20904c9d2293 Size/MD5 checksum: 9301294 c790bf6ecaf6006c91e1cef8a4a77923 Size/MD5 checksum: 646430 f5c54dcdcded52b66ff4147fddc71f59 Size/MD5 checksum: 854314 305e3bf521ff3f2cd96792922a2c625b Size/MD5 checksum: 434900 6a543233716cd4b768afebbea6b61d6a mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 854248 3ea1e1812a2daa168a9533176fe1e074 Size/MD5 checksum: 179608 8541d8cbfbe953440b3ef5dfd517b63e Size/MD5 checksum: 9301454 7f1090c461b1770d05c8ded4308f1e89 Size/MD5 checksum: 364882 c8bc7c3b7c605e37af80ebce9eea919a Size/MD5 checksum: 426150 401882418c4e16b3e58a99d8b021f8b7 Size/MD5 checksum: 635298 81f659a808b56347b350ad675e0c29ce Size/MD5 checksum: 175152 4440f5cfc45930032d5b7ee149c8ffa8 powerpc architecture (PowerPC) Size/MD5 checksum: 181496 f05c77fa28abd1aafcc376ae4e28c587 Size/MD5 checksum: 405258 3bd384a4001434b69039dd3bb1437826 Size/MD5 checksum: 636532 7434d9bb7f4657e77204fa5f708b3421 Size/MD5 checksum: 856934 13a0e913693e549c7562afbe59ee2cc0 Size/MD5 checksum: 377756 8a28b60a850123a811317bf1ab752947 Size/MD5 checksum: 9301808 ff846ca9fe56ce38d25a00ee83cecc2a Size/MD5 checksum: 175654 52166fa0e96a3fbed8c47600bd9b6ccb s390 architecture (IBM S/390) Size/MD5 checksum: 854876 4eb7c4af3574b496997a79de2c00bd59 Size/MD5 checksum: 390766 6f40991adee8e0877e9e0968240fc299 Size/MD5 checksum: 176048 ce6514408234d53d0e09e78de7b34b60 Size/MD5 checksum: 176232 f26d9e37a2b5b6e2ebc11408c2a1c87e Size/MD5 checksum: 401248 30566a8c06b87fa9226e3ee490ed985f Size/MD5 checksum: 627618 c46d97bd8cf40a85cb8882df6e554913 Size/MD5 checksum: 9300662 5a58ee27fad028c3e8e4632426cce41c sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 9298416 e3846fca2a382ccc5596d04e9a5ab469 Size/MD5 checksum: 583752 1085766a6eb6e086a745b65c8d65f3cd Size/MD5 checksum: 171712 0be51d03cf3b023cf6e5899d6b71d798 Size/MD5 checksum: 388500 3cb57fbe22b4fb9d4fad41e9b7d25ed8 Size/MD5 checksum: 376772 3e724ed0289a2c8d42e6cde9155cb4b3 Size/MD5 checksum: 850984 cd8672207fe749f42f909fb135f3ab06 Size/MD5 checksum: 173342 e6a2627dffed9ac3afe3716271d8efb1 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-1281-2 http://www.debian.org/security/ Noah Meyerhans May 21, 2007 Pack. april, debian, security, released, clamav, 1-3etch1, update, anti-viru. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 21, 2007 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here