Several issues have been found in netatalk, an Apple Filing Protocol service. Three issues are related to off-by-one errorrs and resultant heap-based buffer overflow. One issue is related to primitives offered by . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3968-1
Moderate: vim security update. Date: Wed, 21 Dec 2016 16:01:12 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: vim on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: vim security update Advisory ID: SLSA-2016:2972-1 Issue Date: 2016-12-21 CVE Numbers: CVE-2016-1248 -- Security Fix(es): * A vulnerability was found in vim in how certain modeline options were treated. An attacker could craft a file that, when opened in vim with modelines enabled, could execute arbitrary commands with privileges of the user running vim. (CVE-2016-1248) -- SL6 x86_64 vim-X11-7.4.629-5.el6_8.1.x86_64.rpm vim-common-7.4.629-5.el6_8.1.x86_64.rpm vim-debuginfo-7.4.629-5.el6_8.1.x86_64.rpm vim-enhanced-7.4.629-5.el6_8.1.x86_64.rpm vim-filesystem-7.4.629-5.el6_8.1.x86_64.rpm vim-minimal-7.4.629-5.el6_8.1.x86_64.rpm i386 vim-X11-7.4.629-5.el6_8.1.i686.rpm vim-common-7.4.629-5.el6_8.1.i686.rpm vim-debuginfo-7.4.629-5.el6_8.1.i686.rpm vim-enhanced-7.4.629-5.el6_8.1.i686.rpm vim-filesystem-7.4.629-5.el6_8.1.i686.rpm vim-minimal-7.4.629-5.el6_8.1.i686.rpm SL7 x86_64 vim-X11-7.4.160-1.el7_3.1.x86_64.rpm vim-common-7.4.160-1.el7_3.1.x86_64.rpm vim-debuginfo-7.4.160-1.el7_3.1.x86_64.rpm vim-enhanced-7.4.160-1.el7_3.1.x86_64.rpm vim-filesystem-7.4.160-1.el7_3.1.x86_64.rpm vim-minimal-7.4.160-1.el7_3.1.x86_64.rpm - Scientific Linux Development Team . Cautious security notice for vim on Scientific Linux versions 6.x and 7.x addressing concerns over file execution vulnerabilities.. Scientific Linux Update, vim Security Fix, Linux Package Management. . LinuxSecurity.com Team
Low: wget security and bug fix update. Date: Mon, 10 Feb 2014 19:18:59 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Low: wget on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: wget security and bug fix update Advisory ID: SLSA-2014:0151-1 Issue Date: 2014-02-10 CVE Numbers: None -- It was discovered that wget used a file name provided by the server when saving a downloaded file. This could cause wget to create a file with a different name than expected, possibly allowing the server to execute arbitrary code on the client. (CVE-2010-2252) Note: With this update, wget always uses the last component of the original URL as the name for the downloaded file. Previous behavior of using the server provided name or the last component of the redirected URL when creating files can be re-enabled by using the '--trust-server-names' command line option, or by setting 'trust_server_names=on' in the wget start-up file. This update also fixes the following bugs: * Prior to this update, the wget package did not recognize HTTPS SSL certificates with alternative names (subjectAltName) specified in the certificate as valid. As a consequence, running the wget command failed with a certificate error. This update fixes wget to recognize such certificates as valid. -- SL6 x86_64 wget-1.12-1.11.el6_5.x86_64.rpm wget-debuginfo-1.12-1.11.el6_5.x86_64.rpm i386 wget-1.12-1.11.el6_5.i686.rpm wget-debuginfo-1.12-1.11.el6_5.i686.rpm - Scientific Linux Development Team . curl patches system vulnerabilities, resolves filename conflicts and improves TLS certificate validation for CentOS Stream.. wget security update, Scientific Linux, bug fix, file execution issues, SSL certificates. . Severity: Low. LinuxSecurity.com Team
Trac may allow remote attackers to upload files, possibly leading to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Trac: File upload vulnerability Date: June 22, 2005 Bugs: #96572 ID: 200506-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Trac may allow remote attackers to upload files, possibly leading to the execution of arbitrary code. Background ========= Trac is a minimalistic web-based project management, wiki and bug tracking system including a Subversion interface. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/trac < 0.8.4 > = 0.8.4 Description ========== Stefan Esser of the Hardened-PHP project discovered that Trac fails to validate the "id" parameter when uploading attachments to the wiki or the bug tracking system. Impact ===== A remote attacker could exploit the vulnerability to upload arbitrary files to a directory where the webserver has write access to, possibly leading to the execution of arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All Trac users should upgrade to the latest available version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/trac-0.8.4" References ========= [ 1 ] Hardened PHP Advisory 012005 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/200506-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.