Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 11: DLA-3968-1 critical: netatalk buffer overflow issue

Several issues have been found in netatalk, an Apple Filing Protocol service. Three issues are related to off-by-one errorrs and resultant heap-based buffer overflow. One issue is related to primitives offered by . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3968-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz November 28, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : netatalk Version : 3.1.12~ds-8+deb11u2 CVE ID : CVE-2022-22995 CVE-2024-38439 CVE-2024-38440 CVE-2024-38441 Several issues have been found in netatalk, an Apple Filing Protocol service. Three issues are related to off-by-one errorrs and resultant heap-based buffer overflow. One issue is related to primitives offered by SMB and AFP, which might allow an attacker to write arbitrary files and eventually execute arbitrary code. For Debian 11 bullseye, these problems have been fixed in version 3.1.12~ds-8+deb11u2. We recommend that you upgrade your netatalk packages. For the detailed security status of netatalk please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/netatalk Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The recent Debian LTS Advisory DLA-3968-1 concerns security flaws in netatalk, specifically highlighting buffer overflow vulnerabilities that pose significant risks.. Debian security updates, netatalk security, buffer overflow fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 27, 2024 Critical Debian LTS
200

Scientific Linux: SLSA-2016:2972-1 Moderate: vim Execution Risk

Moderate: vim security update. Date: Wed, 21 Dec 2016 16:01:12 -0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: vim on SL6.x, SL7.x i386/x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: vim security update Advisory ID: SLSA-2016:2972-1 Issue Date: 2016-12-21 CVE Numbers: CVE-2016-1248 -- Security Fix(es): * A vulnerability was found in vim in how certain modeline options were treated. An attacker could craft a file that, when opened in vim with modelines enabled, could execute arbitrary commands with privileges of the user running vim. (CVE-2016-1248) -- SL6 x86_64 vim-X11-7.4.629-5.el6_8.1.x86_64.rpm vim-common-7.4.629-5.el6_8.1.x86_64.rpm vim-debuginfo-7.4.629-5.el6_8.1.x86_64.rpm vim-enhanced-7.4.629-5.el6_8.1.x86_64.rpm vim-filesystem-7.4.629-5.el6_8.1.x86_64.rpm vim-minimal-7.4.629-5.el6_8.1.x86_64.rpm i386 vim-X11-7.4.629-5.el6_8.1.i686.rpm vim-common-7.4.629-5.el6_8.1.i686.rpm vim-debuginfo-7.4.629-5.el6_8.1.i686.rpm vim-enhanced-7.4.629-5.el6_8.1.i686.rpm vim-filesystem-7.4.629-5.el6_8.1.i686.rpm vim-minimal-7.4.629-5.el6_8.1.i686.rpm SL7 x86_64 vim-X11-7.4.160-1.el7_3.1.x86_64.rpm vim-common-7.4.160-1.el7_3.1.x86_64.rpm vim-debuginfo-7.4.160-1.el7_3.1.x86_64.rpm vim-enhanced-7.4.160-1.el7_3.1.x86_64.rpm vim-filesystem-7.4.160-1.el7_3.1.x86_64.rpm vim-minimal-7.4.160-1.el7_3.1.x86_64.rpm - Scientific Linux Development Team . Cautious security notice for vim on Scientific Linux versions 6.x and 7.x addressing concerns over file execution vulnerabilities.. Scientific Linux Update, vim Security Fix, Linux Package Management. . LinuxSecurity.com Team

Calendar 2 Dec 21, 2016 Scientific Linux
200

Scientific Linux: SLSA-2014:0151-1 Low: wget Security Fix

Low: wget security and bug fix update. Date: Mon, 10 Feb 2014 19:18:59 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Low: wget on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: wget security and bug fix update Advisory ID: SLSA-2014:0151-1 Issue Date: 2014-02-10 CVE Numbers: None -- It was discovered that wget used a file name provided by the server when saving a downloaded file. This could cause wget to create a file with a different name than expected, possibly allowing the server to execute arbitrary code on the client. (CVE-2010-2252) Note: With this update, wget always uses the last component of the original URL as the name for the downloaded file. Previous behavior of using the server provided name or the last component of the redirected URL when creating files can be re-enabled by using the '--trust-server-names' command line option, or by setting 'trust_server_names=on' in the wget start-up file. This update also fixes the following bugs: * Prior to this update, the wget package did not recognize HTTPS SSL certificates with alternative names (subjectAltName) specified in the certificate as valid. As a consequence, running the wget command failed with a certificate error. This update fixes wget to recognize such certificates as valid. -- SL6 x86_64 wget-1.12-1.11.el6_5.x86_64.rpm wget-debuginfo-1.12-1.11.el6_5.x86_64.rpm i386 wget-1.12-1.11.el6_5.i686.rpm wget-debuginfo-1.12-1.11.el6_5.i686.rpm - Scientific Linux Development Team . curl patches system vulnerabilities, resolves filename conflicts and improves TLS certificate validation for CentOS Stream.. wget security update, Scientific Linux, bug fix, file execution issues, SSL certificates. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Feb 10, 2014 Low Scientific Linux
91

Gentoo: GLSA 200506-21 Important: Trac File Upload Vulnerability Details

Trac may allow remote attackers to upload files, possibly leading to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200506-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Trac: File upload vulnerability Date: June 22, 2005 Bugs: #96572 ID: 200506-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Trac may allow remote attackers to upload files, possibly leading to the execution of arbitrary code. Background ========= Trac is a minimalistic web-based project management, wiki and bug tracking system including a Subversion interface. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/trac < 0.8.4 > = 0.8.4 Description ========== Stefan Esser of the Hardened-PHP project discovered that Trac fails to validate the "id" parameter when uploading attachments to the wiki or the bug tracking system. Impact ===== A remote attacker could exploit the vulnerability to upload arbitrary files to a directory where the webserver has write access to, possibly leading to the execution of arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All Trac users should upgrade to the latest available version: # emerge --sync # emerge --ask --oneshot --verbose "> =www-apps/trac-0.8.4" References ========= [ 1 ] Hardened PHP Advisory 012005 Availability =========== This GLSA and any updates to it are available for viewing at the GentooSecurity Website: https://security.gentoo.org/glsa/200506-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The Gentoo Linux Security Advisory GLSA 200506-21 warns of a critical vulnerability in Trac software affecting file uploads, risking remote code execution. Trac File Upload, Gentoo Security Advisory, Remote Code Execution, Security Vulnerability, Software Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 22, 2005 Important Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here