Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
197

Debian 10: DLA-3223-1 Critical: giflib Buffer Overflow and DoS Risk

This update fixes two file format vulnerabilities in giflib. CVE-2018-11490 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3223-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Helmut Grohne December 05, 2022 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : giflib Version : 5.1.4-3+deb10u1 CVE ID : CVE-2018-11490 CVE-2019-15133 Debian Bug : 904114 This update fixes two file format vulnerabilities in giflib. CVE-2018-11490 The DGifDecompressLine function in dgif_lib.c, as later shipped in cgif.c in sam2p 0.49.4, has a heap-based buffer overflow because a certain "Private-> RunningCode - 2" array index is not checked. This will lead to a denial of service or possibly unspecified other impact. CVE-2019-15133 A malformed GIF file triggers a divide-by-zero exception in the decoder function DGifSlurp in dgif_lib.c if the height field of the ImageSize data structure is equal to zero. For Debian 10 buster, these problems have been fixed in version 5.1.4-3+deb10u1. We recommend that you upgrade your giflib packages. For the detailed security status of giflib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/giflib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance giflib to rectify issues related to file formats, such as buffer overflow vulnerabilities and Denial of Service threats, following the guidance of Debian LTS DLA-3223-1.. giflib security update, debian advisory, file format issues, buffer overflow fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 05, 2022 Critical Debian LTS
89

Fedora Core 4: gedit Update 2.10.2 Moderate: File Format Issue

An updated gedit package that fixes a file name format string vulnerability is now available.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-403 2005-06-26 ---------------------------------------------------------------------Product : Fedora Core 4 Name : gedit Version : 2.10.2 Release : 4 Summary : gEdit is a small but powerful text editor for GNOME. Description : gEdit is a small but powerful text editor designed specifically for the GNOME GUI desktop. gEdit includes a plug-in API (which supports extensibility while keeping the core binary small), support for editing multiple documents using notebook tabs, and standard text editor functions. You'll need to have GNOME and GTK+ installed to use gEdit. ---------------------------------------------------------------------Update Information: An updated gedit package that fixes a file name format string vulnerability is now available. This update has been rated as having moderate security impact by the Red Hat Security Response Team gEdit is a small text editor designed specifically for the GNOME GUI desktop. A file name format string vulnerability has been discovered in gEdit. It is possible for an attacker to create a file with a carefully crafted name which, when the file is opened, executes arbitrary instructions on a victim's machine. Although it is unlikely that a user would manually open a file with such a carefully crafted file name, a user could, for example, be tricked into opening such a file from within an email client. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-1686 to this issue. Users of gEdit should upgrade to this updated package, which contains a backported patch to correct this issue. ---------------------------------------------------------------------* Tue Jun 7 2005 Ray Strode 1:2.10.2-4 - Dont pass user inputas format specifiers to gtk_message_dialog_new (bug 159657). ---------------------------------------------------------------------This update can be downloaded from: 291c49505ea82dec5340de227d1203ec SRPMS/gedit-2.10.2-4.src.rpm 93fda2f09dec2e2fc6428d50bdc7d669 ppc/gedit-2.10.2-4.ppc.rpm 6e300eda8afb5264ebed2d58a52676cd ppc/gedit-devel-2.10.2-4.ppc.rpm 1e584bd71f8a898be0307527e57f4774 ppc/debug/gedit-debuginfo-2.10.2-4.ppc.rpm d5236c9ad6c4fecef9ff43fc388c89ba x86_64/gedit-2.10.2-4.x86_64.rpm 08e1a0e684d3a6746b4ce6451d6b2b3d x86_64/gedit-devel-2.10.2-4.x86_64.rpm ff2961c1627c57a8390a38377525ae5b x86_64/debug/gedit-debuginfo-2.10.2-4.x86_64.rpm 4feaa7449692b5c33ab38d2e7304f236 i386/gedit-2.10.2-4.i386.rpm be814fb7204f079767960071ca248ff7 i386/gedit-devel-2.10.2-4.i386.rpm 271dc9d8beacf6e5121d7497aa0a02c1 i386/debug/gedit-debuginfo-2.10.2-4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ---------------------------------------------------------------------Thanks go to Bernd Bartmann for reminding me to send this announcement out. Sorry for the delay. Ray Strode --fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A revised version of gedit for Fedora Core 4 resolves a document format concern to improve security and safeguard against vulnerabilities.. gedit Update,Fedora Security,Format String Issue,Text Editor Patch. . LinuxSecurity.com Team

Calendar 2 Jun 27, 2005 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here