Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 14.04: 2278-1 Moderate: File Denial Of Service Issues

File could be made to crash or hang if it processed specially crafted data.. =========================================================================Ubuntu Security Notice USN-2278-1 July 15, 2014 file vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: File could be made to crash or hang if it processed specially crafted data. Software Description: - file: Tool to determine file types Details: Mike Frysinger discovered that the file awk script detector used multiple wildcard with unlimited repetitions. An attacker could use this issue to cause file to consume resources, resulting in a denial of service. (CVE-2013-7345) Francisco Alonso discovered that file incorrectly handled certain CDF documents. A attacker could use this issue to cause file to hang or crash, resulting in a denial of service. (CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487) Jan Kaluža discovered that file did not properly restrict the amount of data read during regex searches. An attacker could use this issue to cause file to consume resources, resulting in a denial of service. (CVE-2014-3538) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: file 1:5.14-2ubuntu3.1 libmagic1 1:5.14-2ubuntu3.1 Ubuntu 13.10: file 5.11-2ubuntu4.3 libmagic1 5.11-2ubuntu4.3 Ubuntu 12.04 LTS: file 5.09-2ubuntu0.4 libmagic1 5.09-2ubuntu0.4 Ubuntu 10.04 LTS: file 5.03-5ubuntu1.3 libmagic1 5.03-5ubuntu1.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2278-1 CVE-2013-7345, CVE-2014-0207, CVE-2014-3478, CVE-2014-3479, CVE-2014-3480, CVE-2014-3487, CVE-2014-3538 Package Information: https://launchpad.net/ubuntu/+source/file/1:5.14-2ubuntu3.1 https://launchpad.net/ubuntu/+source/file/5.11-2ubuntu4.3 https://launchpad.net/ubuntu/+source/file/5.09-2ubuntu0.4 https://launchpad.net/ubuntu/+source/file/5.03-5ubuntu1.3 . A vulnerability in the network protocol exposes various Fedora distributions to potential remote exploitation due to inadequate validation of specific inputs.. Denial Of Service, Ubuntu Tool Security, Resource Management. . LinuxSecurity.com Team

Calendar 2 Jul 15, 2014 Ubuntu
87

Debian: DSA-2861-1 Critical: File Tool Denial Of Service

It was discovered that file, a file type classification tool, contains a flaw in the handling of "indirect" magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files. The Common Vulnerabilities and Exposures project . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2861-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso February 16, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : file Vulnerability : denial of service CVE ID : CVE-2014-1943 Debian Bug : 738832 It was discovered that file, a file type classification tool, contains a flaw in the handling of "indirect" magic rules in the libmagic library, which leads to an infinite recursion when trying to determine the file type of certain files. The Common Vulnerabilities and Exposures project ID CVE-2014-1943 has been assigned to identify this flaw. Additionally, other well-crafted files might result in long computation times (while using 100% CPU) and overlong results. For the oldstable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze3. For the stable distribution (wheezy), this problem has been fixed in version 5.11-2+deb7u1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your file packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Announcement DSA-2862-1 reports a vulnerability causing service disruption in the gzip utility, impacting various versions.. File Classification, Denial Of Service, Infinite Recursion. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 16, 2014 Critical Debian
87

Debian: DSA-2422-2 Critical: File Tool CDF Detection Fix

A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression. For reference the original advisory text follows. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2422-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst May 09, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : file Vulnerability : regression fix Problem type : remote Debian-specific: no CVE ID : CVE-2012-1571 A regression was discovered in the security update for file, which lead to false positives on the CDF format. This update fixes that regression. For reference the original advisory text follows. The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate. For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze2. We recommend that you upgrade your file packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian issues Advisory DSA-2423-1 addressing a flaw in the image viewer, improving JPEG format rendering functionality.. Debian, File Tool, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 09, 2012 Critical Debian
87

Debian: DSA-2422-1 Critical: File Tool Malformed Files Crash

The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2422-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer February 29, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : file Vulnerability : missing bounds checks Problem type : remote Debian-specific: no The file type identification tool, file, and its associated library, libmagic, do not properly process malformed files in the Composite Document File (CDF) format, leading to crashes. Note that after this update, file may return different detection results for CDF files (well-formed or not). The new detections are believed to be more accurate. For the stable distribution (squeeze), this problem has been fixed in version 5.04-5+squeeze1. We recommend that you upgrade your file packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu revamps its archive in response to emerging security threats, incorporating improved analysis of corrupted files.. Debian Security, File Tool, CDF Format, Remote Checks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 29, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here