Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for udisks2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3372-1 Rating: moderate References: #1091274 #1109406 Cross-References: CVE-2018-17336 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for udisks2 fixes the following issues: Following security issues was fixed: - CVE-2018-17336: A format string vulnerability in udisks_log (bsc#1109406) Following non-security issues were fixed: - strip trailing newline from sysfs raid level information (bsc#1091274) - Fix watcher error for non-redundant raid devices. (bsc#1091274) This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1247=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libudisks2-0-2.6.5-lp150.2.3.1 libudisks2-0-debuginfo-2.6.5-lp150.2.3.1 typelib-1_0-UDisks-2_0-2.6.5-lp150.2.3.1 udisks2-2.6.5-lp150.2.3.1 udisks2-debuginfo-2.6.5-lp150.2.3.1 udisks2-debugsource-2.6.5-lp150.2.3.1 udisks2-devel-2.6.5-lp150.2.3.1 - openSUSE Leap 15.0 (noarch): udisks2-lang-2.6.5-lp150.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-17336.html https://bugzilla.suse.com/1091274 https://bugzilla.suse.com/1109406 -- . An update for openSUSE addresses a format string security flaw in udisks2. Protect your systems by performing the update immediately..openSUSE Security Update,Udisks2 Patch,Format String Mitigation. . LinuxSecurity.com Team
. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9342 2009-09-06 20:08:02 -------------------------------------------------------------------------------- Name : libsilc Product : Fedora 11 Version : 1.1.8 Release : 7.fc11 URL : Summary : SILC Client Library Description : SILC Client Library libraries for clients to connect to SILC networks. SILC (Secure Internet Live Conferencing) is a protocol which provides secure conferencing services on the Internet over insecure channel. -------------------------------------------------------------------------------- ChangeLog: * Fri Sep 4 2009 Stu Tomlinson 1.1.8-7 - Backport patch to fix stack corruption (CVE-2008-7160) (#521256) * Fri Sep 4 2009 Stu Tomlinson 1.1.8-6 - Backport patch to fix additional string format vulnerabilities (#515648) * Wed Aug 5 2009 Stu Tomlinson 1.1.8-5 - Backport patch to fix string format vulnerability (#515648) * Sat Jul 25 2009 Fedora Release Engineering - 1.1.8-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #515648 - libsilc: format string vulnerability in client entry handling https://bugzilla.redhat.com/show_bug.cgi?id=515648 [ 2 ] Bug #521256 - CVE-2008-7160 libsilc: stack corruption in SilcHttpServer on 64bit archs https://bugzilla.redhat.com/show_bug.cgi?id=521256 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libsilc' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list
It was discovered that Ekiga had format string vulnerabilities beyond those fixed in USN-426-1. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges. . =========================================================== Ubuntu Security Notice USN-434-1 March 09, 2007 ekiga, gnomemeeting vulnerability CVE-2007-0999 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: gnomemeeting 1.2.2-1ubuntu1.2 Ubuntu 6.06 LTS: ekiga 2.0.1-0ubuntu6.2 Ubuntu 6.10: ekiga 2.0.3-0ubuntu3.2 After a standard system upgrade you need to restart Ekiga or reboot your computer to effect the necessary changes. Details follow: It was discovered that Ekiga had format string vulnerabilities beyond those fixed in USN-426-1. If a user was running Ekiga and listening for incoming calls, a remote attacker could send a crafted call request, and execute arbitrary code with the user's privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 13935 390ded46c12911e6ff7f0fb0b41648b1 Size/MD5: 1811 bfaea7c58d0be1c76fb15275584929d8 Size/MD5: 6059950 65fe2d6a31e63a37c5a6217206223192 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 1826502 ab68c7c0c54d6ea2288058f1cd850e0a i386 architecture (x86 compatible Intel/AMD) Size/MD5: 1802224 2323471938830841421f5758518444a0 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 181757861f4574c015fb133a7d223d68945ad87 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 1803946 ab636f2081b328f36025e99cea2f0cd3 Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 26736 820ab04b4cb0423bb9d62f03bf3e4634 Size/MD5: 2090 921caa6df4e1ceeb79438b5f653992c6 Size/MD5: 5572709 9f0a2bcce380677e38b23991320df171 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3687974 428c44b190d3e1e6f97f8d3be08aa6fe i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3658256 2b4c80838f881af9780e65e5be79b26b powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3673874 44119593cb37df9ae0c759df26e9f5b3 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3661004 85ce6c1bc136e1e6699cfb501d537abd Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 27205 ae82839a944aa39b118b1fa6edda3f1c Size/MD5: 1837 90fa46619ab136f7e8d7086916c1bdc0 Size/MD5: 5749938 5ad3458d73d65c6502c312ff0c430a7c amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 3689026 82e52fe078d8ab0102bf647d12cfe4cc i386 architecture (x86 compatible Intel/AMD) Size/MD5: 3668638 4ebd1951ef9e4cc4860223e682c90541 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 3676386 efcac25a055bb4cd5e776550c370880f sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 3671020 41fda4e546004b1a7f456b286e2ce560 . Explore significant Ekiga security flaws present in Ubuntu builds following USN-434-1. Implement strategies to defend against potential threats.. Ekiga Vulnerability, Format String Issue, Ubuntu Security Update. . LinuxSecurity.com Team
A format string vulnerability was discovered in w3m. If a user were tricked into visiting an HTTPS URL protected by a specially crafted SSL certificate, an attacker could execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-399-1 January 03, 2007 w3m vulnerabilities ;aid=1612792&group_id=39518&atid=425439 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: w3m 0.5.1-3ubuntu1.1 Ubuntu 6.06 LTS: w3m 0.5.1-4ubuntu2.6.06 Ubuntu 6.10: w3m 0.5.1-4ubuntu2.6.10 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: A format string vulnerability was discovered in w3m. If a user were tricked into visiting an HTTPS URL protected by a specially crafted SSL certificate, an attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 26918 6c80b8da1759df35d0fbbbfd762be482 Size/MD5: 714 d5fab4328a132271d45443b0c62c9c5f Size/MD5: 1892121 0678b72e07e69c41709d71ef0fe5da13 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 90086 e9be4901190f36350b7c3906e8d5c7c0 Size/MD5: 1119434 544af8fe74b78b80b85b0618934e993f i386 architecture (x86 compatible Intel/AMD) Size/MD5: 88984 b39f657ec9c7fc9f0b66eccf6548ecfd Size/MD5: 1062408 4681dd0f0799ac9418ae11f17c39efb6 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 9154047fbc7739850d784fea04b739763a79b Size/MD5: 1120800 43549c92dd35b1b1945fefed4c10caad sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 89256 e9975d718fb34e212ab9471a19b293b8 Size/MD5: 1087110 ac0ece82654dc503f9aff5c961d766ae Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 35266 4eb07f00d81679ccf53f5c50c3cf5403 Size/MD5: 702 ced346058b3f71ecec26652b9aa919d7 Size/MD5: 1892121 0678b72e07e69c41709d71ef0fe5da13 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 88458 ac45f4fade3fa7f60643b18553ccfb32 Size/MD5: 1119712 d48a1acda4b04bd2b8870d7328d471af i386 architecture (x86 compatible Intel/AMD) Size/MD5: 87464 790cddd717ef3d53576cd44325bbe74c Size/MD5: 1061434 1309934c6ce36eddc7d1fe10c8a397d7 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 89786 7a5076bb3784d7c3ee23a83a799c006e Size/MD5: 1120114 a3464f27e707e26c6282a0913e485330 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 87854 18bcf4fe486d5d5223c6cff38fc2badd Size/MD5: 1084034 f76db440d2206b0f6cccda184bbc1380 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 35266 30be4e65c986ec185ff1bc0855b1debb Size/MD5: 702 0ba7b9609b67a3312af4eda07da0b342 Size/MD5: 1892121 0678b72e07e69c41709d71ef0fe5da13 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 88446 f05692dbf3a8ece4a7c4897fca454fe1 Size/MD5: 1131030 1500cfb7d6066f6df6ac510dbd133a57 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 87712 f17dcbf4a518d4704f203f6694166ab1 Size/MD5: 1085166 861a156c3ac25b0908756cb83c593ff3 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 89888 b98545747a5f409b99fa7667ce034595 Size/MD5: 1136062 b20c1b12d34f3cf52ed85d6a8441eb0e sparcarchitecture (Sun SPARC/UltraSPARC) Size/MD5: 87830 547b4ccbf9cde9c40ad8a18e0a67436e Size/MD5: 1099004 7175fd58a8037a2d6a652a661c09c3ac . Immediate notification regarding w3m on Ubuntu versions 5.10, 6.06 LTS, and 6.10 to address a serious format string vulnerability that could enable code execution.. Ubuntu Security,w3m Update,Format String Issue,HTTPS Threat,Linux Admin. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.