Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 3 articles for you...
89

Fedora 24 D-Bus Update: FEDORA-2016-0a4dc821d5 Moderate Format String Issue

Update to 1.11.6. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2016-0a4dc821d5 2016-10-13 17:12:37.426444 -------------------------------------------------------------------------------- Name : dbus Product : Fedora 24 Version : 1.11.6 Release : 1.fc24 URL : https://https:// Summary : D-BUS message bus Description : D-BUS is a system for sending messages between applications. It is used both for the system-wide message bus service, and as a per-user-login-session messaging facility. -------------------------------------------------------------------------------- Update Information: Update to 1.11.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #1383657 - dbus: Format string vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1383657 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update dbus' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . An enhancement for Fedora 24 has been released to fix a vulnerability in dbus related to format strings, improving security for system communications.. Fedora Security Update, dbus Software Update, Format String Issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 13, 2016 Important Fedora
98

Red Hat: RHSA-2012:1116-01 Moderate: perl-DBD-Pg Format String Issue

An updated perl-DBD-Pg package that fixes two security issues is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: perl-DBD-Pg security update Advisory ID: RHSA-2012:1116-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2012:1116.html Issue date: 2012-07-25 CVE Names: CVE-2012-1151 ==================================================================== 1. Summary: An updated perl-DBD-Pg package that fixes two security issues is now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Perl DBI is a database access Application Programming Interface (API) for the Perl language. perl-DBD-Pg allows Perl applications to access PostgreSQL database servers. Two format string flaws were found in perl-DBD-Pg. A specially-crafted database warning or error message from a server could cause an application using perl-DBD-Pg to crash or, potentially, execute arbitrary code with the privileges of the user running the application. (CVE-2012-1151) All users of perl-DBD-Pg are advised to upgrade to this updatedpackage, which contains a backported patch to fix these issues. Applications using perl-DBD-Pg must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 801733 - CVE-2012-1151 perl-DBD-Pg: Format string flaws by turning db notices into Perl warnings and by preparing DBD statement 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: perl-DBD-Pg-1.49-4.el5_8.i386.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.i386.rpm x86_64: perl-DBD-Pg-1.49-4.el5_8.x86_64.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: perl-DBD-Pg-1.49-4.el5_8.i386.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.i386.rpm ia64: perl-DBD-Pg-1.49-4.el5_8.ia64.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.ia64.rpm ppc: perl-DBD-Pg-1.49-4.el5_8.ppc.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.ppc.rpm s390x: perl-DBD-Pg-1.49-4.el5_8.s390x.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.s390x.rpm x86_64: perl-DBD-Pg-1.49-4.el5_8.x86_64.rpm perl-DBD-Pg-debuginfo-1.49-4.el5_8.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: perl-DBD-Pg-2.15.1-4.el6_3.x86_64.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.x86_64.rpm Red Hat Enterprise Linux Server (v. 6): Source: i386: perl-DBD-Pg-2.15.1-4.el6_3.i686.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.i686.rpm ppc64: perl-DBD-Pg-2.15.1-4.el6_3.ppc64.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.ppc64.rpm s390x: perl-DBD-Pg-2.15.1-4.el6_3.s390x.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.s390x.rpm x86_64: perl-DBD-Pg-2.15.1-4.el6_3.x86_64.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: perl-DBD-Pg-2.15.1-4.el6_3.i686.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.i686.rpm x86_64: perl-DBD-Pg-2.15.1-4.el6_3.x86_64.rpm perl-DBD-Pg-debuginfo-2.15.1-4.el6_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2012-1151 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2012 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFQECalXlSAg2UNWIIRAg5oAJ9Axt76xnJodfYOujBTqPjLjeOKeACglhKk xcNjSdCZiKspR58fJAdc7XU=KmOi -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . A new version of perl-DBD-Pg addresses two critical vulnerabilities, urging users to update to ensure system safety.. perl-DBD-Pg security, Red Hat updates, database access issues, moderate security fix. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jul 25, 2012 Medium Red Hat
200

Scientific Linux 6: CVE-2012-0864 Moderate: glibc Format String Flaw

Moderate: glibc security and bug fix update. Date: Tue, 20 Mar 2012 08:44:52 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: FASTBUGS for SL 6x i386, x86_64 now available MIME-Version: 1.0 The following FASTBUGS have been uploaded to i386: dropwatch-1.2-1.el6.i686.rpm file-5.04-13.el6.i686.rpm file-devel-5.04-13.el6.i686.rpm file-libs-5.04-13.el6.i686.rpm file-static-5.04-13.el6.i686.rpm gawk-3.1.7-9.el6.i686.rpm iok-1.3.13-2.el6.i686.rpm liberation-fonts-common-1.05.1.20090721-5.el6.noarch.rpm liberation-mono-fonts-1.05.1.20090721-5.el6.noarch.rpm liberation-sans-fonts-1.05.1.20090721-5.el6.noarch.rpm liberation-serif-fonts-1.05.1.20090721-5.el6.noarch.rpm libgweather-2.28.0-5.el6.i686.rpm libgweather-devel-2.28.0-5.el6.i686.rpm mod_nss-1.0.8-14.el6_2.i686.rpm python-magic-5.04-13.el6.i686.rpm tsclient-2.0.2-8.el6.i686.rpm tsclient-devel-2.0.2-8.el6.i686.rpm yum-3.2.29-22.el6_2.2.noarch.rpm yum-cron-3.2.29-22.el6_2.2.noarch.rpm x86_64: dropwatch-1.2-1.el6.x86_64.rpm file-5.04-13.el6.x86_64.rpm file-devel-5.04-13.el6.i686.rpm file-devel-5.04-13.el6.x86_64.rpm file-libs-5.04-13.el6.i686.rpm file-libs-5.04-13.el6.x86_64.rpm file-static-5.04-13.el6.x86_64.rpm gawk-3.1.7-9.el6.x86_64.rpm iok-1.3.13-2.el6.x86_64.rpm liberation-fonts-common-1.05.1.20090721-5.el6.noarch.rpm liberation-mono-fonts-1.05.1.20090721-5.el6.noarch.rpm liberation-sans-fonts-1.05.1.20090721-5.el6.noarch.rpm liberation-serif-fonts-1.05.1.20090721-5.el6.noarch.rpm libgweather-2.28.0-5.el6.i686.rpm libgweather-2.28.0-5.el6.x86_64.rpm libgweather-devel-2.28.0-5.el6.i686.rpm libgweather-devel-2.28.0-5.el6.x86_64.rpm mod_nss-1.0.8-14.el6_2.x86_64.rpm python-magic-5.04-13.el6.x86_64.rpm tsclient-2.0.2-8.el6.x86_64.rpm tsclient-devel-2.0.2-8.el6.i686.rpm tsclient-devel-2.0.2-8.el6.x86_64.rpm yum-3.2.29-22.el6_2.2.noarch.rpm yum-cron-3.2.29-22.el6_2.2.noarch.rpm Date: Wed, 21 Mar 2012 15:24:13 -0500 Reply-To: This email address is being protected from spambots. You need JavaScript enabled to view it. Sender: Security Errata for ScientificLinux From: Patrick Riehecky Subject: Security ERRATA Moderate: glibc on SL6.x i386/x86_64 Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it. Synopsis: Moderate: glibc security and bug fix update Issue Date: 2012-03-15 CVE Numbers: CVE-2012-0864 The glibc packages provide the standard C and standard math libraries used by multiple programs on the system. Without these libraries, the Linux system cannot function correctly. An integer overflow flaw was found in the implementation of the printf functions family. This could allow an attacker to bypass FORTIFY_SOURCE protections and execute arbitrary code using a format string flaw in an application, even though these protections are expected to limit the impact of such flaws to an application abort. (CVE-2012-0864) This update also fixes the following bugs: * Previously, the dynamic loader generated an incorrect ordering for initialization according to the ELF specification. This could result in incorrect ordering of DSO constructors and destructors. With this update, dependency resolution has been fixed. * Previously, locking of the main malloc arena was incorrect in the retry path. This could result in a deadlock if an sbrk request failed. With this update, locking of the main arena in the retry path has been fixed. This issue was exposed by a bug fix provided in a previous update. * Calling memcpy with overlapping arguments on certain processors would generate unexpected results. While such code is a clear violation of ANSI/ISO standards, this update restores prior memcpy behavior. All users of glibc are advised to upgrade to these updated packages, which contain patches to resolve these issues. SL6: i386 glibc-2.12-1.47.el6_2.9.i686.rpm glibc-common-2.12-1.47.el6_2.9.i686.rpm glibc-debuginfo-2.12-1.47.el6_2.9.i686.rpm glibc-debuginfo-common-2.12-1.47.el6_2.9.i686.rpm glibc-devel-2.12-1.47.el6_2.9.i686.rpm glibc-headers-2.12-1.47.el6_2.9.i686.rpm glibc-static-2.12-1.47.el6_2.9.i686.rpm glibc-utils-2.12-1.47.el6_2.9.i686.rpm nscd-2.12-1.47.el6_2.9.i686.rpm x86_64 glibc-2.12-1.47.el6_2.9.i686.rpm glibc-2.12-1.47.el6_2.9.x86_64.rpm glibc-common-2.12-1.47.el6_2.9.x86_64.rpm glibc-debuginfo-2.12-1.47.el6_2.9.i686.rpm glibc-debuginfo-2.12-1.47.el6_2.9.x86_64.rpm glibc-debuginfo-common-2.12-1.47.el6_2.9.i686.rpm glibc-debuginfo-common-2.12-1.47.el6_2.9.x86_64.rpm glibc-devel-2.12-1.47.el6_2.9.i686.rpm glibc-devel-2.12-1.47.el6_2.9.x86_64.rpm glibc-headers-2.12-1.47.el6_2.9.x86_64.rpm glibc-static-2.12-1.47.el6_2.9.i686.rpm glibc-static-2.12-1.47.el6_2.9.x86_64.rpm glibc-utils-2.12-1.47.el6_2.9.x86_64.rpm nscd-2.12-1.47.el6_2.9.x86_64.rpm - Scientific Linux Development Team . Recent glibc update for Scientific Linux mitigates format string vulnerabilities and enhances overall performance.. glibc Update, Scientific Linux Security, moderate security fix. . LinuxSecurity.com Team

Calendar 2 Mar 21, 2012 Scientific Linux
172

Ubuntu: USN-438-1 Critical: Inkscape Remote Execution Threat

A flaw was discovered in Inkscape's use of format strings. If a user were tricked into opening a specially crafted URI in Inkscape, a remote attacker could execute arbitrary code with user privileges. . =========================================================== Ubuntu Security Notice USN-438-1 March 20, 2007 inkscape vulnerability CVE-2007-1463 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06 LTS Ubuntu 6.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 5.10: inkscape 0.42-1ubuntu0.2 Ubuntu 6.06 LTS: inkscape 0.43-4ubuntu3.1 Ubuntu 6.10: inkscape 0.44-1ubuntu2.1 After a standard system upgrade you need to restart Inkscape or reboot your computer to effect the necessary changes. Details follow: A flaw was discovered in Inkscape's use of format strings. If a user were tricked into opening a specially crafted URI in Inkscape, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 5.10: Source archives: Size/MD5: 10748 2845c7245a1b7be4c5c751a27b0cc2e7 Size/MD5: 887 97c737882a0f670a9cadb7dd03f2a7d3 Size/MD5: 8001602 653c81be2fc7c80fd9895e908d3a73f1 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 6371548 5edc834d0661390802903328c979ee2a i386 architecture (x86 compatible Intel/AMD) Size/MD5: 5934276 4d1c8ac3b46ad98317cbff623c1cf83a powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 6329196 73c242a09e8445e2c5114e67d3a5326f sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 6009640 55747db48a057dad40e9ee83b0d3eedb Updated packages forUbuntu 6.06 LTS: Source archives: Size/MD5: 21982 e0849e3fa7016a4eec11a03f5135fb95 Size/MD5: 980 f12017904a2dfb65c7e575b7fa61256b Size/MD5: 9185965 e3e92da1464dcee1b42560ff073dfe36 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 7778462 54ea87b063fea676141e1b091bc1431e i386 architecture (x86 compatible Intel/AMD) Size/MD5: 7375678 05bf8ec7cb22080b6744a6408c5e5a4a powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 7865464 96d2703544dfaa08a99cca8c329d9d71 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 7503160 15fd6c1e013186acfd62e5d0a5bd7d75 Updated packages for Ubuntu 6.10: Source archives: Size/MD5: 24944 5687cda78c7255b4fdc0febb5970f861 Size/MD5: 966 179a5be63f3f4eb8df47ab51a5395335 Size/MD5: 9549500 099653446c11d2536d6c4727634eaca5 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 7694504 1499a5ddf8832036d16d75b2ca1432b2 i386 architecture (x86 compatible Intel/AMD) Size/MD5: 7522234 c1e2f801f9ba4d76ef05eecf6ce81ab5 powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 7822556 734c96863c5c6d816f87c302088f88da sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 7549074 7b73eafd429383055b5021f9ebf09d5d . Ubuntu Security Notice USN-438-1 March 20, 2007 inkscape vulnerability CVE-2007-1463 A security issu. inkscape', format, strings, tricked, opening. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 20, 2007 Critical Ubuntu
91

Gentoo: 200602-06 Normal: ImageMagick Format String Issue Risk

A vulnerability in ImageMagick allows attackers to crash the application and potentially execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200602-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ImageMagick: Format string vulnerability Date: February 13, 2006 Bugs: #83542 ID: 200602-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in ImageMagick allows attackers to crash the application and potentially execute arbitrary code. Background ========= ImageMagick is an application suite to manipulate and convert images. It is often used as a utility backend by web applications like forums, content management systems or picture galleries. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/imagemagick < 6.2.5.5 > = 6.2.5.5 Description ========== The SetImageInfo function was found vulnerable to a format string mishandling. Daniel Kobras discovered that the handling of "%"-escaped sequences in filenames passed to the function is inadequate. This is a new vulnerability that is not addressed by GLSA 200503-11. Impact ===== By feeding specially crafted file names to ImageMagick, an attacker can crash the program and possibly execute arbitrary code with the privileges of the user running ImageMagick. Workaround ========= There is no known workaround at this time. Resolution ========= All ImageMagick users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot--verbose "> =media-gfx/imagemagick-6.2.5.5" References ========= [ 1 ] CVE-2006-0082 https://www.cve.org/CVERecord?id=CVE-2006-0082 [ 2 ] GLSA 200503-11 https://security.gentoo.org/glsa/200503-11 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200602-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . A vulnerability in ImageMagick's format string can lead to remote code execution on Gentoo platforms; ensure you update promptly for enhanced security measures.. ImageMagick Security,Gentoo GLSA,Format String Issue. . LinuxSecurity.com Team

Calendar 2 Feb 13, 2006 Gentoo
98

Red Hat Enterprise Linux 2.1 RHSA-2006:0179-01 Critical auth_ldap Fix

An updated auth_ldap packages that fixes a format string security issue is now available for Red Hat Enterprise Linux 2.1. This update has been rated as having critical security impact by the Red Hat Security Response Team. . - ---------------------------------------------------------------------Red Hat Security Advisory Synopsis: Critical: auth_ldap security update Advisory ID: RHSA-2006:0179-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0179.html Issue date: 2006-01-10 Updated on: 2006-01-10 Product: Red Hat Enterprise Linux CVE Names: CVE-2006-0150 - ---------------------------------------------------------------------1. Summary: An updated auth_ldap packages that fixes a format string security issue is now available for Red Hat Enterprise Linux 2.1. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS (Advanced Server) version 2.1 - i386, ia64 Red Hat Linux Advanced Workstation 2.1 - ia64 Red Hat Enterprise Linux ES version 2.1 - i386 Red Hat Enterprise Linux WS version 2.1 - i386 3. Problem description: The auth_ldap package is an httpd module that allows user authentication against information stored in an LDAP database. A format string flaw was found in the way auth_ldap logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if auth_ldap is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0150 to this issue. Note that this issue only affects servers that have auth_ldap installed and configured to perform user authentication against an LDAP database. All users of auth_ldap should upgrade to this updated package, which contains a backported patch to resolve this issue. This issue does not affect the Red Hat Enterprise Linux 3 or 4 distributions as they do not include the auth_ldap package. 4.Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 177421 - CVE-2006-0150 auth_ldap format string issue 6. RPMs required: Red Hat Enterprise Linux AS (Advanced Server) version 2.1: SRPMS: b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm i386: 569bce40fcb6cc7cefa9179d949fb192 auth_ldap-1.4.8-3.1.i386.rpm ia64: 56aea79641ddb17dc98d26b6f20dd439 auth_ldap-1.4.8-3.1.ia64.rpm Red Hat Linux Advanced Workstation 2.1: SRPMS: b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm ia64: 56aea79641ddb17dc98d26b6f20dd439 auth_ldap-1.4.8-3.1.ia64.rpm Red Hat Enterprise Linux ES version 2.1: SRPMS: b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm i386: 569bce40fcb6cc7cefa9179d949fb192 auth_ldap-1.4.8-3.1.i386.rpm Red Hat Enterprise Linux WS version 2.1: SRPMS: b386cc76da4f4dbbcafc5e0200567b76 auth_ldap-1.4.8-3.1.src.rpm i386: 569bce40fcb6cc7cefa9179d949fb192 auth_ldap-1.4.8-3.1.i386.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.cve.org/CVERecord?id=CVE-2006-0150 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2006 Red Hat, Inc. . Important security patch released for auth_ldap module in Red Hat addressing a format specifier vulnerability to enhance security and robustness.. Red Hat Enterprise Linux, auth_ldap Update, Security Best Practices. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 17, 2006 Critical Red Hat
98

Critical Update for mod_auth_pgsql in Red Hat Enterprise Linux 3 and 4

Updated mod_auth_pgsql packages that fix format string security issues are now available for Red Hat Enterprise Linux 3 and 4. This update has been rated as having critical security impact by the Red Hat Security Response Team. . - ---------------------------------------------------------------------Red Hat Security Advisory Synopsis: Critical: mod_auth_pgsql security update Advisory ID: RHSA-2006:0164-01 Advisory URL: https://access.redhat.com/errata/RHSA-2006:0164.html Issue date: 2006-01-05 Updated on: 2006-01-05 Product: Red Hat Enterprise Linux CVE Names: CVE-2005-3656 - ---------------------------------------------------------------------1. Summary: Updated mod_auth_pgsql packages that fix format string security issues are now available for Red Hat Enterprise Linux 3 and 4. This update has been rated as having critical security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux AS version 4 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 4 - i386, ia64, x86_64 3. Problem description: The mod_auth_pgsql package is an httpd module that allows user authentication against information stored in a PostgreSQL database. Several format string flaws were found in the way mod_auth_pgsql logs information. It may be possible for a remote attacker to execute arbitrary code as the 'apache' user if mod_auth_pgsql is used for user authentication. The Common Vulnerabilities and Exposures project assigned the name CVE-2005-3656 to this issue. Please note that this issue only affects servers which have mod_auth_pgsql installed andconfigured to perform user authentication against a PostgreSQL database. All users of mod_auth_pgsql should upgrade to these updated packages, which contain a backported patch to resolve this issue. This issue does not affect the mod_auth_pgsql package supplied with Red Hat Enterprise Linux 2.1. Red Hat would like to thank iDefense for reporting this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed (http://bugzilla.redhat.com/): 177042 - CVE-2005-3656 mod_auth_pgsql format string issue 6. RPMs required: Red Hat Enterprise Linux AS version 3: SRPMS: 78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm i386: 416d662759b7e9a6cac6db24813cadf9 mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm ia64: 4a72fdbf3b94d7d1891e66d8465a5798 mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm ppc: 7b319bd7a03d74b6337b259f96950e8c mod_auth_pgsql-2.0.1-4.ent.1.ppc.rpm s390: c989ef09e9c107cd05e9ca4e75bbc789 mod_auth_pgsql-2.0.1-4.ent.1.s390.rpm s390x: 476139795bf63306aaf2d478fb471982 mod_auth_pgsql-2.0.1-4.ent.1.s390x.rpm x86_64: cb2bd4600e4fab1ffc7e2b1fbb2a6dfb mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm Red Hat Desktop version 3: SRPMS: 78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm i386: 416d662759b7e9a6cac6db24813cadf9 mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm x86_64: cb2bd4600e4fab1ffc7e2b1fbb2a6dfb mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm Red Hat Enterprise Linux ES version 3: SRPMS: 78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm i386: 416d662759b7e9a6cac6db24813cadf9 mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm ia64: 4a72fdbf3b94d7d1891e66d8465a5798mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm x86_64: cb2bd4600e4fab1ffc7e2b1fbb2a6dfb mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm Red Hat Enterprise Linux WS version 3: SRPMS: 78d123ce4dd88d2b473f3def9d1f78d8 mod_auth_pgsql-2.0.1-4.ent.1.src.rpm i386: 416d662759b7e9a6cac6db24813cadf9 mod_auth_pgsql-2.0.1-4.ent.1.i386.rpm ia64: 4a72fdbf3b94d7d1891e66d8465a5798 mod_auth_pgsql-2.0.1-4.ent.1.ia64.rpm x86_64: cb2bd4600e4fab1ffc7e2b1fbb2a6dfb mod_auth_pgsql-2.0.1-4.ent.1.x86_64.rpm Red Hat Enterprise Linux AS version 4: SRPMS: 2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm i386: 19b586cf092086566de31c883b116f8f mod_auth_pgsql-2.0.1-7.1.i386.rpm ia64: 90ca4b0d4160b78edda12d3d300bc2bb mod_auth_pgsql-2.0.1-7.1.ia64.rpm ppc: 514eea209095325a9d0c4acb6c1a181f mod_auth_pgsql-2.0.1-7.1.ppc.rpm s390: 9c32645c2f524537233212c532e6d0a7 mod_auth_pgsql-2.0.1-7.1.s390.rpm s390x: 7eef05e02885fad7fb86485fe2b46630 mod_auth_pgsql-2.0.1-7.1.s390x.rpm x86_64: 542f993464e75b8e6370c453e1dc8c7d mod_auth_pgsql-2.0.1-7.1.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: SRPMS: 2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm i386: 19b586cf092086566de31c883b116f8f mod_auth_pgsql-2.0.1-7.1.i386.rpm x86_64: 542f993464e75b8e6370c453e1dc8c7d mod_auth_pgsql-2.0.1-7.1.x86_64.rpm Red Hat Enterprise Linux ES version 4: SRPMS: 2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm i386: 19b586cf092086566de31c883b116f8f mod_auth_pgsql-2.0.1-7.1.i386.rpm ia64: 90ca4b0d4160b78edda12d3d300bc2bb mod_auth_pgsql-2.0.1-7.1.ia64.rpm x86_64: 542f993464e75b8e6370c453e1dc8c7d mod_auth_pgsql-2.0.1-7.1.x86_64.rpm Red Hat Enterprise Linux WS version 4: SRPMS: 2a46d8268d1d434ed8ec089bf83e62bd mod_auth_pgsql-2.0.1-7.1.src.rpm i386: 19b586cf092086566de31c883b116f8f mod_auth_pgsql-2.0.1-7.1.i386.rpm ia64: 90ca4b0d4160b78edda12d3d300bc2bb mod_auth_pgsql-2.0.1-7.1.ia64.rpm x86_64: 542f993464e75b8e6370c453e1dc8c7dmod_auth_pgsql-2.0.1-7.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://www.cve.org/CVERecord?id=CVE-2005-3656 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2006 Red Hat, Inc. . Essential security patch released for Red Hat's mod_auth_pgsql software to address formatting string vulnerabilities and mitigate potential execution threats.. Red Hat Security, mod_auth_pgsql Update, Format String Fix, RHEL Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 17, 2006 Critical Red Hat
87

Debian 3.1 DSA 841-1 Critical: Mailutils Remote Code Execution

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 841-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze October 4th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mailutils Vulnerability : format string vulnerability Problem type : remote Debian-specific: no CVE ID : CAN-2005-2878 A format string vulnerability has been discovered in GNU mailutils which contains utilities for handling mail that allows a remote attacker to execute arbitrary code on the IMAP server. The old stable distribution (woody) is not affected by this problem. For the stable distribution (sarge) this problem has been fixed in version 0.6.1-4sarge1. For the unstable distribution (sid) this problem has been fixed in version 0.6.90-3. We recommend that you upgrade your mailutils package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 1105 571f9dc4dd73866f6888f7ad40d445a9 Size/MD5 checksum: 37030 cdeaf9acb33abf47aadeb899163db03c Size/MD5 checksum: 3053948 47ff446d55909e2777efb9e912b23de5 Architecture independent components: Size/MD5 checksum: 287326 f8cc3cd1b4d753c77a49a488768fed4a Alpha architecture: Size/MD5 checksum: 606384f54df2eb18e6b761feb6e39c5c025898 Size/MD5 checksum: 538700 4088fade15aa91790a4eeaf968e3deb1 Size/MD5 checksum: 171206 ad50d9f2a50366a91134e355764e8db3 Size/MD5 checksum: 48714 cde882256182f1efc3f65ee5fb8a5a91 Size/MD5 checksum: 87216 b73d7281c7b568e00a09e6102c2f8bcb Size/MD5 checksum: 840400 a3896dfc973058db179400e793584849 Size/MD5 checksum: 66522 14ae8401d93659894b73759b1b478f8b AMD64 architecture: Size/MD5 checksum: 572810 6f359d09d1146ca5ba91342cf47e8aed Size/MD5 checksum: 419252 63ffc694a1ae01ce93cff42a542a23f5 Size/MD5 checksum: 156792 cbf58f684ae6016c66732100bc59549f Size/MD5 checksum: 47420 7819e7f8bedf0cb6a9e736cbbad0261b Size/MD5 checksum: 80310 c1c891e8de7f71ea1747e7345449bccf Size/MD5 checksum: 747904 b8a99a4c9ba9bd23a2d81c3e8b1873a1 Size/MD5 checksum: 63066 7fd0d97ddbdd61306a690c5f135c5eac ARM architecture: Size/MD5 checksum: 527430 4ddcccc6f44fc7df839b2c028fffe55a Size/MD5 checksum: 398996 041963fa2132bf8473f119b9a0c46b98 Size/MD5 checksum: 139946 138bd36d955a0590663691da9a924e87 Size/MD5 checksum: 45920 395f7450d6d6808d9e650dd0191bdc98 Size/MD5 checksum: 73224 3d99823d12f33edbc4ba48a78785c065 Size/MD5 checksum: 611910 85de420573e56df18b696f99986d2e4e Size/MD5 checksum: 58728 1713cfbb377dcf306f502766555e2c56 Intel IA-32 architecture: Size/MD5 checksum: 546638 33c7ba82e32cb44e60ccc11c898350aa Size/MD5 checksum: 368170 eb33117e3ea1af53f9acb25b91d19802 Size/MD5 checksum: 143594 e031d8e9c5e66ace4391f915d8505199 Size/MD5 checksum: 46600 4e5ac10b6ccf7ce323d01631da6406db Size/MD5 checksum: 75060 080e134a5b18a50691573fcb2587ceea Size/MD5 checksum: 648372 0b390cfe6f739dc61b964c60b47b5f22 Size/MD5 checksum: 6045888304f09d9508705d6689ba581380eb6 Intel IA-64 architecture: Size/MD5 checksum: 686370 4cb54d890bc50a94b4c86abdbf33eee7 Size/MD5 checksum: 560412 9ac160e35b8af32107d58726b5b64107 Size/MD5 checksum: 198664 ee929d5849173c9ab70928bc61e69bee Size/MD5 checksum: 51238 9d39ff55ab465b23b5c661b47ae9630d Size/MD5 checksum: 96998 54e94843d30f4eff696ebcdd45c7a539 Size/MD5 checksum: 990306 69e8b44efc1925b8ae388b37274b7b82 Size/MD5 checksum: 72422 245ec7e13466de3d1d43eec6abdb741e HP Precision architecture: Size/MD5 checksum: 595258 d4ca564d255bdc33d1769c1b1063fe8e Size/MD5 checksum: 442204 5c238fde3c655bcf043180e90f47172a Size/MD5 checksum: 158120 b8f5748edf06712cb7dce347f93ef407 Size/MD5 checksum: 47578 6e041420aea5d1edd31c5a34d69bbefa Size/MD5 checksum: 79582 9e03d9c6cbfb8ac2381a82c9098d3117 Size/MD5 checksum: 743390 8039702fb15714fbf208e593387772ef Size/MD5 checksum: 62636 1974df850795b3c8e90f711feed74353 Motorola 680x0 architecture: Size/MD5 checksum: 530392 feb5047c2cb1b1aa622ce00f4fa88a8e Size/MD5 checksum: 342010 8be136e24deac85778b6aed825eedf4b Size/MD5 checksum: 137976 21192aff6dabf3ce2dd720ac621bdd79 Size/MD5 checksum: 46002 11524c5af73a9230b396acfbc8ac70ef Size/MD5 checksum: 71980 b19b14b7d6fab2d65691841b237535c4 Size/MD5 checksum: 585942 96fb6e0b0bd5c77135471137bf4e03f3 Size/MD5 checksum: 58532 5e08996c218aed9d69df307dc5cfc25c Big endian MIPS architecture: Size/MD5 checksum: 546328 fd4c71af25939af23fef5f3264282fb2 Size/MD5 checksum: 435486 3e0e0384e04a09384d770b1ab4baea32 Size/MD5 checksum: 170178 91bdf8e9f748cc7d59720bde9a2902ea Size/MD5 checksum: 47324 92c7228dab7e3eef27830516725d92c2 Size/MD5 checksum: 79408 9a53d5edbbde3e22891c17e46d963df4 Size/MD5 checksum: 736470 05e81cdbde2a46b0390395673a08cc1f Size/MD5 checksum: 63246 23f641022bea23e89754fcfdbe6a0ee7 Little endian MIPS architecture: Size/MD5 checksum: 543782 d3b0685929f7a7509593070bd6c3cb24 Size/MD5 checksum: 435074 0b429dc39083c2f1d297fe74109d9ff1 Size/MD5 checksum: 169236 8f8baa1b0c29f740c6df24eef4be72f4 Size/MD5 checksum: 47348 928829f7677458a3a98a172de42845bf Size/MD5 checksum: 79370 af3aac9553ed1b32b5e202be0c5f25ee Size/MD5 checksum: 733964 4896c6d726bf6bb55ca3799bf16316b1 Size/MD5 checksum: 63062 0b6a4acd7abdce23cc5453eb74fe0ace PowerPC architecture: Size/MD5 checksum: 562656 f67259ab832b0f8c0603cdc67dbe7da5 Size/MD5 checksum: 413256 52af6f53afe953e2b61c6963a7767fa4 Size/MD5 checksum: 157132 dbea4cf9d3c13eb64dbfb6c45afc4656 Size/MD5 checksum: 48140 a17f9d5f6819a01c43203bba60bd1318 Size/MD5 checksum: 77740 a49bb18465fd525432408f04a1a5e2eb Size/MD5 checksum: 703556 0313c6d7732ea9dc02fdfe761d19d285 Size/MD5 checksum: 62720 b872dc38bd68f37eade1d93122b06d5d IBM S/390 architecture: Size/MD5 checksum: 588272 9b08cf5bf32808febe51d504f7a1de28 Size/MD5 checksum: 414258 e4dfb8ba1d2c9ae961f4266535b1db13 Size/MD5 checksum: 156044 e3a2c3bc8577fe048961dfafd65af520 Size/MD5 checksum: 47764 12c866ffaf0c4bdf3e1740b3204159af Size/MD5 checksum: 80440 972141900eb33f9f5af71f2dbd7735af Size/MD5 checksum: 751338 41c5a8f2321793932ed0b656d6d2ab5d Size/MD5 checksum: 63234 c7c4a9cddd4883057bf48259fc48da4d Sun Sparc architecture: Size/MD5 checksum: 538590 c087d0acbb5aaa85a2a604d502405ef2 Size/MD5 checksum: 377926 afe33096c3f86adb272ead55253ee886 Size/MD5 checksum: 139886 9138582e6bdd999321b9073ed8164b64 Size/MD5 checksum: 46012d13c45d9852f0400e61ec550da0f427e Size/MD5 checksum: 73622 0ecb0584c1652b26373dd22c457f1a5a Size/MD5 checksum: 624018 ad86570361a60694083e945abd2a5ff6 Size/MD5 checksum: 58758 b4c553eaee679c961775fcac89cbd168 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent updates to mailutils packages have been issued to address a format string vulnerability that could enable remote code execution in Debian.. mailutils update, remote code execution, format string issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 04, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here