Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 8: MGASA-2022-0325 Moderate FreeCAD Command Injection

Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. (CVE-2021-45844) References: . MGASA-2022-0325 - Updated freecad packages fix security vulnerability Publication date: 16 Sep 2022 URL: https://advisories.mageia.org/MGASA-2022-0325.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-45844 Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. (CVE-2021-45844) References: - https://bugs.mageia.org/show_bug.cgi?id=30137 - https://lists.debian.org/debian-lts-announce/2022/03/msg00005.html - https://lists.debian.org/debian-lts-announce/2022/08/msg00008.html - https://www.cve.org/CVERecord?id=CVE-2021-45844 SRPMS: - 8/core/freecad-0.18.6-1.3.mga8 . The latest FreeCAD patch in Mageia 8 resolves an inadequate input validation vulnerability that could lead to potential command injection threats. Discover further details.. FreeCAD Update, Mageia Security, Command Injection Risk, ODA File Converter, Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 16, 2022 Important Mageia
87

Debian 11: DSA-5229-1 Critical: FreeCAD Shell Command Execution

Two vulnerabilities were discovered in FreeCAD, a CAD/CAM program, which could result in the execution of arbitrary shell commands when opening a malformed file. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5229-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu September 13, 2022 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : freecad CVE ID : CVE-2021-45844 CVE-2021-45845 Two vulnerabilities were discovered in FreeCAD, a CAD/CAM program, which could result in the execution of arbitrary shell commands when opening a malformed file. For the stable distribution (bullseye), these problems have been fixed in version 0.19.1+dfsg1-2+deb11u1. We recommend that you upgrade your freecad packages. For the detailed security status of freecad please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freecad Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical update needed: two FreeCAD exploits permit command line execution through corrupted files.. FreeCAD Security Update, Debian DSA-5229-1, Command Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 13, 2022 Critical Debian
197

Debian Buster: DLA-3076-1 Critical: FreeCAD Command Injection Fix

A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWG files with crafted filenames. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3076-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort August 18, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : freecad Version : 0.18~pre1+dfsg1-5+deb10u1 CVE ID : CVE-2021-45844 Debian Bug : 1005747 A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWG files with crafted filenames. For Debian 10 buster, this problem has been fixed in version 0.18~pre1+dfsg1-5+deb10u1. We recommend that you upgrade your freecad packages. For the detailed security status of freecad please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freecad Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . FreeCAD security update DLA-3076-2 for Debian Buster mitigates risks associated with command injection vulnerabilities. Immediate upgrade is advised.. FreeCAD Security Update, Debian LTS Advisory, Command Injection Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 18, 2022 Critical Debian LTS
197

Debian 9 DLA-2934-1 Moderate: FreeCAD Command Injection Fix

A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWF files with crafted filenames. For Debian 9 stretch, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2934-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort March 07, 2022 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : freecad Version : 0.16+dfsg2-3+deb9u1 CVE ID : CVE-2021-45844 Debian Bug : 1005747 A command injection vulnerability was found in FreeCAD, a parametric 3D modeler, when importing DWF files with crafted filenames. For Debian 9 stretch, this problem has been fixed in version 0.16+dfsg2-3+deb9u1. We recommend that you upgrade your freecad packages. For the detailed security status of freecad please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/freecad Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Security vulnerability detected in FreeCAD. Please make sure to upgrade to the patched version available in Debian 9 stretch.. freecad update, debian security, command injection patch. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Mar 07, 2022 Medium Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here