Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
89

Fedora 40: 2024-129d8ca6fc High: Frysk Type Confusion Events

Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : frysk Product : Fedora 40 Version : 0.4 Release : 94.fc40 URL : https://sourceware.org/frysk/ Summary : Execution analysis and debugging tool-suite Description : Frysk is an execution-analysis technology implemented using native Java and C++. It is aimed at providing developers and sysadmins with the ability to both examine and analyze running multi-host, multi-process, multi-threaded systems. Frysk allows the monitoring of running processes and threads, of locking primitives and will also expose deadlocks, gather data and debug any given process in the system. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 0.4-94 - Rebuilt for java-21-openjdk as system jdk -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build withjava-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important CentOS security patch for groovy resolves several significant type mismatch vulnerabilities in Node.js and JDK enhancement.. Fedora Security Advisory,Frysk Tool,Type Confusion,Execution Analysis,JDK Upgrade. . LinuxSecurity.com Team

Calendar 2 Mar 07, 2024 Fedora
200

Scientific Linux 4: CVE-2011-3193 Moderate: Frysk Buffer Overflow Advisory

Moderate: frysk security update. Date: Thu, 22 Sep 2011 09:29:06 -0500 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: frysk on SL4.x i386/x86_64 MIME-Version: 1.0 Synopsis: Moderate: frysk security update Issue Date: 2011-09-21 CVE Numbers: CVE-2011-3193 frysk is an execution-analysis technology implemented using native Java and C++. It provides developers and system administrators with the ability to examine and analyze multi-host, multi-process, and multithreaded systems while they are running. frysk is released as a Technology Preview for Scientific Linux 4. A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in the embedded Pango library. If a frysk application were used to debug or trace a process that uses HarfBuzz while it loaded a specially-crafted font file, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3193) Users of frysk are advised to upgrade to this updated package, which contains a backported patch to correct this issue. All running frysk applications must be restarted for this update to take effect. SL4: i386 frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64 frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm - Scientific Linux Development Team . Frysk security patch released to resolve a medium-level buffer overflow vulnerability in Scientific Linux 4. Urgent upgrade suggested.. Frysk Security Update, Buffer Overflow Fix, Scientific Linux Errata. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 22, 2011 Important Scientific Linux
98

Red Hat Enterprise Linux 4: RHSA-2011-1327-01 Moderate: Frysk Buffer Error

An updated frysk package that fixes one security issue is now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: frysk security update Advisory ID: RHSA-2011:1327-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1327.html Issue date: 2011-09-21 CVE Names: CVE-2011-3193 ==================================================================== 1. Summary: An updated frysk package that fixes one security issue is now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, x86_64 Red Hat Enterprise Linux WS version 4 - i386, x86_64 3. Description: frysk is an execution-analysis technology implemented using native Java and C++. It provides developers and system administrators with the ability to examine and analyze multi-host, multi-process, and multithreaded systems while they are running. frysk is released as a Technology Preview for Red Hat Enterprise Linux 4. A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in the embedded Pango library. If a frysk application were used to debug or trace a process that uses HarfBuzz while it loaded a specially-crafted font file, it could cause the application to crash or, possibly, execute arbitrary code with theprivileges of the user running the application. (CVE-2011-3193) Users of frysk are advised to upgrade to this updated package, which contains a backported patch to correct this issue. All running frysk applications must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 733118 - CVE-2011-3193 qt/harfbuzz buffer overflow 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-3193 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/support/offerings/techpreview/ 8. Contact: TheRed Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFOeijlXlSAg2UNWIIRAuR+AJ9mkkkACA9/nQH3lbb6ydIM9JkDqQCgj/Xv J8qsJB3q9DHaErKSVu2GAEI=w3MU -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Update released addressing moderate frysk vulnerability on Red Hat Enterprise Linux 4. Users advised to upgrade to enhance security.. frysk update, buffer overflow, Red Hat security. . LinuxSecurity.com Team

Calendar 2 Sep 21, 2011 Red Hat
98

Red Hat: RHSA-2012:1459-01 Moderate: Pthread Security Vulnerability

An updated frysk package that fixes one security issue is now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: frysk security update Advisory ID: RHSA-2011:1327-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1327.html Issue date: 2011-09-21 CVE Names: CVE-2011-3193 ==================================================================== 1. Summary: An updated frysk package that fixes one security issue is now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4 - i386, x86_64 Red Hat Enterprise Linux Desktop version 4 - i386, x86_64 Red Hat Enterprise Linux ES version 4 - i386, x86_64 Red Hat Enterprise Linux WS version 4 - i386, x86_64 3. Description: frysk is an execution-analysis technology implemented using native Java and C++. It provides developers and system administrators with the ability to examine and analyze multi-host, multi-process, and multithreaded systems while they are running. frysk is released as a Technology Preview for Red Hat Enterprise Linux 4. A buffer overflow flaw was found in HarfBuzz, an OpenType text shaping engine used in the embedded Pango library. If a frysk application were used to debug or trace a process that uses HarfBuzz while it loaded a specially-crafted font file, it could cause the application to crash or, possibly, execute arbitrary code with the privileges of the user running the application. (CVE-2011-3193) Users of frysk are advised to upgrade to thisupdated package, which contains a backported patch to correct this issue. All running frysk applications must be restarted for this update to take effect. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 733118 - CVE-2011-3193 qt/harfbuzz buffer overflow 6. Package List: Red Hat Enterprise Linux AS version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux Desktop version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux ES version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm Red Hat Enterprise Linux WS version 4: Source: i386: frysk-0.0.1.2007.08.03-8.el4.i386.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.i386.rpm x86_64: frysk-0.0.1.2007.08.03-8.el4.x86_64.rpm frysk-debuginfo-0.0.1.2007.08.03-8.el4.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2011-3193 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/support/offerings/techpreview/ 8. Contact: The Red Hat security contact is . More contact details athttps://access.redhat.com/security/team/contact/ Copyright 2011 Red Hat, Inc. . The advisory from Red Hat outlines a significant security concern regarding the tool frysk, providing an update to address a critical vulnerability related to buffer overflow.. Frysk Security, Red Hat Update, Moderate Advisory, Execution Analysis, Buffer Overflow. . LinuxSecurity.com Team

Calendar 2 Sep 21, 2011 Red Hat
89

Fedora Core 7: 2008-182 Security: Tuning Network Protocols

Make current version of frysk available to FC5 users. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-739 2006-06-21 ---------------------------------------------------------------------Product : Fedora Core 5 Name : frysk Version : 0.0.1.2006.06.15.rh4 Release : 0.FC5 Summary : Frysk execution analysis tool Description : Frysk is an execution-analysis technology implemented using native Java and C++. It is aimed at providing developers and sysadmins with the ability to both examine and analyze running multi-host, multi-process, multi-threaded systems. Frysk allows the monitoring of running processes and threads, of locking primitives and will also expose deadlocks, gather data and debug any given process in the system. ---------------------------------------------------------------------Update Information: Make current version of frysk available to FC5 users. ---------------------------------------------------------------------* Fri Jun 16 2006 Stepan Kasal - 0.0.1.2006.06.15-3 - Add the non-intermediate hack. - Remove more unwanted files. - Add patch to link statically with libelf; remove elfutils libraries. * Fri Jun 16 2006 Stepan Kasal - 0.0.1.2006.06.15-2 - Suppress warnings caused by _FORTIFY_SOURCE=2 - Remove unwanted files. * Fri Jun 16 2006 Stepan Kasal - 0.0.1.2006.06.15-1 - Add BuildRequires: libgconf-java-devel - Update frysk-unistd.patch * Thu Jun 15 2006 Stepan Kasal - 0.0.1.2006.06.15-0 - Refresh the tarball. - Patch to fix Elf.cxx on 64bit. - Anoter patch required by new linux/unistd.h. - Add BuildRequires: ghostscript * Thu Jun 15 2006 Stepan Kasal - 0.0.1.2006.06.14-1 - Patch for new linux/unistd.h. - Patch to avoid scanf("%a[..]"). * Wed Jun 14 2006 Stepan Kasal - 0.0.1.2006.06.14-0 - New upstream version. - Add BuildRequires: libglade2-devel > = 2.5.1 - Refresh other BuildRequires. - Replace the noxmltest.patch patch by two touchcommands. - Add BuildRequires: autoconf automake, BuildRequires: gcc-java > = 4.1.1 * Thu May 18 2006 Stepan Kasal - 0.0.1.2006.02.19.rh2-0.FC5.3 - Add gmime to BuildRequires. ---------------------------------------------------------------------This update can be downloaded from: c2fa20fae3431d4bef05676bfe4d5648cb3f829d SRPMS/frysk-0.0.1.2006.06.15.rh4-0.FC5.src.rpm c2fa20fae3431d4bef05676bfe4d5648cb3f829d noarch/frysk-0.0.1.2006.06.15.rh4-0.FC5.src.rpm dd89bbd33fa74b6b576ffe783fbdda020ab82eda x86_64/debug/frysk-debuginfo-0.0.1.2006.06.15.rh4-0.FC5.x86_64.rpm ab6ec93ff37a814483dd97ad6959af72ce01a3cc x86_64/frysk-0.0.1.2006.06.15.rh4-0.FC5.x86_64.rpm 7e503948501c43a572882ae2570d610de4d8795a i386/frysk-0.0.1.2006.06.15.rh4-0.FC5.i386.rpm 6aa36bc871604c3ab8b5c8063863c7efd1a28e22 i386/debug/frysk-debuginfo-0.0.1.2006.06.15.rh4-0.FC5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Update for Fedora Core 5 bringing the latest frysk tool to enhance execution analysis capabilities.. Frysk Tool, Fedora Core 5 Update, Execution Analysis. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 21, 2006 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here