Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo: GLSA-202310-07 Moderate: Quake 4 Engine Memory Leak Vulnerability

The Quake 3 engine has a vulnerability that could be exploited to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Quake 3 engine based games: Buffer Overflow Date: May 10, 2006 Bugs: #132377 ID: 200605-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= The Quake 3 engine has a vulnerability that could be exploited to execute arbitrary code. Background ========= Quake 3 is a multiplayer first person shooter. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 games-fps/quake3-bin < 1.32c > = 1.32c 2 games-fps/rtcw < 1.41b > = 1.41b 3 games-fps/enemy-territory < 2.60b > = 2.60b ------------------------------------------------------------------- 3 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== landser discovered a vulnerability within the "remapShader" command. Due to a boundary handling error in "remapShader", there is a possibility of a buffer overflow. Impact ===== An attacker could set up a malicious game server and entice users to connect to it, potentially resulting in the execution of arbitrary code with the rights of the game user. Workaround ========= Do not connect to untrusted game servers. Resolution ========= All Quake 3 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-fps/quake3-bin-1.32c" All RTCW users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-fps/rtcw-1.41b" All Enemy Territory users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =games-fps/enemy-territory-2.60b" References ========= [ 1 ] CVE-2006-2236 https://www.cve.org/CVERecord?id=CVE-2006-2236 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200605-12 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo GLSA-202210-15 recommends that players of Quake 3 engine titles apply updates to mitigate potential buffer overflow vulnerabilities.. Quake Engine, Security Advisory, Game Exploit, Gentoo Linux, Buffer Overflow. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 May 10, 2006 Medium Gentoo
87

Debian 3.1: DSA-929-1 Critical: Petris Code Execution Risk

Steve Kemp from the Debian Security Audit project discovered a buffer overflow in petris, a clone of the Tetris game, which may be exploited to execute arbitary code with group games privileges.. - --------------------------------------------------------------------------Debian Security Advisory DSA 929-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp Jan 9, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Vulnerability : buffer overflow Problem-Type : local Debian-specific: no CVE ID : CVE-2005-3540 Steve Kemp from the Debian Security Audit project discovered a buffer overflow in petris, a clone of the Tetris game, which may be exploited to execute arbitary code with group games privileges. The old stable distribution (woody) does not contain the petris package. For the stable distribution (sarge) this problem has been fixed in version 1.0.1-4sarge0. For the unstable distribution the package will be updated shortly. We recommend that you upgrade your petris package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: petris_1.0.1-4sarge0.diff.gz Size/MD5 checksum: 4255 f043952580a76a670090f5e10456cac0 petris_1.0.1-4sarge0.dsc Size/MD5 checksum: 597 a8f7e7dc2da54370faf95307432ea057 petris_1.0.1.orig.tar.gz Size/MD5 checksum: 1140036ce4098c5305606ebbb66641eb9cea3 Alpha architecture: petris_1.0.1-4sarge0_alpha.deb Size/MD5 checksum: 17164 14925ee0cd40732d78d4d3267e304a6d AMD64 architecture: petris_1.0.1-4sarge0_amd64.deb Size/MD5 checksum: 16118 ae80ded8db7237ac7ffbd235e94583bc ARM architecture: petris_1.0.1-4sarge0_arm.deb Size/MD5 checksum: 14808 710db3e851a54a5c385a691de161ec35 HP Precision architecture: petris_1.0.1-4sarge0_hppa.deb Size/MD5 checksum: 16402 a7f392bda8179958a5cd95299865c1a5 Intel IA-32 architecture: petris_1.0.1-4sarge0_i386.deb Size/MD5 checksum: 15040 2efc32faf40e7402e818a088ab2ba6e2 Intel IA-64 architecture: petris_1.0.1-4sarge0_ia64.deb Size/MD5 checksum: 19610 bea0e1a48f9159ea1ef1c291af8f7974 Motorola 680x0 architecture: petris_1.0.1-4sarge0_m68k.deb Size/MD5 checksum: 14342 84fd7e89e8034c491df081bf562047f5 Big endian MIPS architecture: petris_1.0.1-4sarge0_mips.deb Size/MD5 checksum: 16488 4828a8700d380fe7fee578c4982cadc1 Little endian MIPS architecture: petris_1.0.1-4sarge0_mipsel.deb Size/MD5 checksum: 16434 3da9a116a510b2d095076015494fc72c PowerPC architecture: petris_1.0.1-4sarge0_powerpc.deb Size/MD5 checksum: 17154 246d78ced212deb20bafdffc25b34503 IBM S/390 architecture: petris_1.0.1-4sarge0_s390.deb Size/MD5 checksum: 15928 bafe7066921152a84e610268031b1c3b Sun Sparc architecture: petris_1.0.1-4sarge0_sparc.deb Size/MD5 checksum: 14866 e7a0d84f92bbf1e57d4aef61e257fc48 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . An integer overflow vulnerability inqubix can be leveraged for unauthorized command execution; patch advised for Ubuntu users.. debian security, buffer overflow, petris game, code execution risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 27, 2006 Critical Debian
87

Ubuntu: DSA 167-2 High: Strategy Suite Heap Overflow Vulnerability

Two buffer overflows have been discovered in purity, a game for nerds and hackers, which is installed setgid games on a Debian system. This problem could be exploited to gain unauthorized access to the group games. A malicious user could alter the highscore of several games. . - -------------------------------------------------------------------------- Debian Security Advisory DSA 166-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze September 13th, 2002 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : purity Vulnerability : buffer overflows Problem-Type : local Debian-specific: no Two buffer overflows have been discovered in purity, a game for nerds and hackers, which is installed setgid games on a Debian system. This problem could be exploited to gain unauthorized access to the group games. A malicious user could alter the highscore of several games. This problem has been fixed in version 1-14.2 for the current stable distribution (woody), in version 1-9.1 for the old stable distribution (potato) and in version 1-16 for the unstable distribution (sid). We recommend that you upgrade your purity packages. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - --------------------------------- Source archives: Size/MD5 checksum: 513 a7a4276a6c694131a5b3bd58703c8c05 Size/MD5 checksum: 5147 db47d2d1f51b5f8c97bcb93974b7b5cf Size/MD5 checksum: 22249 19cbbd136a94aae3d175d8ccc963368d Alpha architecture: Size/MD5 checksum: 29176 f69989e76361e30813eb233aa500b9c6 ARM architecture: Size/MD5 checksum: 27762 169dce544dcab575cc126800eeabb6ce Intel IA-32 architecture: Size/MD5 checksum: 27404 6eb60f91f4cd3730bef018115268c568 Motorola 680x0 architecture: Size/MD5 checksum: 26934 d1337244388c4b5a183b379e34b37fd1 PowerPC architecture: Size/MD5 checksum: 27760 140ce3d691acc98c27dd6851972db0e9 Sun Sparc architecture: Size/MD5 checksum: 29952 cb2b48e0465b48b89b220feb30818113 Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 550 8e669427422857640b0531e3566706f9 Size/MD5 checksum: 6171 6901ba40ea0938bab43a893e4f75da8a Size/MD5 checksum: 22249 19cbbd136a94aae3d175d8ccc963368d Alpha architecture: Size/MD5 checksum: 28890 ecb67c79c8047cc631cf63d6fcd93996 ARM architecture: Size/MD5 checksum: 27434 6bb8ed0579e96fcff971086d750937ce Intel IA-32 architecture: Size/MD5 checksum: 26906 7ec62b9371253879b93fe6db0ef75945 Intel IA-64 architecture: Size/MD5 checksum: 30694 7c26d3db982acf14a2e8133cf204e164 HP Precision architecture: Size/MD5 checksum: 29234 ceb6569248e96d1fd415de15f8f26370 Motorola 680x0 architecture: Size/MD5 checksum: 26560 4385599f2f16238c4b2628c9a8fc54cc Big endian MIPS architecture: Size/MD5 checksum: 27798 e6b360203cd31c13f19d5bc257684f64 Little endian MIPS architecture: Size/MD5 checksum: 27756 12bb21c88be3011bfd50045a73361255 PowerPC architecture: Size/MD5 checksum: 27306 c782697984b5e8ae83ed16c594d80437 IBM S/390 architecture: Size/MD5 checksum: 27624 c370933a2db896857c5fa3bb86a2a2db Sun Sparc architecture: Size/MD5 checksum: 29980 e48dcb304202e2e29634bd51dbd307a3 Thesefiles will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Unauthorized access via buffer overflow in transparency poses a threat to leaderboard standings; urgent fix needed.. Purity Game Fix, Debian Security Advisory, Buffer Overflow Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 13, 2002 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here