Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Ubuntu 18.04: DSA 1156-4 Critical: vulnint Memory Leak Vulnerability

Erik Sjölund discovered a buffer overflow in xatitv, one of the programs in the gatos package, that is used to display video with certain ATI video cards. xatitv is installed setuid root in order to gain direct access to the video hardware.. - --------------------------------------------------------------------------Debian Security Advisory DSA 640-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 17th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : gatos Vulnerability : buffer overflow Problem-Type : local Debian-specific: no CVE ID : CAN-2005-0016 Erik Sjölund discovered a buffer overflow in xatitv, one of the programs in the gatos package, that is used to display video with certain ATI video cards. xatitv is installed setuid root in order to gain direct access to the video hardware. For the stable distribution (woody) this problem has been fixed in version 0.0.5-6woody3. For the unstable distribution (sid) this problem has been fixed in version 0.0.5-15. We recommend that you upgrade your gatos package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 629 0005020205c97ebd6f2efdf146846c15 Size/MD5 checksum: 40976 34933c1e1da0fbb172ab919e23b68e02 Size/MD5 checksum: 483916 9c16631afc933bde6f5d5e1421efddb7 Intel IA-32 architecture: Size/MD5 checksum: 148110 2d2e9c2ba2d429175cab205c6ce6860d Size/MD5 checksum: 109748 4c1d0a17839934a2c818e314c5d7d3b2 Size/MD5 checksum: 75460 bc27c6c2ec12dab3b6b3e164ee8f05f2 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your miau package to rectify the memory leak in xacast, safeguarding your Ubuntu environment.. Debian Security, Buffer Overflow, Gatos Package, Xatitv Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 17, 2005 Critical Debian
87

Debian: DSA-509-1 Critical: Gatos Privilege Escalation Risk

If initialization fails due to a missing configuration file, root privileges are not dropped, and xatitv executes the system(3) function without sanitizing user-supplied environment variables.. Debian Security Advisory DSA 509-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman May 29th, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : gatos Vulnerability : privilege escalation Problem-Type : local Debian-specific: no CVE Ids : CAN-2004-0395 Steve Kemp discovered a vulnerability in xatitv, one of the programs in the gatos package, which is used to display video with certain ATI video cards. xatitv is installed setuid root in order to gain direct access to the video hardware. It normally drops root privileges after successfully initializing itself. However, if initialization fails due to a missing configuration file, root privileges are not dropped, and xatitv executes the system(3) function to launch its configuration program without sanitizing user-supplied environment variables. By exploiting this vulnerability, a local user could gain root privileges if the configuration file does not exist. However, a default configuration file is supplied with the package, and so this vulnerability is not exploitable unless this file is removed by the administrator. For the current stable distribution (woody) this problem has been fixed in version 0.0.5-6woody1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you update your gatos package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install correctedpackages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 629 73d7637956bdcc827fb3c9be500902a0 Size/MD5 checksum: 40666 2ff18e9bbf71ea71ce9b2a43486c8cc6 Size/MD5 checksum: 483916 9c16631afc933bde6f5d5e1421efddb7 Intel IA-32 architecture: Size/MD5 checksum: 176268 d64a2e508adbd6423c6a0bbf2426c11b Size/MD5 checksum: 109416 81ada7ba7f2d0d44d2cf107154a2cd93 Size/MD5 checksum: 75040 4c2f9aea5082612027d520bab82dbff5 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical Debian security advisory DSA-509-1 for gatos package addresses privilege escalation risk.. Gatos Privilege Escalation, Debian Security Advisory, Local Escalation Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 08, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here