Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo: GLSA-200503-21 Alert: Grip CDDB Overflow Vulnerability Risk

Grip contains a buffer overflow that can be triggered by a large CDDB response, potentially allowing the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200503-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Grip: CDDB response overflow Date: March 17, 2005 Bugs: #84704 ID: 200503-21 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Grip contains a buffer overflow that can be triggered by a large CDDB response, potentially allowing the execution of arbitrary code. Background ========= Grip is a GTK+ based audio CD player/ripper. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-sound/grip < 3.3.0 > = 3.3.0 Description ========== Joseph VanAndel has discovered a buffer overflow in Grip when processing large CDDB results. Impact ===== A malicious CDDB server could cause Grip to crash by returning more then 16 matches, potentially allowing the execution of arbitrary code with the privileges of the user running the application. Workaround ========= Disable automatic CDDB queries, but we highly encourage users to upgrade to 3.3.0. Resolution ========= All Grip users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-sound/grip-3.3.0" References ========= [ 1 ] CAN-2005-0706 https://www.cve.org/CVERecord?id=CVE-CAN-2005-0706 [ 2 ] Original Bug Report https://sourceforge.net/projects/grip/;atid=103714&func=detail&aid=834724 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200503-21 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Gentoo Linux Security Advisory GLSA 202303-18 discusses a vulnerability in Pidgin that may enable unauthorized access to sensitive information.. Grip,Buffers,Security Advisory,Gentoo,Code Execution. . LinuxSecurity.com Team

Calendar 2 Mar 17, 2005 Gentoo
89

Fedora Core 2: FEDORA-2005-202 Moderate: Grip Buffer Overflow

This fixes a buffer overflow when the CDDB server returns more than 16 matches.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-202 2005-03-09 ---------------------------------------------------------------------Product : Fedora Core 2 Name : grip Version : 3.2.0 Release : 3.fc2 Summary : A front-end for CD rippers and Ogg Vorbis encoders. Description : Grip is a GTK+ based front-end for CD rippers (such as cdparanoia and cdda2wav) and Ogg Vorbis encoders. Grip allows you to rip entire tracks or just a section of a track. Grip supports the CDDB protocol for accessing track information on disc database servers. ---------------------------------------------------------------------Update Information: This fixes a buffer overflow when the CDDB server returns more than 16 matches. ---------------------------------------------------------------------* Wed Mar 9 2005 Bill Nottingham 3.2.0-3.fc2 - add patch to fix overflow when there are too many CDDB matches * Fri Oct 8 2004 Bill Nottingham 3.2.0-3 - add a passel of buildreqs (#135045) * Wed Jul 28 2004 Adrian Havill 3.2.0-2 - rebuilt - add vte-devel to BuildRequires * Sun Jun 20 2004 Karsten Hopp 3.2.0-1 - update to latest stable version - remove obsolete locking and cdparanoia patches * Tue Jun 15 2004 Elliot Lee - rebuilt ---------------------------------------------------------------------This update can be downloaded from: c5c34b3b3b297be7ece95e59dc7c31ce SRPMS/grip-3.2.0-3.fc2.src.rpm 668467205016befb3793a75557a92878 x86_64/grip-3.2.0-3.fc2.x86_64.rpm 79927efa8e6eb9c877f5c933951e1ca2 x86_64/debug/grip-debuginfo-3.2.0-3.fc2.x86_64.rpm 57f3ffa668a0283b27e43255d20ae6d4 i386/grip-3.2.0-3.fc2.i386.rpm 3dbd12ec9d02d4f4b5a7d5bfe68a89bc i386/debug/grip-debuginfo-3.2.0-3.fc2.i386.rpm This update can also be installed with the Update Agent; you can launch theUpdate Agent with the 'up2date' command. -----------------------------------------------------------------------fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora Core 2 has issued an update to fix a critical buffer overflow vulnerability in grip, improving security and reliability for users managing audio CD metadata.. Fedora Core, Grip Update, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar 2 Mar 09, 2005 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here