Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo GLSA-200611-20 Normal: Risk of gv Stack Overflow Vulnerability

GNU gv improperly handles user-supplied data possibly allowing for the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200611-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNU gv: Stack overflow Date: November 24, 2006 Bugs: #154573 ID: 200611-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= GNU gv improperly handles user-supplied data possibly allowing for the execution of arbitrary code. Background ========= GNU gv is a viewer for PostScript and PDF documents. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-text/gv < 3.6.2-r1 > = 3.6.2-r1 Description ========== GNU gv does not properly boundary check user-supplied data before copying it into process buffers. Impact ===== An attacker could entice a user to open a specially crafted document with GNU gv and execute arbitrary code with the rights of the user on the system. Workaround ========= There is no known workaround at this time. Resolution ========= All gv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-text/gv-3.6.2-r1" References ========= [ 1 ] CVE-2006-5864 https://www.cve.org/CVERecord?id=CVE-2006-5864 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200611-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuringthe confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The GNU gv package within Gentoo has encountered a critical stack overflow vulnerability; it's essential to upgrade the software to safeguard against potential execution of arbitrary code.. Gentoo Security, GNU gv, Stack Overflow, Software Update. . LinuxSecurity.com Team

Calendar 2 Nov 24, 2006 Gentoo
87

Debian DSA 176-1 Critical: gv Remote Code Execution Risk

This problem is triggered by scanning the PostScriptfile and can be exploited by an attacker sending a malformedPostScript or PDF file. The attacker is able to cause arbitrary codeto be run with the privileges of the victim.. -------------------------------------------------------------------------- Debian Security Advisory DSA 176-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze October 16th, 2002 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : gv Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE Id : CAN-2002-0838 BugTraq ID : 5808 Zen-parse discovered a buffer overflow in gv, a PostScript and PDF viewer for X11. This problem is triggered by scanning the PostScript file and can be exploited by an attacker sending a malformed PostScript or PDF file. The attacker is able to cause arbitrary code to be run with the privileges of the victim. This problem has been fixed in version 3.5.8-26.1 for the current stable distribution (woody), in version 3.5.8-17.1 for the old stable distribution (potato) and version 3.5.8-27 for the unstable distribution (sid). We recommend that you upgrade your gv package. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato --------------------------------- Source archives: Size/MD5 checksum: 555 3aa3cb663f578cbf02c09f370951a814 Size/MD5 checksum: 29382 2e9e7149b69bf36a80632c8b695b6495 Size/MD5 checksum: 3696098f2f0bd97395d6cea52926ddee736da8 Alpha architecture: Size/MD5 checksum: 278646 b12dd5fef60ff840b3921a511eb28c74 ARM architecture: Size/MD5 checksum: 238918 52892bea304128845836b4c9976d39a3 Intel IA-32 architecture: Size/MD5 checksum: 226416 4f44d7df45cec7b132c1c7c9a6ba84ea Motorola 680x0 architecture: Size/MD5 checksum: 217712 2decb437f1a28beac92edb63f3d31444 PowerPC architecture: Size/MD5 checksum: 244382 cb3bd27b214e391ada83ce0593e16715 Sun Sparc architecture: Size/MD5 checksum: 237878 ba1bdf19f68f62d36c8f58c015867287 Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 559 e7a2b5dfb91d7217d1b171b24682ea41 Size/MD5 checksum: 18453 f9910a58912e1a6fbaef33ff4fe27b94 Size/MD5 checksum: 369609 8f2f0bd97395d6cea52926ddee736da8 Alpha architecture: Size/MD5 checksum: 273262 6cb8adebf56cc25ef43d1358636dc9ca ARM architecture: Size/MD5 checksum: 243382 2707a8a87e133a45cc2a98dd223e7c8f Intel IA-32 architecture: Size/MD5 checksum: 226106 304f32b84e6497612222a26c9dc5c1fd Intel IA-64 architecture: Size/MD5 checksum: 313888 522c58c4d2fecb99424533c4980d1409 HP Precision architecture: Size/MD5 checksum: 252054 aa50a00ebb6d5c304ec94bbf1e65a2c9 Motorola 680x0 architecture: Size/MD5 checksum: 216922 d11c3c10e70fb1593ce15c2b6c3863be Big endian MIPS architecture: Size/MD5 checksum: 252064 6b944b4c04f4488ea380063bdf3324ad Little endian MIPS architecture: Size/MD5 checksum: 250914 87afee172cf73ed91ad0449fadd9bb4b PowerPC architecture: Size/MD5 checksum: 243450 9c77e9860e1044bc4c7b9a7b054e8a4d IBM S/390 architecture: Size/MD5 checksum: 232784 96242f88c593319e0d3fddef928c47d2 Sun Sparc architecture: Size/MD5 checksum: 237798 e5091427da6e76dbb9bb34cf03e94647 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu's recent advisory USN 1234-1 reveals a severe gnome-shell flaw that could enable unauthorized access and manipulation of system resources due to flawed input validation. Debian gv Advisory, Buffer Overflow Threat, PostScript Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 16, 2002 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here