Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
202

openSUSE Leap 42.3 Security Update 2018:1422-1 Moderate: ICU DoS Fix

An update that fixes 8 vulnerabilities is now available.. openSUSE Security Update: Security update for icu ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:1422-1 Rating: moderate References: #1034674 #1034678 #1067203 #1072193 #1077999 #1087932 #929629 #990636 Cross-References: CVE-2014-8146 CVE-2014-8147 CVE-2016-6293 CVE-2017-14952 CVE-2017-15422 CVE-2017-17484 CVE-2017-7867 CVE-2017-7868 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that fixes 8 vulnerabilities is now available. Description: icu was updated to fix two security issues. These security issues were fixed: - CVE-2014-8147: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) used an integer data type that is inconsistent with a header file, which allowed remote attackers to cause a denial of service (incorrect malloc followed by invalid free) or possibly execute arbitrary code via crafted text (bsc#929629). - CVE-2014-8146: The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in International Components for Unicode (ICU) did not properly track directionally isolated pieces of text, which allowed remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via crafted text (bsc#929629). - CVE-2016-6293: The uloc_acceptLanguageFromHTTP function in common/uloc.cpp in International Components for Unicode (ICU) for C/C++ did not ensure that there is a '\0' character at the end of a certain temporary array, which allowed remote attackers to cause a denial of service (out-of-bounds read) orpossibly have unspecified other impact via a call with a long httpAcceptLanguage argument (bsc#990636). - CVE-2017-7868: International Components for Unicode (ICU) for C/C++ 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_moveIndex32* function (bsc#1034674) - CVE-2017-7867: International Components for Unicode (ICU) for C/C++ 2017-02-13 has an out-of-bounds write caused by a heap-based buffer overflow related to the utf8TextAccess function in common/utext.cpp and the utext_setNativeIndex* function (bsc#1034678) - CVE-2017-14952: Double free in i18n/zonemeta.cpp in International Components for Unicode (ICU) for C/C++ allowed remote attackers to execute arbitrary code via a crafted string, aka a "redundant UVector entry clean up function call" issue (bnc#1067203) - CVE-2017-17484: The ucnv_UTF8FromUTF8 function in ucnv_u8.cpp in International Components for Unicode (ICU) for C/C++ mishandled ucnv_convertEx calls for UTF-8 to UTF-8 conversion, which allowed remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted string, as demonstrated by ZNC (bnc#1072193) - CVE-2017-15422: An integer overflow in icu during persian calendar date processing could lead to incorrect years shown (bnc#1077999) This update was imported from the SUSE:SLE-12:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-517=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): icu-52.1-18.1 icu-data-52.1-18.1 icu-debuginfo-52.1-18.1 icu-debugsource-52.1-18.1 libicu-devel-52.1-18.1 libicu-doc-52.1-18.1 libicu52_1-52.1-18.1 libicu52_1-data-52.1-18.1 libicu52_1-debuginfo-52.1-18.1 - openSUSE Leap 42.3 (x86_64): libicu-devel-32bit-52.1-18.1 libicu52_1-32bit-52.1-18.1 libicu52_1-debuginfo-32bit-52.1-18.1 References: https://www.suse.com/security/cve/CVE-2014-8146.html https://www.suse.com/security/cve/CVE-2014-8147.html https://www.suse.com/security/cve/CVE-2016-6293.html https://www.suse.com/security/cve/CVE-2017-14952.html https://www.suse.com/security/cve/CVE-2017-15422.html https://www.suse.com/security/cve/CVE-2017-17484.html https://www.suse.com/security/cve/CVE-2017-7867.html https://www.suse.com/security/cve/CVE-2017-7868.html https://bugzilla.suse.com/1034674 https://bugzilla.suse.com/1034678 https://bugzilla.suse.com/1067203 https://bugzilla.suse.com/1072193 https://bugzilla.suse.com/1077999 https://bugzilla.suse.com/1087932 https://bugzilla.suse.com/929629 https://bugzilla.suse.com/990636 -- . Latest patch addresses several vulnerabilities in openSUSE’s ICU module. Urgent measures suggested for improved protection.. openSUSE Update, ICU Security Issues, Software Patch, Denial of Service Fixes. . LinuxSecurity.com Team

Calendar%202 May 25, 2018 OpenSUSE
89

Fedora 27 ICU Security Advisory: Resolution for Double Free Vulnerability

Resolves: rhbz#1510932 CVE-2017-14952. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-856e8f657d 2017-11-15 15:47:48.467289 --------------------------------------------------------------------------------Name : icu Product : Fedora 27 Version : 57.1 Release : 9.fc27 URL : https://icu-project.org/ Summary : International Components for Unicode Description : Tools and utilities for developing with icu. --------------------------------------------------------------------------------Update Information: Resolves: rhbz#1510932 CVE-2017-14952 --------------------------------------------------------------------------------References: [ 1 ] Bug #1510930 - CVE-2017-14952 icu: Double free in i18n/zonemeta.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1510930 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade icu' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical patch for Fedora addressing the icu double free vulnerability, bolstering system integrity and reliability.. Fedora Update, icu Security Fix, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 15, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here