Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
197

Debian 9: DLA-2427-1 Critical: spice Remote Display Buffer Overflow

Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2427-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta November 01, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : spice Version : 0.12.8-2.1+deb9u4 CVE ID : CVE-2020-14355 Debian Bug : 971750 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when processed by the QUIC image compression algorithm, result in a process crash or potential code execution. For Debian 9 stretch, this problem has been fixed in version 0.12.8-2.1+deb9u4. We recommend that you upgrade your spice packages. For the detailed security status of spice please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/spice Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance your spice software components to address various memory overflow vulnerabilities impacting the SPICE remote visualization framework in Debian.. spice remote display, buffer overflow, Debian security advisory, image decoding, package upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 01, 2020 Critical Debian LTS
203

Mageia 6 MGASA-2019-0083 Critical: KAuth DBus Image Handling Issue

KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References: . MGASA-2019-0083 - Updated kauth packages fix security vulnerability Publication date: 14 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0083.html Type: security Affected Mageia releases: 6 KAuth allows to pass parameters with arbitrary types to helpers running as root over DBus. Certain types can cause crashes and trigger decoding arbitrary images with dynamically loaded plugins. References: - https://bugs.mageia.org/show_bug.cgi?id=24334 - https://kde.org/info/security/advisory-20190209-1.txt SRPMS: - 6/core/kauth-5.42.0-1.1.mga6 . MGASA-2019-0083 - Updated kauth packages fix security vulnerability Publication date: 14 Feb 2019 UR. kauth, allows, parameters, arbitrary, types, helpers, running, certain. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 14, 2019 Critical Mageia
89

Fedora 27: dcraw 9.28.0 Moderate: NULL Pointer Dereference Fix

New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-ae1ced8fb6 2018-07-25 18:44:08.975117 --------------------------------------------------------------------------------Name : dcraw Product : Fedora 27 Version : 9.28.0 Release : 1.fc27 URL : Summary : Tool for decoding raw image data from digital cameras Description : This package contains dcraw, a command line tool to decode raw image data downloaded from digital cameras. --------------------------------------------------------------------------------Update Information: New version of dcraw is available 9.28.0 Security fix for CVE-2018-5801 --------------------------------------------------------------------------------ChangeLog: * Thu Jun 14 2018 Josef Ridky - 9.28.0-1 - New upstream release 9.28.0 (#1585348) - Fix CVE-2018-5801 (#1557160) * Fri Feb 23 2018 Florian Weimer - 9.27.0-8 - Use LDFLAGS from redhat-rpm-config * Tue Feb 20 2018 Nils Philippsen - 9.27.0-7 - require gcc for building * Wed Feb 7 2018 Fedora Release Engineering - 9.27.0-6 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1553334 - CVE-2018-5801 LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp https://bugzilla.redhat.com/show_bug.cgi?id=1553334 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-ae1ced8fb6' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/6FIKKJCNEFO4CWDTBCLSVJ3IKOLRD2CE/ . Version 9.28.0 of dcraw brings an update that addresses CVE-2018-5801, bolstering the security for Fedora 27.. dcraw security fix,Fedora update,CVE-2018-5801,security advisory,raw image tool. . LinuxSecurity.com Team

Calendar 2 Jul 25, 2018 Fedora
89

Fedora 23: Critical Advisory for libwmf Heap Overflow CVE-2015-4696

libwmf-0.2.8.4-46.fc23 - Related: rhbz#1227244 CVE-2015-4696 fix patch context. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14847 2015-09-04 19:45:14.259035 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 23 Version : 0.2.8.4 Release : 46.fc23 URL : https://wvware.sourceforge.net/libwmf.html Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: libwmf-0.2.8.4-46.fc23 - Related: rhbz#1227244 CVE-2015-4696 fix patch context -------------------------------------------------------------------------------- References: [ 1 ] Bug #1227244 - CVE-2015-0848 libwmf: heap overflow when decoding BMP images [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1227244 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Important security patch for libwmf in Fedora, tackling the CVE-2015-4696 flaw related to image processing functionality.. Fedora Update, libwmf Security, Image Processing, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 04, 2015 Critical Fedora
89

Fedora 21 2015-9674 Critical Update: Libwmf Heap Overflow Patch

CVE-2015-0848 heap overflow when decoding BMP images CVE-2015-0848 heap overflow when decoding BMP images. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-9674 2015-06-09 09:02:57 -------------------------------------------------------------------------------- Name : libwmf Product : Fedora 21 Version : 0.2.8.4 Release : 43.fc21 URL : Summary : Windows MetaFile Library Description : A library for reading and converting Windows MetaFile vector graphics (WMF). -------------------------------------------------------------------------------- Update Information: CVE-2015-0848 heap overflow when decoding BMP images CVE-2015-0848 heap overflow when decoding BMP images -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 8 2015 Caolán McNamara - 0.2.8.4-43 - Resolves: rhbz#1227244 CVE-2015-0848 heap overflow when decoding BMP images * Tue Jun 2 2015 Caolán McNamara - 0.2.8.4-42 - Resolves: rhbz#1227244 CVE-2015-0848 heap overflow when decoding BMP images * Sat Feb 21 2015 Till Maas - 0.2.8.4-41 - Rebuilt for Fedora 23 Change https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code -------------------------------------------------------------------------------- References: [ 1 ] Bug #1227243 - CVE-2015-0848, CVE-2015-4588 libwmf: heap overflow when decoding BMP images https://bugzilla.redhat.com/show_bug.cgi?id=1227243 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libwmf' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Investigate the security notice related to libwmf on Fedora 21, as it pertains to a significant heap overflow vulnerability found in BMP image processing.. Heap Overflow, Fedora 21, libwmf Update, Security Advisory, Image Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 24, 2015 Critical Fedora
89

Fedora Core 4: 2006-878 Critical: libtiff Image Flaws Leading To Crashes

The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) files. Tavis Ormandy of Google discovered a number of flaws in libtiff during a security audit. An attacker could create a carefully crafted TIFF file in such a way that it was possible to cause an application linked with libtiff to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465) All users are advised to upgrade to these updated packages, which contain backported fixes for these issues.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-878 2006-08-02 ---------------------------------------------------------------------Product : Fedora Core 4 Name : libtiff Version : 3.7.1 Release : 6.fc4.3 Summary : A library of functions for manipulating TIFF format image files. Description : The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) image format files. TIFF is a widely used file format for bitmapped images. TIFF files usually end in the .tif extension and they are often quite large. The libtiff package should be installed if you need to manipulate TIFF format image files. ---------------------------------------------------------------------Update Information: The libtiff package contains a library of functions for manipulating TIFF (Tagged Image File Format) files. Tavis Ormandy of Google discovered a number of flaws in libtiff during a security audit. An attacker could create a carefully crafted TIFF file in such a way that it was possible to cause an application linked with libtiff to crash or possibly execute arbitrary code. (CVE-2006-3459, CVE-2006-3460, CVE-2006-3461, CVE-2006-3462, CVE-2006-3463, CVE-2006-3464, CVE-2006-3465) All users are advised to upgrade to these updated packages, which contain backported fixes for these issues. ---------------------------------------------------------------------* Tue Aug 1 2006 Matthias Clasen - Fix several vulnerabilities (CVE-2006-3460 CVE-2006-3461 CVE-2006-3462 CVE-2006-3463 CVE-2006-3464 CVE-2006-3465) ---------------------------------------------------------------------This update can be downloaded from: e25a0090188f4a25e04b23d9dabf8618dcd5560a SRPMS/libtiff-3.7.1-6.fc4.3.src.rpm e25a0090188f4a25e04b23d9dabf8618dcd5560a noarch/libtiff-3.7.1-6.fc4.3.src.rpm 0d920d3854947dd1b5ea6035f6462763e252d6c4 ppc/libtiff-3.7.1-6.fc4.3.ppc.rpm f39962656b7efcc8e657427ed2ef51df590aa216 ppc/libtiff-devel-3.7.1-6.fc4.3.ppc.rpm 5f7f56f8e3c0f504a2dc5960cb5d884e54f9c349 ppc/debug/libtiff-debuginfo-3.7.1-6.fc4.3.ppc.rpm 6e45b6be8f666e508e3de4b9c30aab09b57378a2 x86_64/libtiff-3.7.1-6.fc4.3.x86_64.rpm cee15750ace41bfa7e5a3b22d3883010a837febd x86_64/libtiff-devel-3.7.1-6.fc4.3.x86_64.rpm 9d9f9b1ceb5db2ac47667644eb5bd43944d69ea7 x86_64/debug/libtiff-debuginfo-3.7.1-6.fc4.3.x86_64.rpm 12dcfb0c2a959d9da7f581b4c1b93aca0861567d i386/libtiff-3.7.1-6.fc4.3.i386.rpm ad5847f0d6196a9782fc72e80a1b14fabfbffa93 i386/libtiff-devel-3.7.1-6.fc4.3.i386.rpm 6d158f79ae88e9e9fe44e776064bd108532b07f9 i386/debug/libtiff-debuginfo-3.7.1-6.fc4.3.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential patch for Fedora Core 4's libjpeg fixes various vulnerabilities causing crashes and potential arbitrary code execution.. libtiff update,Fedora security,TIFF flaws,image format library. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 02, 2006 Critical Fedora
91

Gentoo GLSA-200501-19 Normal: imlib2 Buffer Overflow Risk

Multiple overflows have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: imlib2: Buffer overflows in image decoding Date: January 11, 2005 Bugs: #77002 ID: 200501-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple overflows have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code. Background ========= imlib2 is an advanced replacement for image manipulation libraries such as libXpm. It is utilized by numerous programs, including gkrellm and several window managers, to display images. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/imlib2 < 1.2.0 > = 1.2.0 Description ========== Pavel Kankovsky discovered that several buffer overflows found in the libXpm library (see GLSA 200409-34) also apply to imlib (see GLSA 200412-03) and imlib2. He also fixed a number of other potential security vulnerabilities. Impact ===== A remote attacker could entice a user to view a carefully-crafted image file, which would potentially lead to the execution of arbitrary code with the rights of the user viewing the image. This affects any program that utilizes of the imlib2 library. Workaround ========= There is no known workaround at this time. Resolution ========= All imlib2 users should upgrade to thelatest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/imlib2-1.2.0" References ========= [ 1 ] CAN-2004-1026 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1026 [ 2 ] GLSA 200412-03 https://security.gentoo.org/glsa/200412-03 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-19 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Numerous buffer overflow vulnerabilities identified in imlib2 may permit unauthorized code execution; Gentoo users are advised to update.. imlib2 security advisory, buffer overflow, image decoding, gentoo updates. . LinuxSecurity.com Team

Calendar 2 Jan 11, 2005 Gentoo
91

Gentoo: GLSA-200501-07 Critical: JPEG Buffer Overflow Remote Access

An integer overflow has been found in the TIFF library image decoding routines and the tiffdump utility, potentially allowing arbitrary code execution. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200501-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: tiff: New overflows in image decoding Date: January 05, 2005 Bugs: #75213 ID: 200501-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An integer overflow has been found in the TIFF library image decoding routines and the tiffdump utility, potentially allowing arbitrary code execution. Background ========= The TIFF library contains encoding and decoding routines for the Tag Image File Format. It is called by numerous programs, including GNOME and KDE applications, to interpret TIFF images. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/tiff < 3.7.1-r1 > = 3.7.1-r1 Description ========== infamous41md found a potential integer overflow in the directory entry count routines of the TIFF library (CAN-2004-1308). Dmitry V. Levin found another similar issue in the tiffdump utility (CAN-2004-1183). Impact ===== A remote attacker could entice a user to view a carefully crafted TIFF image file, which would potentially lead to execution of arbitrary code with the rights of the user viewing the image. This affects any program that makes use of the TIFF library, including many web browsers or mail readers. Workaround ========= There is no known workaround at thistime. Resolution ========= All TIFF library users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/tiff-3.7.1-r1" References ========= [ 1 ] CAN-2004-1183 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1183 [ 2 ] CAN-2004-1308 https://www.cve.org/CVERecord?id=CVE-CAN-2004-1308 [ 3 ] iDEFENSE Advisory ;type=vulnerabilities Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200501-06 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . The Gentoo advisory warns of vulnerabilities in the TIFF library, pointing to potential integer overflow issues that may allow arbitrary code execution on affected systems. Gentoo Security,Tiff Library,Code Execution,Integer Overflow. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 05, 2005 Important Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here