Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
89

Fedora: 2007-605 Critical: libexif Integer Overflow Risk

An integer overflow flaw was found in the way libexif parses EXIF image tags. If a victim opens a carefully crafted EXIF image file it could cause the application linked against libexif to execute arbitrary code or crash. (CVE-2007-4168) Users of libexif should upgrade to these updated packages, which contain a backported patch and are not vulnerable to this issue. . ---------------------------------------------------------------------Fedora Update Notification FEDORA-2007-605 2007-06-25 ---------------------------------------------------------------------Product : Fedora Core 5 Name : libexif Version : 0.6.12 Release : 5 Summary : Library for extracting extra information from image files Description : Most digital cameras produce EXIF files, which are JPEG files with extra tags that contain information about the image. The EXIF library allows you to parse an EXIF file and read the data from those tags. ---------------------------------------------------------------------Update Information: The libexif package contains the EXIF library. Applications use this library to parse EXIF image files. An integer overflow flaw was found in the way libexif parses EXIF image tags. If a victim opens a carefully crafted EXIF image file it could cause the application linked against libexif to execute arbitrary code or crash. (CVE-2007-4168) Users of libexif should upgrade to these updated packages, which contain a backported patch and are not vulnerable to this issue. ---------------------------------------------------------------------* Wed Jun 13 2007 Matthias Clasen - 0.6.12-5 -- Add patch for CVE-2007-4168. Fix bug #243891 ---------------------------------------------------------------------This update can be downloaded from: bc9dd11ff96433a16e43645010014a9839f589db SRPMS/libexif-0.6.12-5.src.rpm bc9dd11ff96433a16e43645010014a9839f589db noarch/libexif-0.6.12-5.src.rpm 57d8ab6e2b78c12a6e66938eb4aacbe821c495c8 ppc/libexif-0.6.12-5.ppc.rpm c5a81715d1d60559cd6da7e35b6828d7b73bf2b1 ppc/debug/libexif-debuginfo-0.6.12-5.ppc.rpm 77683b433a4075bb0c311cffa953cf505e948f35 ppc/libexif-devel-0.6.12-5.ppc.rpm ed31d8bbecdb740de0362c71d25740c03effd546 x86_64/libexif-devel-0.6.12-5.x86_64.rpm bfeaea199b4ed467690bf26aee22ba94ffa189b4 x86_64/libexif-0.6.12-5.x86_64.rpm 8a3f6f9b3efae7ec1265c52f22156085bc127b00 x86_64/debug/libexif-debuginfo-0.6.12-5.x86_64.rpm 4ab5d8f54188d630865bcf89d4edb417d57b3727 i386/debug/libexif-debuginfo-0.6.12-5.i386.rpm 9fb88803c06f1598e542c693f5d9fcac0194b405 i386/libexif-0.6.12-5.i386.rpm aeb3f3584389097bb091d2ab6b046ac57ba0d93b i386/libexif-devel-0.6.12-5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ---------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . A recent patch for libexif on Fedora Core 5 resolves a critical buffer overflow issue related to image decoding processes.. libexif update, Fedora Core 5, security patch, EXIF safety issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2007 Critical Fedora
89

Fedora Core 3: FEDORA-2023-1234 Important: PHP Deserialization Issue

This update includes the latest release of PHP 4.3, including fixes for security issues in the unserializer (CVE CAN-2004-1019) and exif image parsing (CVE CAN-2004-1065).. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2004-568 2004-12-21 ---------------------------------------------------------------------Product : Fedora Core 3 Name : php Version : 4.3.10 Release : 3.2 Summary : The PHP HTML-embedded scripting language. (PHP: Hypertext Preprocessor) Description : PHP is an HTML-embedded scripting language. PHP attempts to make it easy for developers to write dynamically generated webpages. PHP also offers built-in database integration for several commercial and non-commercial database management systems, so writing a database-enabled webpage with PHP is fairly simple. The most common use of PHP coding is probably as a replacement for CGI scripts. The mod_php module enables the Apache Web server to understand and process the embedded PHP language in Web pages. ---------------------------------------------------------------------This update includes the latest release of PHP 4.3, including fixes for security issues in the unserializer (CVE CAN-2004-1019) and exif image parsing (CVE CAN-2004-1065). ---------------------------------------------------------------------* Tue Dec 21 2004 Joe Orton 4.3.10-3.2 - fix umask patch (#143286) * Wed Dec 15 2004 Joe Orton 4.3.10-3.1 - update to 4.3.10, including security fixes (#141135): * unserializer integer overflows, CAN-2004-1019 * exif image parsing overflow, CAN-2004-1065 ---------------------------------------------------------------------This update can be downloaded from: 445609a1342e91f32320fa5864bda37b SRPMS/php-4.3.10-3.2.src.rpm 657606317c0a9ed5bcf37f06dba42538 x86_64/php-4.3.10-3.2.x86_64.rpm 5ddda1be3f052f3cb409cf73363be2ae x86_64/php-devel-4.3.10-3.2.x86_64.rpm 9163bfe74081828227f757b133b076fc x86_64/php-pear-4.3.10-3.2.x86_64.rpm 80b7bf655541e14064c2bd6eaa311077 x86_64/php-imap-4.3.10-3.2.x86_64.rpm e7e92d9b5bd9ea4a245eba6a39ee2536 x86_64/php-ldap-4.3.10-3.2.x86_64.rpm eae6fbeb1108970cd8fd9a7a38d32a9a x86_64/php-mysql-4.3.10-3.2.x86_64.rpm 88dcfa1990eb7bdbdd92715dace2c03e x86_64/php-pgsql-4.3.10-3.2.x86_64.rpm 05966b8d09a58702ba43c9be149ecbaa x86_64/php-odbc-4.3.10-3.2.x86_64.rpm 34cdb5151b5da048f7470170bfb31978 x86_64/php-snmp-4.3.10-3.2.x86_64.rpm df3d6d00a6949d17495c8b99eac5f7c9 x86_64/php-domxml-4.3.10-3.2.x86_64.rpm 7422b0dc974e702a4c96eeecf11ec761 x86_64/php-xmlrpc-4.3.10-3.2.x86_64.rpm c1d70465ed28e238c4a09cbcb356b209 x86_64/php-mbstring-4.3.10-3.2.x86_64.rpm 16a82e15b0e5b3b16fc5eda47133b2f6 x86_64/php-ncurses-4.3.10-3.2.x86_64.rpm eea5e17b82709e33619fa4959db5c766 x86_64/php-gd-4.3.10-3.2.x86_64.rpm b969eb4dc267a438bb7eb742e6c20f2b x86_64/debug/php-debuginfo-4.3.10-3.2.x86_64.rpm f510eb1784120ca41c69d7adc189852b i386/php-4.3.10-3.2.i386.rpm d5f291074444c1dc04f36cedf7395a06 i386/php-devel-4.3.10-3.2.i386.rpm 652ca5be92e965c23150c9c58f875a5c i386/php-pear-4.3.10-3.2.i386.rpm 11399157471806b342090305ef29c474 i386/php-imap-4.3.10-3.2.i386.rpm 190d53059632b6b80b9f757742ae9a60 i386/php-ldap-4.3.10-3.2.i386.rpm 6fc5c6d4a9326e2bb7208573fead0510 i386/php-mysql-4.3.10-3.2.i386.rpm 5c88f752e470135c5c665ef8fb1284d9 i386/php-pgsql-4.3.10-3.2.i386.rpm 4b0eb8f79673794cf6a677cbc3ae255d i386/php-odbc-4.3.10-3.2.i386.rpm a4f62eb0dd02593f9529b141bde10676 i386/php-snmp-4.3.10-3.2.i386.rpm 3591ab4da5e4efe7cd1e1876d589b173 i386/php-domxml-4.3.10-3.2.i386.rpm 0ddcc0fe3c79a2545d8bb2235837044c i386/php-xmlrpc-4.3.10-3.2.i386.rpm 1eae4104b33ee7021403025865de92e0 i386/php-mbstring-4.3.10-3.2.i386.rpm c7fb403a6374fdb70adbadc62eb022cf i386/php-ncurses-4.3.10-3.2.i386.rpm 606c76b1b4e9b0fdd6de1a093ce3190b i386/php-gd-4.3.10-3.2.i386.rpm 864a01494e29026096135b3229363025 i386/debug/php-debuginfo-4.3.10-3.2.i386.rpm This update can also be installed with the UpdateAgent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . The latest patch for Fedora Core 3 incorporates security enhancements for PHP 4.3.10, addressing vulnerabilities related to exif data processing and the unserialization of objects.. Fedora PHP fixes, Exif Parsing Update, Unserialized Data Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Dec 22, 2004 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here