Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian 7: DLA-1370-1 Critical: Quassel Remote Code Exec

It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. . Package : quassel Version : 0.8.0-1+deb7u4 CVE ID : CVE-2018-1000178 It was found that the Quassel IRC client was vulnerable to a remote code execution vulnerability due to insufficient checks in the deserializer code. For Debian 7 "Wheezy", these problems have been fixed in version 0.8.0-1+deb7u4. We recommend that you upgrade your quassel packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Quassel IRC client has issued a critical security update to address remote code execution vulnerabilities impacting Debian 7 Wheezy. Users should update immediately. Quassel IRC, Remote Code Execution, Debian 7 Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 04, 2018 Critical Debian LTS
87

Debian: DSA-4033-1 Important Security Update For Konversation IRC Client

Joseph Bisch discovered that Konversation, an user friendly Internet Relay Chat (IRC) client for KDE, could crash when parsing certain IRC color formatting codes. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4033-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 13, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : konversation CVE ID : CVE-2017-15923 Debian Bug : 881586 Joseph Bisch discovered that Konversation, an user friendly Internet Relay Chat (IRC) client for KDE, could crash when parsing certain IRC color formatting codes. For the oldstable distribution (jessie), this problem has been fixed in version 1.5-2+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 1.6.2-2+deb9u1. We recommend that you upgrade your konversation packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance Konversation post DSA-4033-1: identified crash problem related to IRC formatting. Refer to Debian Security for specifics.. Debian Security Advisory, Konversation Client, IRC Client Crash. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 13, 2017 Important Debian
87

Debian: DSA-4016-1 Critical: Irssi Denial of Service Issues

Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4016-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso November 03, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : irssi CVE ID : CVE-2017-10965 CVE-2017-10966 CVE-2017-15227 CVE-2017-15228 CVE-2017-15721 CVE-2017-15722 CVE-2017-15723 Debian Bug : 867598 879521 Multiple vulnerabilities have been discovered in Irssi, a terminal based IRC client. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-10965 Brian 'geeknik' Carpenter of Geeknik Labs discovered that Irssi does not properly handle receiving messages with invalid time stamps. A malicious IRC server can take advantage of this flaw to cause Irssi to crash, resulting in a denial of service. CVE-2017-10966 Brian 'geeknik' Carpenter of Geeknik Labs discovered that Irssi is susceptible to a use-after-free flaw triggered while updating the internal nick list. A malicious IRC server can take advantage of this flaw to cause Irssi to crash, resulting in a denial of service. CVE-2017-15227 Joseph Bisch discovered that while waiting for the channel synchronisation, Irssi may incorrectly fail to remove destroyed channels from the query list, resulting in use after free conditions when updating the state later on. A malicious IRC server can take advantage of this flaw to cause Irssi to crash, resulting in a denial of service. CVE-2017-15228 Hanno Boeck reported that Irssi does not properly handle installing themes with unterminated colour formatting sequences, leading to a denial ofservice if a user is tricked into installing a specially crafted theme. CVE-2017-15721 Joseph Bisch discovered that Irssi does not properly handle incorrectly formatted DCC CTCP messages. A malicious IRC server can take advantage of this flaw to cause Irssi to crash, resulting in a denial of service. CVE-2017-15722 Joseph Bisch discovered that Irssi does not properly verify Safe channel IDs. A malicious IRC server can take advantage of this flaw to cause Irssi to crash, resulting in a denial of service. CVE-2017-15723 Joseph Bisch reported that Irssi does not properly handle overlong nicks or targets resulting in a NULL pointer dereference when splitting the message and leading to a denial of service. For the oldstable distribution (jessie), these problems have been fixed in version 0.8.17-1+deb8u5. For the stable distribution (stretch), these problems have been fixed in version 1.0.2-1+deb9u3. CVE-2017-10965 and CVE-2017-10966 were already fixed in an earlier point release. We recommend that you upgrade your irssi packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Several concerns detected with the Irssi terminal IRC client. Crucial patch details for Debian users provided.. Irssi Security Update, Debian Advisory, Denial of Service Threat, Terminal Client Vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 03, 2017 Critical Debian
87

Debian: DSA-3068-1 Moderate: Konversation FiSH Encryption Crash Threat

It was discovered that Konversation, an IRC client for KDE, could by crashed when receiving malformed messages using FiSH encryption. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3068-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff November 07, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : konversation CVE ID : CVE-2014-8483 It was discovered that Konversation, an IRC client for KDE, could by crashed when receiving malformed messages using FiSH encryption. For the stable distribution (wheezy), this problem has been fixed in version 1.4-1+deb7u1. For the unstable distribution (sid), this problem has been fixed in version 1.5-1. We recommend that you upgrade your konversation packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Anomalies were detected in Konversation's FiSH encoding, leading to potential system failures. Implement necessary updates for enhanced protection.. Konversation, Debian Security, IRC Client, Encryption Flaw. . LinuxSecurity.com Team

Calendar 2 Nov 07, 2014 Debian
91

Gentoo: GLSA-200807-12 Normal: BitchX Multiple Execution Risks

Multiple vulnerabilities in BitchX may allow for the remote execution of arbitrary code or symlink attacks.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200807-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: BitchX: Multiple vulnerabilities Date: July 21, 2008 Bugs: #190667 ID: 200807-12 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities in BitchX may allow for the remote execution of arbitrary code or symlink attacks. Background ========= BitchX is an IRC client. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/bitchx

Calendar 2 Jul 22, 2008 Gentoo
100

SUSE: Security Advisory for ircii 4.4M Buffer Overflow Issue

The package ircii is an irc client which is used to connect to irc servers and chat with other users. A buffer overflow in the dcc chat feature was found which is exploitable by remote users. Date: Thu, 30 Mar 2000 23:13:09 +0200 (MEST) From: Marc Heuse This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [suse-security-announce] SuSE Security Announcement - ircii SuSE Security Announcement Package: ircii < 4.4M Date: Thu, 23 Mar 2000 11:04:19 GMT Affected SuSE versions: all Vulnerability Type: remote user compromise SuSE default package: no Other affected systems: all unix systems using ircii < 4.4M A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note that we provide this information on an "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. 1. Problem Description The package ircii is an irc client which is used to connect to irc servers and chat with other users. A buffer overflow in the dcc chat feature was found which is exploitable by remote users. 2. Impact Remote users may execute commands as the user running ircii. 3. Solution Update the package from our FTP server. Please verify these md5 checksums of the updates before installing: (For SuSE 6.0, please use the 6.1 updates) 0d928f56148aaa86c0015bbce49d3561 e06dfc1254128cb1683e0487f168bf76 /6.1/n1/irciihlp-4.4M-0.alpha.rpm 56e00c8e2260b2949ce0536035af479f /6.1/n1/ircii-4.4M-0.i386.rpm 29d123a6ac148827c3b2de2a552f4fa8 /6.1/n1/irciihlp-4.4M-0.i386.rpm 10411aceecd18fc7ff7e6e5445e705ec /6.2/n1/ircii-4.4M-0.i386.rpm e8d430af732bd22f8e460f1ff9f45a77 /6.2/n1/irciihlp-4.4M-0.i386.rpm 773184cd39e5bffd72f8432a5efdd24f /6.3/n1/ircii-4.4M-0.i386.rpm 32738de26730d7442fa1adf992bf37fc /6.3/n1/ircii-4.4M-1.i386.rpm 49373ad8be6b9ef1c1c4a1c21481a639 80505bfa6f08330f5a129d59ae58b51a 4a72afe3f807cf1da2c8859c2a3fb743 6c2c3e7773760a9da2d2fa67b07f564a /6.4/n1/irciihlp-4.4M-1.i386.rpm You can find updates on our ftp-Server: for Intel processors for Alpha processors or try the following web pages for a list of mirrors: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE Our webpage for patches: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE Our webpage for security announcements: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE If you want to report vulnerabilities, please contact This email address is being protected from spambots. You need JavaScript enabled to view it. SuSE has got two free security mailing list services to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - moderated and for general/linux/SuSE security discussions. All SuSE security announcements are sent to this list. This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe to the list, send a message to: This email address is being protected from spambots. You need JavaScript enabled to view it. To remove your address from the list, send a message to: This email address is being protected from spambots. You need JavaScript enabled to view it. Send mail to the following for info and FAQ for this list: This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical flaw in the ircii IRC software allows remote adversaries to exploit the dcc chat feature. Make certain you apply the update promptly.. Remote Exploit, IRC Client, Buffer Overflow, SUSE Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 30, 2000 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here