Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux: ASA-201504-25 High Severity Glibc Code Execution Issue

The package glibc before version 2.21-3 is vulnerable to a buffer overflow resulting in arbitrary code execution. . Arch Linux Security Advisory ASA-201504-25 ========================================= Severity: High Date : 2015-04-23 CVE-ID : CVE-2015-1781 Package : glibc Type : arbitrary code execution Remote : Yes Link : Summary ====== The package glibc before version 2.21-3 is vulnerable to a buffer overflow resulting in arbitrary code execution. Resolution ========= Upgrade to 2.21-3. # pacman -Syu "glibc> =2.21-3" The problem has been fixed upstream but a new version has yet to be released. Workaround ========= None. Description ========== A buffer overflow in gethostbyname_r() and related functions performing DNS requests has been fixed. If the NSS functions were called with a misaligned buffer, the buffer length change due to pointer alignment was not taken into account. This could result in application crashes or potentially arbitrary code execution using crafted but syntactically valid DNS responses. Impact ===== A remote attacker can crash or execute arbitrary code by crafting malicious DNS responses to the requests made by an application. To be vulnerable, the application must be passing a misaligned buffer to gethostbyname_r() or related functions. References ========= https://access.redhat.com/security/cve/CVE-2015-1781 https://www.openwall.com/lists/oss-security/2015/04/21/4 https://sourceware.org/git/?p=glibc.git;a=commitdiff;h=2959eda9272a033863c271aff62095abd01bd4e3;hp=7bf8fb104226407b75103b95525364c4667c869f . The Fedora Project Security Announcement FEDORA-2022-3484 introduces a critical vulnerability in the kernel, potentially enabling unauthorized access to sensitive information.. Arch Linux, glibc, Code Execution Issue. . LinuxSecurity.com Team

Calendar 2 Apr 23, 2015 ArchLinux
198

ArchLinux: Fixing the Issue with Chrony Version Number Display

. Hello Guys, Sorry I did a mistake with the version number of chrony. I will rewrite the ASA and post it again best regards -------------------------------------------------------------- Christian Rebischke Website : Twitter : @sh1bumi Jabber : This email address is being protected from spambots. You need JavaScript enabled to view it. PGP : 0x8D8172C8 Fingerprint: A224 6F57 FD0A AC81 3971 EEBE 5EDA 916B 3A2A 7C49 -------------------------------------------------------------- . An inconsistency has been discovered in the version number of ArchLinux's chrony package, necessitating a revision of the advisory to enhance clarity and rectify the information provided.. Chrony Version Error, ArchLinux Update, Software Correction. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 08, 2015 Important ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here