Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
197

Debian 8: DLA-1890-1 Critical: kde4libs Shell Command Flaw

Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out . Package : kde4libs Version : 4:4.14.2-5+deb8u3 CVE ID : CVE-2019-14744 Debian Bug : 934268 Dominik Penner discovered a flaw in how KConfig interpreted shell commands in desktop files and other configuration files. An attacker may trick users into installing specially crafted files which could then be used to execute arbitrary code, e.g. a file manager trying to find out the icon for a file or any application using KConfig. Thus the entire feature of supporting shell commands in KConfig entries has been removed. For Debian 8 "Jessie", this problem has been fixed in version 4:4.14.2-5+deb8u3. We recommend that you upgrade your kde4libs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . CVE-2021-31529 affects libgtk in Ubuntu 20.04. Update promptly to protect against potential remote code execution vulnerabilities.. kde4libs Security Update, Debian 8 Update, Shell Command Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 18, 2019 Critical Debian LTS
197

Debian Wheezy DLA-952-1 Moderate: kde4libs Privilege Escalation

Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . Hash: SHA256 Package : kde4libs Version : 4:4.8.4-4+deb7u3 CVE ID : CVE-2013-2074 CVE-2017-6410 CVE-2017-8422 Debian Bug : 856890 Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-6410 Itzik Kotler, Yonatan Fridburg and Amit Klein of Safebreach Labs reported that URLs are not sanitized before passing them to FindProxyForURL, potentially allowing a remote attacker to obtain sensitive information via a crafted PAC file. CVE-2017-8422 Sebastian Krahmer from SUSE discovered that the KAuth framework contains a logic flaw in which the service invoking dbus is not properly checked. This flaw allows spoofing the identity of the caller and gaining root privileges from an unprivileged account. CVE-2013-2074 It was discovered that KIO would show web authentication credentials in some error cases. For Debian 7 "Wheezy", these problems have been fixed in version 4:4.8.4-4+deb7u3. We recommend that you upgrade your kde4libs packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Urgent KDE4 libraries security patch tackles various threats on Debian Wheezy. Safeguard your system immediately!. Debian Security,kde4libs Update,Privilege Escalation,Security Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 25, 2017 Important Debian LTS
87

Debian Jessie DSA-3849-1 Critical: kde4libs Access Threats

Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3849-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 12, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kde4libs CVE ID : CVE-2017-6410 CVE-2017-8422 Debian Bug : 856890 Several vulnerabilities were discovered in kde4libs, the core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2017-6410 Itzik Kotler, Yonatan Fridburg and Amit Klein of Safebreach Labs reported that URLs are not sanitized before passing them to FindProxyForURL, potentially allowing a remote attacker to obtain sensitive information via a crafted PAC file. CVE-2017-8422 Sebastian Krahmer from SUSE discovered that the KAuth framework contains a logic flaw in which the service invoking dbus is not properly checked. This flaw allows spoofing the identity of the caller and gaining root privileges from an unprivileged account. For the stable distribution (jessie), these problems have been fixed in version 4:4.14.2-5+deb8u2. For the unstable distribution (sid), these problems have been fixed in version 4:4.14.26-2. We recommend that you upgrade your kde4libs packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4567-1 highlights vulnerabilities in libexample affecting data integrity and unauthorized access. Find out more.. Kde4libs, DebianSecurity Advisory, Remote Access Risk, Identity Spoofing, Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 12, 2017 Critical Debian
87

Debian DSA-3643-1 Critical: kde4libs Remote File Overwrite Threat

Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with "../" in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3643-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso August 06, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kde4libs CVE ID : CVE-2016-6232 Debian Bug : 832620 Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with "../" in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive. For the stable distribution (jessie), this problem has been fixed in version 4:4.14.2-5+deb8u1. For the unstable distribution (sid), this problem has been fixed in version 4:4.14.22-2. We recommend that you upgrade your kde4libs packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-3745-1 addressing a vulnerability in libcurl allowing unauthorized access through manipulated URLs.. Debian Security Advisory,kde4libs Archive Issue,Remote Access Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 06, 2016 Critical Debian
172

Ubuntu 15.10: USN-3042-1 Critical: KDE-Libs File Overwrite Threat

KDE-Libs could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-3042-1 July 26, 2016 kde4libs vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: KDE-Libs could be made to overwrite files. Software Description: - kde4libs: KDE 4 core applications and libraries Details: Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled extracting certain archives. If a user were tricked into extracting a specially-crafted archive, a remote attacker could use this issue to overwrite arbitrary files out of the extraction directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libkdecore5 4:4.14.13-0ubuntu1.1 Ubuntu 14.04 LTS: libkdecore5 4:4.13.3-0ubuntu0.3 Ubuntu 12.04 LTS: libkdecore5 4:4.8.5-0ubuntu0.5 After a standard system update you need to reboot your computer to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3042-1 CVE-2016-6232 Package Information: https://launchpad.net/ubuntu/+source/kde4libs/4:4.14.13-0ubuntu1.1 https://launchpad.net/ubuntu/+source/kde4libs/4:4.13.3-0ubuntu0.3 https://launchpad.net/ubuntu/+source/kde4libs/4:4.8.5-0ubuntu0.5 . KDE Libraries in Ubuntu may permit unauthorized users to alter files. Security patch required for mitigation. Discover more details here.. KDE-Libs Vulnerability, Ubuntu Security Notice, Archive Security Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 26, 2016 Critical Ubuntu
87

Debian DSA-3004-1 Critical: kde4libs Privilege Escalation Fix

Sebastian Krahmer discovered that Kauth used Policykit insecurely by relying on the process ID. This could result in privilege escalation. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3004-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff August 11, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kde4libs CVE ID : CVE-2014-5033 Sebastian Krahmer discovered that Kauth used Policykit insecurely by relying on the process ID. This could result in privilege escalation. For the stable distribution (wheezy), this problem has been fixed in version 4:4.8.4-4+deb7u1. For the testing distribution (jessie), this problem has been fixed in version 4:4.13.3-2. For the unstable distribution (sid), this problem has been fixed in version 4:4.13.3-2. We recommend that you upgrade your kde4libs packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Ubuntu Security Notice USN-3451-1 addresses the vulnerability in libgtk3 to mitigate potential remote code execution threats.. debian kde4libs privilege escalation fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 11, 2014 Critical Debian
87

Debian: DSA-1868-1 Moderate: kde4libs Code Issues Affecting Stability

Several security issues have been discovered in kde4libs, core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1868-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steffen Joeris August 19, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : kde4libs Vulnerability : several vulnerabilities Problem type : local (remote) Debian-specific: no CVE Ids : CVE-2009-1690 CVE-2009-1698 CVE-2009-1687 Debian Bugs : 534949 Several security issues have been discovered in kde4libs, core libraries for all KDE 4 applications. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1690 It was discovered that there is a use-after-free flaw in handling certain DOM event handlers. This could lead to the execution of arbitrary code, when visiting a malicious website. CVE-2009-1698 It was discovered that there could be an uninitialised pointer when handling a Cascading Style Sheets (CSS) attr function call. This could lead to the execution of arbitrary code, when visiting a malicious website. CVE-2009-1687 It was discovered that the JavaScript garbage collector does not handle allocation failures properly, which could lead to the execution of arbitrary code when visiting a malicious website. For the stable distribution (lenny), these problems have been fixed in version 4:4.1.0-3+lenny1. The oldstable distribution (etch) does not contain kde4libs. For the testing distribution (squeeze), these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 4:4.3.0-1. We recommend that you upgrade your kde4libs packages. Upgradeinstructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 2149 7bc7675c4aa9e7afd4fa3f83b3f95810 Size/MD5 checksum: 91423 ecc50e9bedff96a3285a031141ea15d6 Size/MD5 checksum: 11264345 05487ff0cbc3da093f19e59184b259c7 Architecture independent packages: Size/MD5 checksum: 3140792 47debc16cde2c9a927252ef09d89c1a3 alpha architecture (DEC Alpha) Size/MD5 checksum: 485854 b888554c3d2658b0af3abfa842c58588 Size/MD5 checksum: 67441346 e6d761db09e246d88139e3416de56611 Size/MD5 checksum: 1468330 b8c3ce39505d2532f2c5d7fc83de01d8 Size/MD5 checksum: 11132464 6b307db1dd606a5fbbad60745cf51236 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 450758 dc184603a57dc4bbcedde957086463c3 Size/MD5 checksum: 65872658 3bc3de5af3ff3722bd7817b6c4a4c4d4 Size/MD5 checksum: 10078022 aec949a2390e430248089ebb3790ed78 Size/MD5 checksum: 1454348 51a11bc442e5155ee37bc276c2cb025e arm architecture (ARM) Size/MD5 checksum: 445060 4c9f86c771e9d24459fc1a1369b19d1c Size/MD5 checksum: 67062788 8ead631de22e777ac573400dc7829728 Size/MD5 checksum: 1501464 e90a472bd53283512dda2c5522b1e779 Size/MD5 checksum: 10159066 44dc0551f1664e6775cca2fc2e9568c8 hppa architecture (HP PA RISC) Size/MD5 checksum: 468294 71da7f31e8f21706831abfb597d6c161 Size/MD5 checksum: 11272148eae478aac58c1e84cb57c9244bc6e633 Size/MD5 checksum: 66023980 bc0eeed2957433fdf38f227d464c4dac Size/MD5 checksum: 1501146 55ebcb8acd0e29c84dad063f030d4b32 i386 architecture (Intel ia32) Size/MD5 checksum: 9495028 0486badbc6a675555500eac834e66770 Size/MD5 checksum: 1494680 7caef230087548ae9fafc4c9cbfa51a6 Size/MD5 checksum: 428258 a2154b9e6f111e00d9fafee2e44950d3 Size/MD5 checksum: 65050706 cc57db2601c136b0ea25aa2aafc9ada4 ia64 architecture (Intel ia64) Size/MD5 checksum: 636012 8835da7f0554073419c9bb1ea699be2f Size/MD5 checksum: 69462428 1a34d47746eb45a014c6a18d7711437e Size/MD5 checksum: 1490832 1731fe69a65e2aaeecbc7c31ba594ea3 Size/MD5 checksum: 14283690 92e7eaeeb3288d64aad305c1f7b46ace mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 411002 fc291f1f164002ffa25f21ab4413d418 Size/MD5 checksum: 1491562 5ad177aedcac523d4414c1b33590a8aa Size/MD5 checksum: 67214842 6bf4782cae7a4bb07600a8c4622d2ba8 Size/MD5 checksum: 8922858 e2081fa92bc60067bf3fab1d9553d9f0 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 1445728 0e93a06b9c99da3e19fe9ed57effc2af Size/MD5 checksum: 64601046 76bcf6fa57c4c9fe4146996227fd483e Size/MD5 checksum: 410088 c1a038807d9bfd9ec21b3d3fb9b4ad3b Size/MD5 checksum: 8776788 a4e68c739bc64700c8cba42746337051 powerpc architecture (PowerPC) Size/MD5 checksum: 10152880 7c3caef790d31e75030798ff255860f0 Size/MD5 checksum: 1504080 2a6f91b2f9d251f7c948db16b26b74e6 Size/MD5 checksum: 488426 f82580483fe29a15a635df5b130889f0 Size/MD5 checksum: 69005164 b5142561ef43d8f394f69723ecfa101e s390 architecture (IBM S/390) Size/MD5 checksum: 1454438 7f6117ffd81b9a759544a84b129451d2 Size/MD5 checksum: 69791606 b67cba5028161769d9227e551ce1e3ce Size/MD5 checksum: 476722 3871456f5fad8399f14f6711bd483635 Size/MD5 checksum: 10410196 3a1c94adbe9d2cdf3aab21e684a2ee09 These files will probably be moved into the stabledistribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian DSA-1869-1 details vulnerabilities in qtbase, providing guidance on updates and information regarding their severity.. Debian Advisory,kde4libs issues,security upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 19, 2009 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here