Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
197

Debian 7: DLA-1174-1 Important: Konversation Denial of Service Patch

It was discovered that there was a denial of service vulnerability in the konversation IRC client related to parsing of color formatting codes. For Debian 7 "Wheezy", this issue has been fixed in konversation version . Hash: SHA256 Package : konversation Version : 1.4-1+deb7u2 CVE ID : CVE-2017-15923 Debian Bug : #881586 It was discovered that there was a denial of service vulnerability in the konversation IRC client related to parsing of color formatting codes. For Debian 7 "Wheezy", this issue has been fixed in konversation version 1.4-1+deb7u2. We recommend that you upgrade your konversation packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . A vulnerability causing excessive resource consumption in konversation for Debian 7 has been fixed in version 1.4-1+deb7u2. Update for better security.. Denial Of Service, Konversation Client, Debian Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Nov 18, 2017 Important Debian LTS
198

Arch Linux: ASA-202311-24 Medium Severity: Kdenlive DoS Vulnerability

The package konversation before version 1.7.3-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201711-19 ========================================= Severity: Medium Date : 2017-11-12 CVE-ID : CVE-2017-15923 Package : konversation Type : denial of service Remote : Yes Link : https://security.archlinux.org/AVG-489 Summary ====== The package konversation before version 1.7.3-1 is vulnerable to denial of service. Resolution ========= Upgrade to 1.7.3-1. # pacman -Syu "konversation> =1.7.3-1" The problem has been fixed upstream in version 1.7.3. Workaround ========= Go to Interface -> Colors in the Configure Konversation dialog and uncheck Allow Colored Text in IRC Messages (near the bottom) Description ========== A denial of service vulnerability has been discovered in Konversation before 1.7.3 when handling colors in IRC messages. Any malicious user connected to the same IRC network could send a carefully crafted message that would crash the Konversation user client. Impact ===== A remote attacker is able to craft messages that can result in the client crashing. References ========= https://kde.org/info/security/advisory-20171112-1.txt ;id=34cc9556c1a089fac6b674d3bd6f2248e9512902 https://security.archlinux.org/CVE-2017-15923 . Arch Linux Security Bulletin ASA-202310-36 Highlights a Moderate Severity KDE Connect Denial Of Service Vulnerability.. Arch Linux, Konversation, Denial Of Service, Security Advisory, Medium Severity. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Nov 14, 2017 Medium ArchLinux
172

Ubuntu 12.04 LTS USN-2401-1 Moderate: Konversation Denial Of Service

Konversation could be made to crash if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-2401-1 November 10, 2014 konversation vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: Konversation could be made to crash if it received specially crafted network traffic. Software Description: - konversation: Internet Relay Chat (IRC) client for KDE Details: Manuel Nickschas discovered that Konversation did not properly perform input sanitization when using Blowfish ECB encryption. A remote attacker could exploit this to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: konversation 1.4-1ubuntu2.1 After a standard system update you need to restart Konversation to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2401-1 CVE-2014-8483 Package Information: https://launchpad.net/ubuntu/+source/konversation/1.4-1ubuntu2.1 . Follow these steps to update Ubuntu 12.04 LTS and address the Konversation crash vulnerability caused by malformed network traffic Ensure your system remains secure. Konversation, Ubuntu 12.04, Denial of Service, Network Exploit. . LinuxSecurity.com Team

Calendar 2 Nov 10, 2014 Ubuntu
198

Arch Linux: ASA-201411-5 Low Severity: konversation Denial Of Service

The package konversation before version 1.5.1-1 is vulnerable to denial of service. . Arch Linux Security Advisory ASA-201411-5 ======================================== Severity: Low Date : 2014-11-09 CVE-ID : CVE-2014-8483 Package : konversation Type : denial of service Remote : Yes Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package konversation before version 1.5.1-1 is vulnerable to denial of service. Resolution ========= Upgrade to 1.5.1-1. # pacman -Syu "konversation> =1.5.1-1" The problem has been fixed upstream [0] in version 1.5.1. Workaround ========= None. Description ========== Konversation's Blowfish ECB encryption support assumes incoming blocks to be the expected 12 bytes. The lack of a sanity-check for the actual size can cause a denial of service and an information leak to the local user. Impact ===== When using Blowfish ECB encryption with another party (an IRC channel or user), sending malformed blocks to konversation can result in a crash or an information leak up to 11 bytes to the local user, due to an out-of-bounds read on a heap-allocated array. References ========= [0] https://github.com/quassel/quassel/commit/8b5ecd https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8483 https://bugs.archlinux.org/task/42698 https://kde.org/info/security/advisory-20141104-1.txt . Debian Security Bulletin DSA-2023-370 details a minor risk of service disruption in gnome-shell versions before 3.36.9.. Arch Linux Denial Service, Konversation Security, Low Severity Advisory. . Severity: Low. LinuxSecurity.com Team

Calendar 2 Nov 09, 2014 Low ArchLinux
87

Debian: DSA-3068-1 Moderate: Konversation FiSH Encryption Crash Threat

It was discovered that Konversation, an IRC client for KDE, could by crashed when receiving malformed messages using FiSH encryption. For the stable distribution (wheezy), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3068-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff November 07, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : konversation CVE ID : CVE-2014-8483 It was discovered that Konversation, an IRC client for KDE, could by crashed when receiving malformed messages using FiSH encryption. For the stable distribution (wheezy), this problem has been fixed in version 1.4-1+deb7u1. For the unstable distribution (sid), this problem has been fixed in version 1.5-1. We recommend that you upgrade your konversation packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Anomalies were detected in Konversation's FiSH encoding, leading to potential system failures. Implement necessary updates for enhanced protection.. Konversation, Debian Security, IRC Client, Encryption Flaw. . LinuxSecurity.com Team

Calendar 2 Nov 07, 2014 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here