Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo 201402-20 High: KVIrc Remote Code Execution Threat

Multiple vulnerabilities have been found in KVIrc, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201402-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: KVIrc: Multiple vulnerabilities Date: February 21, 2014 Bugs: #326149, #330111 ID: 201402-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in KVIrc, the worst of which allows remote attackers to execute arbitrary code. Background ========= KVIrc is a free portable IRC client based on Qt. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/kvirc < 4.1_pre4693 > = 4.1_pre4693 Description ========== Multiple vulnerabilities have been discovered in KVIrc. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or overwrite arbitrary files. Workaround ========= There is no known workaround at this time. Resolution ========= All KVIrc users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/kvirc-4.1_pre4693" NOTE: This is a legacy GLSA. Updates for all affected architectures are available since July 29, 2010. It is likely that your system is already no longer affected by this issue. References ========= [ 1 ] CVE-2010-2451 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2451 [ 2 ] CVE-2010-2452 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2452 [ 3 ] CVE-2010-2785 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2785 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201402-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Numerous vulnerabilities in KVIrc could permit remote code execution. Act promptly to enhance security and address severe risks to protect your environment.. KVIrc Issues,Gentoo High Risks,Remote Code Execution. . LinuxSecurity.com Team

Calendar 2 Feb 21, 2014 Gentoo
87

Debian: DSA-2080-1 High: VLC Media Player Buffer Overflow Vulnerability

It was discovered that incorrect parsing of CTCP commands in kvirc, a KDE-based IRC client, could lead to the execution of arbitrary IRC commands against other users. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2078-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff July 31, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : kvirc Vulnerability : programming error Problem type : remote Debian-specific: no CVE Id(s) : CVE-2010-2785 It was discovered that incorrect parsing of CTCP commands in kvirc, a KDE-based IRC client, could lead to the execution of arbitrary IRC commands against other users. For the stable distribution (lenny), this problem has been fixed in version 2:3.4.0-6. For the unstable distribution (sid), this problem has been fixed in version 4:4.0.0-3. We recommend that you upgrade your kvirc package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 7174211 0f1b85f3b6de354dfd44891923e48ef2 Size/MD5 checksum: 103370 35c6b5b288e21f1b2736a7aee463c8f6 Size/MD5 checksum: 1312 0db5bab03ef6dd87d89a541b7db4300c Architecture independent packages: Size/MD5 checksum: 3485832 d0f825b40255900e945396a6d33467d2 alpha architecture (DEC Alpha) Size/MD5 checksum: 3989286 eb13425c5d3b6d16bf3dbbe6799cdab0 Size/MD5 checksum: 363058 85ad7e56fb7071fab9ca4b49c06ecf36 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 360666 d64d34741c1363195456b2cdf2ce7229 Size/MD5 checksum: 3712634 0e792af0082b16e32dd1cf5618dba238 arm architecture (ARM) Size/MD5 checksum: 3762830 bf42ca885cc6a6eb0b2734f2f13abcbe Size/MD5 checksum: 382752 6bfdcd491c6fb27bbbf8e3eb055d9245 armel architecture (ARM EABI) Size/MD5 checksum: 381176 9b876dec7a7d19261488a4c92fe0e17a Size/MD5 checksum: 3227100 9aaaa2429d77f2266b4f4ebed139dc29 hppa architecture (HP PA RISC) Size/MD5 checksum: 4039054 1ab24d4eff5d6b5745bbaab02dbf3376 Size/MD5 checksum: 386628 b41f84f4b3d213bf69be92498bb7c720 i386 architecture (Intel ia32) Size/MD5 checksum: 362768 065afca44287281e2b862bb4ea7a04b2 Size/MD5 checksum: 3582112 697fa1f8d355470b3dd03359bcc529a0 ia64 architecture (Intel ia64) Size/MD5 checksum: 4665172 a9e86a0948ad4d0d2ec109333e219ea4 Size/MD5 checksum: 385070 867eb6fbd8fa350b38ec2a64c0afea32 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 3364772 ffa424acbb31e619eabc368e07acdd1f Size/MD5 checksum: 385918 03fec2e94f02017936f906c0efa7037f mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 3316258 12712dab0045b527204d270280561c49 Size/MD5 checksum: 363396 e386d21f7024e1242f8e75f788eeb9ca powerpc architecture (PowerPC) Size/MD5 checksum: 379950 66e321f4dd44c84dd6f7fff1a427c5bd Size/MD5 checksum: 3915694 e43cda1285368979b6e4209e2ab2de0b s390 architecture (IBM S/390) Size/MD5 checksum: 3638826 12a1793bbfd297891589d678f0222655 Size/MD5 checksum: 362946 80717eeaad3784f156605ce38b8e2a22 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 3529894 e5848f3feaa2252eb22d3813547b97fd Size/MD5 checksum: 381298e56d344f6c4e1d1f93390f6f5b513617 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian DSA-2079-1 resolves kvirc vulnerabilities that could permit harmful IRC commands. Users are advised to update promptly.. Deian Security, Kvirc Update, Command Execution Risk, Remote Command Risk. . LinuxSecurity.com Team

Calendar 2 Jul 31, 2010 Debian
87

Debian 5.0 Lenny DSA-2065-1 Critical: Kvirc Remote Code Execution

Two security issues have been discovered in the DCC protocol support code of kvirc, a KDE-based next generation IRC client, which allow the overwriting of local files through directory traversal and the execution of arbitrary code through a format string attack. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2065-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff June 27, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : kvirc Vulnerability : several Problem type : remote Debian-specific: no CVE Id(s) : CVE-2010-2451 CVE-2010-2452 Two security issues have been discovered in the DCC protocol support code of kvirc, a KDE-based next generation IRC client, which allow the overwriting of local files through directory traversal and the execution of arbitrary code through a format string attack. For the stable distribution (lenny), these problems have been fixed in version 3.4.0-5. For the unstable distribution (sid), these problems have been fixed in version 4.0.0~svn4340+rc3-1. We recommend that you upgrade your kvirc packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1312642fb2f743d0b4114dc4dcdfe544e860 Size/MD5 checksum: 7174211 0f1b85f3b6de354dfd44891923e48ef2 Size/MD5 checksum: 101743 d17428927906877fe773043410a4bb5d Architecture independent packages: Size/MD5 checksum: 3485708 39744719be3446d37a48e57ed297edfd alpha architecture (DEC Alpha) Size/MD5 checksum: 3982826 3272f368231cbb6c13275125a68f89be Size/MD5 checksum: 382428 71dcf62980972fe41f52e842139672a8 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 3714154 29a1fe15e270cb716826f24d8035af27 Size/MD5 checksum: 384484 f08c49266559130841fc833e54bcbcba arm architecture (ARM) Size/MD5 checksum: 382616 899a31f7400fb1f74535452a592aa173 Size/MD5 checksum: 3762824 69c122869ebad6b1972e61c6dfd80b13 armel architecture (ARM EABI) Size/MD5 checksum: 3226626 8b80597f1c3a8f7d9fe49bc611dad251 Size/MD5 checksum: 381044 73288bff85c515bba0330138d928ec36 hppa architecture (HP PA RISC) Size/MD5 checksum: 4038548 3e5bf52af84b2130cf46844afeaadfc9 Size/MD5 checksum: 386440 0681f6793f4a26de447ad002b06bfe17 i386 architecture (Intel ia32) Size/MD5 checksum: 362590 f3e95dc9feda4e41cc437da223870284 Size/MD5 checksum: 3581898 8ae5b2b063047595b7f1dd18f51aba59 ia64 architecture (Intel ia64) Size/MD5 checksum: 4663430 f45f61754e652f97390b869c8344d660 Size/MD5 checksum: 362898 463ea4de1b7d1af32d91021a2ddd5a79 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 3364482 ca1b2ae7e7b995165d656de6f4a2ab30 Size/MD5 checksum: 386108 081e05d2b3f4071f44bc65846278c9f6 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 3316120 4b6bca4c4bbcacb15fcfc4f1f34b5214 Size/MD5 checksum: 362786 b5f4ce347b82eee021105f9d88ee64ac powerpc architecture (PowerPC) Size/MD5 checksum: 3915092 baed14374f84466548ee8f158f7fa2a5 Size/MD5 checksum: 380006 f7afc26c44037138edaa859a6e74658e s390 architecture (IBM S/390) Size/MD5 checksum: 363707840be0d58d1e4851747cf714cddaa9d8d Size/MD5 checksum: 380118 a2b4ede584e0168c616a8617031f6103 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 386258 631d11f8148f985e4ece7d769b2c41ac Size/MD5 checksum: 3532956 b10c59a393ff583bea1514a75baa628b These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Numerous vulnerabilities in kvirc fixed in recent Debian advisory; upgrade now to mitigate risks of file tampering and code execution. . kvirc packages, Debian security update, remote attack prevention, IRC client security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 27, 2010 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here