Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 7 articles for you...
172

Ubuntu 12.04 ESM: USN-3770-2 Critical: Little CMS Denial of Service

Several security issues were fixed in Little CMS.. =========================================================================Ubuntu Security Notice USN-3770-2 September 20, 2018 lcms, lcms2 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Several security issues were fixed in Little CMS. Software Description: - lcms: Little CMS color management library utilities - lcms2: Little CMS color management library Details: USN-3770-1 fixed a vulnerability in Little CMS. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Pedro Ribeiro discoreved that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2013-4276) Ibrahim El-Sayed discovered that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to cause a denial of service. (CVE-2016-10165) Quang Nguyen discovered that Little CMS incorrectly handled certain files. An attacker could possibly use this issue to execute arbitrary code. (CVE-2018-16435) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: liblcms-utils 1.19.dfsg-1ubuntu3.1 liblcms1 1.19.dfsg-1ubuntu3.1 liblcms2-2 2.2+git20110628-2ubuntu3.3 liblcms2-utils 2.2+git20110628-2ubuntu3.3 After a standard system update you need to restart applications using Little CMS to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3770-2 https://ubuntu.com/security/notices/USN-3770-1 CVE-2013-4276, CVE-2016-10165, CVE-2018-16435 . Several vulnerabilities detected inLittle CMS on Ubuntu 12.04 ESM necessitate immediate patches to ensure security against potential exploits.. Little CMS, Ubuntu Updates, Denial of Service Risks, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 20, 2018 Critical Ubuntu
89

Fedora 20: Critical Buffer Overflow in lcms CVE-2013-4276 Fix

* apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines.". -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-1648 2015-02-04 04:31:04 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 20 Version : 1.19 Release : 13.fc20 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: * apply patch for CVE-2013-4276 * apply patch for "Use of uninitialized values on 64 bit machines." -------------------------------------------------------------------------------- ChangeLog: * Sun Aug 17 2014 Fedora Release Engineering - 1.19-13 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild * Sat Jun 7 2014 Fedora Release Engineering - 1.19-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild * Mon Dec 9 2013 Michael Schwendt - 1.19-11 - apply patch for CVE-2013-4276 (#991757, #992979) - apply patch for "Use of uninitialized values on 64 bit machines." (#1003950) - add %_isa in -libs base package deps - drop %defattr usage * Wed Sep 4 2013 Nils Philippsen - fix bogus dates in changelog -------------------------------------------------------------------------------- References: [ 1 ] Bug #992975 - CVE-2013-4276 lcms: Stack-based buffer overflows in ColorSpace conversion calculator and TIFF compare utility https://bugzilla.redhat.com/show_bug.cgi?id=992975 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages aresigned with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/admin/lists/package-announce.lists.fedoraproject.org/ . Fedora 20 has released a crucial update for its color management system, fixing a critical vulnerability CVE-2013-4276 and addressing performance issues from uninitialized variables. Fedora Color Management Update, lcms Security Patch, critical Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 23, 2015 Critical Fedora
172

Ubuntu 10.04 LTS USN-1043-1 Moderate: lcms DoS Threat Detail

It was discovered that a NULL pointer dereference in the code forhandling transformations of monochrome profiles could allow an attackerto cause a denial of service through a specially crafted image.(CVE-2009-0793) [More...]. ==========================================================Ubuntu Security Notice USN-1043-1 January 12, 2011 lcms vulnerability CVE-2009-0793 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 9.10 Ubuntu 10.04 LTS Ubuntu 10.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: liblcms1 1.16-7ubuntu1.3 Ubuntu 9.10: liblcms1 1.18.dfsg-1ubuntu1.1 Ubuntu 10.04 LTS: liblcms1 1.18.dfsg-1ubuntu2.10.04.1 Ubuntu 10.10: liblcms1 1.18.dfsg-1ubuntu2.10.10.1 In general, a standard system update will make all the necessary changes. Details follow: It was discovered that a NULL pointer dereference in the code for handling transformations of monochrome profiles could allow an attacker to cause a denial of service through a specially crafted image. (CVE-2009-0793) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 26887 e6f7f18b9c8c161cb28b1050ae37a7dc Size/MD5: 1651 061a51a9590122c929a55f97c9af18fe Size/MD5: 911546 b07b623f3e712373ff713fb32cf23651 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 670522 387faeb68c6f2905f4d4dc2e92281394 Size/MD5: 102812 6c0de134fe6e13d9084017c8a848948a Size/MD5: 58336 faea24641f0e5dc794162a38b8094fbf Size/MD5: 160930 658fad1a8975dfa01c7c339f57dedff2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 623192 b25d76f8313405e1769b4d90fbedb59c Size/MD5: 96346573a2703a7a72dce8eac9814eefd972e Size/MD5: 55076 889cd8eea3a342112ebde9cb1f64ddaa Size/MD5: 151876 193ce09714ae6406c9cb3fc651f5db37 lpia architecture (Low Power Intel Architecture): Size/MD5: 629032 f61b32be0b27f2e22a8ba6900adcba69 Size/MD5: 95696 b09d6d68c67b6059af6c1f66cde7532d Size/MD5: 55482 e03b3e83151acf00e8424be1fa559c27 Size/MD5: 148576 eea063a2108327909f558a7557472655 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 756434 602ae82dcfe35b986dc0d6d7b91953b0 Size/MD5: 111268 ef7755b8247f285f679e19e317107992 Size/MD5: 72292 4cfe0928f7f1e79300384fea59b547bc Size/MD5: 169436 4f66b2ebaace414adb1b92c9b30c1130 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 655626 d02eadf3af5519883a25e056fdaafce1 Size/MD5: 98876 f9edda48f4d3051452fb694f2f05c1df Size/MD5: 57910 b32b9a857d42b1b0578d749d166b878e Size/MD5: 159914 d77eeb49466255f257aa1e11cc696a5f Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 9795 2a5bc68b26b8727643fbb5ea97a74b3b Size/MD5: 2024 cf857a038ae254d4b107c5d81d6cf64b Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202526 6348d916764c5cb8f6382079843f324a Size/MD5: 110408 f9c75298dba3171ba1109b1120ad0831 Size/MD5: 62414 8d3b0a4822016b31a2bb1214a183a75a Size/MD5: 157812 ab4a2662a35f8909c2c0dfbf35122963 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 195170 5256a4ac32e45fb6e08331b736e25aad Size/MD5: 103200 583eba21821f02dd1c65a6df84f970c8 Size/MD5: 56996 aaf30568cb8da7faf3a07650445874c7 Size/MD5: 151354 13d4ece3945be36a6f440f50195c827b armel architecture (ARM Architecture): Size/MD5: 190306 8d22c071ec2838bb21302efdcbeb626d Size/MD5: 1023322c29a8beaece5d77c988725e7c6b25ee Size/MD5: 57332 f4d5286b2a3bc760af9cd5c405dc2d93 Size/MD5: 134906 41d7f494e2ace18cbbf4c3b86fda3359 lpia architecture (Low Power Intel Architecture): Size/MD5: 190880 361076583a35d44798ce89d5638adf91 Size/MD5: 101256 bfcb8f35dcefa052b08bbd5e5728ccae Size/MD5: 57728 c4f8b20d28d231af6c16e226c403ffe5 Size/MD5: 147322 f80f89bd1b6babf76e71f90b86d40e42 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203148 d8506d1f197640d414916324fa4267d5 Size/MD5: 114880 2ed6d9e05b95392506086045306fd3cb Size/MD5: 59120 b2e59befb313a9aa02a524153529d79a Size/MD5: 165064 0a390a3e26bbbac204169e9a33a8b70f sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 201662 210aec30d1353f9a3f2d6fb3f1984236 Size/MD5: 106348 8621813760664bb1be69ccc10dc193c4 Size/MD5: 62910 84de59111b2ffc6af10604c8dbf2f918 Size/MD5: 157730 2e8617fa92b8fe5a1b3408606e0aedc4 Updated packages for Ubuntu 10.04 LTS: Source archives: Size/MD5: 9897 50c87fff6501f9194d8417254fbeaa00 Size/MD5: 2048 6316f6fdaca98550248d454f218c8aa8 Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202574 4e5ca751960544d924b6121281992160 Size/MD5: 110512 5206b4b12680e17805854d22ceda3937 Size/MD5: 62666 49174698da1bfbe2d92f81a5ec14d343 Size/MD5: 160052 9656fec5eb5151ec51aa5d3db5ec99c2 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 195106 cd26a05adb7ccae9d3d63200d743f788 Size/MD5: 103198 5c206024aa735e47cc50fd87d475e2e2 Size/MD5: 57140 4599e95ee9101596195863e723e5093a Size/MD5: 153566 a11f5a31a4246f0a385e6c9d9ea7ab83 armel architecture (ARM Architecture): Size/MD5: 181894 0c3fe9347b13d10251b14c3d22037275 Size/MD5: 97396a7275c6d01601e9ba3a36c0f46e38dee Size/MD5: 56768 59f92a7982c01a2340547d093930373b Size/MD5: 137474 7af33a654f466ffe55554f05b3652bf6 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203320 1d35c8ed6530d60354667944d75ce757 Size/MD5: 115178 4f7d8c233e5f27e0794fd2a1f753fb7d Size/MD5: 59198 5354d3f927fb0957a7280ad20522cd5f Size/MD5: 167004 4181e185eb4290f4a506cc6a5ef23332 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 206764 60b6b0499d3d70b45b0c12e160ccfaea Size/MD5: 110080 ee7259f8b863616c4fc1d5a85695b5ea Size/MD5: 64514 7d23af820f62f7efdcadcb8e08d3675d Size/MD5: 159334 974383cd3fd688a1003ec99b3a9113b6 Updated packages for Ubuntu 10.10: Source archives: Size/MD5: 10114 20e7514ba0acbe330b94a4cbce98c605 Size/MD5: 2051 fafeffac18c542d6de316209251f73ad Size/MD5: 894456 2d4078499413febf56db0bcc1d8d4eb9 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 202754 cfdbfd84af2006dc76a1372cd15f6190 Size/MD5: 109764 abd8626f2895847dcfa2ab2ab6159797 Size/MD5: 60076 f1a2fa552f9e06608800457d84fcba5c Size/MD5: 159182 8bd5175d44cc41372d483d3c6f5826f4 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 194744 f32a720f427204fed94e710d68af64fa Size/MD5: 101774 18c07cb47c8aa5d98eea25a88addb09e Size/MD5: 55894 6eb6f435d3fb932825a889cb907a61eb Size/MD5: 150354 5bd5c8298068a83dc7d4340899d3cdbf armel architecture (ARM Architecture): Size/MD5: 193432 2385281b25960d18f6c11fed43bd5db3 Size/MD5: 107328 48594ec3346b71b7f8d57654f011dc88 Size/MD5: 57502 167efcb36ab71e3d7ffb5d02ccd6d2b3 Size/MD5: 139296 cf71751aeb49497b7c277faa31f02d81 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 203088 05a41447398de2349516957ec6bfcd9c Size/MD5: 114178c62a0f29535d5422ede2b40daeb75ca2 Size/MD5: 57940 53f47bd1f12f0f15faf1e04cd4827dc9 Size/MD5: 166136 d069de5b989d6d11fff002a0f823e0f3 . Ubuntu Security Bulletin USN-1043-1: Mitigating the lcms vulnerability within Ubuntu to avoid potential service interruptions caused by manipulated image files.. Ubuntu, lcms, denial of service. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 12, 2011 Important Ubuntu
89

Fedora 10: 2009-3967 Critical: lcms DoS Threat Mitigation

CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3967 2009-04-27 20:37:49 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 10 Version : 1.18 Release : 2.fc10 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 22 2009 kwizart < kwizart at gmail.com > - 1.18-2 - Add lcms-CVE-2009-0793.patch from 1.18a * Mon Mar 23 2009 kwizart < kwizart at gmail.com > - 1.18-1 - Update to 1.18 (final) - Remove upstreamed patches - Disable autoreconf - patch libtool to prevent rpath issue * Fri Mar 20 2009 kwizart < kwizart at gmail.com > - 1.18-0.1.beta2 - Update to 1.18beta2 fix bug #487508: CVE-2009-0723 LittleCms integer overflow fix bug #487512: CVE-2009-0733 LittleCms lack of upper-bounds check on sizes fix bug #487509: CVE-2009-0581 LittleCms memory leak * Mon Mar 2 2009 kwizart < kwizart at gmail.com > - 1.17-10 - Fix circle dependency #452352 * Wed Feb 25 2009 Fedora Release Engineering - 1.17-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Dec 4 2008 kwizart < kwizart at gmail.com > - 1.17-8 - Fix autoreconf and missing auxiliary files. * Sat Nov 29 2008 Ignacio Vazquez-Abrams - 1.17-7 - Rebuild for Python 2.6 -------------------------------------------------------------------------------- References: [ 1 ] Bug #492353 - CVE-2009-0793 lcms: Null pointer dereference (DoS)by handling transformations of monochrome profiles https://bugzilla.redhat.com/show_bug.cgi?id=492353 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Crucial Fedora 10 advisory announcing a vital fix for lcms tackling a Denial of Service vulnerability linked to CVE-2009-0793.. Fedora 10 Update,littleCMS Patch,DoS Fix,Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 09, 2009 Critical Fedora
89

Fedora 9: 2010-4291 Critical Update: lcms DoS Buffer Overflow

CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-3914 2009-04-27 20:37:14 -------------------------------------------------------------------------------- Name : lcms Product : Fedora 9 Version : 1.18 Release : 2.fc9 URL : https://www.littlecms.com/ Summary : Color Management System Description : LittleCMS intends to be a small-footprint, speed optimized color management engine in open source form. -------------------------------------------------------------------------------- Update Information: CVE-2009-0793 The patch was given by lcms upstream on the lcms announce mailing list. % 40littlecms.com -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 22 2009 kwizart < kwizart at gmail.com > - 1.18-2 - Add lcms-CVE-2009-0793.patch from 1.18a * Mon Mar 23 2009 kwizart < kwizart at gmail.com > - 1.18-1 - Update to 1.18 (final) - Remove upstreamed patches - Disable autoreconf - patch libtool to prevent rpath issue * Fri Mar 20 2009 kwizart < kwizart at gmail.com > - 1.18-0.1.beta2 - Update to 1.18beta2 fix bug #487508: CVE-2009-0723 LittleCms integer overflow fix bug #487512: CVE-2009-0733 LittleCms lack of upper-bounds check on sizes fix bug #487509: CVE-2009-0581 LittleCms memory leak * Mon Mar 2 2009 kwizart < kwizart at gmail.com > - 1.17-10 - Fix circle dependency #452352 * Wed Feb 25 2009 Fedora Release Engineering - 1.17-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild * Thu Dec 4 2008 kwizart < kwizart at gmail.com > - 1.17-8 - Fix autoreconf and missing auxiliary files. * Sat Nov 29 2008 Ignacio Vazquez-Abrams - 1.17-7 - Rebuild for Python 2.6 * Tue Oct 28 2008 kwizart < kwizart at gmail.com > - 1.17-6 - Add lcms-fix_s390_lcms_h.patch - Fix #468245 * Tue Jun 3 2008 kwizart < kwizart at gmail.com > -1.17-5 - Fix Array indexing error in ReadCurve - #448066 -------------------------------------------------------------------------------- References: [ 1 ] Bug #492353 - CVE-2009-0793 lcms: Null pointer dereference (DoS) by handling transformations of monochrome profiles https://bugzilla.redhat.com/show_bug.cgi?id=492353 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update lcms' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The latest update for Fedora 9 lcms resolves the security vulnerability identified as CVE-2009-0793, implementing a patch designed to mitigate the risk of denial of service attacks.. Fedora 9 Update,lcmPatch,DoSVulnerability,SecurityPatch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 08, 2009 Critical Fedora
87

Debian Lenny: DSA-1745-2 Critical: Fixes for Lcms Memory Leak

This update fixes a possible regression introduced in DSA-1745-1 and also enhances the security patch. For reference the original advisory text is below. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1745-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steffen Joeris March 25, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : lcms Vulnerability : several vulnerabilities Problem type : local (remote) Debian-specific: no CVE Ids : CVE-2009-0581 CVE-2009-0723 CVE-2009-0733 This update fixes a possible regression introduced in DSA-1745-1 and also enhances the security patch. For reference the original advisory text is below. Several security issues have been discovered in lcms, a color management library. The Common Vulnerabilities andi Exposures project identifies the following problems: CVE-2009-0581 Chris Evans discovered that lcms is affected by a memory leak, which could result in a denial of service via specially crafted image files. CVE-2009-0723 Chris Evans discovered that lcms is prone to several integer overflows via specially crafted image files, which could lead to the execution of arbitrary code. CVE-2009-0733 Chris Evans discovered the lack of upper-gounds check on sizes leading to a buffer overflow, which could be used to execute arbitrary code. For the stable distribution (lenny), these problems have been fixed in version 1.17.dfsg-1+lenny2. For the oldstable distribution (etch), these problems have been fixed in version 1.15-1.1+etch3. For the testing distribution (squeeze) and the unstable distribution (sid), these problems will be fixed soon. We recommend that you upgrade your lcms packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using theapt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Debian (oldstable) - ------------------ Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 5160 16d7404b4dc2f31cfe8c83336013cddd Size/MD5 checksum: 644 5fe77039701cfa261d3ef84842d0e81e Size/MD5 checksum: 791543 95a710dc757504f6b02677c1fab68e73 alpha architecture (DEC Alpha) Size/MD5 checksum: 181316 b06ba5e4b64f5199ef241bd9fe8f293c Size/MD5 checksum: 60246 89c087c9dd7e2d5dd2d78cbfb80c4017 Size/MD5 checksum: 154378 9ab10ab4eae2ad103b2a7abc18e6cfc4 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 149534 1c06e35f87a683ad05c0fb1503859b4b Size/MD5 checksum: 141016 f957d77d929d2e5ab9a4749cafab3b65 Size/MD5 checksum: 53242 52fe759a62f8b111a65550f074c5037b arm architecture (ARM) Size/MD5 checksum: 136610 d7c849cdf0eef3e2c0c1318a31f9e7c1 Size/MD5 checksum: 135176 501beeb4b4309ae863c8c0d46fde6b1a Size/MD5 checksum: 51742 bc7e60d9b5ac44efdf24a0b384f0f173 hppa architecture (HP PA RISC) Size/MD5 checksum: 169464 312f7f7f841c09396a6c30ca76a35754 Size/MD5 checksum: 158496 9d0fa35be0159f82709447b53df2a003 Size/MD5 checksum: 59260 88e7279014e0482a797d54140e74e828 i386 architecture (Intel ia32) Size/MD5 checksum: 50258 fa63f21e62c9fc8b863b60a3b470a840 Size/MD5 checksum: 144134 58a63611f27e80b39537c28171211699 Size/MD5 checksum: 138128 4c01410bae1d6508a77708206032871d ia64 architecture (Intel ia64) Size/MD5 checksum: 78588 17da81143523be8e6ea70be3c4044422 Size/MD5 checksum: 19618068a05087486894adae92031ed3c7d510 Size/MD5 checksum: 205450 66244f6ebdf34dd656cf7bbbe649e110 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 149686 8d5cb21c8f47d5576aa8d7aa5bfc6aa8 Size/MD5 checksum: 173982 7101d5218722dc09f7c89e09b93bd9be Size/MD5 checksum: 52094 72ec336e06cf4042648d9ddd00509f35 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 150926 c6a286b60bc31d2f48f3fb05209f0c83 Size/MD5 checksum: 52290 91070dc723d6e000a7b78cb3221ef280 Size/MD5 checksum: 175070 6f59ce0571035853680e96134062857d powerpc architecture (PowerPC) Size/MD5 checksum: 148372 30e1c544cbe11d7b207a361d0f8fadc7 Size/MD5 checksum: 148342 68e7d1bd20e8a05ea8edc165e746a784 Size/MD5 checksum: 57778 ac6467e6d888c9e64aed8612f0ec0f16 s390 architecture (IBM S/390) Size/MD5 checksum: 54298 37e6c4d12f4f33b9b0e95119a27e9714 Size/MD5 checksum: 143172 a95270d1b8a7c1f282fabdf349bea783 Size/MD5 checksum: 145324 619d5b581922e40d17de03b31db02faf sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 51562 bf67e60a217cf1157fcd0a29a8ac1907 Size/MD5 checksum: 147482 cfef0937ca2d432f04bacbd1e7f8472a Size/MD5 checksum: 138088 e40a9fb196fd26caec11619fbaf60cda Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1299 196c0beecdeffca26d4fd76bfa1f13fa Size/MD5 checksum: 883148 efe7467bac4f10d9b354d5733489334d Size/MD5 checksum: 11880 df69500e72128def5994ef29c66a213a alpha architecture (DEC Alpha) Size/MD5 checksum: 153634 0e6eec2a3310e2e1f700b2a05fd9130d Size/MD5 checksum: 66082 d78ea1ba9b77d499abfcd32762a1cb4d Size/MD5 checksum: 227824 daa5711586870a1c9ed8d3e522e13a5f Size/MD5 checksum: 117318d9a92db2a1208ce29f0907156c0f21ec amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 109436 ca441d44b110249b98976d93ee948968 Size/MD5 checksum: 156844 eeaac6c774c317469343296904f2d8f2 Size/MD5 checksum: 198650 cba03a4c26fbf1d306d669301375d741 Size/MD5 checksum: 59352 5d8f067f54a1a1d1236100ec3198e07b arm architecture (ARM) Size/MD5 checksum: 187620 69df7534d2350b0d746a4c54c822a272 Size/MD5 checksum: 100818 03391efaf6b0e8a2a557fa18fb593a96 Size/MD5 checksum: 56184 d40c2a788175ea465fddf9695ae0c74e Size/MD5 checksum: 135840 b184dfae5d2bc6f63118183b70746792 armel architecture (ARM EABI) Size/MD5 checksum: 136226 0bbf79f1a6a8be0ff7543c3cd4e42140 Size/MD5 checksum: 108536 e28f48cfbca91daa41344b019cf7d5c0 Size/MD5 checksum: 195116 6460336eb5a0445b0c03d9696fb5fcbc Size/MD5 checksum: 60304 e851d20fb24e31bde2831f74c1fd73d8 hppa architecture (HP PA RISC) Size/MD5 checksum: 217310 640dccdf2c7840500c4d4df9f53d1764 Size/MD5 checksum: 181886 dff1392a724aec6efe449767176dfd48 Size/MD5 checksum: 63650 6108c4ddbb4d2b168fb9579e263d89ec Size/MD5 checksum: 120824 fa7b2afd7746de92c8dbbf777a63be00 i386 architecture (Intel ia32) Size/MD5 checksum: 149512 a52ab7fa8e0e8b7876770443f7b33d26 Size/MD5 checksum: 191776 67f020fc2fee74112c13c67b62bd33ac Size/MD5 checksum: 55334 d67ca2db867df6f180f370ea71352ba9 Size/MD5 checksum: 102528 fce72bbf31189287d737104df10fb860 ia64 architecture (Intel ia64) Size/MD5 checksum: 85106 bdb601f8e0628a183552ca9662395003 Size/MD5 checksum: 261388 1f4587b160e1417f7862062607aa9428 Size/MD5 checksum: 168410 32803bd752ab02745c1f5421d77e76e4 Size/MD5 checksum: 184744 c1fc1cfab42a15f14069c7b4291b58d5 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 113914 720820898fadfe0f5c9577b94d7d596d Size/MD5 checksum: 133806 7c5158967ab58f8361c728470a8cf3ca Size/MD5 checksum: 570940c5f8a8e4b11636ee422e67a400d276a Size/MD5 checksum: 221442 cf73eb40bf7fca081eb72164cbad007b mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 116858 5cc0672b4e6631a065822c4dbef8f6dd Size/MD5 checksum: 57180 e788b1715e993fd87bd450c05c8a4edb Size/MD5 checksum: 224906 9af1ae4fd0719c03af6bcd20c06fe8b1 Size/MD5 checksum: 130228 d0ab9d0595147cc05012d6d85c649c16 powerpc architecture (PowerPC) Size/MD5 checksum: 197118 e968b8dc68cade76a972984ee7be6a42 Size/MD5 checksum: 115862 6c63f6f6e720988973299bb7aaf16be1 Size/MD5 checksum: 70946 87bf7ecd279df9b7a4378ad2aa0568b9 Size/MD5 checksum: 163524 888ccce8725b23b03e19ff03cd7c1dba s390 architecture (IBM S/390) Size/MD5 checksum: 61034 91931f080c60c2bed98b07c93a1d815c Size/MD5 checksum: 137822 57fe47c765d8dd2bd68282180786a22a Size/MD5 checksum: 109236 12d604eb4030d11e5396cab3ad2be461 Size/MD5 checksum: 191326 ab66b338cb32e84f441c45d07e44c744 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 58624 973b4ab50eaf18dbb55648a3b49e982c Size/MD5 checksum: 156994 d5a82f96ef78ee2739e35548c1d89953 Size/MD5 checksum: 102080 5aa8adf1027ae2a771f538b0630bcc77 Size/MD5 checksum: 195704 5040b60f738977f0686ab32e1b705bcc These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . The latest patch for lcms via DSA-1745-2 resolves memory leak and integer overflow vulnerabilities along with necessary regression corrections.. Debian Lcms Security Fix, Update Lcms Packages, Debian Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 25, 2009 Critical Debian
89

Fedora 9 Security Advisory: OpenJDK 1.6.0 Critical Lcms Update

lcms in OpenJDK upgraded to 1.18 fixing many related security issues.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2009-3034 2009-03-25 15:23:33 --------------------------------------------------------------------------------Name : java-1.6.0-openjdk Product : Fedora 9 Version : 1.6.0.0 Release : 0.23.b09.fc9 URL : https://icedtea.classpath.org/ Summary : OpenJDK Runtime Environment Description : The OpenJDK runtime environment. --------------------------------------------------------------------------------Update Information: lcms in OpenJDK upgraded to 1.18 fixing many related security issues. --------------------------------------------------------------------------------ChangeLog: * Tue Mar 24 2009 Lillian Angel - 1:1.6.0-0.23.b09 - Updated java-1.6.0-openjdk-lcms.patch. * Tue Mar 24 2009 Lillian Angel - 1:1.6.0-0.22.b09 - Updated release. - Added java-1.6.0-openjdk-securitypatches.patch. * Fri Mar 20 2009 Lillian Angel - 1:1.6.0-0.21.b09 - Added new lcms security patch. * Tue Dec 2 2008 Lillian Angel - 1:1.6.0-0.20.b09 - Set runtests to 0. * Tue Dec 2 2008 Lillian Angel - 1:1.6.0-0.20.b09 - Added new security patch. - Resolves: rhbz#472234 - Resolves: rhbz#472233 - Resolves: rhbz#472231 - Resolves: rhbz#472228 - Resolves: rhbz#472224 - Resolves: rhbz#472218 - Resolves: rhbz#472213 - Resolves: rhbz#472212 - Resolves: rhbz#472211 - Resolves: rhbz#472209 - Resolves: rhbz#472208 - Resolves: rhbz#472206 - Resolves: rhbz#472201 * Mon Sep 22 2008 Lillian Angel - 1:1.6.0-0.19.b09 - Removed update-desktop-database dependency. - Resolves: rhbz#463046 * Mon Sep 8 2008 Lillian Angel - 1:1.6.0-0.18.b09 - Moved hotspot patch to only be applied to jit_arches. * Mon Sep 8 2008 Lillian Angel - 1:1.6.0-0.18.b09 - Added hotspot patch (Patch11) to fix eclipse crashing bug. - Resolves: rhbz#460205 * Mon Sep 8 2008 Lillian Angel -1:1.6.0-0.18.b09 - Added rhino requirement. - Resolves: rhbz#461336 * Wed Jul 16 2008 Dennis Gilmore - 1:1.6.0-0.17.b09 - bump the release to sync all arches * Wed Jul 9 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Add runtests define. - Run test suites on JIT architectures only. * Tue Jul 8 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Only apply hotspot security patch of jitarches. * Wed Jul 2 2008 Lillian Angel - 1:1.6.0-0.16.b09 - Added OpenJDK security patches. * Sat Jun 7 2008 Tom "spot" Callaway - 1:1.6.0-0.16.b09 - enable sparc/sparc64 builds * Sat May 31 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Fix keytool location passed to generate-cacerts.pl. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Generate cacerts file. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Remove jhat patch. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Remove makefile patch. - Update generate-fedora-zip.sh. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Formatting cleanups. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Group all Mauve commands. * Fri May 30 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Formatting cleanups. - Add jtreg_output to src subpackage. * Wed May 28 2008 Lillian Angel - 1:1.6.0.0-0.15.b09 - Updated icedteasnapshot for new release. * Tue May 27 2008 Thomas Fitzsimmons - 1:1.6.0.0-0.15.b09 - Require ca-certificates. - Symlink to ca-certificates cacerts. - Remove cacerts from files list. - Resolves: rhbz#444260 * Mon May 26 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Added eclipse-ecj build requirement for mauve. - Updated icedteasnapshot. * Fri May 23 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Fixed jtreg testing. * Fri May 23 2008 Lillian Angel - 1:1.6.0.0-0.14.b09 - Updated icedteasnapshot. - Updated release. - Added jtreg testing. * Thu May 22 2008 Lillian Angel - 1:1.6.0.0-0.13.b09 - Added new patch java-1.6.0-openjdk-java-access-bridge-tck.patch. - Updatedrelease. * Mon May 5 2008 Lillian Angel - 1:1.6.0.0-0.12.b09 - Updated release. - Updated icedteasnapshot. - Resolves: rhbz#445182 - Resolves: rhbz#445183 * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Fixed javaws.desktop installation. * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Updated icedteasnapshot. - Removed java-1.6.0-openjdk-jconsole.desktop and java-1.6.0-openjdk-policytool.desktop files. * Tue Apr 29 2008 Lillian Angel - 1:1.6.0.0-0.11.b09 - Updated release. - Added archbuild and archinstall definitions for ia64. - Resolves: rhbz#433843 --------------------------------------------------------------------------------References: [ 1 ] Bug #487509 - CVE-2009-0581 LittleCms memory leak https://bugzilla.redhat.com/show_bug.cgi?id=487509 [ 2 ] Bug #487508 - CVE-2009-0723 LittleCms integer overflow https://bugzilla.redhat.com/show_bug.cgi?id=487508 [ 3 ] Bug #487512 - CVE-2009-0733 LittleCms lack of upper-bounds check on sizes https://bugzilla.redhat.com/show_bug.cgi?id=487512 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update java-1.6.0-openjdk' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Transitioning to OpenJDK 1.6.0 rectifies a number of security flaws in lcms for those utilizing Fedora.. OpenJDK Security, Fedora Update, Runtime Environment Fixes. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Mar 25, 2009 Critical Fedora
99

Slackware 12.2: 2009-083-01 Critical: Lcms Denial Of Service

New lcms packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. More details about the issues may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] lcms (SSA:2009-083-01) New lcms packages are available for Slackware 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, and -current to fix security issues. More details about the issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-2009-0581 https://www.cve.org/CVERecord?id=CVE-2009-0723 https://www.cve.org/CVERecord?id=CVE-2009-0733 Here are the details from the Slackware 12.2 ChangeLog: +--------------------------+ patches/packages/lcms-1.18-i486-1_slack12.2.tgz: Upgraded to lcms-1.18. This update fixes security issues discovered in LittleCMS by Chris Evans. These flaws could cause program crashes (denial of service) or the execution of arbitrary code as the user of the lcms-linked program. For more information, see: https://www.cve.org/CVERecord?id=CVE-2009-0581 https://www.cve.org/CVERecord?id=CVE-2009-0723 https://www.cve.org/CVERecord?id=CVE-2009-0733 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ HINT: Getting slow download speeds from ftp.slackware.com? Give slackware.osuosl.org a try. This is another primary FTP site for Slackware that can be considerably faster than downloading directly from ftp.slackware.com. Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating additional FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 10.0: ftp://ftp.slackware.com/pub/slackware/slackware-10.0/patches/packages/lcms-1.18-i486-1_slack10.0.tgz Updated package for Slackware10.1: ftp://ftp.slackware.com/pub/slackware/slackware-10.1/patches/packages/lcms-1.18-i486-1_slack10.1.tgz Updated package for Slackware 10.2: ftp://ftp.slackware.com/pub/slackware/slackware-10.2/patches/packages/lcms-1.18-i486-1_slack10.2.tgz Updated package for Slackware 11.0: ftp://ftp.slackware.com/pub/slackware/slackware-11.0/patches/packages/lcms-1.18-i486-1_slack11.0.tgz Updated package for Slackware 12.0: ftp://ftp.slackware.com/pub/slackware/slackware-12.0/patches/packages/lcms-1.18-i486-1_slack12.0.tgz Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/lcms-1.18-i486-1_slack12.1.tgz Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/lcms-1.18-i486-1_slack12.2.tgz Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 10.0 package: 6a3369ac79791ca0999dbf57aed56207 lcms-1.18-i486-1_slack10.0.tgz Slackware 10.1 package: fbf182d254c740f688672713f64a17e5 lcms-1.18-i486-1_slack10.1.tgz Slackware 10.2 package: 2d96b95ba90abca6af5da84727078fc7 lcms-1.18-i486-1_slack10.2.tgz Slackware 11.0 package: 0814537987ca4994a4a331a3e47bcc98 lcms-1.18-i486-1_slack11.0.tgz Slackware 12.0 package: e6752bdf112b27d6c17758aaac7a02f6 lcms-1.18-i486-1_slack12.0.tgz Slackware 12.1 package: 9f8b2abb83ac254bb4c0fe85e519b02a lcms-1.18-i486-1_slack12.1.tgz Slackware 12.2 package: 70a303fa6a5aa390c09723153abf3589 lcms-1.18-i486-1_slack12.2.tgz Slackware -current package: 9b9ee19b1b2b1ada4ae15044d7218365 lcms-1.18-i486-1.tgz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg lcms-1.18-i486-1_slack12.2.tgz Then restart any daemons that are linked with lcms. +-----+ . Recent lcms updates for Slackware address critical vulnerabilities and improve overall system performance. Ensure you upgrade today!. Slackware Update,Lcms Packages,Service Issue,Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 24, 2009 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here