Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat Enterprise Linux 5 RHSA-2009-0339-01 Moderate: lcms Memory Leak

Updated lcms packages that resolve several security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: lcms security update Advisory ID: RHSA-2009:0339-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0339.html Issue date: 2009-03-19 CVE Names: CVE-2009-0581 CVE-2009-0723 CVE-2009-0733 ==================================================================== 1. Summary: Updated lcms packages that resolve several security issues are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 3. Description: Little Color Management System (LittleCMS, or simply "lcms") is a small-footprint, speed-optimized open source color management engine. Multiple integer overflow flaws which could lead to heap-based buffer overflows, as well as multiple insufficient input validation flaws, were found in LittleCMS. An attacker could use these flaws to create a specially-crafted image file which could cause an application using LittleCMS to crash, or, possibly, execute arbitrary code when opened by a victim. (CVE-2009-0723, CVE-2009-0733) A memory leak flaw was found in LittleCMS. An application using LittleCMS could use excessive amount of memory, and possibly crash after using all available memory, if used to open specially-crafted images. (CVE-2009-0581) Red Hat would like to thank Chris Evans from the Google Security Team for reporting theseissues. All users of LittleCMS should install these updated packages, which upgrade LittleCMS to version 1.18. All running applications using the lcms library must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 487508 - CVE-2009-0723 LittleCms integer overflow 487509 - CVE-2009-0581 LittleCms memory leak 487512 - CVE-2009-0733 LittleCms lack of upper-bounds check on sizes 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: lcms-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm python-lcms-1.18-0.1.beta1.el5_3.2.i386.rpm x86_64: lcms-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-1.18-0.1.beta1.el5_3.2.x86_64.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.x86_64.rpm python-lcms-1.18-0.1.beta1.el5_3.2.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.i386.rpm x86_64: lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.x86_64.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: lcms-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.i386.rpm python-lcms-1.18-0.1.beta1.el5_3.2.i386.rpm ia64: lcms-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-1.18-0.1.beta1.el5_3.2.ia64.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.ia64.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.ia64.rpm python-lcms-1.18-0.1.beta1.el5_3.2.ia64.rpm ppc: lcms-1.18-0.1.beta1.el5_3.2.ppc.rpm lcms-1.18-0.1.beta1.el5_3.2.ppc64.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.ppc.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.ppc64.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.ppc.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.ppc64.rpm python-lcms-1.18-0.1.beta1.el5_3.2.ppc.rpm s390x: lcms-1.18-0.1.beta1.el5_3.2.s390.rpm lcms-1.18-0.1.beta1.el5_3.2.s390x.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.s390.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.s390x.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.s390.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.s390x.rpm python-lcms-1.18-0.1.beta1.el5_3.2.s390x.rpm x86_64: lcms-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-1.18-0.1.beta1.el5_3.2.x86_64.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-debuginfo-1.18-0.1.beta1.el5_3.2.x86_64.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.i386.rpm lcms-devel-1.18-0.1.beta1.el5_3.2.x86_64.rpm python-lcms-1.18-0.1.beta1.el5_3.2.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-0581 https://www.cve.org/CVERecord?id=CVE-2009-0723 https://www.cve.org/CVERecord?id=CVE-2009-0733 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4(GNU/Linux) iD8DBQFJwm7PXlSAg2UNWIIRAiuOAJkBWmEEmlCS+nUhTtSnYvgtqK8g6QCgntf0 YlCwYMT+IfOs+Xhy+xqEizA=/vxi -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important security patch released for lcms on Red Hat, fixing several vulnerabilities. Update immediately.. lcms security patch, Red Hat Enterprise Linux update, lcms buffer overflow, memory leak fix. . LinuxSecurity.com Team

Calendar 2 Mar 19, 2009 Red Hat
200

Scientific Linux SL5.x Moderate Advisory: Lcms Input Validation Issue

Moderate: lcms security update. Date: Wed, 7 Jan 2009 15:40:38 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for lcms on SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: lcms security update Issue date: 2009-01-07 CVE Names: CVE-2008-5316 CVE-2008-5317 Multiple insufficient input validation flaws were discovered in LittleCMS. An attacker could use these flaws to create a specially-crafted image file which could cause an application using LittleCMS to crash, or, possibly, execute arbitrary code when opened. (CVE-2008-5316, CVE-2008-5317) SL 5.x SRPMS: lcms-1.15-1.2.2.el5_2.2.src.rpm i386: lcms-1.15-1.2.2.el5_2.2.i386.rpm lcms-devel-1.15-1.2.2.el5_2.2.i386.rpm python-lcms-1.15-1.2.2.el5_2.2.i386.rpm x86_64: lcms-1.15-1.2.2.el5_2.2.i386.rpm lcms-1.15-1.2.2.el5_2.2.x86_64.rpm lcms-devel-1.15-1.2.2.el5_2.2.i386.rpm lcms-devel-1.15-1.2.2.el5_2.2.x86_64.rpm python-lcms-1.15-1.2.2.el5_2.2.x86_64.rpm -Connie Sieh -Troy Dawson . The latest Lcms security patch for Scientific Linux SL5.x resolves critical input handling vulnerabilities. Make sure to keep your system up-to-date.. Scientific Linux, lcms, security update, input validation, SL5.x. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 07, 2009 Important Scientific Linux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here