Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 10 Buster: DLA-3233-1 Moderate: Leptonlib DoS Issue

This update fixes a denial of service vulnerability in leptonlib. It can be made to crash with an arithmetic exception on specially crafted JPEG files. For Debian 10 buster, this problem has been fixed in version . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3233-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Helmut Grohne December 08, 2022 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : leptonlib Version : 1.76.0-1+deb10u2 CVE ID : CVE-2022-38266 This update fixes a denial of service vulnerability in leptonlib. It can be made to crash with an arithmetic exception on specially crafted JPEG files. For Debian 10 buster, this problem has been fixed in version 1.76.0-1+deb10u2. We recommend that you upgrade your leptonlib packages. For the detailed security status of leptonlib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/leptonlib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3234-1 tackles a denial of service vulnerability in leptonlib caused by an arithmetic fault within specially crafted PNG images.. debian lts advisory, leptonlib package upgrade, denial of service fix. . LinuxSecurity.com Team

Calendar%202 Dec 08, 2022 Debian LTS
197

Debian 9: DLA-2612-1 Critical: Leptonlib Buffer Over-Read Problem

Several issues have been found by ClusterFuzz in leptonlib, an image processing library. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2612-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Thorsten Alteholz March 31, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : leptonlib Version : 1.74.1-1+deb9u1 CVE ID : CVE-2020-36277 CVE-2020-36278 CVE-2020-36279 CVE-2020-36281 Several issues have been found by ClusterFuzz in leptonlib, an image processing library. All issues are related to heap-based buffer over-read in several functions or a denial of service (application crash) with crafted data. For Debian 9 stretch, these problems have been fixed in version 1.74.1-1+deb9u1. We recommend that you upgrade your leptonlib packages. For the detailed security status of leptonlib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/leptonlib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Urgent security notice DLA-2612-2 details patches for leptonlib issues in Debian. Immediate update advised.. Debian LTS, Leptonlib Update, Buffer Issues, Image Processing Security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 31, 2021 Critical Debian LTS
197

Debian 7 Wheezy DLA-1302-1 Critical: Leptonlib DoS Risk

Different flaws have been found in leptonlib, an image processing library. . Package : leptonlib Version : 1.69-3.1+deb7u2 CVE ID : CVE-2018-7186 CVE-2018-7440 Debian Bug : 890548 891932 Different flaws have been found in leptonlib, an image processing library. CVE-2018-7186 Leptonica did not limit the number of characters in a %s format argument to fscanf or sscanf, that made it possible to remote attackers to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact via a long string. CVE-2018-7440 The gplotMakeOutput function allowed command injection via a $(command) approach in the gplot rootname argument. This issue existed because of an incomplete fix for CVE-2018-3836. For Debian 7 "Wheezy", these problems have been fixed in version 1.69-3.1+deb7u2. We recommend that you upgrade your leptonlib packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance leptonlib to address significant vulnerabilities that could result in denial of service and expose command injection threats.. leptonlib Security Update, Debian LTS Advisory, Command Injection Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 07, 2018 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200