Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora Core 3: 2005-815 Critical: Lesstif Stack Overflow Issue

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-815 2005-08-26 ---------------------------------------------------------------------Product : Fedora Core 3 Name : lesstif Version : 0.93.36 Release : 6.FC3.2 Summary : An OSF/Motif(R) clone. Description : LessTif is a free replacement for OSF/Motif(R), which provides a full set of widgets for application development (menus, text entry areas, scrolling windows, etc.). LessTif is source compatible with OSF/Motif(R) 1.2. The widget set code is the primary focus of development. If you are installing lesstif, you also need to install lesstif-clients. ---------------------------------------------------------------------* Fri May 6 2005 Thomas Woerner 0.93-36-6.FC3.2 - fixed possible libXpm overflows (#151640) - allow to write XPM files with absolute path names again (#140815) * Fri Nov 26 2004 Thomas Woerner 0.93.36-6.FC3.1 - fixed CAN-2004-0687 (integer overflows) and CAN-2004-0688 (stack overflows) in embedded Xpm library (#135080) - latest Xpm patches: CAN-2004-0914 (#135081) ---------------------------------------------------------------------This update can be downloaded from: 76df08792027e75229e837cffcbb476a SRPMS/lesstif-0.93.36-6.FC3.2.src.rpm 013397612e73b1dc3fa6280a1ca8e599 x86_64/lesstif-0.93.36-6.FC3.2.x86_64.rpm 576eb1fe1829b35b680292d122ec0048 x86_64/lesstif-devel-0.93.36-6.FC3.2.x86_64.rpm d83b1cedb08ff23388264006f864aa58 x86_64/debug/lesstif-debuginfo-0.93.36-6.FC3.2.x86_64.rpm daf976dcd539551a9fcd4a6105e3b953 x86_64/lesstif-0.93.36-6.FC3.2.i386.rpm daf976dcd539551a9fcd4a6105e3b953 i386/lesstif-0.93.36-6.FC3.2.i386.rpm 89f43a0e8fc6c30eecc1db4dcc61236b i386/lesstif-devel-0.93.36-6.FC3.2.i386.rpm e8dbbcccd334047d50aea2b3e6eaf134 i386/debug/lesstif-debuginfo-0.93.36-6.FC3.2.i386.rpm This update can also be installed with the Update Agent; you can launch theUpdate Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Announcement for Fedora Core 3 Lesstif Release, addressing critical security issues and improving overall functionality for users.. Fedora Core Lesstif Update, Security Patch, Stack Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 26, 2005 Critical Fedora
91

Gentoo Linux OpenMotif GLSA 200503-08 Moderate libXpm Exploit Risk

A new vulnerability has been discovered in libXpm, which is included in OpenMotif and LessTif, that can potentially lead to remote code execution. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200503-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: OpenMotif, LessTif: New libXpm buffer overflows Date: March 04, 2005 Bugs: #83655, #83656 ID: 200503-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A new vulnerability has been discovered in libXpm, which is included in OpenMotif and LessTif, that can potentially lead to remote code execution. Background ========= LessTif is a clone of OSF/Motif, which is a standard user interface toolkit available on Unix and Linux. OpenMotif also provides a free version of the Motif toolkit for open source applications. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-libs/openmotif < 2.2.3-r3 > = 2.2.3-r3 *> = 2.1.30-r9 2 x11-libs/lesstif < 0.94.0-r2 > = 0.94.0-r2 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Chris Gilbert discovered potentially exploitable buffer overflow cases in libXpm that weren't fixed in previous libXpm security advisories. Impact ===== A carefully-crafted XPM file could crash applications makinguse of the OpenMotif or LessTif toolkits, potentially allowing the execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All OpenMotif users should upgrade to an unaffected version: # emerge --sync # emerge --ask --oneshot --verbose x11-libs/openmotif All LessTif users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-libs/lesstif-0.94.0-r2" References ========= [ 1 ] CAN-2005-0605 https://www.cve.org/CVERecord?id=CVE-CAN-2005-0605 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200503-08 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2005 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Review the GLSA 202010-12 alert concerning GTK and its associated libraries. Address potential vulnerabilities in libXau immediately!. OpenMotif Issue, Gentoo Advisory, LibXpm Exploit, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar 2 Mar 04, 2005 Gentoo
87

Debian 3.0: DSA 560-1 Critical: lesstif Stack And Integer Overflows Fix

Chris Evans discovered several stack and integer overflows in the libXpm library which is included in LessTif.. -------------------------------------------------------------------------- Debian Security Advisory DSA 560-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze October 7th, 2004 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : lesstif1-1 Vulnerability : integer and stack overflows Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0687 CAN-2004-0688 CERT advisory : VU#537878 VU#882750 Chris Evans discovered several stack and integer overflows in the libXpm library which is included in LessTif. For the stable distribution (woody) this problem has been fixed in version 0.93.18-5. For the unstable distribution (sid) this problem has been fixed in version 0.93.94-10. We recommend that you upgrade your lesstif packages. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 692 a1757aae53924ec16a8582d60acfa5ec Size/MD5 checksum: 18115 9fa1574040e20fcc8f9db88b142dfd5d Size/MD5 checksum: 3600427 74bce66719adb680009f145ef801bce2 Architecture independent components: Size/MD5 checksum: 339348 86aaf17c6eccbac85ec4e194b62d05b7 Alpha architecture: Size/MD5 checksum: 183756 aaa375321301bf45ec95fcd7e376a925 Size/MD5checksum: 7399496 6c8839d9a882ccaf3bc99d6c88685b41 Size/MD5 checksum: 1100714 fc5b0393ea458073ffd29eddcae4dd0d Size/MD5 checksum: 713120 e9bd9d63307eef50c29a1fc48f9f1e1e ARM architecture: Size/MD5 checksum: 158462 0bb887e815c83842d879be197e41c426 Size/MD5 checksum: 6214936 86810e278a8c46a27cb98ee0444b1024 Size/MD5 checksum: 894320 d94f7f15ade5cc03e0ac419a921fa335 Size/MD5 checksum: 620784 78d6a08103ad50220119de9bdd218acc Intel IA-32 architecture: Size/MD5 checksum: 148112 c464f618bda90bcfc8ddf09d59070c4b Size/MD5 checksum: 5954758 300ea20ec0af04d67aecd0a9e68cccbb Size/MD5 checksum: 738430 fa48592fe8b3b345e4df8c56ec4e8b10 Size/MD5 checksum: 536492 ca45180dbbaf3537e2aad5405942ac17 Intel IA-64 architecture: Size/MD5 checksum: 222072 6b1def7a98cd201e991dae273b93988a Size/MD5 checksum: 10756100 fb15b36bd10dcffe1fdcc5b2658d430a Size/MD5 checksum: 1249232 f4c80e2ce686e59fc9f5960674059c30 Size/MD5 checksum: 944234 4e78634a4c817273d5c293590708548d HP Precision architecture: Size/MD5 checksum: 172516 63e479b669cf3b38f9d4c62c75ca5d3c Size/MD5 checksum: 6313042 62f017141dc0c3fe4748472f825588db Size/MD5 checksum: 1008430 8c34690e5f70886daf81a8fef2f451a1 Size/MD5 checksum: 723070 0a38a179efc3fe6009796b539f49cb64 Motorola 680x0 architecture: Size/MD5 checksum: 141456 10da8908854abbb0c98d1a95207626a4 Size/MD5 checksum: 6076914 42ce3b01e32ac3ca9cf3900d7927938d Size/MD5 checksum: 712328 9b6fc7bb8e15d6c5967fa880a3302316 Size/MD5 checksum: 532364 50f567b4cd787a935f0decea5b3b7141 Big endian MIPS architecture: Size/MD5 checksum: 170248 eea62a3e4b445ca3755d364ea5c7b097 Size/MD5 checksum: 7144190 6d8bb7146c18e45682044e875740ec86 Size/MD5 checksum: 938112 4b291f18eb34a21a967a0aa052a433df Size/MD5 checksum: 592742 a9295f6110af40b67057701950ab367c Little endian MIPS architecture: Size/MD5 checksum: 169158 d110da7fced1a57038be236d0b81ef4f Size/MD5 checksum: 6904756 237e7efdab8bd85abbf159efce715817 Size/MD5 checksum: 934608 e0e2fbaa3892e373bd6586df59f90f53 Size/MD5 checksum: 585130 5572e58387954127dd5e7e7c78bb3a29 PowerPC architecture: Size/MD5 checksum: 157670 d9a39f6138425b73745adbb77c4d5482 Size/MD5 checksum: 6233274 5cf38ef3779dab2b224d5e79fa2c4997 Size/MD5 checksum: 899064 eda6deb97f58702ceef1286953aa1c3e Size/MD5 checksum: 616680 c2814eb4ca67f3bec571fd2e6bae55dd IBM S/390 architecture: Size/MD5 checksum: 156348 deff9c2433184aa5276b0cc9b10a6fa2 Size/MD5 checksum: 6192754 42b8296ce9e90a70a250d1279ff9277f Size/MD5 checksum: 797050 860d1bd8aa96e531a2f7a9c88aee6ad7 Size/MD5 checksum: 618298 63d480480acba05a1e1bbc6e54f18998 Sun Sparc architecture: Size/MD5 checksum: 154114 c694390b6176b315c44e64cc247c2dc5 Size/MD5 checksum: 6195404 32a85c66271baf22813f17c586207d6c Size/MD5 checksum: 834710 7863befa290ccf691640d44bd7b569b1 Size/MD5 checksum: 602214 41f094d53f20658690c295b60a8b7177 These files will probably be moved into the stable distribution on its next update. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Examine the vulnerabilities in Debian's lesstif, concentrating on integer and stack overflow threats. Learn the steps to upgrade your system and address these security risks. Lesstif Patch, DebianSecurity, Integer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 07, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here