Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 20.04 LTS USN-6220-1 High: libxml2 Memory Corruption Vulnerability

lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file.. =========================================================================Ubuntu Security Notice USN-6216-1 July 11, 2023 lib3mf vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: lib3mf could be made to execute arbitrary code if it opens a specially crafted 3MF file. Software Description: - lib3mf: Lib3MF is a C++ implementation of the 3D Manufacturing Format Details: It was discovered that lib3mf did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted 3MF file, a local attacker could possibly use this issue to cause applications using lib3mf to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: lib3mf-dev 1.8.1+ds-3ubuntu0.2 lib3mf1 1.8.1+ds-3ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6216-1 CVE-2021-21772 Package Information: https://launchpad.net/ubuntu/+source/lib3mf/1.8.1+ds-3ubuntu0.2 . Vulnerability identified in lib3mf on Ubuntu 20.04, allowing arbitrary code execution through specifically crafted 3MF files when accessed by various applications.. lib3mf,Ubuntu Security Notice,critical threat. . LinuxSecurity.com Team

Calendar 2 Jul 12, 2023 Ubuntu
91

Fedora: FEDORA-202208-01 Moderate: Foreign Code Compromise in lib3mf

A vulnerability in lib3mf could lead to remote code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202208-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: 3MF Consortium lib3mf: Remote code execution Date: August 04, 2022 Bugs: #775362 ID: 202208-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability in lib3mf could lead to remote code execution. Background ========= lib3mf is an implementation of the 3D Manufacturing Format file standard. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/lib3mf < 2.1.1 > = 2.1.1 Description ========== Incorrect memory handling within lib3mf could result in a use-after- free. Impact ===== An attacker that can provide malicious input to an application using 3MF Consortium's lib3mf could achieve remote code execution. Workaround ========= There is no known workaround at this time. Resolution ========= All 3MF Consortium lib3mf users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/lib3mf-2.1.1" References ========= [ 1 ] CVE-2021-21772 https://nvd.nist.gov/vuln/detail/CVE-2021-21772 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202208-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us.Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2022 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Gentoo users must be aware of a critical lib3mf vulnerability that allows remote code execution. Immediate upgrades and audits are essential to protect systems. lib3mf Exploit, Gentoo Security Alert, Remote Code Execution, Software Update Guide. . LinuxSecurity.com Team

Calendar 2 Aug 04, 2022 Gentoo
203

Mageia: 2021-0368 Moderate Risk: Lib3mf Code Execution Threat

A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability (CVE-2021-21772). . MGASA-2021-0368 - Updated lib3mf packages fix security vulnerability Publication date: 25 Jul 2021 URL: https://advisories.mageia.org/MGASA-2021-0368.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-21772 A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability (CVE-2021-21772). A new package 'act' is introduced to build newer version of lib3mf. Also, openscad is rebuilt against this updated library. References: - https://bugs.mageia.org/show_bug.cgi?id=29018 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/WDGGB65YBQL662M3MOBNNJJNRNURW4TG/ - https://www.cve.org/CVERecord?id=CVE-2021-21772 SRPMS: - 8/core/lib3mf-2.1.1-1.mga8 - 8/core/act-1.6.0-4.mga8 - 8/core/openscad-2021.01-1.2.mga8 . The latest lib3mf updates fix a critical use-after-free vulnerability in Mageia, strengthening defenses against possible exploits.. Mageia Update, Lib3mf Package, Use-After-Free, Software Security, Critical Patch. . LinuxSecurity.com Team

Calendar 2 Jul 25, 2021 Mageia
87

Debian: DSA-4887-1 Moderate: Lib3MF Use-After-Free Code Execution Threat

A use-after-free was discovered in Lib3MF, a C++ implementation of the 3D Manufacturing Format, which could result in the execution of arbitrary code if a malformed file is opened. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4887-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff April 08, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : lib3mf CVE ID : CVE-2021-21772 Debian Bug : 985092 A use-after-free was discovered in Lib3MF, a C++ implementation of the 3D Manufacturing Format, which could result in the execution of arbitrary code if a malformed file is opened. For the stable distribution (buster), this problem has been fixed in version 1.8.1+ds-3+deb10u1. We recommend that you upgrade your lib3mf packages. For the detailed security status of lib3mf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/lib3mf Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical use-after-free flaw in Lib3MF poses an arbitrary code execution threat. It's imperative to update your software packages without delay.. Lib3MF Security Update, Debian DSA-4887-1, Use After Free Risk. . LinuxSecurity.com Team

Calendar 2 Apr 08, 2021 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here