Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA 976-1 Urgent: Libast Code Execution Security Vulnerability

Johnny Mast discovered a buffer overflow in libast, the library of assorted spiffy things, that can lead to the execution of arbitary code. This library is used by eterm which is installed setgid uid which leads to a vulnerability to alter the utmp file.. - --------------------------------------------------------------------------Debian Security Advisory DSA 976-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze February 15th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : libast, libast1 Vulnerability : buffer overflow Problem type : local Debian-specific: no CVE ID : CVE-2006-0224 Johnny Mast discovered a buffer overflow in libast, the library of assorted spiffy things, that can lead to the execution of arbitary code. This library is used by eterm which is installed setgid uid which leads to a vulnerability to alter the utmp file. For the old stable distribution (woody) this problem has been fixed in version 0.4-3woody2. For the stable distribution (sarge) this problem has been fixed in version 0.6-0pre2003010606sarge1. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your libast packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 611 7ae117d391242963294499b684e783b6 Size/MD5 checksum: 127092 fd7f99bde6a540fe50c27761b63e27cf Size/MD5 checksum: 150283 9424286314c1d816699b28964b91d015 Alpha architecture: Size/MD5 checksum: 30314 549273ceedb6d3836361ec4308df13b7 Size/MD5 checksum: 46418 324e44548cf1c1ae9befb810f3ebc3cc ARM architecture: Size/MD5 checksum: 28496 702865048ba5822eef10de3cd9007819 Size/MD5 checksum: 37076 e454fa52adb41c91c0e9b806caf1418c Intel IA-32 architecture: Size/MD5 checksum: 24804 cb4f324b197dad2f1069af530e1f7051 Size/MD5 checksum: 33096 2eae854498d4ee6a27badcf8603cab7e Intel IA-64 architecture: Size/MD5 checksum: 37426 fab097ad84832a872a0af9f6b61a4db7 Size/MD5 checksum: 47926 530f9e8878f21ee1f2dbcb0dbd16db7d HP Precision architecture: Size/MD5 checksum: 30870 9c9be1baeb94f828c281db145cac7e45 Size/MD5 checksum: 45820 e782f8f5846a48d7eb8a2791c61255e8 Motorola 680x0 architecture: Size/MD5 checksum: 25178 4293a0569fb9f3266e8644e332c1f2bf Size/MD5 checksum: 32990 b78f08fede449151bde20f5b4ee82ea2 Big endian MIPS architecture: Size/MD5 checksum: 24826 ccdf8838e4a6c7c7ecc29916d76af616 Size/MD5 checksum: 40754 9ea070dc4626dadb799bd45eeb27269b Little endian MIPS architecture: Size/MD5 checksum: 24932 2b5ff0209b86917d9e31ca111e57dffb Size/MD5 checksum: 40440 ec95a2b1e72608b7deb882df9b7d7eef PowerPC architecture: Size/MD5 checksum: 28186 ec060589a8ac75ebb4da6cf071698503 Size/MD5 checksum: 41774 9ebee23c3319be0192868528f3f82c36 IBM S/390 architecture: Size/MD5 checksum: 27124 f7a1cd1dff3d333919825565958c36d1 Size/MD5 checksum: 33494 48314490169bae367f5e93dedc58b6a0 Sun Sparc architecture: Size/MD5 checksum: 30330 c620f4c7d89db5f750a1ba792d8f5f95 Size/MD5 checksum: 3886250c09ef80e55176619c4b65ea0191bc2 Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 576 9420ee95768da2f860552aac0b32b5e6 Size/MD5 checksum: 390719 52a0ee946d87bdf807d0a18b71bbf5e2 Alpha architecture: Size/MD5 checksum: 67308 524177839f05a53e16da08d221cf4270 Size/MD5 checksum: 127226 6dad9a361f0ec9550bfb06325f6eca9b AMD64 architecture: Size/MD5 checksum: 63212 5274afc640d0abb29f71c8445506aa6c Size/MD5 checksum: 94440 43c04d451f85e18b68be0fc83d62fdd9 ARM architecture: Size/MD5 checksum: 55832 4987f49c1ed5d819cb91386474216675 Size/MD5 checksum: 90590 09e5736d3ae6ba985dcc86607536aad3 Intel IA-32 architecture: Size/MD5 checksum: 56184 3baf39df1af7fb0370f1487d97fa328d Size/MD5 checksum: 84908 26f77c7997a59f621d3ec32a563fd0f4 Intel IA-64 architecture: Size/MD5 checksum: 77708 744fe6d6a70465912b66f42e7ab0f650 Size/MD5 checksum: 123406 7e47159f62b98acce66f18aa1fb3059a HP Precision architecture: Size/MD5 checksum: 65842 3a61b0d8cfb2b93da56bca7695ab34c5 Size/MD5 checksum: 104328 da13a39f4f86b7b06f18e143e6697a9b Motorola 680x0 architecture: Size/MD5 checksum: 54526 df42f2ef3b882894e5d7062474a03f7a Size/MD5 checksum: 80642 4f3f46861e8cf01acfa83c5cb99761e6 Big endian MIPS architecture: Size/MD5 checksum: 55404 0fe139bd8d3ab4082b0368418158e5cf Size/MD5 checksum: 100148 842ed436fd72d2763551d0b5c727f6f0 Little endian MIPS architecture: Size/MD5 checksum: 55708 e6fef4a2764657e3a6c5379ad4ca734b Size/MD5 checksum: 99892 8006e1709f1170b4cb68f12029abf246 PowerPC architecture: Size/MD5 checksum: 58540 51c6c2e4c1e31f127995e5b2305f0e4b Size/MD5 checksum: 98048 fabbf05a9a0d89b311cfc6153d807fcc IBM S/390architecture: Size/MD5 checksum: 63928 78518a64a55be0d18f82ec1610e756dc Size/MD5 checksum: 90818 0c68ab4af0d61a5a5e5cce80827c81ca Sun Sparc architecture: Size/MD5 checksum: 57060 8efa5b2512f3a5e209c7b5512d129479 Size/MD5 checksum: 91510 abb85b30007dbe82c7a20b4040d4e7aa These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Critical security flaw patched in libast for Debian's stable versions with key update guidance provided.. libast buffer overflow, debian advisory, code execution fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2006 Critical Debian
91

Gentoo: GLSA-202310-05 Critical: LibXYZ Privilege Escalation Vulnerability

A buffer overflow in LibAST may result in execution of arbitrary code with escalated privileges.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200601-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: LibAST: Privilege escalation Date: January 29, 2006 Bugs: #120106 ID: 200601-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in LibAST may result in execution of arbitrary code with escalated privileges. Background ========= LibAST is a utility library that was originally intended to accompany Eterm, but may be used by various other applications. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-libs/libast < 0.7 > = 0.7 Description ========== Michael Jennings discovered an exploitable buffer overflow in the configuration engine of LibAST. Impact ===== The vulnerability can be exploited to gain escalated privileges if the application using LibAST is setuid/setgid and passes a specifically crafted filename to LibAST's configuration engine. Workaround ========= Identify all applications linking against LibAST and verify they are not setuid/setgid. Resolution ========= All users should upgrade to the latest version and run revdep-rebuild: # emerge --sync # emerge --ask --oneshot --verbose > =x11-libs/libast-0.7 # revdep-rebuild References ========= [ 1 ] CVE-2006-0224 https://www.cve.org/CVERecord?id=CVE-2006-0224 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200601-14 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . A critical severity Debian notice highlighting a security flaw in LibXYZ leading to unauthorized access. Immediate patching advised.. libast, buffer overflow, gentoo advisory, privilege escalation, security update. . LinuxSecurity.com Team

Calendar 2 Jan 29, 2006 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here