Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 20.04 LTS USN-6570-1: Severe RCE vulnerability in libfreetype

Several security issues were fixed in libclamunrar.. ========================================================================== Ubuntu Security Notice USN-6569-1 January 08, 2024 libclamunrar vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.10 - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS Summary: Several security issues were fixed in libclamunrar. Software Description: - libclamunrar: anti-virus utility for Unix - unrar support Details: it was discovered that libclamunrar incorrectly handled directories when extracting RAR archives. A remote attacker could possibly use this issue to overwrite arbitrary files and execute arbitrary code. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 23.04. (CVE-2022-30333) It was discovered that libclamunrar incorrectly validated certain structures when extracting RAR archives. A remote attacker could possibly use this issue to execute arbitrary code. (CVE-2023-40477) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.10: libclamunrar11 1.0.4-0ubuntu0.23.10.1 Ubuntu 23.04: libclamunrar9 0.103.11-0ubuntu0.23.04.1 Ubuntu 22.04 LTS: libclamunrar9 0.103.11-0ubuntu0.22.04.1 Ubuntu 20.04 LTS: libclamunrar9 0.103.11-0ubuntu0.20.04.1 This update uses a new upstream release, which includes additional bug fixes. In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6569-1 CVE-2022-30333, CVE-2023-40477 Package Information: https://launchpad.net/ubuntu/+source/libclamunrar/1.0.4-0ubuntu0.23.10.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.23.04.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.22.04.1 https://launchpad.net/ubuntu/+source/libclamunrar/0.103.11-0ubuntu0.20.04.1 . Critical flaws in libclamunrar have been addressed in Ubuntu updates, significantly diminishing the chances of remote exploitation.. Libclamunrar Security Update, Ubuntu Security Notice, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 08, 2024 Critical Ubuntu
197

Debian 10: DLA-3653-1 Critical: libclamunrar Buffer Overflow Execution Risk

A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3653-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort November 15, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libclamunrar Version : 0.103.10-0+deb10u1 CVE ID : CVE-2023-40477 A buffer overflow was found in the RAR code used by libclamunrar, which could result in arbitrary code execution when processing malicious RAR archives. For Debian 10 buster, this problem has been fixed in version 0.103.10-0+deb10u1. We recommend that you upgrade your libclamunrar packages. For the detailed security status of libclamunrar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libclamunrar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-3654-1 highlights a security vulnerability in libxyz, posing a risk of unauthorized data access.. debian 10 libclamunrar update, buffer overflow mitigate, security advisory details. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 15, 2023 Critical Debian LTS
100

SUSE: 2023:4297-2 Critical: Clamav CVE-2023-40478 Patch

* bsc#1216625 Cross-References: * CVE-2023-40477 . # Security update for clamav Announcement ID: SUSE-SU-2023:4297-1 Rating: important References: * bsc#1216625 Cross-References: * CVE-2023-40477 CVSS scores: Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for clamav fixes the following issues: * Updated to version 0.103.11: * CVE-2023-40477: Updated libclamunrar dependency to version 6.2.12 (bsc#1216625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-4297=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * clamav-debugsource-0.103.11-3.30.1 * clamav-0.103.11-3.30.1 * clamav-debuginfo-0.103.11-3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2023-40477.html * https://bugzilla.suse.com/show_bug.cgi?id=1216625 . Crucial safety patch for clamav addressing CVE-2023-40477 in SUSE systems is now accessible.. clamav update,SUSE security advisory, SUSE Linux Enterprise. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 31, 2023 Important SuSE
197

Debian 7: DLA-1014-1 Critical: Libclamunrar Code Execution Risk

It was discovered that there was an arbitrary code execution vulnerability in libcamunrar, a library to add unrar support to the Clam anti-virus software. This was caused by an integer overflow resulting in a negative value of the . Hash: SHA256 Package : libclamunrar Version : 0.99-0+deb7u2 CVE ID : CVE-2017-7520 Debian Bug : #867223 It was discovered that there was an arbitrary code execution vulnerability in libcamunrar, a library to add unrar support to the Clam anti-virus software. This was caused by an integer overflow resulting in a negative value of the ``DestPos`` variable, which allows the attacker to write out of bounds when setting ``Mem[DestPos]``. For Debian 7 "Wheezy", this issue has been fixed in libclamunrar version 0.99-0+deb7u2. We recommend that you upgrade your libclamunrar packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Enhance libclamunrar to address a potential security vulnerability stemming from an integer overflow that could lead to arbitrary code execution.. libclamunrar maintainers, Debian security updates, code execution risks. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 05, 2017 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":547,"type":"x","order":1,"pct":78.48,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.88,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.34,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here