Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
198

Ubuntu: 202209-13 Severity: lib32-libssl Denial of Service

The package lib32-libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure. . Arch Linux Security Advisory ASA-201803-18 ========================================= Severity: Medium Date : 2018-03-19 CVE-ID : CVE-2018-1000120 CVE-2018-1000121 CVE-2018-1000122 Package : lib32-libcurl-compat Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-660 Summary ====== The package lib32-libcurl-compat before version 7.59.0-1 is vulnerable to multiple issues including denial of service and information disclosure. Resolution ========= Upgrade to 7.59.0-1. # pacman -Syu "lib32-libcurl-compat> =7.59.0-1" The problems have been fixed upstream in version 7.59.0. Workaround ========= None. Description ========== - CVE-2018-1000120 (denial of service) It was found that libcurl did not safely parse FTP URLs when using the CURLOPT_FTP_FILEMETHOD method. An attacker, able to provide a specially crafted FTP URL to an application using libcurl, could write a NULL byte at an arbitrary location, resulting in a crash, or an unspecified behavior. - CVE-2018-1000121 (denial of service) A NULL pointer dereference exists in the LDAP code of curl > = 7.21.0 and < curl 7.59.0, allowing an attacker to cause a denial of service. libcurl-using applications that allow LDAP URLs, or that allow redirects to LDAP URLs could be made to crash by a malicious server. - CVE-2018-1000122 (information disclosure) A buffer over-read exists in curl > = 7.20.0 and < 7.59.0 in the RTSP+RTP handling code that allows an attacker to cause a denial of service or information leakage. When asked to transfer an RTSP URL, curl could calculate a wrong data length to copy from the read buffer. The memcpy call would copy data from the heap following the buffer to a storage area that would subsequently be delivered to the application (if it didn't cause a crash). This could lead to information leakageor a denial of service for the application if the server offering the RTSP data can trigger this. Impact ===== A remote attacker is able to crash the application or disclose sensitive information on the affected host. References ========= https://curl.se/docs/CVE-2018-1000120.html https://github.com/curl/curl/commit/535432c0adb62fe167ec09621500470b6fa4eb0f https://curl.se/docs/CVE-2018-1000121.html https://github.com/curl/curl/commit/9889db043393092e9d4b5a42720bba0b3d58deba https://curl.se/docs/CVE-2018-1000122.html https://github.com/curl/curl/commit/d52dc4760f6d9ca1937eefa2093058a952465128 https://security.archlinux.org/CVE-2018-1000120 https://security.archlinux.org/CVE-2018-1000121 https://security.archlinux.org/CVE-2018-1000122 . Fedora Security Notice FSN-202103-12 highlights issues with lib32-libxml2 prior to version 2.9.10-1.. Arch Linux, libcurl compatibility, security advisory, medium severity. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Mar 20, 2018 Medium ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here