Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
91

Gentoo: GLSA-201705-01 Normal: Libevent Remote Code Execution Risk

Multiple vulnerabilities have been found in libevent, the worst of which allows remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201705-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libevent: Multiple vulnerabilities Date: May 07, 2017 Bugs: #608042 ID: 201705-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in libevent, the worst of which allows remote attackers to execute arbitrary code. Background ========= libevent is a library to execute a function when a specific event occurs on a file descriptor. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/libevent < 2.1.7_rc > = 2.1.7_rc Description ========== Multiple vulnerabilities have been discovered in libevent. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All libevent users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/libevent-2.1.7_rc" References ========= [ 1 ] CVE-2016-10195 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-10195 [ 2 ] CVE-2016-10196 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-10196 [ 3 ] CVE-2016-10197 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-10197 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201705-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws in libevent can lead to remote code execution and Denial of Service attacks. It's advisable to upgrade immediately for enhanced security.. libevent security,Gentoo advisory,remote code execution,denial of service,multiple vulnerabilities. . LinuxSecurity.com Team

Calendar 2 May 07, 2017 Gentoo
172

Ubuntu 16.10: USN-3228-1 Critical: libevent Denial of Service

Several security issues were fixed in libevent.. =========================================================================Ubuntu Security Notice USN-3228-1 March 13, 2017 libevent vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Several security issues were fixed in libevent. Software Description: - libevent: Asynchronous event notification library Details: Guido Vranken discovered that libevent incorrectly handled memory when processing certain data. A remote attacker could possibly use this issue with an application that uses libevent to cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.10: libevent-2.0-5 2.0.21-stable-2ubuntu0.16.10.1 Ubuntu 16.04 LTS: libevent-2.0-5 2.0.21-stable-2ubuntu0.16.04.1 Ubuntu 14.04 LTS: libevent-2.0-5 2.0.21-stable-1ubuntu1.14.04.2 Ubuntu 12.04 LTS: libevent-2.0-5 2.0.16-stable-1ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3228-1 CVE-2016-10195, CVE-2016-10196, CVE-2016-10197 Package Information: https://launchpad.net/ubuntu/+source/libevent/2.0.21-stable-2ubuntu0.16.10.1 https://launchpad.net/ubuntu/+source/libevent/2.0.21-stable-2ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libevent/2.0.21-stable-1ubuntu1.14.04.2 https://launchpad.net/ubuntu/+source/libevent/2.0.16-stable-1ubuntu0.2 . Enhance your Ubuntu installation by applying updates that address libevent security flaws present in various versions, posing significant risks.. Libevent Security Update, Ubuntu Vulnerability Advisory, Remote CodeExploit, Denial of Service, Critical Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 13, 2017 Critical Ubuntu
87

Debian 8: DSA-3789-1 Critical: libevent DoS Remote Code Execution

Several vulnerabilities were discovered in libevent, an asynchronous event notification library. They would lead to Denial Of Service via application crash, or remote code execution. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3789-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 15, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libevent CVE ID : CVE-2016-10195 CVE-2016-10196 CVE-2016-10197 Debian Bug : 854092 Several vulnerabilities were discovered in libevent, an asynchronous event notification library. They would lead to Denial Of Service via application crash, or remote code execution. For the stable distribution (jessie), these problems have been fixed in version 2.0.21-stable-2+deb8u1. For the unstable distribution (sid), these problems have been fixed in version 2.0.21-stable-3. We recommend that you upgrade your libevent packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-3790-1 alerts users concerning vulnerabilities in Samba that may result in service disruption and potential unauthorized access. Users are advised to upgrade promptly.. Debian, libevent, DoS exploits, remote execution, security patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 15, 2017 Critical Debian
99

Slackware 14.1 Libevent Advisory SSA:2016-085-01 Critical: Buffer Overflow

New libevent packages are available for Slackware 14.1 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libevent (SSA:2016-085-01) New libevent packages are available for Slackware 14.1 and -current to fix security issues. Here are the details from the Slackware 14.1 ChangeLog: +--------------------------+ patches/packages/libevent-2.0.22-i486-1_slack14.1.txz: Upgraded. Multiple integer overflows in the evbuffer API allow context-dependent attackers to cause a denial of service or possibly have other unspecified impact via "insanely large inputs" to the (1) evbuffer_add, (2) evbuffer_expand, or (3) bufferevent_write function, which triggers a heap-based buffer overflow or an infinite loop. For more information, see: https://www.cve.org/CVERecord?id=CVE-2014-6272 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/libevent-2.0.22-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/libevent-2.0.22-x86_64-1_slack14.1.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.1 package: ab84c0702044de88f1b051ed3d3d1c40 libevent-2.0.22-i486-1_slack14.1.txz Slackware x86_64 14.1 package: bc5d1dff8d2f3758b0feddf00d2c6229 libevent-2.0.22-x86_64-1_slack14.1.txz Slackware -current package: b195a6e34b8ce7043da6cd57670db4a7 l/libevent-2.0.22-i586-1.txz Slackware x86_64 -current package: 7a755ece3e378f244a3c327369e7f2ac l/libevent-2.0.22-x86_64-1.txz Installationinstructions: +------------------------+ Upgrade the package as root: # upgradepkg libevent-2.0.22-i486-1_slack14.1.txz +-----+ . Updated libevent versions for Slackware 14.1 tackle security vulnerabilities with essential enhancements to avert potential buffer overflow issues.. Libevent Updates, Slackware Packages, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 25, 2016 Critical Slackware
172

Ubuntu 14.10 USN-2477-1 Critical: libevent Denial of Service Risk

libevent could be made to crash or run programs if it processed specially crafted data.. =========================================================================Ubuntu Security Notice USN-2477-1 January 19, 2015 libevent vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: libevent could be made to crash or run programs if it processed specially crafted data. Software Description: - libevent: Asynchronous event notification library Details: Andrew Bartlett discovered that libevent incorrectly handled large inputs to the evbuffer API. A remote attacker could possibly use this issue with an application that uses libevent to cause a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.10: libevent-2.0-5 2.0.21-stable-1ubuntu1.14.10.1 Ubuntu 14.04 LTS: libevent-2.0-5 2.0.21-stable-1ubuntu1.14.04.1 Ubuntu 12.04 LTS: libevent-2.0-5 2.0.16-stable-1ubuntu0.1 Ubuntu 10.04 LTS: libevent-1.4-2 1.4.13-stable-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: CVE-2014-6272 Package Information: https://launchpad.net/ubuntu/+source/libevent/2.0.21-stable-1ubuntu1.14.10.1 https://launchpad.net/ubuntu/+source/libevent/2.0.21-stable-1ubuntu1.14.04.1 https://launchpad.net/ubuntu/+source/libevent/2.0.16-stable-1ubuntu0.1 https://launchpad.net/ubuntu/+source/libevent/1.4.13-stable-1ubuntu0.1 . Ubuntu Security Notice USN-2478-1 addresses a libxml2 vulnerability that may result in information exposure and potential system compromise.. Denial Of Service, Libevent Flaw, Ubuntu Security Notice. . Severity: Critical.LinuxSecurity.com Team

Calendar 2 Jan 19, 2015 Critical Ubuntu
198

Arch Linux: ASA-201504-1 High: Libxml2 XML Entity Expansion Vulnerability

The package libevent before version 2.0.22-1 is vulnerable to a potential heap overflow. . Arch Linux Security Advisory ASA-201501-4 ======================================== Severity: Medium Date : 2015-01-13 CVE-ID : CVE-2014-6272 Package : libevent Type : heap overflow Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package libevent before version 2.0.22-1 is vulnerable to a potential heap overflow. Resolution ========= Upgrade to 2.0.22-1. # pacman -Syu "libevent> =2.0.22-1" The problem has been fixed upstream in version 2.0.22. Workaround ========= The potential heap overflow can be prevented by not using evbuffer_add(), evbuffer_prepend(), evbuffer_expand(), exbuffer_reserve_space(), or evbuffer_read() in a way leading to the use of a buffer chunk larger than a single size_t. Description ========== A defect in the libevent evbuffer API could possibly leave some programs that use the evbuffer API open to potential heap overflows. A program using the evbuffer_add(), evbuffer_prepend(), evbuffer_expand(), exbuffer_reserve_space(), or evbuffer_read() functions may be vulnerable if an attacker is able to coax the linked program into trying to make a buffer larger than that which would fit into a single size_t. Impact ===== An attacker may be able to execute arbitrary code in a program using a vulnerable version of libevent. Upstream has attempted to identify any programs using libevent in a vulnerable way and has not as of yet found any that do but, as a precaution, recommends upgrading. References ========= https://bugs.archlinux.org/task/43366 https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2014-6272 . Arch Linux alert regarding libevent buffer overflow, it is advised to update promptly to mitigate possible remote code execution vulnerabilities.. libevent security, heap overflow threat, Arch Linux advisory. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Jan 13, 2015 Medium ArchLinux
87

Debian 7 (Wheezy) DSA-3119-1 Critical: Libevent Heap Overflow

Andrew Bartlett of Catalyst reported a defect affecting certain applications using the Libevent evbuffer API. This defect leaves applications which pass insanely large inputs to evbuffers open to a possible heap overflow or infinite loop. In order to exploit this flaw, . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3119-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Salvatore Bonaccorso January 06, 2015 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libevent CVE ID : CVE-2014-6272 Debian Bug : 774645 Andrew Bartlett of Catalyst reported a defect affecting certain applications using the Libevent evbuffer API. This defect leaves applications which pass insanely large inputs to evbuffers open to a possible heap overflow or infinite loop. In order to exploit this flaw, an attacker needs to be able to find a way to provoke the program into trying to make a buffer chunk larger than what will fit into a single size_t or off_t. For the stable distribution (wheezy), this problem has been fixed in version 2.0.19-stable-3+deb7u1. For the upcoming stable distribution (jessie) and the unstable distribution (sid), this problem will be fixed soon. We recommend that you upgrade your libevent packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-3120-1 presents a security patch for openssl addressing possible denial of service or data exposure vulnerabilities.. Debian DSA-3119-1, Heap Overflow Risk, Libevent Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 06, 2015 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here