Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 12.04 ESM USN-3454-2 Critical: Libffi Code Execution

A security issue was fixed in libffi.. =========================================================================Ubuntu Security Notice USN-3454-2 October 24, 2017 libffi vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: A security issue was fixed in libffi. Software Description: - libffi: Foreign Function Interface library (development files, 32bit) Details: USN-3454-1 fixed a vulnerability in libffi. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that libffi incorrectly enforced an executable stack. An attacker could possibly use this issue, in combination with another vulnerability, to facilitate executing arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libffi6 3.0.11~rc1-5ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3454-2 https://ubuntu.com/security/notices/USN-3454-1 CVE-2017-1000376 . Ubuntu Security Notice USN-4567-3 deals with a glibc vulnerability that may enable unauthorized code execution. Immediate upgrade advised.. libffi Vulnerability, Ubuntu Security Notice, Security Issue, System Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 24, 2017 Critical Ubuntu
89

Fedora 26: 2017-06-22 moderate: libffi executable stack

Disable executable stack for aarch64 builds.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3fcc0d9152 2017-06-22 13:34:50.950218 --------------------------------------------------------------------------------Name : libffi Product : Fedora 26 Version : 3.1 Release : 11.fc26 URL : https://sourceware.org/libffi/ Summary : A portable foreign function interface library Description : Compilers for high level languages generate code that follow certain conventions. These conventions are necessary, in part, for separate compilation to work. One such convention is the "calling convention". The calling convention is a set of assumptions made by the compiler about where function arguments will be found on entry to a function. A calling convention also specifies where the return value for a function is found. Some programs may not know at the time of compilation what arguments are to be passed to a function. For instance, an interpreter may be told at run-time about the number and types of arguments used to call a given function. `Libffi' can be used in such programs to provide a bridge from the interpreter program to compiled code. The `libffi' library provides a portable, high level programming interface to various calling conventions. This allows a programmer to call any function specified by a call interface description at run time. FFI stands for Foreign Function Interface. A foreign function interface is the popular name for the interface that allows code written in one language to call code written in another language. The `libffi' library really only provides the lowest, machine dependent layer of a fully featured foreign function interface. A layer must exist above `libffi' that handles type conversions for values passed between the two languages. --------------------------------------------------------------------------------Update Information: Disableexecutable stack for aarch64 builds. --------------------------------------------------------------------------------References: [ 1 ] Bug #1462832 - CVE-2017-1000376 libffi: Requests an executable stack [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1462832 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libffi' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 27 libffi patch enhances security by disabling executable stacks on aarch64 architectures, mitigating essential vulnerabilities.. Fedora Update, Libffi Security, Executable Stack Fix. . LinuxSecurity.com Team

Calendar 2 Jun 22, 2017 Fedora
197

Debian 7 Wheezy DLA-997-1 Critical: libffi Code Execute Threat

libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. . Hash: SHA512 Package : libffi Version : 3.0.10-3+deb7u1 CVE ID : CVE-2017-1000376 libffi requests an executable stack allowing attackers to more easily trigger arbitrary code execution by overwriting the stack. Please note that libffi is used by a number of other libraries. For Debian 7 "Wheezy", these problems have been fixed in version 3.0.10-3+deb7u1. We recommend that you upgrade your libffi packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libffi framework versions promptly due to a severe vulnerability that permits unauthorized code execution on Debian LTS platforms. Take immediate action!. Debian LTS, libffi Update, Code Execution Flaw. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 21, 2017 Critical Debian LTS
87

Debian DSA-3889-1: Libffi Stack Issue Resolved - i386 Exploit Risk

libffi, a library used to call code written in one language from code written in a different language, was enforcing an executable stack on the i386 architecture. While this might not be considered a vulnerability by itself, this could be leveraged when exploiting other vulnerabilities, like for example . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3889-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Yves-Alexis Perez June 19, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libffi CVE ID : CVE-2017-1000376 Debian Bug : 751907 libffi, a library used to call code written in one language from code written in a different language, was enforcing an executable stack on the i386 architecture. While this might not be considered a vulnerability by itself, this could be leveraged when exploiting other vulnerabilities, like for example the "stack clash" class of vulnerabilities discovered by Qualys Research Labs. For the full details, please refer to their advisory published at: For the oldstable distribution (jessie), this problem has been fixed in version 3.1-2+deb8u1. For the stable distribution (stretch), this problem has been fixed in version 3.2.1-4. For the testing distribution (buster), this problem has been fixed in version 3.2.1-4. For the unstable distribution (sid), this problem has been fixed in version 3.2.1-4. We recommend that you upgrade your libffi packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notification DSA-3889-1 outlines a vulnerability in libffi affecting i386 architecture, which may lead to possible threat exploits.. Libffi Security, DebianAdvisory, Executable Stack, Stack Clash Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 19, 2017 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here