Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 5 articles for you...
197

Debian 8: DLA-1447-1 Moderate: Integer Overflow in Libidn Leads to DoS

An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of . Package : libidn Version : 1.29-1+deb8u3 CVE ID : CVE-2017-14062 Debian Bug : 873903 An integer overflow vulnerability was discovered in libidn, the GNU library for Internationalized Domain Names (IDNs), in its Punycode handling (a Unicode characters to ASCII encoding) allowing a remote attacker to cause a denial of service against applications using the library. For Debian 8 "Jessie", this problem has been fixed in version 1.29-1+deb8u3. We recommend that you upgrade your libidn packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical integer vulnerability has been identified in libidn impacting Debian 8 systems. Immediate upgrade is recommended to mitigate potential denial of service threats.. libidn update, integer overflow vulnerability, debian security advisory. . LinuxSecurity.com Team

Calendar 2 Jul 27, 2018 Debian LTS
89

Fedora 27: FEDORA-2018-02e23192f5 Critical: libidn Integer Overflow

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent libidn patch on Fedora 27 resolves critical integer overflow vulnerabilities, enhancing system security with the latest version's implementation..libidn Update,Fedora 27 Security,Integer Overflow Fix,IDN Support,Latest Upstream Release. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 06, 2018 Critical Fedora
89

Fedora 27 libidn Security Update: Integer Overflow Fix for CVE-2017-14062

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-02e23192f5 2018-04-06 15:00:04.588443 --------------------------------------------------------------------------------Name : libidn Product : Fedora 27 Version : 1.34 Release : 1.fc27 URL : Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Fedora upgrade for libidn has resolved an integer overflow vulnerability identified as CVE-2017-14062.. Fedora 27 libidn update,integer overflowpatch,security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 06, 2018 Critical Fedora
89

Fedora 28 FEDORA-2018-f749c70191 Moderate: libidn Integer Overflow Fix

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 28 introduces significant updates to libidn, addressing a critical integer overflow vulnerability and enhancing its domain name handling capabilities..Fedora Security Update, libidn Patch, Integer Overflow Fix. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Apr 06, 2018 Medium Fedora
89

Fedora 28: FEDORA-2018-f749c70191 critical: libidn Integer Overflow

Update to the latest upstream release, which fixes CVE-2017-14062.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-f749c70191 2018-04-06 11:07:50.699727 --------------------------------------------------------------------------------Name : libidn Product : Fedora 28 Version : 1.34 Release : 1.fc28 URL : http://www.gnu.org/software/libidn/ Summary : Internationalized Domain Name support library Description : GNU Libidn is an implementation of the Stringprep, Punycode and IDNA specifications defined by the IETF Internationalized Domain Names (IDN) working group, used for internationalized domain names. --------------------------------------------------------------------------------Update Information: Update to the latest upstream release, which fixes CVE-2017-14062. --------------------------------------------------------------------------------References: [ 1 ] Bug #1486882 - CVE-2017-14062 libidn2: Integer overflow in puny_decode.c/decode_digit https://bugzilla.redhat.com/show_bug.cgi?id=1486882 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libidn' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent Fedora security patch for libidn tackles integer underflow vulnerability and improves IDN functionality.. libidnsecurity, integer overflow fix, Fedora security update, libidn update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 06, 2018 Critical Fedora
172

Ubuntu 12.04 ESM: USN-3434-2 Critical: Libidn Denial of Service

Libidn could be made to crash or run programs if it processed specially crafted input.. =========================================================================Ubuntu Security Notice USN-3434-2 October 23, 2017 libidn vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: Libidn could be made to crash or run programs if it processed specially crafted input. Software Description: - libidn: implementation of IETF IDN specifications Details: USN-3434-1 fixed a vulnerability in Libidn. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: It was discovered that Libidn incorrectly handled decoding certain digits. A remote attacker could use this issue to cause Libidn to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: libidn11 1.23-2ubuntu0.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3434-2 https://ubuntu.com/security/notices/USN-3434-1 CVE-2017-14062 . Address Libidn security flaw in Ubuntu 12.04 ESM to mitigate potential crash threats and strengthen system integrity.. Libidn Security, Ubuntu Update, Crash Risk, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 23, 2017 Critical Ubuntu
197

Debian 7 Wheezy DLA-1084-1: Moderate Integer Overflow in libidn

It was discovered that there was an integer overflow vulnerability in libidn's Punycode handling (an encoding used to convert Unicode characters to ASCII) which would have allowed remote attackers to cause a denial of service. . Hash: SHA256 Package : libidn Version : 1.25-2+deb7u3 CVE ID : CVE-2017-14062 Debian Bug : #873903 It was discovered that there was an integer overflow vulnerability in libidn's Punycode handling (an encoding used to convert Unicode charactersto ASCII) which would have allowed remote attackers to cause a denial of service. For Debian 7 "Wheezy", this issue has been fixed in libidn version 1.25-2+deb7u3. We recommend that you upgrade your libidn packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'` This email address is being protected from spambots. You need JavaScript enabled to view it. / chris-lamb.co.uk `- . Buffer overflow in libidn's Punycode processing can lead to remote denial of service. Please upgrade to libidn 1.25-2+deb7u3 without delay.. libidn Update, Debian Security, Denial of Service Fix. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2017 Debian LTS
87

Debian Jessie DSA-3658-1 Moderate: Libidn DoS Risks Identified

Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash). . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3658-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso September 01, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libidn CVE ID : CVE-2015-8948 CVE-2016-6261 CVE-2016-6263 Hanno Boeck discovered multiple vulnerabilities in libidn, the GNU library for Internationalized Domain Names (IDNs), allowing a remote attacker to cause a denial of service against an application using the libidn library (application crash). For the stable distribution (jessie), these problems have been fixed in version 1.29-1+deb8u2. For the testing distribution (stretch), these problems have been fixed in version 1.33-1. For the unstable distribution (sid), these problems have been fixed in version 1.33-1. We recommend that you upgrade your libidn packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover the most recent advisory for Debian regarding libidn, which highlights several vulnerabilities potentially leading to Denial of Service (DoS) incidents.. Libidn Vulnerabilities, Debian Security Updates, DoS Threats. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 01, 2016 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here