Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
89

Fedora 44 libkdcraw Important DoS Vulnern 2026-bef0050737

LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bef0050737 2026-04-13 21:06:00.498961+00:00 -------------------------------------------------------------------------------- Name : libkdcraw Product : Fedora 44 Version : 26.03.80 Release : 2.fc44 URL : https://invent.kde.org/graphics/libkdcraw Summary : A C++ interface around LibRaw library Description : Libkdcraw is a C++ interface around LibRaw library used to decode RAW picture files. More information about LibRaw can be found at http://www.libraw.org. -------------------------------------------------------------------------------- Update Information: LibRaw 0.22.1 and rebuilds Release 3.1.12.0 (Apr 1, 2026) -- compared to 3.1.11.0 oiiotool: Better type understanding with -i:ch= and other cleanup #5056 texture: Fix texture overblur with st-blur parameters #5071 #5080 (by Pascal Lecocq) (3.1.12.0, 3.0.17.0) IBA: Handle offset data windows in fillholes_pushpull #5105 (3.1.12.0, 3.0.17.0) ImageInput: check_open fixes and new validity checks #5087 (3.1.12.0, 3.0.17.0) bmp: Use check_open to guard against corrupt resolutions #5086 (3.1.12.0, 3.0.17.0) heif: Fix invalid read writing 8-bit images with dimensions not a multiple of 64 #5095 (by Brecht Van Lommel) ico: Various validity checks and error handling for corruptions #5088 (3.1.12.0, 3.0.17.0) jpeg: Improved safety and error reporting for jpeg and iptc #5081 jpeg2000: Suppress leak when reading with OpenJPH #5098 psd: Fixes against corrupt files with better validation #5089 (3.1.12.0, 3.0.17.0) rla: Lots of additional validity checking and safety #5094 (3.1.12.0, 3.0.17.0) tiff: Support GPS fields, and othermetadata enhancements #5050 tiff: Fix buffer overrun and improve error reporting #5082, fix wrong number of values passed to invert_photometric #5083, check for invalid bit depth in palette images #5091 ImageSpec: metadata_val improved safety #5096 (3.1.12.0, 3.0.17.0) fix: Fix UB-sanitizer warning about alignment #5097 fix: Catch exceptions in print-uncaught-messages destructor #5103 fix: Enhanced exception safety for our use of OpenColorIO #5114 fix: Fix possible fmt exceptions where we might have passed null string #5115 build: Test building with clang 22.1, fix warnings uncovered #5067 build: Improve security by pinning auto-build dependencies by hash #5076 build: Include idiff in the python wheels we build #5104 (3.1.12.0, 3.0.17.0) build(pybind11): Address new pybind11 float/int auto-conversion behavior #5058 build(win): Embed manifest in OIIO executables to enable long path handling #5066 (by Nathan Rusch) ci: Add CI test for MSVS 2026 #5060 (3.1.12.0, 3.0.17.0) ci: For security, replace workflow substitutions with safer env substitutions #5070 ci: Speed up slow benchmarks for debug and sanitizer CI tests #5077 ci: On Mac Intel CI variant, don't install openvdb, for speed #5065 (3.1.12.0, 3.0.17.0) ci: Bump GitHub Actions to latest versions #5078 #5110 #5119 ci: Fix broken Mac CI and wheel building by specifying full compiler paths #5100 #5101 (3.1.12.0, 3.0.17.0) ci: Update certificates to be able to install icc #5122 (3.1.12.0, 3.0.17.0) ci: Turn off nightly workflows for user forks #5042 tests: New ref outputs for tiff-misc, heif no-avif, and ffmpeg 8.1 cases #5075 #5079 #5099 #5112 docs: Update description for dwaCompressionLevel #5074 (by Aamir Raza) docs: Fix formatting examples for version macros #5073 docs: Keep TextureSystem docs in sync with ImageCache #5085 (3.1.12.0, 3.0.17.0) docs: Fix typos and incorrect attribute name in a comment #5093 (3.1.12.0, 3.0.17.0) docs: Fix misstatement about oiiotool --if #5102 (3.1.12.0, 3.0.17.0) admin: Draft policy on use ofAI coding assistants #5072 (3.1.12.0, 3.0.17.0) ci: Freetype adjustments #4999 Update to 5.1 (#2451401) Update to 5.0 (#2447841) -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Gwyn Ciesla - 26.03.80-2 - Libraw rebuild * Mon Mar 16 2026 Steve Cossette - 26.03.80-1 - 26.03.80 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2447841 - swayimg-.5.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2447841 [ 2 ] Bug #2451401 - swayimg-5.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2451401 [ 3 ] Bug #2454235 - CVE-2026-5318 LibRaw: LibRaw: Denial of Service via out-of-bounds write in JPEG DHT Parser [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454235 [ 4 ] Bug #2454464 - CVE-2026-5342 LibRaw: LibRaw: Out-of-bounds read via `load_flags/raw_width` argument manipulation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2454464 [ 5 ] Bug #2455346 - LibRaw-0.22.1 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455346 [ 6 ] Bug #2456557 - CVE-2026-20884 LibRaw: LibRaw: Arbitrary code execution via integer overflow in deflate_dng_load_raw [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2456557 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bef0050737' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Libkdcraw update for Fedora 44 addresses critical issues to prevent potential DoS attacks from LibRaw vulnerabilities.. libkdcraw update, Fedora 44 security, LibRaw DoS fix, software patching, security vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 13, 2026 Important Fedora
200

Moderate Advisory for Scientific Linux 7: SLSA-2018-3065-1 on libkdcraw

* LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5805) * LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp (CVE-2018-5800) . Synopsis: Moderate: libkdcraw security update Advisory ID: SLSA-2018:3065-1 Issue Date: 2018-10-30 CVE Numbers: CVE-2018-5800 CVE-2018-5801 CVE-2018-5802 CVE-2018-5805 CVE-2018-5806 --* LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5805) * LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp (CVE-2018-5800) * LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp (CVE-2018-5801) * LibRaw: Out-of-bounds read in kodak_radc_load_raw function internal/dcraw_common.cpp (CVE-2018-5802) * LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5806) --SL7 x86_64 libkdcraw-4.10.5-5.el7.i686.rpm libkdcraw-4.10.5-5.el7.x86_64.rpm libkdcraw-debuginfo-4.10.5-5.el7.i686.rpm libkdcraw-debuginfo-4.10.5-5.el7.x86_64.rpm libkdcraw-devel-4.10.5-5.el7.i686.rpm libkdcraw-devel-4.10.5-5.el7.x86_64.rpm - Scientific Linux Development Team . A security alert regarding libkdcraw on Scientific Linux reveals several buffer overflow vulnerabilities, requiring immediate updates to ensure system security. libkdcraw, buffer overflow, scientific linux, libraw, security advisory. . LinuxSecurity.com Team

Calendar%202 Nov 26, 2018 Scientific Linux
98

Red Hat Enterprise Linux 7: RHSA-2018:3065-01 Moderate Buffer Overflow

An update for libkdcraw is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libkdcraw security update Advisory ID: RHSA-2018:3065-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2018:3065 Issue date: 2018-10-30 CVE Names: CVE-2018-5800 CVE-2018-5801 CVE-2018-5802 CVE-2018-5805 CVE-2018-5806 ==================================================================== 1. Summary: An update for libkdcraw is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64le, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, ppc64le 3. Description: Libkdcraw is a C++ interface around the LibRaw library used to decode the RAW picture files. Security Fix(es): * LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5805) * LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp (CVE-2018-5800) * LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp(CVE-2018-5801) * LibRaw: Out-of-bounds read in kodak_radc_load_raw function internal/dcraw_common.cpp (CVE-2018-5802) * LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp (CVE-2018-5806) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1553332 - CVE-2018-5800 LibRaw: Heap-based buffer overflow in LibRaw::kodak_ycbcr_load_raw function in internal/dcraw_common.cpp 1553334 - CVE-2018-5801 LibRaw: NULL pointer dereference in LibRaw::unpack function src/libraw_cxx.cpp 1553335 - CVE-2018-5802 LibRaw: Out-of-bounds read in kodak_radc_load_raw function internal/dcraw_common.cpp 1591887 - CVE-2018-5805 LibRaw: Stack-based buffer overflow in quicktake_100_load_raw() function in internal/dcraw_common.cpp 1591897 - CVE-2018-5806 LibRaw: NULL pointer dereference in leaf_hdr_load_raw() function in internal/dcraw_common.cpp 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: libkdcraw-4.10.5-5.el7.src.rpm x86_64: libkdcraw-4.10.5-5.el7.i686.rpm libkdcraw-4.10.5-5.el7.x86_64.rpm libkdcraw-debuginfo-4.10.5-5.el7.i686.rpm libkdcraw-debuginfo-4.10.5-5.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: libkdcraw-debuginfo-4.10.5-5.el7.i686.rpm libkdcraw-debuginfo-4.10.5-5.el7.x86_64.rpm libkdcraw-devel-4.10.5-5.el7.i686.rpm libkdcraw-devel-4.10.5-5.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: libkdcraw-4.10.5-5.el7.src.rpm ppc64le: libkdcraw-4.10.5-5.el7.ppc64le.rpm libkdcraw-debuginfo-4.10.5-5.el7.ppc64le.rpm libkdcraw-devel-4.10.5-5.el7.ppc64le.rpm x86_64: libkdcraw-4.10.5-5.el7.i686.rpm libkdcraw-4.10.5-5.el7.x86_64.rpm libkdcraw-debuginfo-4.10.5-5.el7.i686.rpm libkdcraw-debuginfo-4.10.5-5.el7.x86_64.rpm libkdcraw-devel-4.10.5-5.el7.i686.rpm libkdcraw-devel-4.10.5-5.el7.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7): Source: libkdcraw-4.10.5-5.el7.src.rpm aarch64: libkdcraw-4.10.5-5.el7.aarch64.rpm libkdcraw-debuginfo-4.10.5-5.el7.aarch64.rpm libkdcraw-devel-4.10.5-5.el7.aarch64.rpm ppc64le: libkdcraw-4.10.5-5.el7.ppc64le.rpm libkdcraw-debuginfo-4.10.5-5.el7.ppc64le.rpm libkdcraw-devel-4.10.5-5.el7.ppc64le.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: libkdcraw-4.10.5-5.el7.src.rpm x86_64: libkdcraw-4.10.5-5.el7.i686.rpm libkdcraw-4.10.5-5.el7.x86_64.rpm libkdcraw-debuginfo-4.10.5-5.el7.i686.rpm libkdcraw-debuginfo-4.10.5-5.el7.x86_64.rpm libkdcraw-devel-4.10.5-5.el7.i686.rpm libkdcraw-devel-4.10.5-5.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2018-5800 https://access.redhat.com/security/cve/CVE-2018-5801 https://access.redhat.com/security/cve/CVE-2018-5802 https://access.redhat.com/security/cve/CVE-2018-5805 https://access.redhat.com/security/cve/CVE-2018-5806 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.6_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBW9gQLNzjgjWX9erEAQg7UhAAnh++yW3SuJ1Aex938RaQzFbumI95KXv6 JR4yYvjA5hNUomkjV353TlbNSAN2Nb6m68INXHEj33et6AmRYoWzxcZInvX/DwZp mubqxnOEXFglhq95uYRU6z2zNOVD/9WomD3UHuBKbp8EOGrhbBOa2i8cbdyTOOeP m+J4lSkW4HciuOWxrJon2puF+JIaMsCTYgb88a9DOJIFCg29K9jYg2cXDHtpiDjP XFK2N1pvxgnRhfMaHuVo5dNcdc7Fkg6IfVineWE0aR9JsR3AxewBg99t2uWEHqxw C+ThzEcFUy3tF5hppfY5Yr3jEqBA6XE3a/vPum6hClZVCPxZ6bkkmQqzzJYWULka V2wBcSRkdItL++F6OMVr29JsNIO7vlo1jf8ac+LfAFk8oLkcoy1SgHJWKGozi95e 7PVPoOt15pqNy0dS5DmIkrti4Zl2RJcx24dSf6Z/JofjOTo4KqbBb/cQrTuusShH Izg0EbBE8j94xjKlPHvjCKZfq71xRpaBOZfMP4jc34cH5P2otNFBwL4fOEBsvp6i 55TGnETNU3euvMuTqqb4rDwte/niXn3AzJXlqrE79701C3TRNstSW3noHrb8sRET J+QJUtgeICCsNLOvuUAJBiEKCfdwatrToZSwcVjd/pKb8u/NfRyt9wd3aL7K51d8 MfIVFJoq0vU=EkDe -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest advisory from Red Hat outlines a security patch for libkdcraw, resolving various reported vulnerabilities. Discover further details.. Red Hat Security, Libkdcraw Update, Moderate Advisory, Buffer Overflow Fix. . LinuxSecurity.com Team

Calendar%202 Oct 30, 2018 Red Hat
172

Ubuntu 12.04 LTS USN-1978-1 Critical: libKDcraw Denial of Service

libKDcraw could be made to crash if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1978-1 September 30, 2013 libkdcraw vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: libKDcraw could be made to crash if it opened a specially crafted file. Software Description: - libkdcraw: RAW picture decoding library Details: It was discovered that libKDcraw incorrectly handled photo files. If a user or automated system were tricked into processing a specially crafted photo file, applications linked against libKDcraw could be made to crash, resulting in a denial of service. (CVE-2013-1438, CVE-2013-1439) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libkdcraw20 4:4.8.5-0ubuntu0.3 After a standard system update you need to restart your session to make all the necessary changes. References: CVE-2013-1438, CVE-2013-1439 Package Information: https://launchpad.net/ubuntu/+source/libkdcraw/4:4.8.5-0ubuntu0.3 . An update notice for Ubuntu 12.04 LTS highlights improvements for libkdcraw to address stability problems triggered by maliciously designed files.. libKDcraw Fix, Ubuntu Update, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 30, 2013 Critical Ubuntu
91

Gentoo: GLSA-202310-15 Normal: libpng and libjpeg Issues

Multiple vulnerabilities have been found in LibRaw and libkdcraw, the worst of which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201309-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: LibRaw, libkdcraw: Multiple vulnerabilities Date: September 15, 2013 Bugs: #471694, #482926 ID: 201309-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in LibRaw and libkdcraw, the worst of which may lead to arbitrary code execution. Background ========= LibRaw is a library for reading RAW files obtained from digital photo cameras. libkdcraw is a wrapper for LibRaw within KDE. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libraw < 0.15.4 > = 0.15.4 2 kde-base/libkdcraw < 4.10.5-r1 > = 4.10.5-r1 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in LibRaw and libkdcraw. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could entice a user to open a specially crafted file, possibly resulting in arbitrary code execution or Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All LibRaw users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libraw-0.15.4" All libkdcrawusers should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =kde-base/libkdcraw-4.10.5-r1" References ========= [ 1 ] CVE-2013-1438 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1438 [ 2 ] CVE-2013-1439 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1439 [ 3 ] CVE-2013-2126 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2126 [ 4 ] CVE-2013-2127 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-2127 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201309-09 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2013 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical flaws in LibRaw and libkdcraw may result in arbitrary code execution or denial-of-service attacks, necessitating urgent updates for Gentoo users.. Gentoo Linux Security, LibRaw Update, libkdcraw Advisory. . LinuxSecurity.com Team

Calendar%202 Sep 15, 2013 Gentoo
172

Ubuntu 12.04 LTS USN-1885-1 High: libKDcraw Denial Of Service

libKDcraw could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1885-1 June 18, 2013 libkdcraw vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 LTS Summary: libKDcraw could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libkdcraw: RAW picture decoding library Details: It was discovered that libKDcraw incorrectly handled broken full-color images. If a user or automated system were tricked into processing a specially crafted raw image, applications linked against libKDcraw could be made to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 LTS: libkdcraw20 4:4.8.5-0ubuntu0.2 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1885-1 CVE-2013-2126 Package Information: https://launchpad.net/ubuntu/+source/libkdcraw/4:4.8.5-0ubuntu0.2 . The libKDcraw flaw in Ubuntu can lead to system crashes or unauthorized code execution, impacting version 12.04 LTS.. libKDcraw, Ubuntu patch, denial of service. . LinuxSecurity.com Team

Calendar%202 Jun 18, 2013 Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200