Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
100

SUSE Linux 11-SP4: 2018:1471-1 Moderate: Libmikmod Buffer Overflow

An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for libmikmod ______________________________________________________________________________ Announcement ID: SUSE-SU-2018:1471-1 Rating: moderate References: #625547 Cross-References: CVE-2009-3995 CVE-2010-2546 Affected Products: SUSE Linux Enterprise Software Development Kit 11-SP4 SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for libmikmod fixes the following issues: - CVE-2010-2546: Multiple heap-based buffer overflows in loaders/load_it.c in libmikmod, might allow remote attackers to execute arbitrary code via (1) crafted samples or (2) crafted instrument definitions in an Impulse Tracker file, related to panpts, pitpts, and IT_ProcessEnvelope. NOTE: some of these details are obtained from third party information. NOTE: this vulnerability exists because of an incomplete fix for CVE-2009-3995. (bsc#625547). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Software Development Kit 11-SP4: zypper in -t patch sdksp4-libmikmod-13630=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-libmikmod-13630=1 Package List: - SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64): libmikmod-3.1.11a-116.2.3.1 libmikmod-devel-3.1.11a-116.2.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64): libmikmod-debuginfo-3.1.11a-116.2.3.1 libmikmod-debugsource-3.1.11a-116.2.3.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (x86_64): libmikmod-debuginfo-32bit-3.1.11a-116.2.3.1 References: https://www.suse.com/security/cve/CVE-2009-3995.html https://www.suse.com/security/cve/CVE-2010-2546.html https://bugzilla.suse.com/625547 . SUSE Security Patch for libmikmod tackles moderate security flaws, offering a comprehensive repair instruction manual.. SUSE Linux, libmikmod, security update, software development, patch management. . LinuxSecurity.com Team

Calendar 2 May 30, 2018 SuSE
91

Gentoo: GLSA-201203-10 Moderate: libmikmod Denial of Service

Multiple buffer overflow vulnerabilities in libmikmod may allow an attacker to execute arbitrary code or cause a Denial of Service condition. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201203-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: libmikmod: User-assisted execution of arbitrary code Date: March 06, 2012 Bugs: #335892 ID: 201203-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple buffer overflow vulnerabilities in libmikmod may allow an attacker to execute arbitrary code or cause a Denial of Service condition. Background ========= libmikmod is a library to play a wide range of module formats. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libmikmod < 3.2.0_beta2-r3 > = 3.2.0_beta2-r3 *> = 3.1.12-r1 Description ========== Multiple boundary errors have been found in load_it.c in libmikmod, which may cause a buffer overflow. Impact ===== A remote attacker could entice a user to open specially crafted files in an application linked against libmikmod, possibly resulting in execution of arbitrary code with the permissions of the user running the application, or Denial of Service. Workaround ========= There is no known workaround at this time. Resolution ========= All libmikmod 3.2 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot -v "> =media-libs/libmikmod-3.2.0_beta2-r3" All libmikmod 3.1 users should upgrade to thelatest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libmikmod-3.1.12-r1" Packages which depend on this library may need to be recompiled. Tools such as revdep-rebuild may assist in identifying some of these packages. References ========= [ 1 ] CVE-2010-2546 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2546 [ 2 ] CVE-2010-2971 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-2971 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201203-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2012 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Critical vulnerabilities identified in libmikmod; immediate update recommended to maintain system integrity per Gentoo advisory.. libmikmod Update, Buffer Overflow Fixes, Gentoo Advisory. . LinuxSecurity.com Team

Calendar 2 Mar 06, 2012 Gentoo
172

Ubuntu 8.04, 9.04, 9.10 USN-995-1 Critical: libMikMod DoS

It was discovered that libMikMod incorrectly handled songs with different channel counts. If a user were tricked into opening a crafted song file, an attacker could cause a denial of service. (CVE-2007-6720) [More...]. ==========================================================Ubuntu Security Notice USN-995-1 September 29, 2010 libmikmod vulnerabilities CVE-2007-6720, CVE-2009-0179, CVE-2009-3995, CVE-2009-3996, CVE-2010-2546, CVE-2010-2971 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 9.04 Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: libmikmod2 3.1.11-6ubuntu3.8.04.1 Ubuntu 9.04: libmikmod2 3.1.11-6ubuntu3.9.04.1 Ubuntu 9.10: libmikmod2 3.1.11-6ubuntu4.1 In general, a standard system update will make all the necessary changes. Details follow: It was discovered that libMikMod incorrectly handled songs with different channel counts. If a user were tricked into opening a crafted song file, an attacker could cause a denial of service. (CVE-2007-6720) It was discovered that libMikMod incorrectly handled certain malformed XM files. If a user were tricked into opening a crafted XM file, an attacker could cause a denial of service. (CVE-2009-0179) It was discovered that libMikMod incorrectly handled certain malformed Impulse Tracker files. If a user were tricked into opening a crafted Impulse Tracker file, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3995, CVE-2010-2546, CVE-2010-2971) It was discovered that libMikMod incorrectly handled certain malformed Ultratracker files. If a user were tricked into opening a crafted Ultratrackerfile, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2009-3996) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 339148 88b89686ec91f5173c6dd8b80ce8e64e Size/MD5: 730 9d56dccce0535ee3c48ca642da04705a Size/MD5: 611590 705106da305e8de191549f1e7393185c amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 266550 9200823b863117753bac8a1aae63c2ca Size/MD5: 155628 cff0d15986f092c78cda7bb3a657e1f6 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 244016 27453dd915f85ccd7dba0710ecab4acc Size/MD5: 146476 b67d8d50c02001e45eb618d51f4329a1 lpia architecture (Low Power Intel Architecture): Size/MD5: 248392 706f9438583e4364b4265ec8d8543bc4 Size/MD5: 148608 5c727d7e661e44044017cb7bd6ab3402 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 285392 c4ebd492d87451cc2979554da7e6fa34 Size/MD5: 173928 e45de26f887292b7482eca418459e60c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 258120 702fbd120d05a9f1d645f85ec45ea211 Size/MD5: 148446 029492bfe2015986538e1f141ab51f93 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 338916 a771044f7ddf578a1618e1667effd243 Size/MD5: 1150 031a6ed819b4e9f59dc4614f42f91109 Size/MD5: 611590 705106da305e8de191549f1e7393185c amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 265286 5189d1d5a185819b8f0a3860fd3ecc2b Size/MD5: 156988 f76e952924eceebdde01d9671f96b9b9 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 244312 00502a3a984d2b40bffdf46d016caa20 Size/MD5: 147096 8cb46dd80877e60c1300e0b471a42cba lpia architecture (Low Power Intel Architecture): Size/MD5: 24781833fa14fe4ee9a538eb1c998928a302ab Size/MD5: 148464 75e5cde38085b939f4c3ad709f2a6b0d powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 281656 34e746a50fbd0acd34192b9e899e161f Size/MD5: 172672 69ec0a2145ea106602c2f3fa454bc346 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 255260 70cb1b7d5521b00ae993686d9336bb12 Size/MD5: 149422 d9e458beb786bbe71ecbf51f3ba6e758 Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 338972 b044cd4c0262d4d38fc94de90fb520d4 Size/MD5: 1130 1feb8d8fcb433337e8ddad65e2076e4a Size/MD5: 611590 705106da305e8de191549f1e7393185c amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 267300 627cc54b1a4b2ed57ae5c1de295e614c Size/MD5: 157340 c36998f34e2807dbb8af42934b8ede5e i386 architecture (x86 compatible Intel/AMD): Size/MD5: 244300 063e16e7e89f79a9d8b457a3881b5820 Size/MD5: 148654 615e8ada1a87f7aee7e5ccd51c2dca4e lpia architecture (Low Power Intel Architecture): Size/MD5: 247994 fe717add1af434a346b59982f5e3c7c5 Size/MD5: 151404 e13a0f651953441fc9cc5958ef874d0d powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 281960 9199bd4701581881b31df45c5ede258f Size/MD5: 174950 ad1450f700117577ddede6fc3755d5da sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 260378 cd74bc83de2b60ed9cf4fc442e0352e1 Size/MD5: 152910 b684a3227432d45c220bb1378a4ed3d7 . ==========================================================Ubuntu Security Notice USN-995-1 September. libmikmod, incorrectly, handled, songs, different, channel, counts. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 29, 2010 Critical Ubuntu
87

Debian: DSA-2082-2 Urgent: Libxslt Remote Code Execution Risk

Tomas Hoger discovered that the upstream fix for CVE-2009-3995 was insufficient. This update provides a corrected package. For the stable distribution (lenny), this problem has been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2081-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff August 01, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : libmikmod Vulnerability : buffer overflow Problem type : local(remote) Debian-specific: no CVE Id(s) : CVE-2010-2546 Tomas Hoger discovered that the upstream fix for CVE-2009-3995 was insufficient. This update provides a corrected package. For the stable distribution (lenny), this problem has been fixed in version 3.1.11-6.0.1+lenny1. For the unstable distribution (sid), these problems have been fixed in version 3.1.11-6.3. We recommend that you upgrade your libmikmod packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 336967 ca68ebbfb298a9c14a336cc5f7b6e2be Size/MD5 checksum: 611590 705106da305e8de191549f1e7393185c Size/MD5 checksum: 1054 3adf23f76d6b836353eb083894b2edda alpha architecture (DEC Alpha) Size/MD5 checksum: 378792 9b14009df43780c2ab59a463166ebb79 Size/MD5 checksum: 221884 a42979a1da367c4f69900d3bf1ae9b39 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 157322 ce474be591039ff4be7d5ee135843826 Size/MD5 checksum: 265884 110914191600ae14129f7eb19d0b1bcd arm architecture (ARM) Size/MD5 checksum: 264304 826fb250128a4b1ae4e162905511325c Size/MD5 checksum: 164188 fe126f9049055da0488c99c0a1302188 armel architecture (ARM EABI) Size/MD5 checksum: 156030 fc6c72a6f744a7a91d4bf03ff80d05aa Size/MD5 checksum: 254782 a87e79aff815b07d268e72ce3339580a hppa architecture (HP PA RISC) Size/MD5 checksum: 185908 bfd2bef7c32052a0e86034fb1b53c842 Size/MD5 checksum: 299318 cbc4ccf6d266dba38584d207264ad01c i386 architecture (Intel ia32) Size/MD5 checksum: 244670 b1b25246bbbd3cf9a7da0c69e2f4f2d0 Size/MD5 checksum: 147386 a12b38dc7073d64ff37c6703815bc116 ia64 architecture (Intel ia64) Size/MD5 checksum: 264660 4a4051d527d120ffd545a0c088c483f0 Size/MD5 checksum: 395202 1f1f581e859df98e23ef05ba53fe68a8 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 291244 d9d41f15a064b0dd9735c7ae0a998478 Size/MD5 checksum: 167322 a810e2fff330cfe4fe7fb0c16670bac2 powerpc architecture (PowerPC) Size/MD5 checksum: 173252 32d48dbf160ac85e0568daf8533699fc Size/MD5 checksum: 282846 5b9e5173f1d5ee31cbad0b62bba66a25 s390 architecture (IBM S/390) Size/MD5 checksum: 268638 a741a17fd11d265fff8420e4aaf34b62 Size/MD5 checksum: 172640 552690944cf6a7657a6ac226a3196230 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 150000 67f1bbe7204ac9fa77210a8d060b8a52 Size/MD5 checksum: 258350 16e8bd8c040d866080500a904129a77c These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updatesmain For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical vulnerability patched in libmikmod distributions for Debian; update guidelines provided.. libmikmod upgrade, Debian security, buffer overflow fix, software update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 01, 2010 Critical Debian
87

Debian 5.0 Lenny DSA-2071-1 Critical: Libmikmod Buffer Overflow Exploit

Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2071-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff July 14, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : libmikmod Vulnerability : buffer overflows Problem type : local(remote) Debian-specific: no CVE Id(s) : CVE-2009-3995 CVE-2009-3996 Dyon Balding discovered buffer overflows in the MikMod sound library, which could lead to the execution of arbitrary code if a user is tricked into opening malformed Impulse Tracker or Ultratracker sound files. For the stable distribution (lenny), these problems have been fixed in version 3.1.11-6+lenny1. For the unstable distribution (sid), these problems have been fixed in version 3.1.11-6.2. We recommend that you upgrade your libmikmod packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1038 9741350a41a54261dbf242f02aa325fd Size/MD5 checksum: 611590705106da305e8de191549f1e7393185c Size/MD5 checksum: 336630 4e4d04d2c9b5bcdd3edb3b04e683ea86 alpha architecture (DEC Alpha) Size/MD5 checksum: 221696 e01fb2f9c7e693ae7b0727a552da31a1 Size/MD5 checksum: 378570 dd8abb7da4195af53aed1e57750d2f1f amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 157216 b3836423b8875f21d5ae01d5f9b533c5 Size/MD5 checksum: 265776 935b94d522dd814337b06acd07184fb7 arm architecture (ARM) Size/MD5 checksum: 164040 f2fdc8c7f4c7f54ec75ffd179c98ddca Size/MD5 checksum: 264064 2eba8b4037ca117fc8920563d2b05ca3 armel architecture (ARM EABI) Size/MD5 checksum: 155766 916c6a467219ed4a5e0da68168c1e591 Size/MD5 checksum: 254664 77c56898614f92c30e0ad5ef2de7c0cc hppa architecture (HP PA RISC) Size/MD5 checksum: 185910 6b044e5ce0fb2de4fc37a8ddbbd037a0 Size/MD5 checksum: 299236 40db7231bf6258319f45412c1d46df50 i386 architecture (Intel ia32) Size/MD5 checksum: 244570 c4363c834307008b053bb1899a13013f Size/MD5 checksum: 147266 3d8adb8a243afb7a614052ba7494e01e ia64 architecture (Intel ia64) Size/MD5 checksum: 264426 c2d6c1a0d1b32ff27030ec2f1cd3ebe4 Size/MD5 checksum: 391590 39c904baed7a4462ccbf10805cae88c0 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 167728 708a04685879d374730d4b94dd87a7d8 Size/MD5 checksum: 292908 f52fce4500f59af99befc30fab46d48d mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 291132 c1c7fa74ce5a2d4e580aae5f5db21b8d Size/MD5 checksum: 167172 65bd1438a4cac985a0dc555f9b0eb54f powerpc architecture (PowerPC) Size/MD5 checksum: 284010 0d98c66f1cbc9c34f87d1c9721fa7681 Size/MD5 checksum: 173082 a953d970966c47adc2d55d2c5959835b s390 architecture (IBM S/390) Size/MD5 checksum: 172646 e10ca9b6552459194a6d6d46799103dd Size/MD5 checksum: 268534 98768623fa899a4e2835dfced3b90d10 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 150056ed9837041b097d69e887eacce18917df Size/MD5 checksum: 256132 bb7c09b265c54f42447199100d626c32 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian addresses severe buffer overflow vulnerabilities in libmikmod, enabling potential execution of unauthorized code via corrupted audio files.. Debian Security, Buffer Overflows, libmikmod Update, Sound Library Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 14, 2010 Critical Debian
89

Fedora 11: 2009-9112 Moderate: Libmikmod Crash Resolved

. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9112 2009-08-28 21:17:00 -------------------------------------------------------------------------------- Name : libmikmod Product : Fedora 11 Version : 3.2.0 Release : 5.beta2.fc11 URL : Summary : A MOD music file player library Description : libmikmod is a library used by the mikmod MOD music file player for UNIX-like systems. Supported file formats include MOD, STM, S3M, MTM, XM, ULT and IT. -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 28 2009 Jindrich Novy 3.2.0-5.beta2 - fix CVE-2007-6720 (#479829) - fix CVE-2009-0179 (#479833) -------------------------------------------------------------------------------- References: [ 1 ] Bug #479829 - CVE-2007-6720 mikmod: crash or abort when loading/playing multiple files with different number of channels https://bugzilla.redhat.com/show_bug.cgi?id=479829 [ 2 ] Bug #479833 - CVE-2009-0179 mikmod: crash when loading XM files https://bugzilla.redhat.com/show_bug.cgi?id=479833 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libmikmod' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Explore the Fedora 11 patch notes concerning libmikmod, highlighting crucial resolutions for major stability problems.. libmikmodUpdate,Fedora 11 Fix,MICMOD Crash Issues,Open Source Music Library. . LinuxSecurity.com Team

Calendar 2 Aug 28, 2009 Fedora
89

Fedora: 2009-9095 Critical: Libmikmod Crash Issue Resolved

. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-9095 2009-08-28 21:16:30 -------------------------------------------------------------------------------- Name : libmikmod Product : Fedora 10 Version : 3.2.0 Release : 4.beta2.fc10 URL : Summary : A MOD music file player library Description : libmikmod is a library used by the mikmod MOD music file player for UNIX-like systems. Supported file formats include MOD, STM, S3M, MTM, XM, ULT and IT. -------------------------------------------------------------------------------- ChangeLog: * Fri Aug 28 2009 Jindrich Novy 3.2.0-4.beta2 - fix CVE-2007-6720 (#479829) - fix CVE-2009-0179 (#479833) -------------------------------------------------------------------------------- References: [ 1 ] Bug #479833 - CVE-2009-0179 mikmod: crash when loading XM files https://bugzilla.redhat.com/show_bug.cgi?id=479833 [ 2 ] Bug #479829 - CVE-2007-6720 mikmod: crash or abort when loading/playing multiple files with different number of channels https://bugzilla.redhat.com/show_bug.cgi?id=479829 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update libmikmod' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Essential patch for libmikmod resolving instability issues in FEDORA-2009-9095, crucial for audio playback capability in Fedora 10..libmikmod, Music Player, Fedora Update, Crash Fix, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 28, 2009 Critical Fedora
100

SUSE: 2009:006 Moderate: Curl DoS And Gtk2 Fixes Announcement

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2009:006 Date: Tue, 10 Mar 2009 15:00:00 +0000 Cross-References: CVE-2007-6720, CVE-2008-2364, CVE-2008-5101 CVE-2008-5347, CVE-2008-5348, CVE-2008-5349 CVE-2008-5350, CVE-2008-5351, CVE-2008-5352 CVE-2008-5353, CVE-2008-5354, CVE-2008-5356 CVE-2008-5357, CVE-2008-5358, CVE-2008-5359 CVE-2008-5360, CVE-2008-6393, CVE-2009-0037 CVE-2009-0179, CVE-2009-0749, CVE-2009-0848 Content of this advisory: 1) Solved Security Vulnerabilities: - curl - libmikmod - apache2 - optipng - psi - java-1_6_0-openjdk - gtk2 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for moresevere vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - curl When HTTP-redirect following was enabled curl followed any URL, even one to e.g. local files (CVE-2009-0037). Affected Products: openSUSE 10.3-11.1, SLES9, SLES10 - libmikmod Specially crafted XM files or playing mod files with varying number of channels could crash applications using libmikmod (CVE-2009-0179, CVE-2007-6720). Affected Products: openSUSE 10.3-11.1, SLES9, SLES10 - apache2 A DoS condition in apache2's mod_proxy has been fixed (CVE-2008-2364). Affected Products: SLES10 - optipng Specially crafted BMP files could overflow a buffer in optipng (CVE-2008-5101), specially crafted GIF files could crash optipng (CVE-2009-0749). Affected Products: openSUSE 10.3-11.1 - psi Remote attackers could crash the Psi instant messaging client via the file transfer port (CVE-2008-6393). Affected Products: openSUSE 10.3-11.1 - java-1_6_0-openjdk OpenJDK Java 1.6.0 was upgraded to build b14, fixing quite a lot of security issues. It fixes at least: 4486841 UTF8 decoder should adhere to corrigendum to Unicode 3.0.1 CVE-2008-5351 6484091 FileSystemView leaks directory info CVE-2008-5350 aka SUN SOLVE 246266 6497740 Limit the size of RSA public keys CVE-2008-5349 6588160 jaas krb5 client leaks OS-level UDP sockets (all platforms) CVE-2008-5348 6592792 Add com.sun.xml.internal to the "package.access" property in $JAVA_HOME/lib/security/java.security CVE-2008-5347 aka SUN SOLVE 246366 6721753 File.createTempFile produces guessable file names CVE-2008-5360 6726779 ConvolveOp on USHORT raster can cause the JVM crash. CVE-2008-5359 aka SUN SOLVE 244987 6733336 Crash on malformed font CVE-2008-5356 aka SUN SOLVE 244987 6733959 Insufficient checks for "Main-Class" manifest entry in JAR files CVE-2008-5354 aka SUN SOLVE 244990 6734167 Calendar.readObject allows elevation of privileges CVE-2008-5353 6751322 Vulnerability report: Sun Java JRE TrueType Font Parsing Heap Overflow CVE-2008-5357 aka SUN SOLVE 244987 6755943 Java JAR Pack200 Decompression should enforce stricter header checks CVE-2008-5352 aka SUN SOLVE 244992 6766136 corrupted gif image may cause crash in java splashscreen library. CVE-2008-5358 aka SUN SOLVE 244987 Affected Products: openSUSE 11.0,11.1 - gtk2 A SUSE specific patch to GTK2 accidentally added a relative search path for gtk modules therefore allowed local attackers have gtk programs load modules from untrusted places (CVE-2009-0848). Affected Products: openSUSE 11.0,11.1 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained inyour key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Summary Report Announcement ID: SUSE-SR:2023:052 provides information about resolved security issues and software enhancements..SUSE Security Summary,curl issue fix,apache DoS,libmikmod update,gtk2 security patch. . LinuxSecurity.com Team

Calendar 2 Mar 10, 2009 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here