Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
203

Mageia: 2020-0062 Moderate: Libmp4v2 Integer Underflow And Overflow

Updated libmp4v2 packages fix security vulnerabilities: The libmp4v2 library through version 2.1.0 is vulnerable to an integer underflow when parsing an MP4Atom in mp4atom.cpp. An attacker could exploit this to cause a denial of service via crafted MP4 file (CVE-2018-14325). . MGASA-2020-0062 - Updated libmp4v2 packages fix security vulnerabilities Publication date: 28 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0062.html Type: security Affected Mageia releases: 7 CVE: CVE-2018-14325, CVE-2018-14326, CVE-2018-14379, CVE-2018-14403, CVE-2018-14446 Updated libmp4v2 packages fix security vulnerabilities: The libmp4v2 library through version 2.1.0 is vulnerable to an integer underflow when parsing an MP4Atom in mp4atom.cpp. An attacker could exploit this to cause a denial of service via crafted MP4 file (CVE-2018-14325). The libmp4v2 library through version 2.1.0 is vulnerable to an integer overflow and resultant heap-based buffer overflow when resizing an MP4Array for the ftyp atom in mp4array.h. An attacker could exploit this to cause a denial of service via crafted MP4 file (CVE-2018-14326). MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted MP4 file, because access to the data structure has different expectations about layout as a result of this type confusion (CVE-2018-14379). MP4NameFirstMatches in mp4util.cpp in MP4v2 2.0.0 mishandles substrings of atom names, leading to use of an inappropriate data type for associated atoms. The resulting type confusion can cause out-of-bounds memory access (CVE-2018-14403). MP4Integer32Property::Read in atom_avcC.cpp in MP4v2 2.1.0 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted MP4 file(CVE-2018-14446). References: - https://bugs.mageia.org/show_bug.cgi?id=25962 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/6YCHVOYPIBGM5HYUMQ77KZH2IHSITKVE/ - https://www.cve.org/CVERecord?id=CVE-2018-14325 - https://www.cve.org/CVERecord?id=CVE-2018-14326 - https://www.cve.org/CVERecord?id=CVE-2018-14379 - https://www.cve.org/CVERecord?id=CVE-2018-14403 - https://www.cve.org/CVERecord?id=CVE-2018-14446 SRPMS: - 7/core/libmp4v2-2.1.0-0.4.mga7 . MGASA-2020-0063 pertains to vulnerabilities in libpng that can impact Mageia 8. Safeguard against potential exploitation risks.. libmp4v2, security update, Mageia, integer overflow, buffer overflow. . LinuxSecurity.com Team

Calendar 2 Jan 28, 2020 Mageia
203

Mageia 6 MGASA-2019-0048 Critical: libmp4v2 Double Free Issue

This release address a potential security issue in libmp4v2 for Mageia 6: CVE-2018-14054: libmp4v2: Double free in the MP4StringProperty class in mp4property.cpp References: . MGASA-2019-0048 - Updated libmp4v2 packages fix security vulnerability Publication date: 23 Jan 2019 URL: https://advisories.mageia.org/MGASA-2019-0048.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-14054 This release address a potential security issue in libmp4v2 for Mageia 6: CVE-2018-14054: libmp4v2: Double free in the MP4StringProperty class in mp4property.cpp References: - https://bugs.mageia.org/show_bug.cgi?id=24175 - https://www.openwall.com/lists/oss-security/2019/01/09/2 - https://www.cve.org/CVERecord?id=CVE-2018-14054 SRPMS: - 6/core/libmp4v2-2.0.0-9.1.mga6 . MGASA-2019-0048 - Updated libmp4v2 packages fix security vulnerability Publication date: 23 Jan 2019. libmp4v2, release, address, potential, security, mageia, cve-2018-14054. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 23, 2019 Critical Mageia
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here