Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":2,"type":"x","order":1,"pct":25,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
203

Mageia 10 libneon Important Davfs2 Mount Adjustment Alert 2026-0051

Security update. Publication date: 16 Jul 2026 URL: https://advisories.mageia.org/MGAA-2026-0051.html Type: bugfix Affected Mageia releases: 10 Description: Update of libneon fixes davfs2 not being able to mount as an ordinary user. References: - https://bugs.mageia.org/show_bug.cgi?id=35770 SRPMS: - 10/core/libneon-0.36.0-1.1.mga10 . A security update for Mageia that addresses the mounting issue with davfs2 for users. Learn more about it here.. Mageia libneon update security mount issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 15, 2026 Important Mageia
91

Gentoo: GLSA 200406-03 Normal: Multiple Libneon Risks in Sitecopy

sitecopy includes a vulnerable version of the neon library.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200406-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: sitecopy: Multiple vulnerabilities in included libneon Date: June 05, 2004 Bugs: #51585 ID: 200406-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= sitecopy includes a vulnerable version of the neon library. Background ========= sitecopy easily maintains remote websites. It makes it simple to keep a remote site synchronized with the local site with one command. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/sitecopy

Calendar%202 Jun 05, 2004 Gentoo
91

Gentoo GLSA-200405-25 Normal: tla Heap Overflow In libneon

tla includes a vulnerable version of the neon library.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: tla: Heap-based buffer overflow in included libneon Date: May 30, 2004 Bugs: #51586 ID: 200405-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= tla includes a vulnerable version of the neon library. Background ========= GNU Arch (tla) is a revision control system suited for widely distributed development. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/tla < 1.2.1_pre1 > = 1.2.1_pre1 Description ========== Stefan Esser discovered a vulnerability in the code of the neon library (GLSA 200405-13): if a malicious date string is passed to the ne_rfc1036_parse() function, it can trigger a string overflow into static heap variables. tla includes it's own version of the library. Impact ===== When connected to a malicious WebDAV server, this vulnerability could allow execution of arbitrary code with the rights of the user running tla. Workaround ========= There is no known workaround at this time. Resolution ========= All users of tla should upgrade to the latest stable version: # emerge sync # emerge -pv "> =dev-util/tla-1.2.1_pre1" # emerge "> =dev-util/tla-1.2.1_pre1" References ========= [ 1 ] GLSA 200405-13 https://security.gentoo.org/glsa/200405-13 Availability =========== This GLSA andany updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200405-25 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Technologies, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Using GnuPG with Mozilla - iD8DBQFAuk10vcL1obalX08RAklNAJ9uzVdVB672bZA1g4Yvzh6wdYYGYgCfTTbO FjznYZungR0LfQiTV5UnlMY=HYAf -----END PGP SIGNATURE----- . Buffer overflow vulnerability in TLA's neon module on Gentoo systems may allow remote code execution from compromised servers. Immediate update advised!. Gentoo Security Advisory,tla Update,Neon Library Code. . LinuxSecurity.com Team

Calendar%202 May 30, 2004 Gentoo
91

Gentoo: GLSA-200405-01 Normal: libneon Format String Code Execution

There are multiple format string vulnerabilities in libneon which may allow a malicious WebDAV server to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Multiple format string vulnerabilities in neon 0.24.4 and earlier Date: May 09, 2004 Bugs: #48448 ID: 200405-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= There are multiple format string vulnerabilities in libneon which may allow a malicious WebDAV server to execute arbitrary code. Background ========= neon provides an HTTP and WebDAV client library. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/neon = 0.24.5 Description ========== There are multiple format string vulnerabilities in libneon which may allow a malicious WebDAV server to execute arbitrary code under the context of the process using libneon. Impact ===== An attacker may be able to execute arbitrary code under the context of the process using libneon. Workaround ========= A workaround is not currently known for this issue. All users are advised to upgrade to the latest version of the affected package. Resolution ========= Neon users should upgrade to version 0.24.5 or later: # emerge sync # emerge -pv "> =net-misc/neon-0.24.5" # emerge "> =net-misc/neon-0.24.5" References ========= [ 1 ] CVE https://www.cve.org/CVERecord?id=CVE-CAN-2004-0179 Availability =========== This GLSA and any updates to it areavailable for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200405-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Technologies, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ . Gentoo GLSA-202312-01 highlights various vulnerabilities in libneon related to format strings that could compromise security. An upgrade is advised.. libneon vulnerabilities,Gentoo security,format string exploit,webdav security. . LinuxSecurity.com Team

Calendar%202 May 09, 2004 Gentoo
87

Debian neon Critical Format String Remote Exec Vulnerability DSA 487-1

These vulnerabilities could exploited by a malicious WebDAV server to execute arbitrary code with libneon's privileges.. Debian Security Advisory DSA 487-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman April 16th, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : neon Vulnerability : format string Problem-Type : remote Debian-specific: no CVE Ids : CAN-2004-0179 Multiple format string vulnerabilities were discovered in neon, an HTTP and WebDAV client library. These vulnerabilities could potentially be exploited by a malicious WebDAV server to execute arbitrary code with the privileges of the process using libneon. For the current stable distribution (woody) these problems have been fixed in version 0.19.3-2woody3. For the unstable distribution (sid), these problems have been fixed in version 0.24.5-1. We recommend that you update your neon package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 582 4753d19632b3ba69e7d97f61b21da8b1 Size/MD5 checksum: 4081 6ed8f310baae56db47a34f3affdf0dd5 Size/MD5 checksum: 499574 9dbb8c276e5fc58a707b6e908abdce63 Alpha architecture: Size/MD5 checksum: 122054 f8455a4aca0ad0eed97b8635f7552ecc Size/MD5 checksum: 77894 12283440f135e0b68b328151c78d5240 ARM architecture: Size/MD5 checksum: 100820 6ac65c11b484429f9f388ae0bab9136c Size/MD5 checksum: 70256 d16830700754df93ec06fcc72d952be6 Intel IA-32 architecture: Size/MD5 checksum: 94820 7a7f0c168b101390a619ffde40f9efc3 Size/MD5 checksum: 65780 b72a10b0dbcbfb149b36b3053627a9d2 Intel IA-64 architecture: Size/MD5 checksum: 131246 dda199f3b1d6598bb8aa2f6ba37521d4 Size/MD5 checksum: 96250 043f6b4d3eb394bcaa2b7dda6a78b676 HP Precision architecture: Size/MD5 checksum: 118574 d7904398181654ebc8eab408a2d96cec Size/MD5 checksum: 80776 fdb1f1e337ee50318cbccfeeda0ec32f Motorola 680x0 architecture: Size/MD5 checksum: 93110 7993e9e642cbefb27ea6a7085615bb55 Size/MD5 checksum: 67668 fc37364b5b44454a637b69b591ce8c04 Big endian MIPS architecture: Size/MD5 checksum: 110704 3fbe497c5ac44aee13457fcfe9b785cf Size/MD5 checksum: 68644 29c7188a9dfe0da26a218eea6714997b Little endian MIPS architecture: Size/MD5 checksum: 110502 73eb5e6338f9ce6f5fd0c0cd27cbac48 Size/MD5 checksum: 68626 f85bcdab3e2957d53f00569966eaa3b6 PowerPC architecture: Size/MD5 checksum: 107168 c1994dba85b7e2150b1419fd4da44a14 Size/MD5 checksum: 71544 5e1812c5242835b7567d3549a334d9d8 IBM S/390 architecture: Size/MD5 checksum: 96930 022ad2200a279efc9ab1482e599b47d3 Size/MD5 checksum: 70958 632017c6cd495f5a35a3ced63f2bab88 Sun Sparc architecture: Size/MD5 checksum: 102406 d3e5c72b6de6f90f2272c62d4ee3c88c Size/MD5 checksum: 70812 c36ba230074c19cb6a58b76da986767d These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailinglist: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical Debian Security Advisory DSA 487-1 reveals format string issues allowing remote code execution with libneon's privileges.. Debian Security Advisory, Format String, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 17, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":2,"type":"x","order":1,"pct":25,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200