Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
100

SUSE: 2022:3730-2 Critical: libosip2 Buffer Overflow Patch

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3724-1 Rating: important References: #1204225 Cross-References: CVE-2022-41550 CVSS scores: CVE-2022-41550 (NVD) : 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVE-2022-41550 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Desktop 12-SP5 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Linux Enterprise Software Development Kit 12-SP5 SUSE Linux Enterprise Workstation Extension 12-SP5 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libosip2 fixes the following issues: - CVE-2022-41550: Fixed an integer overflow in osip_body_parse_header (bsc#1204225). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Workstation Extension 12-SP5: zypper in -t patch SUSE-SLE-WE-12-SP5-2022-3724=1 - SUSE Linux Enterprise Software Development Kit 12-SP5: zypper in -t patch SUSE-SLE-SDK-12-SP5-2022-3724=1 Package List: - SUSE Linux Enterprise Workstation Extension 12-SP5 (x86_64): libosip2-3.5.0-21.3.1 libosip2-debuginfo-3.5.0-21.3.1 libosip2-debugsource-3.5.0-21.3.1 - SUSE Linux Enterprise Software Development Kit 12-SP5 (aarch64 ppc64le s390x x86_64): libosip2-3.5.0-21.3.1 libosip2-debuginfo-3.5.0-21.3.1 libosip2-debugsource-3.5.0-21.3.1 libosip2-devel-3.5.0-21.3.1 References: https://www.suse.com/security/cve/CVE-2022-41550.html https://bugzilla.suse.com/1204225 . SUSE has released a security update for libosip2 addressing an integer overflow vulnerability, categorized with a high importance rating.. libosip2 Update,SUSE Security Advisory,Important Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 25, 2022 Important SuSE
203

Mageia 8: MGASA-2022-0389 Critical: Libosip2 Integer Overflow

GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. (CVE-2022-41550) References: - https://bugs.mageia.org/show_bug.cgi?id=30963 . MGASA-2022-0389 - Updated libosip2 packages fix security vulnerability Publication date: 23 Oct 2022 URL: https://advisories.mageia.org/MGASA-2022-0389.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-41550 GNU oSIP v5.3.0 was discovered to contain an integer overflow via the component osip_body_parse_header. (CVE-2022-41550) References: - https://bugs.mageia.org/show_bug.cgi?id=30963 - - https://www.cve.org/CVERecord?id=CVE-2022-41550 SRPMS: - 8/core/libosip2-5.0.0-4.1.mga8 . The security patch MGASA-2022-0389 for libosip2 tackles an integer overflow flaw found in GNU oSIP.. Mageia, Libosip2, Integer Overflow, Security Update, MGASA-2022-0389. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 23, 2022 Critical Mageia
202

openSUSE: 2022:10147-1 Important Libosip2 Integer Overflow Fix

An update that fixes one vulnerability is now available. . openSUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2022:10147-1 Rating: important References: #1204225 Cross-References: CVE-2022-41550 CVSS scores: CVE-2022-41550 (SUSE): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: openSUSE Backports SLE-15-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for libosip2 fixes the following issues: - CVE-2022-41550: Fixed an integer overflow in the header parser (boo#1204225) Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP4: zypper in -t patch openSUSE-2022-10147=1 Package List: - openSUSE Backports SLE-15-SP4 (aarch64 i586 ppc64le s390x x86_64): libosip2-12-5.2.1-bp154.2.3.1 libosip2-devel-5.2.1-bp154.2.3.1 References: https://www.suse.com/security/cve/CVE-2022-41550.html https://bugzilla.suse.com/1204225 . An update for openSUSE addressing a critical integer overflow vulnerability in libosip2 is now available. Please install the most recent patch immediately.. openSUSE Security Updates, Libosip2 Integer Overflow, Important Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 13, 2022 Important OpenSUSE
87

Debian: DSA-3879-1 Critical: libosip2 Denial of Service Issues

Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian Security Advisory DSA-3879-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Moritz Muehlenhoff June 13, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libosip2 CVE ID : CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 Multiple security vulnerabilities have been found in oSIP, a library implementing the Session Initiation Protocol, which might result in denial of service through malformed SIP messages. For the stable distribution (jessie), these problems have been fixed in version 4.1.0-2+deb8u1. For the upcoming stable distribution (stretch), these problems have been fixed in version 4.1.0-2.1. For the unstable distribution (sid), these problems have been fixed in version 4.1.0-2.1. We recommend that you upgrade your libosip2 packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent updates for libosip2 are necessary due to several vulnerabilities in the oSIP library, ensuring a more secure Debian setup.. libosip2 Update, Debian Security Advisory, Denial Of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 13, 2017 Critical Debian
202

openSUSE Leap 42.2 Important: libosip2 Heap Overflow DoS Threat

An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. openSUSE Security Update: Security update for libosip2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2017:1127-1 Rating: important References: #1034570 #1034571 #1034572 #1034574 Cross-References: CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 Affected Products: openSUSE Leap 42.2 openSUSE Leap 42.1 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: This update for libosip2 fixes the following issues: Changes in libosip2: - CVE-2017-7853: In libosip2 in GNU 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS. (boo#1034570) - CVE-2016-10326: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. (boo#1034571) - CVE-2016-10325: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. (boo#1034572) - CVE-2016-10324: In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. (boo#1034574) Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE Leap 42.2: zypper in -t patchopenSUSE-2017-526=1 - openSUSE Leap 42.1: zypper in -t patch openSUSE-2017-526=1 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE Leap 42.2 (x86_64): libosip2-4.1.0-5.3.1 libosip2-debuginfo-4.1.0-5.3.1 libosip2-debugsource-4.1.0-5.3.1 libosip2-devel-4.1.0-5.3.1 - openSUSE Leap 42.1 (i586 x86_64): libosip2-4.1.0-5.1 libosip2-debuginfo-4.1.0-5.1 libosip2-debugsource-4.1.0-5.1 libosip2-devel-4.1.0-5.1 References: https://www.suse.com/security/cve/CVE-2016-10324.html https://www.suse.com/security/cve/CVE-2016-10325.html https://www.suse.com/security/cve/CVE-2016-10326.html https://www.suse.com/security/cve/CVE-2017-7853.html https://bugzilla.suse.com/1034570 https://bugzilla.suse.com/1034571 https://bugzilla.suse.com/1034572 https://bugzilla.suse.com/1034574 . Important patch for Fedora fixes severe vulnerabilities in libosip2, improving overall system reliability and security.. openSUSE Update, libosip2 Patch, Security Fixes, Critical Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 28, 2017 Important OpenSUSE
197

Debian 7: DLA-898-1 Critical: libosip2 Heap Overflow DoS Threat

CVE-2016-10324 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in . Hash: SHA512 Package : libosip2 Version : 3.6.0-4+deb7u1 CVE ID : CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2017-7853 CVE-2016-10324 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_clrncpy() function defined in osipparser2/osip_port.c. CVE-2016-10325 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the _osip_message_to_str() function defined in osipparser2/osip_message_to_str.c, resulting in a remote DoS. CVE-2016-10326 In libosip2 in GNU oSIP 4.1.0, a malformed SIP message can lead to a heap buffer overflow in the osip_body_to_str() function defined in osipparser2/osip_body.c, resulting in a remote DoS. CVE-2017-7853 In libosip2 in GNU oSIP 5.0.0, a malformed SIP message can lead to a heap buffer overflow in the msg_osip_body_parse() function defined in osipparser2/osip_message_parse.c, resulting in a remote DoS. For Debian 7 "Wheezy", these problems have been fixed in version 3.6.0-4+deb7u1. We recommend that you upgrade your libosip2 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libosip2 to address heap buffer overflow vulnerabilities in Debian 7 stemming from improperly formatted SIP communications. Urgent security patch required.. Debian Security, libosip2 Update, DoS Threats, Buffer Overflow Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 16, 2017 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here