Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
197

Debian Jessie: DLA-2168-1 Critical: libplist Memory Issues

libplist is a library for reading and writing the Apple binary and XML property lists format. It's part of the libimobiledevice stack, providing access to iDevices (iPod, iPhone, iPad ...). . Package : libplist Version : 1.11-3+deb8u1 CVE ID : CVE-2017-5209 CVE-2017-5545 CVE-2017-5834 CVE-2017-5835 CVE-2017-6435 CVE-2017-6436 CVE-2017-6439 CVE-2017-7982 Debian Bug : 851196 852385 854000 860945 libplist is a library for reading and writing the Apple binary and XML property lists format. It's part of the libimobiledevice stack, providing access to iDevices (iPod, iPhone, iPad ...). CVE-2017-5209 The base64decode function in base64.c allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data. CVE-2017-5545 The main function in plistutil.c allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. CVE-2017-5834 The parse_dict_node function in bplist.c allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. CVE-2017-5835 libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. CVE-2017-6435 The parse_string_node function in bplist.c allows local users to cause a denial of service (memory corruption) via a crafted plist file. CVE-2017-6436 The parse_string_node function in bplist.c allows local users to cause a denial of service (memory allocation error) via a crafted plist file. CVE-2017-6439 Heap-based buffer overflow in the parse_string_node function in bplist.c allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file. CVE-2017-7982 Integer overflow in the plist_from_bin function in bplist.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file. For Debian 8 "Jessie", these problems have been fixed in version 1.11-3+deb8u1. We recommend that you upgrade your libplist packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance libplist to version 1.11-3+deb8u1 to mitigate several security vulnerabilities and safeguard against data leaks.. libplist security, debian advisory, memory corruption, DoS, info disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Apr 02, 2020 Critical Debian LTS
99

Slackware 14.2: 2017-320-01 Moderate: Libplist Threat Fix

New libplist packages are available for Slackware 14.2 and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] libplist (SSA:2017-320-01) New libplist packages are available for Slackware 14.2 and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/libplist-2.0.0-i586-1_slack14.2.txz: Upgraded. This update fixes several security issues. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-6440 https://www.cve.org/CVERecord?id=CVE-2017-6439 https://www.cve.org/CVERecord?id=CVE-2017-6438 https://www.cve.org/CVERecord?id=CVE-2017-6437 https://www.cve.org/CVERecord?id=CVE-2017-6436 https://www.cve.org/CVERecord?id=CVE-2017-6435 https://www.cve.org/CVERecord?id=CVE-2017-5836 https://www.cve.org/CVERecord?id=CVE-2017-5835 https://www.cve.org/CVERecord?id=CVE-2017-5834 https://www.cve.org/CVERecord?id=CVE-2017-5545 https://www.cve.org/CVERecord?id=CVE-2017-5209 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/libplist-2.0.0-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/libplist-2.0.0-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 14.2 package: 3e2f07b94d23021ef78c81ec8ca10148 libplist-2.0.0-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 17e0490072a2374726f4311244f1d1c9 libplist-2.0.0-x86_64-1_slack14.2.txz Slackware -current package: bdf0b49378aa70133e740b9c4797e050 l/libplist-2.0.0-i586-1.txz Slackware x86_64 -current package: e5ac1fa583f9a9e2710c41d90c1100dd l/libplist-2.0.0-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg libplist-2.0.0-i586-1_slack14.2.txz +-----+ . Updated libplist modules for Slackware 14.2 and -current resolve multiple vulnerabilities, keeping your environment protected.. libplist packages, slackware upgrade, security patch. . LinuxSecurity.com Team

Calendar%202 Nov 17, 2017 Slackware
172

Ubuntu 17.04 USN-3429-1 Critical: Libplist Denial Of Service

Libplist could be made to crash if it opened a specially craftedfile.. =========================================================================Ubuntu Security Notice USN-3429-1 September 25, 2017 libplist vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Libplist could be made to crash if it opened a specially crafted file. Software Description: - libplist: Library for handling Apple binary and XML property lists Details: Wang Junjie discovered that Libplist incorrectly handled certain files. If a user were tricked into opening a crafted file, an attacker could possibly use this to cause a crash or denial or service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: libplist-utils 1.12-3.1ubuntu0.17.04.1 libplist3 1.12-3.1ubuntu0.17.04.1 python-plist 1.12-3.1ubuntu0.17.04.1 Ubuntu 16.04 LTS: libplist-utils 1.12-3.1ubuntu0.16.04.1 libplist3 1.12-3.1ubuntu0.16.04.1 python-plist 1.12-3.1ubuntu0.16.04.1 Ubuntu 14.04 LTS: libplist-utils 1.10-1ubuntu0.1 libplist1 1.10-1ubuntu0.1 python-plist 1.10-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3429-1 CVE-2017-7982 Package Information: https://launchpad.net/ubuntu/+source/libplist/1.12-3.1ubuntu0.17.04.1 https://launchpad.net/ubuntu/+source/libplist/1.12-3.1ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/libplist/1.10-1ubuntu0.1 . Keep your Ubuntu installations secure by applying the necessary updates to resolve the libplist vulnerability impacting several versions. Discover further details here.. libplist vulnerability, Denial Of Service, Ubuntu Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2017 Critical Ubuntu
198

Arch Linux: ASA-201705-18 High: libplist Remote Command Risks

The package libplist before version 2.0.0-1 is vulnerable to multiple issues including arbitrary command execution, denial of service and information disclosure. . Arch Linux Security Advisory ASA-201705-18 ========================================= Severity: High Date : 2017-05-16 CVE-ID : CVE-2017-5209 CVE-2017-5545 CVE-2017-5834 CVE-2017-5835 CVE-2017-5836 CVE-2017-6435 CVE-2017-6436 CVE-2017-6437 CVE-2017-6438 CVE-2017-6439 CVE-2017-6440 Package : libplist Type : multiple issues Remote : Yes Link : https://security.archlinux.org/AVG-215 Summary ====== The package libplist before version 2.0.0-1 is vulnerable to multiple issues including arbitrary command execution, denial of service and information disclosure. Resolution ========= Upgrade to 2.0.0-1. # pacman -Syu "libplist> =2.0.0-1" The problems have been fixed upstream in version 2.0.0. Workaround ========= None. Description ========== - CVE-2017-5209 (information disclosure) The base64decode function in base64.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via split encoded Apple Property List data. - CVE-2017-5545 (denial of service) The main function in plistutil.c in libimobiledevice libplist through 1.12 allows attackers to obtain sensitive information from process memory or cause a denial of service (buffer over-read) via Apple Property List data that is too short. - CVE-2017-5834 (denial of service) The parse_dict_node function in bplist.c in libplist allows attackersto cause a denial of service (out-of-bounds heap read and crash) via a crafted file. - CVE-2017-5835 (denial of service) libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. - CVE-2017-5836 (denial of service) The plist_free_data function in plist.c in libplist allows attackers to cause a denial of service (crash) via vectors involving aninteger node that is treated as a PLIST_KEY and then triggers an invalid free. - CVE-2017-6435 (denial of service) The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory corruption) via a crafted plist file. - CVE-2017-6436 (denial of service) The parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. - CVE-2017-6437 (denial of service) The base64encode function in base64.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds read) via a crafted plist file. - CVE-2017-6438 (arbitrary command execution) Heap-based buffer overflow in the parse_unicode_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) and possibly code execution via a crafted plist file. - CVE-2017-6439 (denial of service) Heap-based buffer overflow in the parse_string_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (out-of-bounds write) via a crafted plist file. - CVE-2017-6440 (denial of service) The parse_data_node function in bplist.c in libimobiledevice libplist 1.12 allows local users to cause a denial of service (memory allocation error) via a crafted plist file. Impact ===== An attacker is able to crash the process, read sensitive information or execute arbitrary code on the host by providing a crafted plist fileor string. References ========= https://github.com/libimobiledevice/libplist/issues/93 https://github.com/libimobiledevice/libplist/issues/94 https://github.com/libimobiledevice/libplist/issues/95 https://github.com/libimobiledevice/libplist/issues/99 https://github.com/libimobiledevice/libplist/issues/98 https://github.com/libimobiledevice/libplist/issues/100 https://github.com/libimobiledevice/libplist/blob/master/NEWS https://bugzilla.redhat.com/show_bug.cgi?id=1412613 https://bugzilla.redhat.com/show_bug.cgi?id=1416002 https://bugzilla.redhat.com/show_bug.cgi?id=1418591 https://bugzilla.redhat.com/show_bug.cgi?id=1418592 https://bugzilla.redhat.com/show_bug.cgi?id=1418593 https://security.archlinux.org/CVE-2017-5209 https://security.archlinux.org/CVE-2017-5545 https://security.archlinux.org/CVE-2017-5834 https://security.archlinux.org/CVE-2017-5835 https://security.archlinux.org/CVE-2017-5836 https://security.archlinux.org/CVE-2017-6435 https://security.archlinux.org/CVE-2017-6436 https://security.archlinux.org/CVE-2017-6437 https://security.archlinux.org/CVE-2017-6438 https://security.archlinux.org/CVE-2017-6439 https://security.archlinux.org/CVE-2017-6440 . The Arch Linux Security Notice ASA-202305-11 points out significant flaws in libxml2 requiring immediate rectification.. libplist issues, Arch Linux advisory, command risks. . LinuxSecurity.com Team

Calendar%202 May 17, 2017 ArchLinux
89

Fedora 24: libplist Security Advisory - Memory Issues and Updates

Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-3849af4477 2017-05-12 14:08:49.129401 --------------------------------------------------------------------------------Name : libplist Product : Fedora 24 Version : 2.0.0 Release : 1.fc24 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the different node types * Extend date/time range and date conversion issues * Add plist_is_binary() and plist_from_memory() functions to the interface * Plug several memory leaks * Speed improvements for handling large plist files Includes security fixes for: * CVE-2017-6440 * CVE-2017-6439 * CVE-2017-6438 * CVE-2017-6437 * CVE-2017-6436 * CVE-2017-6435 * CVE-2017-5836 * CVE-2017-5835 * CVE-2017-5834 * CVE-2017-5545 * CVE-2017-5209 ... and several others that didn't receive any CVE (yet). --------------------------------------------------------------------------------References: [1 ] Bug #1432965 - CVE-2017-6440 libplist: Memory allocation error in parse_data_node https://bugzilla.redhat.com/show_bug.cgi?id=1432965 [ 2 ] Bug #1432959 - CVE-2017-6439 libplist: Heap-based buffer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432959 [ 3 ] Bug #1432956 - CVE-2017-6438 libplist: Heap-based buffer overflow in parse_unicode_node https://bugzilla.redhat.com/show_bug.cgi?id=1432956 [ 4 ] Bug #1432954 - CVE-2017-6437 libplist: Out-of-bounds heap read in base64encode function https://bugzilla.redhat.com/show_bug.cgi?id=1432954 [ 5 ] Bug #1432951 - CVE-2017-6436 libplist: Integer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432951 [ 6 ] Bug #1412613 - CVE-2017-5209 libplist: base64decode buffer over-read via split encoded Apple Property List data https://bugzilla.redhat.com/show_bug.cgi?id=1412613 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial patch released for Fedora 24 addressing libplist security flaws. Immediate upgrade recommended.. Fedora Security, Libplist Update, Memory Management Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 12, 2017 Critical Fedora
89

Fedora 25 libplist Security Update: Critical Buffer Overflow Issues

Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-4047180cd3 2017-05-12 04:05:28.496941 --------------------------------------------------------------------------------Name : libplist Product : Fedora 25 Version : 2.0.0 Release : 1.fc25 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: Version 2.0.0 Changes: * New light-weight custom XML parser * Remove libxml2 dependency * Refactor binary plist parsing * Improved malformed XML and binary plist detection and error handling * Add parser debug/error output (when compiled with --enable-debug), controlled via environment variables * Fix unicode character handling * Add PLIST_IS_* helper macros for the different node types * Extend date/time range and date conversion issues * Add plist_is_binary() and plist_from_memory() functions to the interface * Plug several memory leaks * Speed improvements for handling large plist files Includes security fixes for: * CVE-2017-6440 * CVE-2017-6439 * CVE-2017-6438 * CVE-2017-6437 * CVE-2017-6436 * CVE-2017-6435 * CVE-2017-5836 * CVE-2017-5835 * CVE-2017-5834 * CVE-2017-5545 * CVE-2017-5209 ... and several others that didn't receive any CVE (yet). --------------------------------------------------------------------------------References: [1 ] Bug #1432965 - CVE-2017-6440 libplist: Memory allocation error in parse_data_node https://bugzilla.redhat.com/show_bug.cgi?id=1432965 [ 2 ] Bug #1432959 - CVE-2017-6439 libplist: Heap-based buffer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432959 [ 3 ] Bug #1432956 - CVE-2017-6438 libplist: Heap-based buffer overflow in parse_unicode_node https://bugzilla.redhat.com/show_bug.cgi?id=1432956 [ 4 ] Bug #1432954 - CVE-2017-6437 libplist: Out-of-bounds heap read in base64encode function https://bugzilla.redhat.com/show_bug.cgi?id=1432954 [ 5 ] Bug #1432951 - CVE-2017-6436 libplist: Integer overflow in parse_string_node https://bugzilla.redhat.com/show_bug.cgi?id=1432951 [ 6 ] Bug #1412613 - CVE-2017-5209 libplist: base64decode buffer over-read via split encoded Apple Property List data https://bugzilla.redhat.com/show_bug.cgi?id=1412613 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The libxml2 security enhancement for CentOS 7 addresses several serious vulnerabilities, such as command injection and improper input validation.. libplist Security Update,Fedora 25,Buffer Overflow,Memory Leak,Critical Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 12, 2017 Critical Fedora
89

Fedora 26: Urgent Security Update for libplist with Key Fixes

- Update to upstream 2.0.0 - Fixes the following CVEs plus others - CVE-2017-6440 CVE-2017-6439 CVE-2017-6438 CVE-2017-6437 CVE-2017-6436 CVE-2017-6435 CVE-2017-5836 CVE-2017-5835 CVE-2017-5834 CVE-2017-5545 CVE-2017-5209. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-d8173aacff 2017-05-02 15:56:05.733668 --------------------------------------------------------------------------------Name : libplist Product : Fedora 26 Version : 2.0.0 Release : 1.fc26 URL : https://libimobiledevice.org/ Summary : Library for manipulating Apple Binary and XML Property Lists Description : libplist is a library for manipulating Apple Binary and XML Property Lists --------------------------------------------------------------------------------Update Information: - Update to upstream 2.0.0 - Fixes the following CVEs plus others -CVE-2017-6440 CVE-2017-6439 CVE-2017-6438 CVE-2017-6437 CVE-2017-6436 CVE-2017-6435 CVE-2017-5836 CVE-2017-5835 CVE-2017-5834 CVE-2017-5545 CVE-2017-5209 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade libplist' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent Fedora 26 library revision tackles several security vulnerabilities linked to libplist. This patch resolves numerous CVE references.. libplist update,Fedorasecurity,software updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 02, 2017 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200