Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian DSA-1387 Critical: librpcsecgss Buffer Overflow Threat

It has been discovered that the original patch for a buffer overflow in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (CVE-2007-3999, DSA-1368-1) was insufficient to protect from arbitrary code execution in some environments.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1387 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer October 15th, 2007 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : librpcsecgss Vulnerability : buffer overflow Problem type : remote Debian-specific: no CVE ID : CVE-2007-4743 It has been discovered that the original patch for a buffer overflow in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (CVE-2007-3999, DSA-1368-1) was insufficient to protect from arbitrary code execution in some environments. The old stable distribution (sarge) does not contain a librpcseggss package. For the stable distribution (etch), this problem has been fixed in version 0.14-2etch3. For the unstable distribution (sid), this problem has been fixed in version 0.14-4. We recommend that you upgrade your librpcsecgss package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 1038 dbb737ea9be3a8c959754d43b63982f4 Size/MD5 checksum: 363503 0d4cdee46a98731b1b71e30504589281 Size/MD5checksum: 1849 c7078a95bfcf735d6d31c2d5f3ef25cd Alpha architecture: Size/MD5 checksum: 36716 ed385368f5108ea22a704a288631c5f6 Size/MD5 checksum: 57488 93acfd2f2984d657222aca703e58d1a5 AMD64 architecture: Size/MD5 checksum: 47982 bc12c0c2c58dc51888c7269319dca08b Size/MD5 checksum: 34174 376f547b1227b6f8faaf9c1acca32ea1 ARM architecture: Size/MD5 checksum: 31182 3d7ccf54913d51bb1db0724008ad3e9d Size/MD5 checksum: 43822 904c1a29bd61e225f2d7eb8f6230c367 HP Precision architecture: Size/MD5 checksum: 36920 cd4f99818fefce5824eaf808bf31fe03 Size/MD5 checksum: 50996 a962c70ecf318b82c49e67814a50aff1 Intel IA-32 architecture: Size/MD5 checksum: 31308 925e844098880d4f3f4cdc6ae36ddee1 Size/MD5 checksum: 42004 87f60564e6ebf3a0d2a7bd4d5bffe949 Intel IA-64 architecture: Size/MD5 checksum: 63390 774a0fdb01e0e94e7194edfe7156a0e8 Size/MD5 checksum: 47070 729964f2405fcc237f1dfcb8ae6640e5 Big endian MIPS architecture: Size/MD5 checksum: 49386 f55502c118efeba50b3b38bad88f6d6c Size/MD5 checksum: 32302 f1c08ffd0614f188011a27d7ee9b1261 Little endian MIPS architecture: Size/MD5 checksum: 50160 e7d887c8bf5f597f3a755dbbe8c409dc Size/MD5 checksum: 32930 633e57cdd675769637f55c04c8e496e3 PowerPC architecture: Size/MD5 checksum: 47160 38fd21665791bd6b6bc7b8d66f28f89b Size/MD5 checksum: 34494 da7f562b38579a589fb15736a5e585c7 IBM S/390 architecture: Size/MD5 checksum: 34930 ae3cac28da2073fef0f02bc587747d56 Size/MD5 checksum: 45480 89c63c16c6572437621e217bf64285ea Sun Sparc architecture: Size/MD5 checksum: 30776 6a70b84b9837c00688044e6ad0d89810 Size/MD5 checksum: 43336 26a3bc069f160803f64014ca0a7550f9 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover the latest update addressing the buffer overflow vulnerability in Debian's librpcsecgss, resolving serious risks of arbitrary code execution.. Debian Security Advisory,librpcsecgss upgrade,buffer overflow fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 15, 2007 Critical Debian
87

Debian: DSA-1368-1 Critical: Librpcsecgss Remote Execution Risk

It was discovered that a buffer overflow of the library for secure RPC communication over the rpcsec_gss protocol allows the execution of arbitrary code.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1368-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff September 4th, 2007 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : librpcsecgss Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-3999 It was discovered that a buffer overflow of the library for secure RPC communication over the rpcsec_gss protocol allows the execution of arbitrary code. The oldstable distribution (sarge) doesn't contain librpcsecgss. For the stable distribution (etch) this problem has been fixed in version 0.14-2etch1. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your librpcsecgss packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Source archives: Size/MD5 checksum: 746 253bb12cce7ac18b200108dfcb430b6a Size/MD5 checksum: 1479 b655fc49163d87b9b0a61ae4ead7721b Size/MD5 checksum: 363503 0d4cdee46a98731b1b71e30504589281 Alpha architecture: Size/MD5 checksum: 57274 f14e33d1d2ad81884ac8fccaa0f15e27 Size/MD5 checksum: 36550 9dcab36859a73b0977b9650718631483 AMD64 architecture: Size/MD5 checksum: 47116 928402ec8a65a5071ba876261a850131 Size/MD5 checksum: 34222 99f2ff17bc0bce9cf2242c9d374ff961 ARM architecture: Size/MD5 checksum: 43648 f861205801b8d530476b3d69b0e5402f Size/MD5 checksum: 31024 a79a82b857f7d899b584d083a0ce3efa HP Precision architecture: Size/MD5 checksum: 50824 ea6a2f15ebde8f2c64c70182e84df600 Size/MD5 checksum: 36736 5a512850ced537e2de50f5fcd8880a66 Intel IA-32 architecture: Size/MD5 checksum: 41846 f5482b2709d90570e398c191ccd1893f Size/MD5 checksum: 31140 56656d7169d4ac2339a1e5ec705ff68d Intel IA-64 architecture: Size/MD5 checksum: 63226 b03f78f2b82ee21f0c033d7af52ecc4d Size/MD5 checksum: 46920 0b0316daa0d61728c9ca92655ee4f91d Big endian MIPS architecture: Size/MD5 checksum: 49210 a923779962e060499fd5e1a692cd9069 Size/MD5 checksum: 32104 824d370664a00841e9751d27ae605ccb Little endian MIPS architecture: Size/MD5 checksum: 49992 00fb0f876f96ef4667f563ccc027c5a6 Size/MD5 checksum: 32766 5ea360f6ad92040b47516337dd8ecab2 PowerPC architecture: Size/MD5 checksum: 46960 e0fbf26dfe4ce36758c2f07cacd7e04b Size/MD5 checksum: 34342 d1d69480834e466a535be68003fc4e4c IBM S/390 architecture: Size/MD5 checksum: 45304 3efc20a854c8e919cc5f45615abbb2ca Size/MD5 checksum: 34746 e6e26b7798b81efa49d854cd607398b2 Sun Sparc architecture: Size/MD5 checksum: 43142 d2d11ef956723155ad3431a9372f1fa8 Size/MD5 checksum: 30610 fb28cf21d0f2aea6fb7b36f17235a69c These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updatesmain For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. buffer, overflow, library, secure, communication, rpcsec. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 04, 2007 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200