Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
172

Ubuntu 16.04 ESM: USN-5720-1 Moderate: Libzstd Info Disclosure Threat

Zstandard could be made to expose sensitive information. =========================================================================Ubuntu Security Notice USN-5720-1 November 09, 2022 libzstd vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Zstandard could be made to expose sensitive information Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that Zstandard was not properly managing file permissions when generating output files. A local attacker could possibly use this issue to cause a race condition and gain unauthorized access to sensitive data. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libzstd1 1.3.1+dfsg-1~ubuntu0.16.04.1+esm3 zstd 1.3.1+dfsg-1~ubuntu0.16.04.1+esm3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5720-1 CVE-2021-24031, CVE-2021-24032 . Ubuntu Security Notice USN-5720-2 concerns flaws in libzstd that could allow for the potential leakage of confidential information via localized exploits.. libzstd security, Ubuntu issue, information exposure risk, update instructions. . LinuxSecurity.com Team

Calendar 2 Nov 09, 2022 Ubuntu
172

Ubuntu 16.04 ESM Advisory USN-5593-1 Moderate: libzstd Code Exec Risk

Zstandard could be made to execute arbitrary code if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-5593-1 September 01, 2022 libzstd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: Zstandard could be made to execute arbitrary code if it received specially crafted input. Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that Zstandard incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: libzstd1 1.3.1+dfsg-1~ubuntu0.16.04.1+esm2 zstd 1.3.1+dfsg-1~ubuntu0.16.04.1+esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5593-1 CVE-2019-11922 . A vulnerability in Zstandard may enable arbitrary code execution with specially formed inputs, affecting various Ubuntu versions. Refer to the provided update guidelines.. libzstd vulnerabilities, arbitrary code execution, Ubuntu security advisory. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2022 Ubuntu
172

Ubuntu: 4760-1 Critical: Libzstd Information Exposure Risk

libzstd could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4760-1 March 08, 2021 libzstd vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: libzstd could be made to expose sensitive information. Software Description: - libzstd: fast lossless compression algorithm Details: It was discovered that libzstd incorrectly handled file permissions. A local attacker could possibly use this issue to access certain files, contrary to expectations. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libzstd1 1.4.5+dfsg-4ubuntu0.1 zstd 1.4.5+dfsg-4ubuntu0.1 Ubuntu 20.04 LTS: libzstd1 1.4.4+dfsg-3ubuntu0.1 zstd 1.4.4+dfsg-3ubuntu0.1 Ubuntu 18.04 LTS: libzstd1 1.3.3+dfsg-2ubuntu1.2 zstd 1.3.3+dfsg-2ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4760-1 CVE-2021-24031, CVE-2021-24032 Package Information: https://launchpad.net/ubuntu/+source/libzstd/1.4.5+dfsg-4ubuntu0.1 https://launchpad.net/ubuntu/+source/libzstd/1.4.4+dfsg-3ubuntu0.1 https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.2 . The Ubuntu security notice USN-4760-1 draws attention to vulnerabilities in libzstd that may lead to the exposure of confidential information across various versions.. libzstd exposures, Ubuntu updates, security threats. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 08, 2021 Critical Ubuntu
197

Debian: DLA-2574-1 Important: Libpng Security Update Alert

It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2573-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta February 20, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libzstd Version : 1.1.2-1+deb9u1 Debian Bug : 981404 982519 It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. For Debian 9 stretch, this problem has been fixed in version 1.1.2-1+deb9u1. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu LTS has published notice USN-4872-1 to fix a synchronization issue in the libjpeg-turbo image processing library's security.. Debian LTS, Libzstd Security Update, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 20, 2021 Important Debian LTS
87

Debian: DSA-4859-1 Moderate: Libzstd Race Condition Threat

It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4859-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 20, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libzstd Debian Bug : 982519 It was discovered that zstd, a compression utility, was vulnerable to a race condition: it temporarily exposed, during a very short timeframe, a world-readable version of its input even if the original file had restrictive permissions. For the stable distribution (buster), this problem has been fixed in version 1.3.8+dfsg-3+deb10u2. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian's libzstd package received a crucial update that addresses race condition vulnerabilities, enhancing system security and reliability against unauthorized access or data corruption. Debian Security Advisory, Libzstd Update, Race Condition Fix. . LinuxSecurity.com Team

Calendar 2 Feb 20, 2021 Debian
87

Debian: DSA-4850-1 Critical: World-Readable Permissions in Libzstd

It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4850-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Sebastien Delafond February 10, 2021 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libzstd Debian Bug : 981404 It was discovered that zstd, a compression utility, temporarily exposed a world-readable version of its input even if the original file had restrictive permissions. For the stable distribution (buster), this problem has been fixed in version 1.3.8+dfsg-3+deb10u1. We recommend that you upgrade your libzstd packages. For the detailed security status of libzstd please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libzstd Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Notice DSA-4851-1 for libxcrypt resolves insecure, universal access permissions flaw. Upgrade is advised.. libzstd permissions exposure, debian security advisory, compression utility issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 10, 2021 Critical Debian
172

Ubuntu 18.04 LTS USN-4108-1 Critical: Libzstd Arbitrary Code Execution

Zstandard could be made to execute arbitrary code if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4108-1 August 21, 2019 libzstd vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS Summary: Zstandard could be made to execute arbitrary code if it received specially crafted input. Software Description: - libzstd: fast lossless compression algorithm -- development files Details: It was discovered that Zstandard incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libzstd1 1.3.3+dfsg-2ubuntu1.1 zstd 1.3.3+dfsg-2ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4108-1 CVE-2019-11922 Package Information: https://launchpad.net/ubuntu/+source/libzstd/1.3.3+dfsg-2ubuntu1.1 . A significant alert regarding a vulnerability in Ubuntu's libzstd, which could enable remote attackers to execute arbitrary code via intricately constructed inputs.. Ubuntu Security Notice, libzstd update, critical vulnerability, arbitrary code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 21, 2019 Critical Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here