Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 17.04/16.10/16.04 USN-3310-1 Moderate: Lintian Code Execution

lintian could be made to run programs if it processed a specially crafted package.. =========================================================================Ubuntu Security Notice USN-3310-1 June 06, 2017 lintian vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS Summary: lintian could be made to run programs if it processed a specially crafted package. Software Description: - lintian: Debian package checker Details: Jakub Wilk discovered that lintian incorrectly handled deserializing certain YAML files. If a user or automated system were tricked into running lintian on a specially crafted package, a remote attacker could possibly use this issue to execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: lintian 2.5.50.1ubuntu0.1 Ubuntu 16.10: lintian 2.5.48ubuntu0.1 Ubuntu 16.04 LTS: lintian 2.5.43ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3310-1 CVE-2017-8829 Package Information: https://launchpad.net/ubuntu/+source/lintian/2.5.50.1ubuntu0.1 https://launchpad.net/ubuntu/+source/lintian/2.5.48ubuntu0.1 https://launchpad.net/ubuntu/+source/lintian/2.5.43ubuntu0.1 . The recent Security Update USN-3310-2 addresses a critical vulnerability in OpenSSL that could allow unauthorized access on various Ubuntu releases.. lintian Exploit, Ubuntu Security Update, Code Execution Risk. . LinuxSecurity.com Team

Calendar 2 Jun 06, 2017 Ubuntu
172

Ubuntu 6.06 LTS USN-891-1 Moderate: Lintian Code Execution Report

It was discovered that lintian did not correctly validate certainfilenames when processing input. If a user or an automated systemwere tricked into running lintian on a specially crafted set of files,a remote attacker could execute arbitrary code with user privileges. [More...]. ==========================================================Ubuntu Security Notice USN-891-1 January 28, 2010 lintian vulnerabilities CVE-2009-4013, CVE-2009-4014, CVE-2009-4015 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 Ubuntu 9.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: lintian 1.23.16ubuntu2.1 Ubuntu 8.04 LTS: lintian 1.23.46ubuntu0.1 Ubuntu 8.10: lintian 1.24.3ubuntu0.1 Ubuntu 9.04: lintian 2.2.5ubuntu1.1 Ubuntu 9.10: lintian 2.2.17ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that lintian did not correctly validate certain filenames when processing input. If a user or an automated system were tricked into running lintian on a specially crafted set of files, a remote attacker could execute arbitrary code with user privileges. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 830 a47fe6f70e2eba48fb33d0564b9725e4 Size/MD5: 276511 50d6bfca45e5bed01983bdc83b00d19a Architecture independent packages: Size/MD5: 238462 db9ef682ad8968f5654e5cf61eefb758 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 1015 f920dd072c6a0f3a468999c3bbbbe121 Size/MD5: 396901 7778649c0f4fb64428b9b4ff895e1a37 Architecture independentpackages: Size/MD5: 329624 9a624f6eb3664bb2c22be3d1af3206d6 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 1244 0f8c73db743ead863a7d3488b476ee0d Size/MD5: 485785 a7d56250c3cb465c4312aa40ad5beda0 Architecture independent packages: Size/MD5: 359254 a6caa1f945de160e203f28bbfd842912 Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 1284 e4c08e6d5485857e84d5354cdf01e9f6 Size/MD5: 634606 d3fee56c7bedbe0088ce8749f44bcacf Architecture independent packages: Size/MD5: 437450 927b8d2bf0fde9a62267a44d7f1779d3 Updated packages for Ubuntu 9.10: Source archives: Size/MD5: 1283 2845994c571ce78a3be8b2121c950db9 Size/MD5: 747007 dab8b5b18c5f0904df90b07027223af0 Architecture independent packages: Size/MD5: 475958 4b633e03d586b04674a9c8266b6d3273 . Mitigating lintian security weaknesses in Ubuntu may enable remote code execution with user-level permissions on compromised installations.. Ubuntu Security,Lintian Issue,Remote Code Attack,Linux Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 28, 2010 Important Ubuntu
87

Debian DSA-1979-1 Critical: Lintian Local Flaws and Command Execution

Multiple vulnerabilities have been discovered in lintian, a Debian package checker. The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1979-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert January 27, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : lintian Vulnerability : multiple Problem type : local Debian-specific: no CVE Id(s) : CVE-2009-4013 CVE-2009-4014 CVE-2009-4015 Multiple vulnerabilities have been discovered in lintian, a Debian package checker. The following Common Vulnerabilities and Exposures project ids have been assigned to identify them: CVE-2009-4013: missing control files sanitation Control field names and values were not sanitised before using them in certain operations that could lead to directory traversals. Patch systems' control files were not sanitised before using them in certain operations that could lead to directory traversals. An attacker could exploit these vulnerabilities to overwrite arbitrary files or disclose system information. CVE-2009-4014: format string vulnerabilities Multiple check scripts and the Lintian::Schedule module were using user-provided input as part of the sprintf/printf format string. CVE-2009-4015: arbitrary command execution File names were not properly escaped when passing them as arguments to certain commands, allowing the execution of other commands as pipes or as a set of shell commands. For the oldstable distribution (etch), these problems have been fixed in version 1.23.28+etch1. For the stable distribution (lenny), these problems have been fixed in version 1.24.2.1+lenny1. For the testing distribution (squeeze), these problems will be fixed soon. For the unstabledistribution (sid), these problems have been fixed in version 2.3.2 We recommend that you upgrade your lintian packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch (oldstable) - ------------------------------------------- Source archives: Size/MD5 checksum: 322293 127f82c30379e65c24a53044143d00cc Size/MD5 checksum: 824 f99d118c811bdd611fb4ee81b53c2684 Architecture independent packages: Size/MD5 checksum: 275856 26cd4deb23c37aee3469c0eb2e86fd83 Debian GNU/Linux 5.0 alias lenny (stable) - ----------------------------------------- Source archives: Size/MD5 checksum: 470561 7df7c88fa5add0762f6c7873f6601fbe Size/MD5 checksum: 1160 b38dd3251e8354b62d7a4191a88211ed Architecture independent packages: Size/MD5 checksum: 358170 2ca70ec0a83fb608eca83c0beac8bf81 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian Security Advisory DSA-2005-2 highlights significant vulnerabilities found within the globus packages. Immediate action is advised.. Debian Security Advisory, Lintian Flaws, Package Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 27, 2010 Critical Debian
87

Debian: DSA 630-1 Moderate: Lintian Insecure Temporary Directory

Jeroen van Wolffelaar discovered a problem in lintian, the Debian package checker. The program removes the working directory even if it wasn't created at program start, removing an unrelated file or directory a malicious user inserted via a symlink attack.. --------------------------------------------------------------------------Debian Security Advisory DSA 630-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 10th, 2005 http://www.debian.org/security/faq --------------------------------------------------------------------------Package : lintian Vulnerability : insecure temporary directory Problem-Type : local Debian-specific: yes CVE ID : CAN-2004-1000 Debian Bug : 286681 Jeroen van Wolffelaar discovered a problem in lintian, the Debian package checker. The program removes the working directory even if it wasn't created at program start, removing an unrelated file or directory a malicious user inserted via a symlink attack. For the stable distribution (woody) this problem has been fixed in version 1.20.17.1. For the unstable distribution (sid) this problem has been fixed in version 1.23.6. We recommend that you upgrade your lintian package. Upgrade Instructions --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 505 03d54a4d67f1c784cbee0fdac29fd9d6 Size/MD5 checksum: 198277 886c05fe72a348ca3db23856c59bf8af Architectureindependent components: Size/MD5 checksum: 171384 bc968e0eeebad128e743d716e4bc10e7 These files will probably be moved into the stable distribution on its next update. ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian Security Advisory DSA 631-1 announces a remedy for an unprotected temporary folder in apt-transport-https related to symbolic link vulnerabilities.. Debian Security,lintian fix,package updates,security threats. . LinuxSecurity.com Team

Calendar 2 Jan 10, 2005 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here