Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux 3.14.24-1 Medium: Linux-LTS Local DoS and Escalation Advisory

The package linux-lts before version 3.14.24-1 is vulnerable to local denial service and privilege escalation via various issues. . Arch Linux Security Advisory ASA-201411-15 ========================================= Severity: Medium Date : 2014-11-17 CVE-ID : CVE-2014-3610, CVE-2014-3611, CVE-2014-3646, CVE-2014-3647, CVE-2014-7825, CVE-2014-7826, CVE-2014-8369 Package : linux-lts Type : local denial of service, privilege escalation Remote : No Link : https://wiki.archlinux.org/title/CVE-2014 Summary ====== The package linux-lts before version 3.14.24-1 is vulnerable to local denial service and privilege escalation via various issues. Resolution ========= Upgrade to 3.14.24-1. # pacman -Syu "linux-lts> =3.14.24-1" The problem has been fixed upstream in version 3.14.24. Workaround ========= None. Description ========== CVE-2014-3610: The WRMSR processing functionality in the KVM subsystem in the Linux kernel does not properly handle the writing of a non-canonical address to a model-specific register, which allows guest OS users to cause a denial of service (host OS crash) by leveraging guest OS privileges, related to the wrmsr_interception function in arch/x86/kvm/svm.c and the handle_wrmsr function in arch/x86/kvm/vmx.c. CVE-2014-3611: Race condition in the __kvm_migrate_pit_timer function in arch/x86/kvm/i8254.c in the KVM subsystem in the Linux kernel allows guest OS users to cause a denial of service (host OS crash) by leveraging incorrect PIT emulation. CVE-2014-3646: arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. CVE-2014-3647: arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. CVE-2014-7825:kernel/trace/trace_syscalls.c in the Linux kernel does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protection mechanism via a crafted application. CVE-2014-7826: kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application. CVE-2014-8369: The kvm_iommu_map_pages function in virt/kvm/iommu.c in the Linux kernel miscalculates the number of pages during the handling of a mapping failure, which allows guest OS users to cause a denial of service (host OS page unpinning) or possibly have unspecified other impact by leveraging guest OS privileges. NOTE: this vulnerability exists because of an incorrect fix for CVE-2014-3601. Impact ===== A local OS user may be able to cause a kernel crash in various ways, or escalate privileges. References ========= http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3610 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3611 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3646 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3647 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7825 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7826 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-8369 . Arch Linux Security Advisory ASA-201411-15 ========================================= Severity: Mediu. package, linux-lts, version, vulnerable, local, denial, service, privilege. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Nov 17, 2014 Medium ArchLinux
87

Debian: DSA-1492-1 Moderate: WML Local Denial of Service

Frank Lichtenheld and Nico Golde discovered that WML, an off-line HTML generation toolkit, creates insecure temporary files in the eperl and ipp backends and in the wmg.cgi script, which could lead to local denial of service by overwriting files.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1492-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff February 10, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : wml Vulnerability : insecure temporary files Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-0665 CVE-2008-0666 Debian Bug : 463907 Frank Lichtenheld and Nico Golde discovered that WML, an off-line HTML generation toolkit, creates insecure temporary files in the eperl and ipp backends and in the wmg.cgi script, which could lead to local denial of service by overwriting files. For the stable distribution (etch), these problems have been fixed in version 2.0.11-1etch1. The old stable distribution (sarge) is not affected. We recommend that you upgrade your wml packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 656 3c12d2b00552d3db815957c01c73b2cf Size/MD5 checksum: 3115230a26feebf4e59e9a6940f54c69dde05b5 Size/MD5 checksum: 24577 3242a88ced8598120cf6aba2bf9f69c4 alpha architecture (DEC Alpha) Size/MD5 checksum: 453998 29f9f2cffcd5becc205ba36a988a216f amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 452700 88033d2e3347e9b94061826b7856cdb0 hppa architecture (HP PA RISC) Size/MD5 checksum: 454656 5dd770e936b54880605d9d8c5c639d10 i386 architecture (Intel ia32) Size/MD5 checksum: 451672 be10fe25928ce83aadf119d98eb5cd43 ia64 architecture (Intel ia64) Size/MD5 checksum: 458406 c153522ee017b612f57a40b2e87787cb mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 450848 8dc62d7f99bf8a7e55b4ebf825cc8500 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 449418 32d7a95ff9c4a184fe7f23f1e8a1cea3 powerpc architecture (PowerPC) Size/MD5 checksum: 452594 65e04ee9b968599ec772c95c7c24ee41 s390 architecture (IBM S/390) Size/MD5 checksum: 451058 dbbcea5a32cdcd5e6a0407665270fdd6 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 450772 297e44c330a2acc9c4829b46f53f1004 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-1492-1 http://www.debian.org/security/ Moritz Muehlenhoff February 10, . frank, lichtenheld, golde, off-line, generation, toolkit, creates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 10, 2008 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here