Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 4 articles for you...
172

Ubuntu 14.04 LTS USN-2254-1 Moderate: PHP Local And Remote Risks

Several security issues were fixed in PHP.. =========================================================================Ubuntu Security Notice USN-2254-1 June 23, 2014 php5 vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS - Ubuntu 13.10 - Ubuntu 12.04 LTS - Ubuntu 10.04 LTS Summary: Several security issues were fixed in PHP. Software Description: - php5: HTML-embedded scripting language interpreter Details: Christian Hoffmann discovered that the PHP FastCGI Process Manager (FPM) set incorrect permissions on the UNIX socket. A local attacker could use this issue to possibly elevate their privileges. This issue only affected Ubuntu 12.04 LTS, Ubuntu 13.10, and Ubuntu 14.04 LTS. (CVE-2014-0185) Francisco Alonso discovered that the PHP Fileinfo component incorrectly handled certain CDF documents. A remote attacker could use this issue to cause PHP to hang or crash, resulting in a denial of service. (CVE-2014-0237, CVE-2014-0238) Stefan Esser discovered that PHP incorrectly handled DNS TXT records. A remote attacker could use this issue to cause PHP to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2014-4049) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS: libapache2-mod-php5 5.5.9+dfsg-1ubuntu4.1 php5-cgi 5.5.9+dfsg-1ubuntu4.1 php5-cli 5.5.9+dfsg-1ubuntu4.1 php5-fpm 5.5.9+dfsg-1ubuntu4.1 Ubuntu 13.10: libapache2-mod-php5 5.5.3+dfsg-1ubuntu2.4 php5-cgi 5.5.3+dfsg-1ubuntu2.4 php5-cli 5.5.3+dfsg-1ubuntu2.4 php5-fpm 5.5.3+dfsg-1ubuntu2.4 Ubuntu 12.04 LTS: libapache2-mod-php5 5.3.10-1ubuntu3.12 php5-cgi 5.3.10-1ubuntu3.12 php5-cli 5.3.10-1ubuntu3.12 php5-fpm 5.3.10-1ubuntu3.12 Ubuntu 10.04 LTS: libapache2-mod-php5 5.3.2-1ubuntu4.25 php5-cgi 5.3.2-1ubuntu4.25 php5-cli 5.3.2-1ubuntu4.25 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2254-1 CVE-2014-0185, CVE-2014-0237, CVE-2014-0238, CVE-2014-4049 Package Information: https://launchpad.net/ubuntu/+source/php5/5.5.9+dfsg-1ubuntu4.1 https://launchpad.net/ubuntu/+source/php5/5.5.3+dfsg-1ubuntu2.4 https://launchpad.net/ubuntu/+source/php5/5.3.10-1ubuntu3.12 https://launchpad.net/ubuntu/+source/php5/5.3.2-1ubuntu4.25 . Various CVEs associated with PHP vulnerabilities have been announced and patched across different Ubuntu versions, addressing threats from both local and remote attackers.. PHP Risks, Ubuntu Security, Denial of Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 23, 2014 Important Ubuntu
98

Red Hat 4.7: RHSA-2009:1588-02 Important: Local DoS Risk

Updated kernel packages that fix security issues are now available for Red Hat Enterprise Linux 4.7 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: kernel security update Advisory ID: RHSA-2009:1588-02 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1588.html Issue date: 2009-11-17 CVE Names: CVE-2009-3547 ==================================================================== 1. Summary: Updated kernel packages that fix security issues are now available for Red Hat Enterprise Linux 4.7 Extended Update Support. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 4.7.z - i386, ia64, noarch, ppc, s390, s390x, x86_64 Red Hat Enterprise Linux ES version 4.7.z - i386, ia64, noarch, x86_64 3. Description: The kernel packages contain the Linux kernel, the core of any Linux operating system. This update fixes the following security issues: * a NULL pointer dereference flaw was found in each of the following functions in the Linux kernel: pipe_read_open(), pipe_write_open(), and pipe_rdwr_open(). When the mutex lock is not held, the i_pipe pointer could be released by other processes before it is used to update the pipe's reader and writer counters. This could lead to a local denial of service or privilege escalation. (CVE-2009-3547, Important) Users should upgrade to these updated packages, which contain a backported patch to correct these issues. The system must be rebooted for this update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. Thisupdate is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 530490 - CVE-2009-3547 kernel: fs: pipe.c null pointer dereference 6. Package List: Red Hat Enterprise Linux AS version 4.7.z: Source: kernel-2.6.9-78.0.28.EL.src.rpm i386: kernel-2.6.9-78.0.28.EL.i686.rpm kernel-debuginfo-2.6.9-78.0.28.EL.i686.rpm kernel-devel-2.6.9-78.0.28.EL.i686.rpm kernel-hugemem-2.6.9-78.0.28.EL.i686.rpm kernel-hugemem-devel-2.6.9-78.0.28.EL.i686.rpm kernel-smp-2.6.9-78.0.28.EL.i686.rpm kernel-smp-devel-2.6.9-78.0.28.EL.i686.rpm kernel-xenU-2.6.9-78.0.28.EL.i686.rpm kernel-xenU-devel-2.6.9-78.0.28.EL.i686.rpm ia64: kernel-2.6.9-78.0.28.EL.ia64.rpm kernel-debuginfo-2.6.9-78.0.28.EL.ia64.rpm kernel-devel-2.6.9-78.0.28.EL.ia64.rpm kernel-largesmp-2.6.9-78.0.28.EL.ia64.rpm kernel-largesmp-devel-2.6.9-78.0.28.EL.ia64.rpm noarch: kernel-doc-2.6.9-78.0.28.EL.noarch.rpm ppc: kernel-2.6.9-78.0.28.EL.ppc64.rpm kernel-2.6.9-78.0.28.EL.ppc64iseries.rpm kernel-debuginfo-2.6.9-78.0.28.EL.ppc64.rpm kernel-debuginfo-2.6.9-78.0.28.EL.ppc64iseries.rpm kernel-devel-2.6.9-78.0.28.EL.ppc64.rpm kernel-devel-2.6.9-78.0.28.EL.ppc64iseries.rpm kernel-largesmp-2.6.9-78.0.28.EL.ppc64.rpm kernel-largesmp-devel-2.6.9-78.0.28.EL.ppc64.rpm s390: kernel-2.6.9-78.0.28.EL.s390.rpm kernel-debuginfo-2.6.9-78.0.28.EL.s390.rpm kernel-devel-2.6.9-78.0.28.EL.s390.rpm s390x: kernel-2.6.9-78.0.28.EL.s390x.rpm kernel-debuginfo-2.6.9-78.0.28.EL.s390x.rpm kernel-devel-2.6.9-78.0.28.EL.s390x.rpm x86_64: kernel-2.6.9-78.0.28.EL.x86_64.rpm kernel-debuginfo-2.6.9-78.0.28.EL.x86_64.rpm kernel-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-largesmp-2.6.9-78.0.28.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-smp-2.6.9-78.0.28.EL.x86_64.rpm kernel-smp-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-xenU-2.6.9-78.0.28.EL.x86_64.rpm kernel-xenU-devel-2.6.9-78.0.28.EL.x86_64.rpm Red Hat Enterprise Linux ES version4.7.z: Source: kernel-2.6.9-78.0.28.EL.src.rpm i386: kernel-2.6.9-78.0.28.EL.i686.rpm kernel-debuginfo-2.6.9-78.0.28.EL.i686.rpm kernel-devel-2.6.9-78.0.28.EL.i686.rpm kernel-hugemem-2.6.9-78.0.28.EL.i686.rpm kernel-hugemem-devel-2.6.9-78.0.28.EL.i686.rpm kernel-smp-2.6.9-78.0.28.EL.i686.rpm kernel-smp-devel-2.6.9-78.0.28.EL.i686.rpm kernel-xenU-2.6.9-78.0.28.EL.i686.rpm kernel-xenU-devel-2.6.9-78.0.28.EL.i686.rpm ia64: kernel-2.6.9-78.0.28.EL.ia64.rpm kernel-debuginfo-2.6.9-78.0.28.EL.ia64.rpm kernel-devel-2.6.9-78.0.28.EL.ia64.rpm kernel-largesmp-2.6.9-78.0.28.EL.ia64.rpm kernel-largesmp-devel-2.6.9-78.0.28.EL.ia64.rpm noarch: kernel-doc-2.6.9-78.0.28.EL.noarch.rpm x86_64: kernel-2.6.9-78.0.28.EL.x86_64.rpm kernel-debuginfo-2.6.9-78.0.28.EL.x86_64.rpm kernel-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-largesmp-2.6.9-78.0.28.EL.x86_64.rpm kernel-largesmp-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-smp-2.6.9-78.0.28.EL.x86_64.rpm kernel-smp-devel-2.6.9-78.0.28.EL.x86_64.rpm kernel-xenU-2.6.9-78.0.28.EL.x86_64.rpm kernel-xenU-devel-2.6.9-78.0.28.EL.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-3547 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFLAsHPXlSAg2UNWIIRAnrUAJ4kZabgvSp+lrl8C90AgZpxkYp25gCgo4KI DDCDA11FNUHQsUDt6VPn4Bg=yPx5 -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Urgent update for kernel packages in Red Hat Enterprise Linux has been released to resolve severe security vulnerabilities.. Kernel Updates, Red Hat Security, Local Denial Service. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Nov 17, 2009 Important Red Hat
87

Debian: DSA-1476-1 Moderate: PulseAudio Local Escalation Risk Fix

Marcus Meissner discovered that the PulseAudio sound server performed insufficent checks when dropping privileges, which could lead to local privilege escalation. . - ------------------------------------------------------------------------Debian Security Advisory DSA-1476-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 27, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : pulseaudio Vulnerability : programming error Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-0008 Marcus Meissner discovered that the PulseAudio sound server performed insufficent checks when dropping privileges, which could lead to local privilege escalation. For the stable distribution (etch), this problem has been fixed in version 0.9.5-5etch1. The old stable distribution (sarge) doesn't contain pulseaudio. We recommend that you upgrade your pulseaudio packages. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1233 b34fa2bde59f7573cd7d98e4a4fd3bbb Size/MD5 checksum: 13795 1e33e53f8b7039660703b69e540c3134 alpha architecture (DEC Alpha) Size/MD5 checksum: 26246 26ac18428582ba9bddaa068dac554ef3 Size/MD5 checksum: 12124 be7c5020f14ab1d4d42c25971a9cd3d5 Size/MD5checksum: 51694 96bf106f9eaa2b2886f232b67640459c Size/MD5 checksum: 104558 569dbf3b38743366faf06614190b8ae3 Size/MD5 checksum: 234580 b63b7003e66b575b3a1bc8f01586f2a8 Size/MD5 checksum: 13292 1d13960e7259bcad75f1982de28b499c Size/MD5 checksum: 14994 99dc8bdcdf59d406bcc04848636b9137 Size/MD5 checksum: 14112 98f49ae5f1450f6ba083cf8da8181b39 Size/MD5 checksum: 10326 7348c8cf21069977254cb2396f5d116b Size/MD5 checksum: 8480 5a10c706a46cef310605427e0bd07c70 Size/MD5 checksum: 333462 27bbb8db2410e576cb62ff19ef3e3303 Size/MD5 checksum: 14080 aacb5a84922cec35b9fecab4e67cb931 Size/MD5 checksum: 10140 c7d693e9c7386de3cf3e8110a47c79b2 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 13826 578fd8db92fbe7e3de290485ff95e303 Size/MD5 checksum: 49936 b3f6ddebe15fca4168ce83776dde3f01 Size/MD5 checksum: 11710 6553e8f4e1f9961cda0442e41f1947a1 Size/MD5 checksum: 10638 daf963fde23467906c0106d9e1418785 Size/MD5 checksum: 13504 1dd34b9d03e8dd2c3a52d2aac14db451 Size/MD5 checksum: 26506 2ea8fee1df14bc165652b9a21929a9ae Size/MD5 checksum: 10472 c7a35c424c2e727097583c615d1b94d5 Size/MD5 checksum: 179602 a78b117537b5127dd963b22357666af2 Size/MD5 checksum: 8272 2cf3ec52c708269d7cbc31f88ac2d80b Size/MD5 checksum: 331246 d2110a116bcea0aab87f6bfca7dea46e Size/MD5 checksum: 13964 76e40243bbcbdc5291b7c34e6c22bea6 Size/MD5 checksum: 14854 480a6e8e58773afb43831ac3feeead52 Size/MD5 checksum: 107352 0a4f8784469c13aae47e4345b9c437e0 arm architecture (ARM) Size/MD5 checksum: 11048 a0d20bf2035a5bd5dd619687e66a9c8a Size/MD5 checksum: 93116 098eff163b4a8ad8d27c3ce29ca16923 Size/MD5 checksum: 10814 9362f403a530a83777159a1bcf93e183 Size/MD5 checksum: 12310 f1aac2d54b5173dea44885d7750e097e Size/MD5 checksum: 12226 8c54d4d198375dd9a3c3287d37877e41 Size/MD5checksum: 13814 f27fbb2ba7902c287c9bbd48d5079d7e Size/MD5 checksum: 9590 2646570ddfb1d93a9910664dd4613f16 Size/MD5 checksum: 290400 7f952e628a10a367c844466b7618901c Size/MD5 checksum: 12862 095d6627a244b6d7aa5a75c04b176add Size/MD5 checksum: 46234 e85a1d154ff40302d3e0be940132add7 Size/MD5 checksum: 23806 f04c556c74b6454a64ee06785258b489 Size/MD5 checksum: 7922 1c290875056f6a7946705fdbf2c90d51 Size/MD5 checksum: 158780 f0c89a4019d3e18a3b80f3268db4d882 hppa architecture (HP PA RISC) Size/MD5 checksum: 111242 54c36a80ae9bed189575e3aaf2c95608 Size/MD5 checksum: 11084 62d1f5ab6377cccf2803a1738ff0ac05 Size/MD5 checksum: 54510 1be7659e6bc6515b1a76b711fa246437 Size/MD5 checksum: 14728 1562e6d7751ed10a82938df9708b3929 Size/MD5 checksum: 8838 ab60a2d0d3f94f5480a03973e2da1b65 Size/MD5 checksum: 15730 82d69961f22dc85448dbf71e32e4dbab Size/MD5 checksum: 198326 7075968157e3ba2cfaeb4685071e779e Size/MD5 checksum: 14188 7b5af25ab5157987096e8c76a98f94e5 Size/MD5 checksum: 14338 387c480faaafe23c7d27df937540b1a9 Size/MD5 checksum: 27416 a425644bb55eb172e7bbd650278e5fb5 Size/MD5 checksum: 12650 8db7161b902ae31b089b319333ec6ad4 Size/MD5 checksum: 341878 85c3887e6a81c5fee2b5621f285f8c5e Size/MD5 checksum: 12416 7a006bbaee890fc9f99c2eda4cffa612 i386 architecture (Intel ia32) Size/MD5 checksum: 291984 32898413c48b4d49a22bd051c4212f3f Size/MD5 checksum: 12766 61b203e2237645276801db7e8ee72531 Size/MD5 checksum: 8042 1a9b20dfb185843d73db6810ae895fc2 Size/MD5 checksum: 9872 26193c70cb04f3952a31749c4dfaa552 Size/MD5 checksum: 47566 97462f144fe0a656eba26a30ddfe3678 Size/MD5 checksum: 12780 d3bec4695f2c1db67d5d87ef0b1e1f9e Size/MD5 checksum: 98194 bad5b868a0208e9c9df50e3a1a6a791e Size/MD5 checksum: 12560 51658e134d4f3b6d6c8a493854e327f0 Size/MD5checksum: 10146 3165b1384d15df98ccbf4a35107cc93e Size/MD5 checksum: 11298 bd022b089360cd5ba98a7a03e4ce8c91 Size/MD5 checksum: 161382 5a0e2b280c74f8a7962aa73b6c8eec30 Size/MD5 checksum: 13884 8f0faed0aea194deeaa3f040713e3c6e Size/MD5 checksum: 24544 a40262f58ad280ae689913380adee18f ia64 architecture (Intel ia64) Size/MD5 checksum: 17348 141ef04b628426bb5e30ee429a35b6d3 Size/MD5 checksum: 16380 a2b13cc815e269e73650cfd60fc7b7e9 Size/MD5 checksum: 139466 497653203b1893715352d817f8dbb0ed Size/MD5 checksum: 13962 2302eb79bf36a48a3718ffcff220f0fa Size/MD5 checksum: 71274 801f77ce5d813d940a420a43c47a5024 Size/MD5 checksum: 12704 657041da30c3161864288c49e4f0bf5c Size/MD5 checksum: 9552 9a90052fb92e1d2f65b51a72c36c609d Size/MD5 checksum: 33080 a4941a97f2b0fc3244cac0150ed32b35 Size/MD5 checksum: 12608 890dfdcd017c734181896a864acc52ed Size/MD5 checksum: 15820 6e92859fff30f611d9670e051f915fe1 Size/MD5 checksum: 16432 de732fe14a9358ba4dccfb60827ceb6c Size/MD5 checksum: 423326 2c6367ce7c652556b675eb6bb7e46123 Size/MD5 checksum: 246556 1894a9180f68abdf21ae96b908d9b0d0 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 91420 8057beaf4e3f2c25971ee56bc2b797a9 Size/MD5 checksum: 12906 53ceb42f6d0bd240c9ec231f92eef2b6 Size/MD5 checksum: 12318 846be755612e2d8ee864721585e80ce5 Size/MD5 checksum: 8150 344a7db0984ded84cb4506094d6e3ad9 Size/MD5 checksum: 13934 a560804aa6cfa5dedd1ca18f801334f2 Size/MD5 checksum: 47706 d8408325b113b70059f12c0bd3b51e2a Size/MD5 checksum: 10458 284ba26c3970616cf807ee1ae0c5af8a Size/MD5 checksum: 24154 3a357eb463de655206e1b91d595b770b Size/MD5 checksum: 12398 d816087eafa8817c433ad7cfc986a195 Size/MD5 checksum: 9704 ee1c60f17ae2722268cc0e16b92492f3 Size/MD5 checksum: 283546 84617d1c69662db1a8ccc0d726c54efa Size/MD5 checksum: 195526 971a39fd64d1a238800768dac0adcfcc Size/MD5 checksum: 11616 583e54c6b4b46448a517516a98c8a1d3 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 286058 c544f0b84472f06a0bb1a9168d97172a Size/MD5 checksum: 8140 fbc6b74842aee1cb8ce02d4a04449147 Size/MD5 checksum: 12338 0c9a3e6e923a64b63d93fe7144ee71a5 Size/MD5 checksum: 12924 2f448ce1f1f3efaac7ad331c0a0a7675 Size/MD5 checksum: 93150 3773f063ebacc40610eae6a87efb9635 Size/MD5 checksum: 11640 867c37100d6d3d599cb0087154e695e7 Size/MD5 checksum: 197852 8d0751903f32ac85d79f7c7079bd538c Size/MD5 checksum: 10470 ffe9677a8876bd79c9a90b68fc9e83ed Size/MD5 checksum: 9752 97b0505e6f8be78d588419bfa983a5ca Size/MD5 checksum: 47858 3d156b29744730cfdf580492409ed18e Size/MD5 checksum: 13948 a23f635d74e3fd6a161259cc8d7aff0d Size/MD5 checksum: 24258 7a82a47f649cde4bc30ffeb7851f6ca6 Size/MD5 checksum: 12328 12bc5183aeb0556c6cfd93f0ef9cf35e powerpc architecture (PowerPC) Size/MD5 checksum: 18728 33bd26b58a6a3236a9fad6d5e8cbbea7 Size/MD5 checksum: 15326 945c8fe4ba486a3d1f5fb8a10313ba57 Size/MD5 checksum: 12188 2da2a35d12e9d7de560a510d176539d5 Size/MD5 checksum: 13976 2779cefd3e1d9dd52298e3488a43448a Size/MD5 checksum: 11614 6bc10d2d0eb9ca8f550711edca6423d8 Size/MD5 checksum: 15284 491eaa3c20d0959cdd04641656d8addf Size/MD5 checksum: 354844 c31fea45dc96160c13a7b66a060d634a Size/MD5 checksum: 15502 bcd70972964cfa86110bee9a6a1505ef Size/MD5 checksum: 101802 a18a6537d5d713bd0558c8f0ad249c9e Size/MD5 checksum: 55646 0f750ad4ac8dda19e0bc3040c04c8f7c Size/MD5 checksum: 30152 5df65eee7d68ceed32fae184b1b9001c Size/MD5 checksum: 9764 cb68e61cd8fb03f1e2d26d0b297967da Size/MD5 checksum: 187752 cf2371d1505f2ee08b609352d22c414a s390 architecture (IBM S/390) Size/MD5 checksum: 25942 0c2ce90a506f671b1b522d4d4a323228 Size/MD5 checksum: 14674 49f98c167a3a245dc0b0d3f26a9ebe31 Size/MD5 checksum: 13460 cddc4e03edcd1f8d36dc002df4ef9ea4 Size/MD5 checksum: 12176 0b5766d05c74930f8a044c3ce084ec9f Size/MD5 checksum: 14342 88b09e20ae652b177db0f0f61c461d88 Size/MD5 checksum: 10446 61a44b460b10abc4b8e73ef80bac346b Size/MD5 checksum: 51378 203a15cd5e5a77e776c5ecb6543e21a7 Size/MD5 checksum: 109096 8a14dddddc305e862f5a007ef2f5aa24 Size/MD5 checksum: 8372 e638b65b2635e101382e890499505b10 Size/MD5 checksum: 320758 f85d3f4c8ce42e174e1ee1e83f7b018e Size/MD5 checksum: 11712 c00a2198e2f3382b9b59ea542d1a2a69 Size/MD5 checksum: 13680 b32fad1ac9c06537e7a812a8c4e15172 Size/MD5 checksum: 175992 28ebd7f09cd900444761111a781e0609 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 10024 2e222ba1fe2dd6a2012c557c3817c9b7 Size/MD5 checksum: 8104 fbbeb078420f51a55700bec7e012aa1a Size/MD5 checksum: 11008 9aa3bd323afc84041d44a1df3de60ebf Size/MD5 checksum: 171106 864084977173738d1e63517e145fd7c2 Size/MD5 checksum: 12396 457318a80c8a837b87f60216e9e11f50 Size/MD5 checksum: 293208 171a90622ce7063eea81abe2dc54e7dd Size/MD5 checksum: 9798 2007ca84fe0f3b714a7bb9fb2034c48c Size/MD5 checksum: 97120 eaa2dd2c767ebe8df597fb148f5a22cf Size/MD5 checksum: 13746 730dc0d290eee22bcbed544136bb9d22 Size/MD5 checksum: 12676 529a011e332137683d4522783a278682 Size/MD5 checksum: 46048 3bcb521163e5f02dd192a5d55d169e1c Size/MD5 checksum: 12460 9551719654ec31880c448a3cd9c7e023 Size/MD5 checksum: 24352 6910ac3dfa461f40cf67a30b9c16c9e7 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main Fordpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Resolution for local privilege escalation flaw in PulseAudio components on Debian platforms. Update advised.. PulseAudio Update, Debian Security Patch, Privilege Escalation Fix. . LinuxSecurity.com Team

Calendar%202 Jan 27, 2008 Debian
87

Debian 3.1 DSA-1237-1: Kernel Update Fixes DoS Threats and Risks

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1237-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Dann Frazier December 17th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : kernel-source-2.4.27 Vulnerability : several Problem-Type : local/remote Debian-specific: no CVE ID : CVE-2006-4093 CVE-2006-4538 CVE-2006-4997 CVE-2006-5174 CVE-2006-5649 CVE-2006-5871 Several local and remote vulnerabilities have been discovered in the Linux kernel that may lead to a denial of service or the execution of arbitrary code. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2005-4093 Olof Johansson reported a local DoS (Denial of Service) vulnerability on the PPC970 platform. Unpriveleged users can hang the system by executing the "attn" instruction, which was not being disabled at boot. CVE-2006-4538 Kirill Korotaev reported a local DoS (Denial of Service) vulnerability on the ia64 and sparc architectures. A user could cause the system to crash by executing a malformed ELF binary due to insufficient verification of the memory layout. CVE-2006-4997 ADLab Venustech Info Ltd reported a potential remote DoS (Denial of Service) vulnerability in the IP over ATM subsystem. A remote system could cause the system to crash by sending specially crafted packets that would trigger an attempt to free an already-freed pointer resulting in a system crash. CVE-2006-5174 Martin Schwidefsky reported a potential leak of sensitive information on s390 systems. The copy_from_user function did not clear the remaining bytes of the kernel buffer after receiving a fault on the userspace address, resulting in a leak ofuninitialized kernel memory. A local user could exploit this by appending to a file from a bad address. CVE-2006-5649 Fabio Massimo Di Nitto reported a potential remote DoS (Denial of Service) vulnerability on powerpc systems. The alignment exception only checked the exception table for -EFAULT, not for other errors. This can be exploited by a local user to cause a system crash (panic). CVE-2006-5871 Bill Allombert reported that various mount options are ignored by smbfs when UNIX extensions are enabled. This includes the uid, gid and mode options. Client systems would silently use the server-provided settings instead of honoring these options, changing the security model. This update includes a fix from Haroldo Gamal that forces the kernel to honor these mount options. Note that, since the current versions of smbmount always pass values for these options to the kernel, it is not currently possible to activate unix extensions by omitting mount options. However, this behavior is currently consistent with the current behavior of the next Debian release, 'etch'. The following matrix explains which kernel version for which architecture fix the problems mentioned above: Debian 3.1 (sarge) Source 2.4.27-10sarge5 Alpha architecture 2.4.27-10sarge5 ARM architecture 2.4.27-2sarge5 Intel IA-32 architecture 2.4.27-10sarge5 Intel IA-64 architecture 2.4.27-10sarge5 Motorola 680x0 architecture 2.4.27-3sarge5 Big endian MIPS 2.4.27-10.sarge4.040815-2 Little endian MIPS 2.4.27-10.sarge4.040815-2 PowerPC architecture 2.4.27-10sarge5 IBM S/390 architecture 2.4.27-2sarge5 Sun Sparc architecture 2.4.27-9sarge5 The following matrix lists additional packages that were rebuilt for compatibility with or to take advantage of this update: Debian 3.1 (sarge) fai-kernels 1.9.1sarge5 kernel-image-2.4.27-speakup 2.4.27-1.1sarge4 mindi-kernel 2.4.27-2sarge4 systemimager 3.2.3-6sarge4 We recommend that you upgrade your kernel package immediately and reboot the machine. If you have built a custom kernel from the kernel source package, you will need to rebuild to take advantage of these fixes. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 831 b970d762bf162cdfc8df32549bbdd566 Size/MD5 checksum: 32299 1007b0e6ba417ea12969e495056b2d5e Size/MD5 checksum: 840 381052d0f0e53b867b8190d9bf0e0d1b Size/MD5 checksum: 34450 4fe66843eb3dde9636a292726b0720ca Size/MD5 checksum: 1581 f670c9495d1e6b3fc0dae34079be2703 Size/MD5 checksum: 99762 689742b819b03635be81e56f236f015b Size/MD5 checksum: 1143 aa5d275cbb5e611a430558c75d2ddce6 Size/MD5 checksum: 55593 e8517a3876c679cf01ccdbdaf666c4fd Size/MD5 checksum: 876 7416f4d8d7d4d468977f966d6cb680da Size/MD5 checksum: 12864 5d32bbaecfcef58ac406939346922caa Size/MD5 checksum: 1074 cf00f7439b32b998ac35cf9bc0ba17ce Size/MD5 checksum: 24784 bb76d31c4e97594546a1ce46205627be Size/MD5 checksum: 832 61fe3968d2b8e2a0ae27d86bdadd82dd Size/MD5 checksum: 10570 982fd40704097c18838e3954de9d946e Size/MD5 checksum: 732 ea5120c744a0c6680bd77bc262018e6d Size/MD5 checksum: 18921 f898a597de3f981b99848160f092f06e Size/MD5 checksum: 1051 007ebb5db36532e0bef9462411d7a25b Size/MD5 checksum: 309221 e9154cdadd12cf9d3042fc3c69906796 Size/MD5 checksum: 1131 6b22f4ecad2ce3d2404d606c77da9dc7 Size/MD5 checksum: 1464751 d1891087138beef4e77784e3b29230b5 Size/MD5 checksum: 900 6b7eaed1211e79eeb7822c470588dc10 Size/MD5 checksum: 755526 437a36887a3730d49c6681e163085c91 Size/MD5 checksum: 38470181 56df34508cdc47a53d15bc02ffe4f42d Size/MD5 checksum: 750 49de53f3e66da5396a7c447411eda404 Size/MD5 checksum: 5089 400dd7c2ce12ba55e876cb90a035095f Size/MD5 checksum: 9501 a4ad085824ade5641f1c839d945dd301 Architecture independent components: Size/MD5 checksum: 3581076 e1bbfffc57dbdfd0b9cd2d0a66a7744b Size/MD5 checksum: 710724 9535988810d9c8f3f4019720bd49a30b Size/MD5 checksum: 31034148 28894dd804436675aedfc296a8ee4d63 Size/MD5 checksum: 27696 90eb280799013da95a3c1188e8b84d50 Size/MD5 checksum: 2420804 1a05dca524994806146a6900efa71899 Alpha architecture: Size/MD5 checksum: 5690 26d3f171f62b80b0b8e978652f8f485a Size/MD5 checksum: 8074 4f676244465a1b8492343ffc27de9b7b Size/MD5 checksum: 4572104 d92c8a0b7398b6b41d52c7a55a3d88f1 Size/MD5 checksum: 270932 be9e18785e87f29f8632a9fc973b0bbb Size/MD5 checksum: 272886 dea691efa19f4b82691124fa62e8963f Size/MD5 checksum: 4574778 a40c45730f344deb8cfcc1d1a7ad2488 Size/MD5 checksum: 273276 95820aca7779957cdc5b380de2241a4d Size/MD5 checksum: 275206 01567b6608388db6ecbea1a4cfa5a99f Size/MD5 checksum: 16516634 eb2e92ade4debc9bfdedb40134b3efd6 Size/MD5 checksum: 16970506 2b58db598e31823c08f993da80ab10d0 Size/MD5 checksum: 16531732f6b0507544d219740e11894d49906179 Size/MD5 checksum: 16983616 735c022a0d097f46a03348fe91a6e7ac Size/MD5 checksum: 20480 505188720fcfed347602c30bb1cd5f6c ARM architecture: Size/MD5 checksum: 483596 fe85544eabe959ce72f05dda8d65185a Size/MD5 checksum: 4726650 4729ca286f8e2314f6c5cdfaefbe93aa Size/MD5 checksum: 1695008 4beae00e1c3e83463a772fe17aebc80f Size/MD5 checksum: 1059362 ee2f850805f19c7fdfdb8c866566cc56 Size/MD5 checksum: 7376966 26755e712c14e0003b0d599ccc1bac98 Size/MD5 checksum: 3165708 f673a41f1403e7a85e9cdbfc6cffb23b Size/MD5 checksum: 3687138 022d79de206311aa2364e5449915a94d Size/MD5 checksum: 18868 b0530590361123733515d0cd21bb01c9 Intel IA-32 architecture: Size/MD5 checksum: 8224 ae479d6dbd6c171e94a25e5b59b4243f Size/MD5 checksum: 10534 c2e539824425af065b4617aa3589b782 Size/MD5 checksum: 1823160 c058363ae7646c370f77d620c6bb6438 Size/MD5 checksum: 297168 19b508f76e107d8cf988560b3fd04a8b Size/MD5 checksum: 298340 073efbc2d728e4ee3b30e980d2d0f5e6 Size/MD5 checksum: 298200 94f48b9438f8e100590c8874b3c05e0c Size/MD5 checksum: 300156 1143aa70f66386bf4789431e80810b2d Size/MD5 checksum: 297050 44f3d785ad2c70829373321327e6e3e6 Size/MD5 checksum: 297978 7795ea75d534ded9d2a7ade27fc3cf21 Size/MD5 checksum: 299650 9676b8d779e9dd09f0583d950e2fd2d5 Size/MD5 checksum: 1825394 6ca7de755e3890e989cfaa2271a0ba3d Size/MD5 checksum: 299390 5973792d7e12022780b7d4d51e1f2372 Size/MD5 checksum: 300664 948a088ae36738d5de11375009a162b6 Size/MD5 checksum: 300562 620f476d04bfe3a906b9110d9495f902 Size/MD5 checksum: 302114 14db999e3504855ab0239341e41b8d0d Size/MD5 checksum: 299548 6b842b2221e6afa94332d6e2e434f5e2 Size/MD5 checksum: 300286 483ea0ad7316d1c82e1d667d8826d536 Size/MD5 checksum: 302128 d5f9b05985e032d4ce522283566b0fdd Size/MD5 checksum: 11046010 e32bdedde43897d24792ce5199c8e428 Size/MD5 checksum: 12024834 edfa4a6008fde7599fbd7e5081cc2bb9 Size/MD5 checksum: 12336042 d2c1f84d0c771fa8de10c87e0cb35e70 Size/MD5 checksum: 12679824 4ab0ad4ca8bf76e6614768cee8245c24 Size/MD5 checksum: 11708878 7842c8dfed5e6c2cbbed136807b5cf7f Size/MD5 checksum: 12083292 b45dd7f50ef9f4726711c4af87368037 Size/MD5 checksum: 12415392 b56e1c928e816d53f6cba41f0138e91d Size/MD5 checksum: 11052302 255d69882c14e9a92cf951b2fff9263f Size/MD5 checksum: 12036374 f576550eacb4d17f1388b89ce9615f06 Size/MD5 checksum: 12355204 cd85e4ca2b25cecddd0077b4eb47a0ce Size/MD5 checksum: 12695118 31480c61a3ac3c71d4a1b9703b8d8139 Size/MD5 checksum: 11723728 3e4e06b330cd1ac479769baac326df7b Size/MD5 checksum: 12098618 541559dcbaa99bbd02642fe31b063ffd Size/MD5 checksum: 12434342 5813dbe009eea4141a872752874f0335 Size/MD5 checksum: 267586 95d23b87e054f0a8dc82edd6a7f51f60 Size/MD5 checksum: 292452 d090775026be223c949e0f86f5b1f646 Size/MD5 checksum: 298278 f8cc95014790c87b62bf81b2b2d2d674 Size/MD5 checksum: 303840 f1362454b42361047297b1ef7f90769c Size/MD5 checksum: 286252 d67de5ec744bad676981089e5623561c Size/MD5 checksum: 292100 0ce7cff58a32eb924199a652062a7e9f Size/MD5 checksum: 296978 fdb699b60e0d3ae5fa4df76e0203c603 Size/MD5 checksum: 269980 77410fc804084d2169ceb1319a9e690f Size/MD5 checksum: 294862 b6270e45a1acfc537b6d9ba474e163d7 Size/MD5 checksum: 300698 939c08139e1e17f754d9d676ca3f9c04 Size/MD5 checksum: 306442 507f4d8c295e1c4549b06ded67009b98 Size/MD5 checksum: 288692 900499f7b356261f9859d051c96a54e8 Size/MD5 checksum: 294624 64620786d42099ead5e5bdb829f7c573 Size/MD5 checksum: 2995126a06f4d16650536bdcd1dd7f44851a3d Size/MD5 checksum: 4773910 8c3955d4fa6d3af721c7d820a2e9d5a1 Size/MD5 checksum: 11308946 ac2eca7ddc6e0fcfa0b7d835b28d3c41 Size/MD5 checksum: 16632 bab2d60567d5858c019407cca58d6688 Size/MD5 checksum: 7775346 31814a4d66ec8053772ad147a4a62b26 Intel IA-64 architecture: Size/MD5 checksum: 5190 00c8fff6af32adf62f8c91794745931b Size/MD5 checksum: 7486 b40d48a972ee0cb277b63a649e0d01f2 Size/MD5 checksum: 4678756 01467522c3106fab54cf6983a9c6487d Size/MD5 checksum: 239184 cd07eff9264141e6ddbd015f5f76e99e Size/MD5 checksum: 240504 03b131531af57cd2f46cf8ff8ba93f45 Size/MD5 checksum: 239212 457102e92a389246447410ce172bbd2f Size/MD5 checksum: 240498 66cc452b54b87366d7755da6693aa76c Size/MD5 checksum: 4689752 b5ef21aee13412359cdb7fb5e039de74 Size/MD5 checksum: 242570 3dbd1ce3bbfed1c7c4aeb3de2396cf77 Size/MD5 checksum: 243234 14ed081560b4008f6e391b325b39544f Size/MD5 checksum: 242366 4acf18300727b24afe4f223623e5c44d Size/MD5 checksum: 243558 f48e9a34ea714966024f24277293d1d6 Size/MD5 checksum: 7262 4cc86fa5dd7f157ab7fa3747f9ac8573 Size/MD5 checksum: 7274 7b6dec36049b6f277b72c2c6a24dd538 Size/MD5 checksum: 7290 00cf535d95cb5a827d53219de9d2b0a1 Size/MD5 checksum: 7302 093e0825e05675fd728a7db694531f1a Size/MD5 checksum: 16665798 0dfd99eeb9d1c8933ec71f0cdc80a71e Size/MD5 checksum: 17023766 09ae0a0c0b133abe047cd50b8e09f02e Size/MD5 checksum: 16623970 2b70e151d5c13c89d7646dc01d28a277 Size/MD5 checksum: 16970478 affcf0503482e489ae8384b3d7279fce Size/MD5 checksum: 16677620 d997c6d47e3592b0ab8c82917548102b Size/MD5 checksum: 17037020 75b4b47d8ebd8cd91327cfeaf76dd0d9 Size/MD5 checksum: 16630570 11c5c2ea12f3cab5865b225f765d71c0 Size/MD5 checksum:16988538 f8b022aa39e91bccc24ab3adaab2c7aa Size/MD5 checksum: 22224 a4d38a63b6bd0399aa84d50d23f09cf6 Motorola 680x0 architecture: Size/MD5 checksum: 2642370 64f44bc3e9c3313cb7aecf789ddb51de Size/MD5 checksum: 2545710 6dcdfedd3356d0f20e7899da7a7ff2bd Size/MD5 checksum: 2396790 5d278c185e1ca1d34e65dc657cbcbe96 Size/MD5 checksum: 2478704 181df694d051555f0253ff27e9f0863c Size/MD5 checksum: 2326206 033f694ed1a6acc24efb07ecdbbe125c Size/MD5 checksum: 2397324 f716f0313d88c62779569712078ae0c8 Size/MD5 checksum: 2262406 c0c6fbb7a1160688f8e8c7ae97d43e9a Size/MD5 checksum: 16338 f9b14151760944376dfbbbfc47b73346 IBM S/390 architecture: Size/MD5 checksum: 4578000 97fce93cc2ebc4da7c0a7bab1c157aef Size/MD5 checksum: 4579864 fc815cfb54bdfed711c2c09fae740500 Size/MD5 checksum: 2774574 86262b4b2bb4c6db5471c97dcc1747b4 Size/MD5 checksum: 991868 a712b00ecf74c79fadeeb0f50b298618 Size/MD5 checksum: 2966354 5ebdd9b9fa80cdbdf0049683eaad24ee Size/MD5 checksum: 2782140 11029023c05ea13dc51206e74bdb2391 Size/MD5 checksum: 995678 a642f56da45718fe0a665ad1836f6112 Size/MD5 checksum: 2974550 749696ce8a74c220819579cb14ebff3a Size/MD5 checksum: 19338 c86219a43c645a82ee1782d94dc6dce8 Sun Sparc architecture: Size/MD5 checksum: 8328 1e092e0877937ac5dbf46e347992c7d3 Size/MD5 checksum: 10550 164dc9869ea386fd3169864645d89a98 Size/MD5 checksum: 2023482 b50d08e5c4c12fff4473e77babeda1ab Size/MD5 checksum: 162670 2c495f6b6e414dc24f2c676ecd84dda4 Size/MD5 checksum: 164478 f59e33098dec7e1ff68b162aab6d56a6 Size/MD5 checksum: 201214 fa92988ddfba0e9f03ace13f365dfc77 Size/MD5 checksum: 202452 d56ab1dd8ddb9d4b10de13c37c4c4af5 Size/MD5 checksum: 2025304 c036f26f3bb2c1a7f1acc7588b54c389 Size/MD5 checksum: 164532 18adb86c0d3ce5b6424b277ce2e39794 Size/MD5 checksum: 166318 d3fa63eab9ddab3f6b5db8f385ffe458 Size/MD5 checksum: 202940 c03ec973495d21f03df3f156c3dc033b Size/MD5 checksum: 204266 547fb57dd64584ee765c427d2c0554fd Size/MD5 checksum: 3597102 1c5334adb92bbaf0ce96e82abcf6d77e Size/MD5 checksum: 3784076 3d1b5e5c3e147bf760c6077fa36eb783 Size/MD5 checksum: 6377902 7bd0e77ec9494b0ed352917b829fa5a0 Size/MD5 checksum: 6543220 a73b077777c3a22ca9538666d3ff8aee Size/MD5 checksum: 3605072 14ac1e3ce17cbf64bfd7a61f520cf494 Size/MD5 checksum: 3792788 38ef858c0ff9158cf44590782f5664e0 Size/MD5 checksum: 6385736 5dfaf6a6a6e5a809a38458ef79661d3b Size/MD5 checksum: 6550182 97b6ef3ce231c448687bf357daae4faf Size/MD5 checksum: 18200 1465507e83184c1c32b2015530dc39c9 AMD64 architecture: Size/MD5 checksum: 17252 8c0ddf9b2b2c5f7ac695d7f10af7aeb5 HP Precision architecture: Size/MD5 checksum: 19334 22608a5cbf78b9dfb49a91685513485e Big endian MIPS architecture: Size/MD5 checksum: 4681544 e5ad300c16978417dfdb04a55b3cf505 Size/MD5 checksum: 3854770 6fb17fc57af59997c55dc5d15fe86324 Size/MD5 checksum: 3857642 135e1590f21c14db5765422dadd03571 Size/MD5 checksum: 7186300 c841f01587ec79fc411bda056d663a04 Size/MD5 checksum: 20448 02fd1e80e83a5c3e7b6b16832b77cc26 Little endian MIPS architecture: Size/MD5 checksum: 4686676 eb7e81b8a3a6829252a02251aed92b08 Size/MD5 checksum: 3037974 ea0208a51612c1e34a6aa60410d21c3d Size/MD5 checksum: 2999656 ec0c25c38b5e7a8a65142bbc52b8220d Size/MD5 checksum: 4107630 deefd96c7f6b2e3e954c98284d367e61 Size/MD5 checksum: 2141986 e3ea6afd27d393fcdf6b20a755fa7a41 Size/MD5 checksum: 7048130 dd624bc0af5d1e39be9084a58ad575d5 Size/MD5 checksum: 46775666179a00efde69e2bef158f584b667bc9 Size/MD5 checksum: 20488 41476ba7fba16f7453c72fad3ac7279a PowerPC architecture: Size/MD5 checksum: 143604 dbd3e6559ab4d24640e78fa5096b8d4d Size/MD5 checksum: 143402 0ac835db06b6feb1b662ffe7cee6b1ca Size/MD5 checksum: 157358 df24d8751cee33c2ec3490fe3c58aab5 Size/MD5 checksum: 157652 f95e05ad17a85a314f36ad794231bd19 Size/MD5 checksum: 157408 19f3fa73f641f93a734b5a0c1d92800a Size/MD5 checksum: 4684386 33f89f6ff68d4697590dc56da8f5c85b Size/MD5 checksum: 4694600 0d7e24209c0c22ad726ddc7d2046f5e4 Size/MD5 checksum: 4802248 dc4bb7170432243f61d1ccf10820518f Size/MD5 checksum: 2502696 794593451ab3047561014f148290650c Size/MD5 checksum: 1819296 026d70d2989c1f5345280777f8430d33 Size/MD5 checksum: 13486360 c02196059ed6f7103d6faa2a45320828 Size/MD5 checksum: 12759400 e9108a2f987765ff915435b199bda15e Size/MD5 checksum: 13792416 3af28a8ab21e298043311c0e15b19184 Size/MD5 checksum: 65868 b0f73596dd19e6c41d0fa64f5c3d7e22 Size/MD5 checksum: 11006 c537fc249b24e8d4c57165e6f4d6ad5a Size/MD5 checksum: 10928 11f29b35752d4f50ea28b345001efb2b Size/MD5 checksum: 18902 a8338f398511cd07bd619b812f18d76b These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - --------------------------------------------------------------------------Debian Security Advisory. updated, package, --------------------------------------------------------------------------debian. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 17, 2006 Critical Debian
87

Debian Log2mail Severe Format String Vulnerability DSA 513-1

Exploit could cause arbitrary code to be executed with the privileges of the log2mail process.. Debian Security Advisory DSA 513-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman June 3rd, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : log2mail Vulnerability : format string Problem-Type : local/remote Debian-specific: no CVE Ids : CAN-2004-0450 This email address is being protected from spambots. You need JavaScript enabled to view it. discovered a format string vulnerability in log2mail, whereby a user able to log a specially crafted message to a logfile monitored by log2mail (for example, via syslog) could cause arbitrary code to be executed with the privileges of the log2mail process. By default, this process runs as user 'log2mail', which is a member of group 'adm' (which has access to read system logfiles). CAN-2004-0450: log2mail format string vulnerability via syslog(3) in printlog() For the current stable distribution (woody), this problem has been fixed in version 0.2.5.2. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you update your log2mail package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 483 2a1a8392e2e4ef146ad437e8d0abfd3b Size/MD5 checksum: 29532 a593de7eb31e492bcaec9f2cbf0d8c8a Alpha architecture: Size/MD5 checksum: 70318a09d0a7d8585c1c4845e5fe479e7d94f ARM architecture: Size/MD5 checksum: 31408 92dea5294c75b0b3befc50584de55b3a Intel IA-32 architecture: Size/MD5 checksum: 38750 1ac164fad7f976532b264a9ff5ea4ced Intel IA-64 architecture: Size/MD5 checksum: 49242 5704ea6ac083a7f7800b2ac2df8d31db HP Precision architecture: Size/MD5 checksum: 44726 9946fba7d6e7d1590073413e282e5aa0 Motorola 680x0 architecture: Size/MD5 checksum: 38700 e6ca7eefcb0adca40309075c14970877 Big endian MIPS architecture: Size/MD5 checksum: 48576 a2a96b0be1b4a8bc83a17db7fa2a51a1 Little endian MIPS architecture: Size/MD5 checksum: 47872 bcff2fb39c25c51270e0330fdafa5b87 PowerPC architecture: Size/MD5 checksum: 37056 2b8f844e4abf80505823c24dd1f0a7d8 IBM S/390 architecture: Size/MD5 checksum: 37280 86d660937516c317493412ba005ea2fb Sun Sparc architecture: Size/MD5 checksum: 34914 8ba63250986eb25923bcf1229f18bfe7 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Critical log2mail format string risk allows arbitrary code execution, impacting system security and requiring immediate updates.. Debian log2mail risk, critical security update, format string attack, arbitrary code execution, DSA advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 08, 2004 Critical Debian
87

Ubuntu: DSA 230-5 Low: Apache Unauthenticated Access Vulnerability

eldav, a WebDAV client for Emacs, creates temporary files without taking appropriate security precautions. This vulnerability could be exploited by a local user to create or overwrite files with the privileges of the user running emacs and eldav.. -------------------------------------------------------------------------- Debian Security Advisory DSA 325-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman June 19th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : eldav Vulnerability : insecure temporary file Problem-Type : local Debian-specific: no CVE Ids : CAN-2003-0438 eldav, a WebDAV client for Emacs, creates temporary files without taking appropriate security precautions. This vulnerability could be exploited by a local user to create or overwrite files with the privileges of the user running emacs and eldav. For the stable distribution (woody) this problem has been fixed in version 0.0.20020411-1woody1. The old stable distribution (potato) does not contain an eldav package. For the unstable distribution (sid) this problem has been fixed in version 0.7.2-1. We recommend that you update your eldav package. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 592 9dd06517b53570a595d5c368924ceda1 Size/MD5 checksum: 3814 c4400b418452e1aea9a115a2af82e1aa Size/MD5checksum: 12319 3b62e4b9b05eb1c8ef27e9f5d3b98db2 Architecture independent components: Size/MD5 checksum: 15546 5dc5beca6a1c57b5a4b32968ebc07da4 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Discover the details of Debian advisory DSA 325-1, addressing vulnerabilities in eldav related to temporary files and corrective actions.. temporary file security,debian eldav advisory,local access exposure,webdav emacs security. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Jun 20, 2003 Low Debian
87

Ubuntu: DSA 255-2 High: Network Analyzer Memory Leak Issue

Due to insufficient bounds checking performed by the whois parser, it may be possible to corrupt memory on the system stack.. -------------------------------------------------------------------------- Debian Security Advisory DSA 254-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze February 27th, 2003 http://www.debian.org/security/faq -------------------------------------------------------------------------- Package : traceroute-nanog Vulnerability : buffer overflow Problem-Type : local, remote Debian-specific: no CVE Id : CAN-2002-1051 CAN-2002-1364 CAN-2002-1386 CAN-2002-1387 BugTraq Id : 4956 6166 6274 6275 A vulnerability has been discovered in NANOG traceroute, an enhanced version of the Van Jacobson/BSD traceroute program. A buffer overflow occurs in the 'get_origin()' function. Due to insufficient bounds checking performed by the whois parser, it may be possible to corrupt memory on the system stack. This vulnerability can be exploited by a remote attacker to gain root privileges on a target host. Though, most probably not in Debian. The Common Vulnerabilities and Exposures (CVE) project additionally identified the following vulnerabilities which were already fixed in the Debian version in stable (woody) and oldstable (potato) and are mentioned here for completeness (and since other distributions had to release a separate advisory for them): * CAN-2002-1364 (BugTraq ID 6166) talks about a buffer overflow in the get_origin function which allows attackers to execute arbitrary code via long WHOIS responses. * CAN-2002-1051 (BugTraq ID 4956) talks about a format string vulnerability that allows local users to execute arbitrary code via the -T (terminator) command line argument. * CAN-2002-1386 talks about a buffer overflow that may allow local users to execute arbitrary code via a long hostname argument. * CAN-2002-1387 talks about the spray mode that mayallow local users to overwrite arbitrary memory locations. Fortunately, the Debian package drops privileges quite early after startup, so those problems aer not likely to result in an exploit on a Debian machine. For the current stable distribution (woody) the above problem has been fixed in version 6.1.1-1.2. For the old stable distribution (potato) the above problem has been fixed in version 6.0-2.2. For the unstable distribution (sid) these problems have been fixed in version 6.3.0-1. We recommend that you upgrade your traceroute-nanog package. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato --------------------------------- Source archives: Size/MD5 checksum: 578 c0a65b3b527a4939ceb53195eb67078f Size/MD5 checksum: 6651 74ae0eb419bd8bcbcf3f0f591b1015aa Size/MD5 checksum: 27020 39246e5b1d44d6276489d4801c4a7bfb Alpha architecture: Size/MD5 checksum: 23168 67c44d189c1c2c8384e49fda6dc25df1 ARM architecture: Size/MD5 checksum: 19872 4f9a429c9eb0623e02ebcf226dcfb20a Intel IA-32 architecture: Size/MD5 checksum: 18588 78445b5c9cbef332d14f22e40dce094b Motorola 680x0 architecture: Size/MD5 checksum: 17742 a797b9831aee1f5bdca3fa879a39fc34 PowerPC architecture: Size/MD5 checksum: 19550 66ccd20f5d062885425531ee141d0cf1 Sun Sparc architecture: Size/MD5 checksum: 22154 623a8662411fd9a00fea53688237c60d Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 589d7eb4bd225e4f2fc16c021776da0c081 Size/MD5 checksum: 6769 fbe2f9d877d77681846838bf7dea67f2 Size/MD5 checksum: 27560 493e77d8cf0e86744668e3efd4622378 Alpha architecture: Size/MD5 checksum: 23882 82ddf32182750bc2fa044a6cf9a85733 ARM architecture: Size/MD5 checksum: 20374 e23517c29047740b8d8b0ae7820e10f8 Intel IA-32 architecture: Size/MD5 checksum: 19068 2be7ec42cc04ffff294a53b3156126d2 Intel IA-64 architecture: Size/MD5 checksum: 26644 6c77e2d0deca24c66840705f790bdb80 HP Precision architecture: Size/MD5 checksum: 21754 562203dd8680bc949e13af13665a5bf7 Motorola 680x0 architecture: Size/MD5 checksum: 18360 511b65c864403cdd3837a5f864349244 Big endian MIPS architecture: Size/MD5 checksum: 21370 67ea3bb02eae05d9036cacd9b2077a04 Little endian MIPS architecture: Size/MD5 checksum: 21414 4d3606016b222a566fc9b9221b1cf7e5 PowerPC architecture: Size/MD5 checksum: 20320 378a7f4eaf2b14f30d8d1e97d5562bdc IBM S/390 architecture: Size/MD5 checksum: 20286 3433605f96800f3028330cac370018e8 Sun Sparc architecture: Size/MD5 checksum: 23038 2785266b4cd3c7c14ebd50be2095dcf4 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . A significant memory corruption affecting traceroute-nanog due to buffer overflow risks identified in Debian distributions.. Debian Advisory, Traceroute Exploit, Memory Corruption Issue, Security Bulletin. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 27, 2003 Important Debian
87

Debian: 242-1 Critical: Local And Remote KDE Command Risks

The KDE team discovered several vulnerabilities in the K DesktopEnvironment. In some instances KDE fails to properly quote parametersof instructions passed to a command shell for execution.. -------------------------------------------------------------------------- Debian Security Advisory DSA 242-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze January 24th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : kdebase Vulnerability : several Problem-type : local, remote Debian-specific: no CVE Id : CAN-2002-1393 The KDE team discovered several vulnerabilities in the K Desktop Environment. In some instances KDE fails to properly quote parametersof instructions passed to a command shell for execution. These parameters may incorporate data such as URLs, filenames and e-mail addresses, and this data may be provided remotely to a victim in an e-mail, a webpage or files on a network filesystem or other untrusted source. By carefully crafting such data an attacker might be able to execute arbitary commands on a vulnerable system using the victim's account and privileges. The KDE Project is not aware of any existing exploits of these vulnerabilities. The patches also provide better safe guards and check data from untrusted sources more strictly in multiple places. For the current stable distribution (woody), these problems have been fixed in version 2.2.2-14.2. The old stable distribution (potato) does not contain KDE packages. For the unstable distribution (sid), these problems will most probably not be fixed but new packages for KDE 3.1 for sid are expected for this year. We recommend that you upgrade your KDE packages. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use theline for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 1155 1c2f6bce7cc06f7fa556d177ee0d1f8c Size/MD5 checksum: 64429 c01b3398beac82fe7a91ebf23f76dc44 Size/MD5 checksum: 13035693 3c17b6821bbd05c7e04682c70cb7de8a Architecture independent components: Size/MD5 checksum: 3140290 c3d56e354504de6160ce99e7c32a72d4 Size/MD5 checksum: 961472 157b717319bcc918f160226e7cf27b80 Alpha architecture: Size/MD5 checksum: 488248 fa12a97ffda1a308dd9d2b8aabbe3a3a Size/MD5 checksum: 6991312 0105faf2cfa7ef754405e0889d11ca4b Size/MD5 checksum: 107402 b6c9731bbbe46af37889cb30312ba88f Size/MD5 checksum: 48790 13302a13b5656ee42f964570711950a8 Size/MD5 checksum: 1988546 e297c55e00b54bd23659bea7ffd25e6f Size/MD5 checksum: 435722 71a05c9ee98d6a36ff1bc79571d06612 Size/MD5 checksum: 2228458 0b8d04e160a2c86a18d57121ea880c26 Size/MD5 checksum: 537934 c2f3ccfb077fdd9e0e0e62bda19270e2 Size/MD5 checksum: 482142 bb862e074491d4e4e8a247b93a009de3 Size/MD5 checksum: 45328 b7d43c6ab5c05be3ba783bd4cf21ea41 Size/MD5 checksum: 269834 c95c03e6914fc08a0629f3a69c306ec4 ARM architecture: Size/MD5 checksum: 418176 120c1c79fd7e5addb73104ecac014e03 Size/MD5 checksum: 6519720 072c37c220bba66c7ca49ad4684ebbc1 Size/MD5 checksum: 85824 b863022ccb62bcf6c8507403a7cef4a7 Size/MD5 checksum: 47866 a13e51117646d5127d7d8a8536d03aa0 Size/MD5 checksum: 1679988 d92d5c6ea6246c7c04148ded871a72ef Size/MD5 checksum: 390400251485955001545cdd230f022e16ef71 Size/MD5 checksum: 1925914 c6f262f5ae4796304d498c5bd565ea6a Size/MD5 checksum: 456860 08333dfdecf4b47a304000430e73b44e Size/MD5 checksum: 374834 5acfa19be2dc4f43b0ae9f6b27985627 Size/MD5 checksum: 45336 99a5b5668b5e90af15f9997dea0f4808 Size/MD5 checksum: 215360 65c4d19f324ff5a370acf0294cb7d73d Intel IA-32 architecture: Size/MD5 checksum: 407314 2ce33f8648b83c55f30113d01506cf13 Size/MD5 checksum: 6485854 cc5c871ea43054b6f19157b90c48c06c Size/MD5 checksum: 83350 bdfae8fd937cc0467bf297403ea448d1 Size/MD5 checksum: 47100 e9f36485f457971f7411266bd7d2614c Size/MD5 checksum: 1651936 ca733bd1a0e47861d5091c73dada22e2 Size/MD5 checksum: 395278 09d12dc33bb2dab7cf6396ecd6e6bba0 Size/MD5 checksum: 1928578 f46c5020af0388f6a20543eb203b9158 Size/MD5 checksum: 458384 27eeee0d5b9424eb6f57ef3eaf3f467c Size/MD5 checksum: 395632 cb9dc1d1ed88d2cf16df73a36087c41c Size/MD5 checksum: 45330 bb8b258083caf8b8456619c6e1b0a9fc Size/MD5 checksum: 220344 14fea5cf957bb2c4959d2ea4bb397df0 Intel IA-64 architecture: Size/MD5 checksum: 611832 fe5f4d19cdcea1f0b378fd2f09630cde Size/MD5 checksum: 7540560 6984cff6d03ae45876e96b7fec4136a8 Size/MD5 checksum: 119374 cfd44212e4b5d62bc9bf140bf4054995 Size/MD5 checksum: 51566 af625ce0ebf2721f5a9481a4b5e119c6 Size/MD5 checksum: 2464980 b19f9decc0fd7ef4215d853497d64082 Size/MD5 checksum: 538412 ee0162d17b7ba6b7847d08d27f50d967 Size/MD5 checksum: 2489362 de025813a71a7b0b1209965bb57fa218 Size/MD5 checksum: 598042 2185c46daca7d4b081f612e8247b6129 Size/MD5 checksum: 550982 96b731e339d9ff3df38960cfcb1e7caf Size/MD5 checksum: 45330 a30de08f2e62fde15f316c554a6800b8 Size/MD5checksum: 346972 4677e6485e519d90d8eed385b377bbf8 HP Precision architecture: Size/MD5 checksum: 513192 51eba589e816ae2b14200d6923a3ade1 Size/MD5 checksum: 6985794 338e3eb6f2dc15796b88b0ac4671d998 Size/MD5 checksum: 105460 bd901d74c3ec5205781851bce7226f36 Size/MD5 checksum: 48964 bb7f6ee31cdee2d338c6747e658af52f Size/MD5 checksum: 2084626 042caf97086e0ad384371414b963a17b Size/MD5 checksum: 445474 b751ed5983fe980c8127af6a0da01b34 Size/MD5 checksum: 2189758 5ad9ce3d760959f42f4c5f7e029c21f6 Size/MD5 checksum: 517018 e8a55b4f796115ef43263311bb782bb0 Size/MD5 checksum: 456262 3970caca2ea860ad6715ae01126e1aee Size/MD5 checksum: 45334 fddf721297cca5b07bae506121d2c229 Size/MD5 checksum: 259614 ac37d3dac4b58cf3ac8ae176a4ff45d8 Motorola 680x0 architecture: Size/MD5 checksum: 403152 55c8cb224c709b5cbe392e5d99b042a2 Size/MD5 checksum: 6472374 4d4a1fc3eafa38436117f8fec2ce7a4d Size/MD5 checksum: 84120 41ef7583f7195fd4d4eca580beddb265 Size/MD5 checksum: 46874 b7b36120c3ea71ff888dcef22339fb70 Size/MD5 checksum: 1632726 c8967a9d522c2e3b3081fbb55245aa62 Size/MD5 checksum: 381006 55c06d0a2e92a6d2f10baa52596ce0f1 Size/MD5 checksum: 1915036 4b4c87e51c0c9956dbdcd86d791c6d00 Size/MD5 checksum: 457528 dd6eaef7d9a94d5966ae6b618c3234d9 Size/MD5 checksum: 393846 20162b8beaed03d0692f2ac1607eedee Size/MD5 checksum: 45344 ac59effd72b55ec63f8adbb4b991b798 Size/MD5 checksum: 211366 fbaea0782cc52e90e9aef31d21f2524b Big endian MIPS architecture: Size/MD5 checksum: 413108 29ff0a80dd054c1f4931cdacf44fe404 Size/MD5 checksum: 6475834 c1e983e0ff0056df4e6bbc6ab0af9411 Size/MD5 checksum: 80554 92459355041d16af3a47565306f0d5d8 Size/MD5 checksum: 488462fb1633106f3b509ed034eb7af54bf00 Size/MD5 checksum: 1530524 77862c6732a82616a2422ea6f72988ea Size/MD5 checksum: 380842 cf4136bf0b5c80e88ed601b0925aee09 Size/MD5 checksum: 1884486 e14e3946246d08805d8d0107c9cd9e91 Size/MD5 checksum: 477090 40d6ad88fb6da678d316e70b239c78d4 Size/MD5 checksum: 419432 e45d08eab4f5f468749e3fc45b1dfc4c Size/MD5 checksum: 45336 04f7bea60736940e070534a1d3b364aa Size/MD5 checksum: 205360 2ac7f073aada97ab56a038e6772ab0f1 Little endian MIPS architecture: Size/MD5 checksum: 408158 0ca3969d0094189073261304e2544caf Size/MD5 checksum: 6448294 b81b50148dc734714d48963053ce60e5 Size/MD5 checksum: 80012 3c767fcfb250d857c1ba1846a68baef8 Size/MD5 checksum: 48952 62dcbd951b837fb7bd76f09788b47c83 Size/MD5 checksum: 1512654 ddc88773fdb5c5ce14ad5108d89c888f Size/MD5 checksum: 378598 ff5b79ede18320674132db668675d91f Size/MD5 checksum: 1869070 e29237753588295d3f2a9a31afad687d Size/MD5 checksum: 473420 833020f22abdb04dc6459224b86023e2 Size/MD5 checksum: 416214 57559eec0d46cb9f0fbae6ec1d4112f8 Size/MD5 checksum: 45330 577ccdb13c76c79253c00c67466f05bf Size/MD5 checksum: 202814 a37a67286bedc4ae07140ed9f234dd80 PowerPC architecture: Size/MD5 checksum: 423964 d3fc8129f4b7921602b9df7ab1b9de6f Size/MD5 checksum: 6494140 02f058e0b3b916693b51ac55eccdd2e8 Size/MD5 checksum: 84924 656540ee1b6f7c1ec20be24bf131efd0 Size/MD5 checksum: 47946 60b1369752fcb126cb9a44adc9d4917f Size/MD5 checksum: 1664594 929a7dd3305b76c9297c8deb0d7c6482 Size/MD5 checksum: 387834 44dca94eda6cbe00ebee80768b44cf0a Size/MD5 checksum: 1930536 03ea5af9e956612eaba89ef4c2a17a60 Size/MD5 checksum: 459102 9ba6631dc8c020c69cf048594697c173 Size/MD5checksum: 368952 9d1a7b0c108b314e2cc472f9599691eb Size/MD5 checksum: 45332 10fbb24ba44e4423a84513a580231331 Size/MD5 checksum: 219826 6d51ef66df5cc9d0336637c70c1e3cdc IBM S/390 architecture: Size/MD5 checksum: 434278 31ba9869bf2d68273cf59115a73465da Size/MD5 checksum: 6575916 8b93871e110b86883eaba8c4537cfefe Size/MD5 checksum: 84750 bd07fda46bbacdf44219e54ef908129e Size/MD5 checksum: 47308 3553545f9db49f25951c7a2ada7c7e5f Size/MD5 checksum: 1698400 7491783da345495131cdedf189f6f769 Size/MD5 checksum: 391534 a9756236891d61e398f2186aadc338c1 Size/MD5 checksum: 1977338 0cdba6fca2234903a1c320a328483d8e Size/MD5 checksum: 477916 ec0d11ad9c65a4a5dd2438608497a3ed Size/MD5 checksum: 428072 7825222ddd9f9035edfa4a05bb7a7de0 Size/MD5 checksum: 45328 7a06b706e196d45bddcb0f8324d6e8b4 Size/MD5 checksum: 226906 c6718269d1e9829a1aeec7a1f0790ae9 Sun Sparc architecture: Size/MD5 checksum: 426898 ed3e16a8c84e9d3fdc3a49ee30319407 Size/MD5 checksum: 6528296 205f82e13b21142c402374ccbffa7440 Size/MD5 checksum: 86026 ca3fff6a267390750e8561edd8ed8afd Size/MD5 checksum: 47274 2c2489d57108b616b3b4ef6484f38328 Size/MD5 checksum: 1670568 e93bf69e3ce9dcffb4e5a9a86334e24f Size/MD5 checksum: 390220 7e97d3e2f38ee71db8bc61c2613c2e17 Size/MD5 checksum: 1939454 f16d7177a66fafd1cb9e8b840a9c22ac Size/MD5 checksum: 468166 6123ddbb79f8834575045b4441272a03 Size/MD5 checksum: 390696 559e7e5604fca8befdccdac237749f66 Size/MD5 checksum: 45334 a13493bd02632bb5c439a49763f6e54d Size/MD5 checksum: 218684 94cb63a979fd02118c8f447e0fbab73f These files will be moved into the stable distribution after new KDE packages have been uploaded into unstable (sid) and compiled for allarchitectures. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . A range of vulnerabilities has been detected within KDE, which could allow cybercriminals to execute unauthorized operations on compromised Debian systems.. Debian Security,KDE Vulnerabilities,Command Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 24, 2003 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200