Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian 2.2 DSA-092-1 Critical: wmtv Local Root Access Exploit

Nicolas Boullis found a nasty security problem in the wmtv (adockable video4linux tv player for windowmaker) package asdistributed in Debian GNU/Linux 2.2.. -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory DSA-092-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman December 6, 2001 - ------------------------------------------------------------------------ Package : wmtv Problem type : local root exploit Debian-specific: no Nicolas Boullis found a nasty security problem in the wmtv (a dockable video4linux tv player for windowmaker) package as distributed in Debian GNU/Linux 2.2. wmtv can optionally run a command if you double-click on the tv window. This command can be specified using the -e command-line option. However since wmtv is installed suid root this command was also run as root, which gives local users a very simple way to get root access. This has been fixed in version 0.6.5-2potato1 by dropping root privileges before executing the command. We recommend that you upgrade your wmtv package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 71436864099e31a54191828eba1a5af1 MD5 checksum: fcfed7fae275bcd74f135db0fb315e27 MD5 checksum: 2ee18b3f1261137e8772d4f6a9dd0031 Alpha architecture: MD5 checksum: da07aa390b028396000c8c8ebf180c44 ARM architecture: MD5 checksum: b0ee729c7de7dfb2b3e1c4c7a8f37e69 Intel IA-32 architecture: MD5 checksum: fd3ce69d983ae4b316114628c7c5fc74 Motorola 680x0 architecture: MD5 checksum: 774a7f254a1a1f27cd7a03f66ac11308 PowerPC architecture: MD5 checksum:3b98c87d44c9570e4001ceec82d832be Sun Sparc architecture: MD5 checksum: 7ecfd9e694e3b22b101c52c7f8c4f627 These packages will be moved into the stable distribution on its next revision. For not yet released architectures please refer to the appropriate directory . - -- - ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQB1AwUBPA7GYajZR/ntlUftAQHtmQL/YTlZ47trRge7XUCwxPM5bDVtGQY/t43b GiZS8/BUQ90fAcqVQx5TMjrUrNPMUIKopZDVuyjJhUeAcNID9cmvfWeeGTrhyfzJ 6WK9y+8bC23kTolSktu6aC1wa2IXFgDK =29dg -----END PGP SIGNATURE----- . Immediate action is required to tackle the security flaw in the wmtv application impacting individuals utilizing Debian GNU/Linux platforms.. Debian GNU/Linux,wmtv exploit,root access fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 06, 2001 Critical Debian
100

SuSE: 2001:13 Moderate: Sudo Buffer Overflow Leading To Root Access

sudo(8) previous to version 1.6.3p6 is vulnerable by a buffer overflow in it's logging code, which could lead to local root compromise.. ______________________________________________________________________________ SuSE Security Announcement Package: sudo Announcement-ID: SuSE-SA:2001:13 Date: Wednesday, April 18th, 2001 12.26 MEST Affected SuSE versions: 6.1, 6.2, 6.3, 6.4, 7.0, 7.1 Vulnerability Type: possible local root compromise Severity (1-10): 6 SuSE default package: no Other affected systems: all systems using sudo Content of this advisory: 1) security vulnerability resolved: sudo problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information The setuid application sudo(8) allows a user to execute commands under the privileges of another user (including root). sudo(8) previous to version 1.6.3p6 is vulnerable by a buffer overflow in it's logging code, which could lead to local root compromise. There is no exploit known to be public. A useful workaround isn't possible, the only fix is to install the new sudo packages. Download the update package from locations described below and install the package with the command `rpm -Uhv file.rpm'. The md5sum for each file is in the line below. You can verify the integrity of the rpm files using the command `rpm --checksig --nogpg file.rpm', independently from the md5 signatures below. i386 Intel Platform: SuSE-7.1 b0d658c98effd4e11bed6d8c1f5f80f9 source rpm: a4b44f0998a165b3a69c598075420b7f SuSE-7.0 a002d657c7faf24b9fb5b430061e6c19 source rpm: d9ebc68015886fb642a1795e21bde788 SuSE-6.4 8a25b40ba081be885b214410b3c662ce source rpm: 9a13efa0d76a4fe3cbda7dcd2e2befe0 SuSE-6.3 a6e359c6449d764199bce3b7bc2867d8 source rpm: b89db78d5b8d04b10ac6e17c29cec1c4 SuSE-6.2 c3fbbff2219bf948f9b209eefafab4fe source rpm: 85ae3e3b9ef159201bb661e8f83e82d3 SuSE-6.1 Packets for 6.1 won't be available, sorry. Try to install the 6.2-RPM, please. Sprac Platform: SuSE-7.1 5531c5be20082b084e940d4e66dffea0 source rpm: 98fb9920e8de32727deb5e4295ee70d4 SuSE-7.0 cdd87431019ace22d0a2b0d46b294856 source rpm: 846035dcf0e42d22aac5d0dc77d90a02 AXP Alpha Platform: SuSE-7.0 c0fea14a3c0e565892f150cf97d971ed source rpm: 42651a443d7ca62415bc2d3ef3dc5bde SuSE-6.4 9a177de02176df90d8006fc7e8adae0d source rpm: 9f52a3df082ba513cbc0af5da6cccbe4 SuSE-6.3 5bbe1f211cb53758ad2840d192280269 source rpm: 4687f818ab5dbc50b1c0a3b907775f30 PPC PowerPC Platform: SuSE-7.1 199a677423a84bc577a7a9199e5e22d4 source rpm: 49ed607375823b56d819e0610e3a8d31 SuSE-7.0 03ffbcf07ba9a4222c75b162c97f9292 source rpm: a07d0b0283ca83e14c4d58ca9bcc933c SuSE-6.4 b5c9dee89ee0101fa8ac5795c1e8e49c source rpm: bfc917660898fdf9f2de170895ca7b22 ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - New RPMs for HylaFax, a Fax Server, are currently being build, which fix a format bug in hfaxd, which could lead to local root privilege. - NEdit a GUI-style text editor needs an update due to a tmp race condition. The source code is currently beingreviewed and new RPMs will be available within the next days. - Updated man RPMs will be available in a few days. - In the past weeks, some security related bugs in the Linux kernel 2.2 and 2.4 were found. An announcement, that addresses this will be released this week. - Samba has serveral security problems, which could lead to local root access. Samba 2.0.8 fixes these problems. New RPMs are currently being build. ______________________________________________________________________________ 3) standard appendix: SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ============================================== SuSE's security contact is . ============================================== ______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. SuSE GmbH makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. . Debian Security Advisory about a sudo vulnerability enabling local privilege escalation through buffer overflow prior to version 1.6.3p6.. SuSE Security,Sudo Vulnerability,Buffer Overflow,Local Root Access,Security Announcement. . LinuxSecurity.com Team

Calendar 2 Apr 18, 2001 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here