Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
87

Debian 3.0: DSA 583-1 Critical: LVM10 Symlink Attack Fix

Trustix developers discovered insecure temporary file creation in a supplemental script in the lvm10 package that didn't check for existing temporary directories, allowing local users to overwrite files via a symlink attack.. -------------------------------------------------------------------------- Debian Security Advisory DSA 583-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze November 3rd, 2004 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : lvm10 Vulnerability : insecure temporary directory Problem-Type : local Debian-specific: no CVE ID : CAN-2004-0972 Debian Bug : 279229 Trustix developers discovered insecure temporary file creation in a supplemental script in the lvm10 package that didn't check for existing temporary directories, allowing local users to overwrite files via a symlink attack. For the stable distribution (woody) this problem has been fixed in version 1.0.4-5woody2. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your lvm10 package. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 561 e5870dc0de9c2e47201d8f7dab0af624 Size/MD5 checksum: 7964 a9eb089d9ed491a569889a1ca0bd1be4 Size/MD5 checksum: 373104 9081ae96e94bef6c4c2e8c5f2dcc654c Alpha architecture: Size/MD5 checksum: 1199872 95321cf32c955269ef5e22eb35177c85 ARM architecture: Size/MD5 checksum: 2078632 02b80c8320640d88da71503228c088b7 Intel IA-32 architecture: Size/MD5 checksum: 1987842 546d12296630017a50ab164b385fbfb4 Intel IA-64 architecture: Size/MD5 checksum: 1633240 da929a10feb0e9d5f7869034fc4a311b HP Precision architecture: Size/MD5 checksum: 2110980 07bc200b8abbfc9b050df98794fc0bf9 Motorola 680x0 architecture: Size/MD5 checksum: 1995258 504c02f300ef94797076b24aeffac698 Big endian MIPS architecture: Size/MD5 checksum: 818778 c11595f00382bee32dbf839461e173eb Little endian MIPS architecture: Size/MD5 checksum: 800362 21d8ec07ef0d6592fce08921e3e11b6f PowerPC architecture: Size/MD5 checksum: 2213258 9b92a1958c65664c6256c41a7e29fba7 IBM S/390 architecture: Size/MD5 checksum: 2043052 9395c323525bc9cfe04bf045ba76dd30 Sun Sparc architecture: Size/MD5 checksum: 2095860 ba67c6e9188fad3ca653279f199188a6 These files will probably be moved into the stable distribution on its next update. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Resolution for the vulnerable temporary folder in the lvm10 package, which permits local users to manipulate and replace files through symbolic link exploits.. Debian Advisory,lvm10 Security Patch,Symlink Attack Fix,Local File Overwrite,Temporary File Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 03, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here