Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 22.04 LTS USN-5392-1 Moderate Mutt Info Exposure and Crash Bug

Several security issues were fixed in Mutt.. =========================================================================Ubuntu Security Notice USN-5392-1 April 28, 2022 mutt vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 21.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 ESM Summary: Several security issues were fixed in Mutt. Software Description: - mutt: text-based mailreader supporting MIME, GPG, PGP and threading Details: It was discovered that Mutt incorrectly handled certain requests. An attacker could possibly use this issue to expose sensitive information. This issue only affected Ubuntu 20.04 LTS. (CVE-2021-32055) It was discovered that Mutt incorrectly handled certain input. An attacker could possibly use this issue to cause a crash, or expose sensitive information. (CVE-2022-1328) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS: mutt 2.1.4-1ubuntu1.1 Ubuntu 21.10: mutt 2.0.5-4.1ubuntu0.1 Ubuntu 20.04 LTS: mutt 1.13.2-1ubuntu0.5 Ubuntu 18.04 LTS: mutt 1.9.4-3ubuntu0.6 Ubuntu 16.04 ESM: mutt 1.5.24-1ubuntu0.6+esm2 mutt-patched 1.5.24-1ubuntu0.6+esm2 In general, a standard system update will make all the necessary changes. References: CVE-2021-32055, CVE-2022-1328 Package Information: https://launchpad.net/ubuntu/+source/mutt/2.1.4-1ubuntu1.1 https://launchpad.net/ubuntu/+source/mutt/2.0.5-4.1ubuntu0.1 https://launchpad.net/ubuntu/+source/mutt/1.13.2-1ubuntu0.5 https://launchpad.net/ubuntu/+source/mutt/1.9.4-3ubuntu0.6 . Issues with Mutt addressed in recent Ubuntu updates. Learn about the specifics and suggested measures for each impacted version.. Mutt Updates, Ubuntu Security, EmailClient Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 28, 2022 Important Ubuntu
87

Debian: DSA-2874-1 Critical: Mutt Buffer Overflow DoS Threat

Beatrice Torracca and Evgeni Golov discovered a buffer overflow in the mutt mailreader. Malformed RFC2047 header lines could result in denial of service or potentially the execution of arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2874-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 12, 2014 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : mutt CVE ID : CVE-2014-0467 Debian Bug : 708731 Beatrice Torracca and Evgeni Golov discovered a buffer overflow in the mutt mailreader. Malformed RFC2047 header lines could result in denial of service or potentially the execution of arbitrary code. For the oldstable distribution (squeeze), this problem has been fixed in version 1.5.20-9+squeeze3. For the stable distribution (wheezy), this problem has been fixed in version 1.5.21-6.2+deb7u2. For the unstable distribution (sid), this problem has been fixed in version 1.5.22-2. We recommend that you upgrade your mutt packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance mutt to address significant buffer overflow vulnerabilities that could result in denial of service (DoS) or arbitrary code execution. Discover methods to protect your infrastructure.. mutt security update, buffer overflow fix, debian advisory, mailreader threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 12, 2014 Critical Debian
87

Debian Woody DSA 700-1 Critical: Mailreader Cross-Site Scripting Fix

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 700-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze March 30th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mailreader Vulnerability : missing input sanitising Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-0386 Ulf Härnhammar from the Debian Security Audit Project discovered a cross-site scripting problem in mailreader, a simple, but powerful WWW mail reader system, when displaying messages of the MIME types text/enriched or text/richtext. For the stable distribution (woody) this problem has been fixed in version 2.3.29-5woody2. For the unstable distribution (sid) this problem has been fixed in version 2.3.29-11. We recommend that you upgrade your mailreader package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 623 42f2edc38e5e563013f08deb401daed2 Size/MD5 checksum: 40004 7c68b982f9c7e45504411805d622d4e1 Size/MD5 checksum: 307934 8e2687227ac737f244994e19ca3ba575 Architecture independent components: Size/MD5 checksum: 352696 32dfa7f100f7716b0b47b85b60c5c3d8 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Update mailreader to address the cross-site scripting vulnerability highlighted in Debian Security Advisory DSA 700-1.. Debian Packages, Mailreader Update, Cross-Site Scripting Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 30, 2005 Critical Debian
87

Debian 3.0 Advisory DSA 534-1 Critical: Mailreader Remote Access

A directory traversal vulnerability was discovered in mailreader whereby remote attackers could view arbitrary files with the privileges of the nph-mr.cgi process (by default, www-data). Debian Security Advisory DSA 534-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman July 22nd, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : mailreader Vulnerability : directory traversal Problem-Type : remote Debian-specific: no CVE Ids : CAN-2002-1581 A directory traversal vulnerability was discovered in mailreader whereby remote attackers could view arbitrary files with the privileges of the nph-mr.cgi process (by default, www-data) via relative paths and a null byte in the configLanguage parameter. For the current stable distribution (woody), this problem has been fixed in version 2.3.29-5woody1. For the unstable distribution (sid), this problem will be fixed soon. We recommend that you update your mailreader package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 623 40827025821290e7130571a78fd0b06d Size/MD5 checksum: 39678 b172e5b8957ee2f6b44122e0d3c99e06 Size/MD5 checksum: 307934 8e2687227ac737f244994e19ca3ba575 Architecture independent components: Size/MD5 checksum: 362912 d3708d9d7ecc4064797f12cbe7d8489e These files will probably be movedinto the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Ubuntu Security Notice USN-5083-1 resolves a flaw in the web server that permits path traversal, allowing unapproved external access.. mailreader vulnerability,directory traversal,Debian security advisory,remote file access. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 23, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here