Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 542
Alerts This Week
Warning Icon 1 542

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 20.04 LTS: USN-6367-1 Critical: Firefox WebP Denial of Service

Firefox could be made to crash or run programs if it opened a malicious website.. ========================================================================== Ubuntu Security Notice USN-6367-1 September 14, 2023 firefox vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: Firefox could be made to crash or run programs if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: It was discovered that Firefox did not properly manage memory when handling WebP images. If a user were tricked into opening a webpage containing malicious WebP image file, an attacker could potentially exploit these to cause a denial of service or execute arbitrary code. (CVE-2023-4863) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: firefox 117.0.1+build2-0ubuntu0.20.04.1 After a standard system update you need to restart Firefox to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6367-1 CVE-2023-4863 Package Information: https://launchpad.net/ubuntu/+source/firefox/117.0.1+build2-0ubuntu0.20.04.1 . Harmful SVG files in Chrome may leverage flaws, resulting in system failures or unauthorized commands on Fedora 36.. firefox patch, ubuntu security, denial of service fix, webp exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 14, 2023 Critical Ubuntu
172

Ubuntu 6.06, 8.04, 8.10, 9.04: 801-1 Critical TIFF Code Execution

Tielei Wang and Tom Lane discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, an attacker could execute arbitrary code with the privileges of the user invoking the program. [More...]. ==========================================================Ubuntu Security Notice USN-801-1 July 13, 2009 tiff vulnerability CVE-2009-2347 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libtiff4 3.7.4-1ubuntu3.6 Ubuntu 8.04 LTS: libtiff4 3.8.2-7ubuntu3.4 Ubuntu 8.10: libtiff4 3.8.2-11ubuntu0.8.10.3 Ubuntu 9.04: libtiff4 3.8.2-11ubuntu0.9.04.3 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Tielei Wang and Tom Lane discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, an attacker could execute arbitrary code with the privileges of the user invoking the program. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 21054 b184fc5a65469b42e7339ed36fcbd352 Size/MD5: 764 5a34b751c2d11afb70070d2173891226 Size/MD5: 1280113 02cf5c3820bda83b35bb35b45ae27005 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 220964 32b03a7ff77bfc052f81ead1310ba61d Size/MD5: 282410 b7e639de426fd499ce7898ab5d22082d Size/MD5: 475680 9ae1232f31f5a56ed48d36523996b7ef Size/MD5: 4473660343671d61e34c5937708dc3f64efda Size/MD5: 49912 26dd138e59ad8f287ce4e39ea04159e0 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 206140 9d5d67fb3830c0126ddfe56e7be8a78c Size/MD5: 259038 c4cd6b64f45de6c2387180bf0c029d64 Size/MD5: 461908 b93598c6a241ed4dcc2ea9fd55eeb82f Size/MD5: 44704 7da9d28905050b7a436f20ef2417eb83 Size/MD5: 49242 2f45bd92eb474e4f78cba91d45e9a2ec powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 239858 d721fc667879d1ef8f4e0f23c5ada2ea Size/MD5: 288108 f142f5e1d8856c927cd9705e67a1dfa7 Size/MD5: 476004 e2b229ae0592a3a8ce273cffaf5b3c40 Size/MD5: 46954 64dd6f32ba8a52094fdd37a7f82a9e07 Size/MD5: 51588 488453ac8da21d2ca65822a39ff8a703 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 208814 982a4a1b64aeeadc5e7b0bc962990754 Size/MD5: 270074 7135dfc15e5c4c691cd0902475815ba1 Size/MD5: 466750 a61aa69f5e417585d6448d03270582de Size/MD5: 44656 06f194d15eed1792831306e39f983e6d Size/MD5: 49788 27a6b68bc6c95fa630f215f0ddf9a77b Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 19568 5bfb2cb6842497228bf9ac35340964c2 Size/MD5: 860 439a48e1a2ff200bb5656e9674a001bc Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 186484 7d1ec8bbd94dc0e66d064716586c0b07 Size/MD5: 570808 3ff13c20038ba528af352e55e2d6d1bc Size/MD5: 130788 aa56546b961c12c6d24cd52a4df380a7 Size/MD5: 5076 00b209a590da754d7012caafea71a7cd Size/MD5: 10492 ea0e67a0e5fa1ed557455be73ae0a919 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 175322 acdeefa0cfe2c524098027f12af53c69 Size/MD5: 552282 32c8f66f4749fc2a54be66e42f4edbd6 Size/MD5: 1224880d278f298f7c5ed6c4357b88218f6c32 Size/MD5: 5044 89d1f18fc0e9b23bbb136707316e9392 Size/MD5: 9934 b9316510bba0f91803c9e735da48e176 lpia architecture (Low Power Intel Architecture): Size/MD5: 177040 3e71f1789624abbd10d1532c8f6ca38a Size/MD5: 554844 3cc1263bcb56cf9746716990a2ae8136 Size/MD5: 123640 6c75304de5001fe2263d45cf788aabf0 Size/MD5: 4916 1098e8a9fff0cbd1ae0820d62d2268f6 Size/MD5: 9982 97ac08252336fa2d32439ab8ccc5578e powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 223464 5466be5e47908622c79d3ef14ac40f64 Size/MD5: 576826 43e6e505da757ddcb637d2e5f5c90e55 Size/MD5: 134100 5c09d9828d094ec8fd5c3119d0a833a3 Size/MD5: 7510 6ca2d1d4c524e5115870adf6e494c6db Size/MD5: 13286 c0c749c9caf673a2d0f5b1cf93f9c0c2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 178862 b46ce275aa291e14b580256de7f2d00d Size/MD5: 558208 6a5c431715bde6315033dc2639a7d007 Size/MD5: 122246 128a30981124c2535cda616dbfa6ff1f Size/MD5: 4814 6374c4cad1d0106074e308514a668557 Size/MD5: 10704 14a879255294ef774e6778848ac63954 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 39176 060a8ab7b01f6cf67746e2bdc8f9fede Size/MD5: 1328 4f1f59e4f8173b22b2b1fc5b75993d56 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334762 c06570f8ef3133f29215f3522b32000d amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 250516 091e3d2f7dcdd470ebb60bd0985898b1 Size/MD5: 134144 5cdfdbc0e599956a5cc39c93c3e766e0 Size/MD5: 6282 e5184d8cabee9e62fe95c02dd5ceb42c Size/MD5: 11898 0f9cdc8d758e49247bca6aca38b76e29 Size/MD5: 191614 c43454705f0e70af2c02274660e19fe1 i386 architecture (x86 compatibleIntel/AMD): Size/MD5: 233308 3a6665da1bd3d77c9e8bc89305d1bc88 Size/MD5: 125952 7c515ac8b3281482eea7dcc0b3fc07d2 Size/MD5: 6268 915e7137fa484b78bf4ab12eb8b020a3 Size/MD5: 11232 08dc61532601140dceacd61301f3c157 Size/MD5: 176244 3779c5312783f177bceef089f6d7c413 lpia architecture (Low Power Intel Architecture): Size/MD5: 235792 8d83dd863f9392f20540777ffea6e973 Size/MD5: 127646 0a3313ab87db8c462ec040eab933fd3c Size/MD5: 6132 e019a27add2bf0ad3dcc17351ba391bf Size/MD5: 11288 4d6ba5f06725040c5288edf43f848ea5 Size/MD5: 178536 1f8bb64685cbcf23af9c493ef3fe3c50 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 256482 83002f03cd860be09b0c3f422b0cd303 Size/MD5: 137238 0c56ea5382757b05719a14a54292344a Size/MD5: 8728 afa7813cf255183979211a6bbd49c34a Size/MD5: 14240 16314a49bc8b221ba0f4b33b221da280 Size/MD5: 221282 7fc666a2e5b2fbff826327911d0ddb2c sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 237676 2d1d8633f7d524ab4da9ad3a86e86372 Size/MD5: 124088 131aad61d078a6b62615f90abedc91c9 Size/MD5: 6016 36855fafb32b6d9d5d04f87202c7fa49 Size/MD5: 12050 99a62c3a0072c968696cbdce177619b2 Size/MD5: 183806 1bdaeb372368abdc1d9dd98695b1d0da Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 39178 4bfb276aca2734298c06b0ed5de2a246 Size/MD5: 1328 0c41ba9d08e1fe09c45eb5079a5ea137 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334774 1d7901d92961ad1c2ed2abb160774861 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 191662 903599a6ede36e4fd1fe8eed3b04c604 Size/MD5: 250586 891e5abb016617849d19ebb6f353900d Size/MD5: 134188 f63adbd5a185f439dbcbe06b0a95bf8d Size/MD5: 6282 470be440355d54b6af5dfddab3712524 Size/MD5: 11900 19eab0f2ea2f0f429d0592e4f9215467 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 176262 5a64f79c12421333b2b2767e073d5a47 Size/MD5: 233314 3eb4d2a53824a6f143b83ebf0f96383d Size/MD5: 126052 f3c7a181b29c9a4425b8e2450951b612 Size/MD5: 6274 abd097b82311d12ab9d0095dac3f920e Size/MD5: 11230 85fa172925507f83aade40478755a640 lpia architecture (Low Power Intel Architecture): Size/MD5: 178528 6c38679ccf2f15472b125ab385aea232 Size/MD5: 235774 5be19819dbae74a5ce75fdb653f3f3f6 Size/MD5: 127640 747e3ebae6796377b62391bc7738fa14 Size/MD5: 6122 fd52e98057e643705b2e8a9433256046 Size/MD5: 11284 bdf6765cb1655577d5140e0fd5367556 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 221288 6e7ed33c09eedff6fa8591240a0f73cf Size/MD5: 256324 126de3077a84e0e0476293fff4a9e166 Size/MD5: 137082 3f0452f2d9a5651517a77189ff2aec98 Size/MD5: 8722 6f8b287c5fc7a7cd125a76e331866e1a Size/MD5: 14228 8b742dac3af6a1e2bc832c4cbea9829d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 183798 1675983d18499b14fc89910828a5673d Size/MD5: 237646 b2b5c339bf9fc368e16af644de35b6aa Size/MD5: 123998 b6071b6cffd26da1a5b1eb188322bbc5 Size/MD5: 5974 c0906d3bcebd191f70a55c4969d4c5ff Size/MD5: 12018 88d2b2e7354ff9f52da6d62d6e7ad732 . The latest Ubuntu security advisory describes a vulnerability in GIF handling that could lead to unauthorized code execution via crafted image files.. tiff exploit, ubuntu update, image vulnerability, code execution risk. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 13, 2009 Critical Ubuntu
172

Ubuntu: 797-1 Critical: TIFF Library Denial Of Service Risk

It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service. [More...]. ==========================================================Ubuntu Security Notice USN-797-1 July 06, 2009 tiff vulnerability CVE-2009-2285 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libtiff4 3.7.4-1ubuntu3.4 Ubuntu 8.04 LTS: libtiff4 3.8.2-7ubuntu3.2 Ubuntu 8.10: libtiff4 3.8.2-11ubuntu0.8.10.1 Ubuntu 9.04: libtiff4 3.8.2-11ubuntu0.9.04.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 19878 69684a7a9c033fb40c755d2bb4dffaa2 Size/MD5: 764 2a6cbe50d507d9c402ad4e92fa1a66b8 Size/MD5: 1280113 02cf5c3820bda83b35bb35b45ae27005 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 220708 159dcfd51cf69df380ea71620b922f04 Size/MD5: 282354 541c2a6b0fe97743b984dd97c20395fd Size/MD5: 475612 4cb99e064c4547553f0edb081c529809 Size/MD5: 446624f662fbcf9fa548ab4f8b8754306c69b Size/MD5: 49846 953651334379bbaca92baf34950e2405 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 205896 f5ca6a96e1d3dedb3daea18094d65ac3 Size/MD5: 258978 6f612fbbf5ef115b4dcce981dcacf46f Size/MD5: 461822 ccb6e0322690b9e0f4064ee72813bd1f Size/MD5: 44646 fedd7054ff09c4a761f0bf052adc9dbb Size/MD5: 49176 4b422744db9046b2e6c24e2eeb8d0863 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 239714 2c126df7fad173e8e8facfbfe70d96bf Size/MD5: 288002 38a94eccdd4d769d5c833a4c18861a66 Size/MD5: 475924 aae7d86246008c63a0ef95a08b5f4eb2 Size/MD5: 46874 da98b514589753068801921dc68ceae6 Size/MD5: 51514 80ac11ceaaffc8f848967b0811b7f5e2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 208520 4abc2ee74c41ba87917b975a7cb758ed Size/MD5: 269972 3cdfd7084bf54d17643e2f00793fb3a5 Size/MD5: 466632 b2c1bfb026aac831ced2ce4dafebf860 Size/MD5: 44594 f97d5668dd1b3deeb9992be92e1ffc7f Size/MD5: 49728 c4ce31f33d03dc294f40ada0bc955887 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 18378 450fcf81a838b9c67637987a2b39088b Size/MD5: 860 92cf9f6d3136c5b6fb52e4d123c0fdd5 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 186242 28dff44adbabe76ab7e85ff2da365f9d Size/MD5: 570796 315cdea73e2f4c28c891848d7e7e4fc0 Size/MD5: 130702 854535fab48a5f2a37a9256f61a38ab5 Size/MD5: 5064 4097c51386aaaafbfeae9eabaeb997c9 Size/MD5: 10494 49c45bed31e28bcd9d5e706f1c8db3cc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 175048 01226d438f325312684575560d86d93b Size/MD5: 552280 36c3a1e37d12f1992346a057e4dab075 Size/MD5: 12240044cb0efa99a513084835be466da2cb7d Size/MD5: 5048 db565d6e40fa1b15e6ff9b87a599c0d7 Size/MD5: 9942 c7f799a523da81cee7c90ade65be2ccd lpia architecture (Low Power Intel Architecture): Size/MD5: 177116 df191c9d5e2f48103589d92a59b902d1 Size/MD5: 554842 2d10224badec0434fbb9d21d432df89d Size/MD5: 123556 534d8b03274794d0563a3b48001143c7 Size/MD5: 4920 264e617e42f1c8972cb1b2bb18a91574 Size/MD5: 9976 e5940f1dbb7d090a4e5d47cca0daeca2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 223238 2385fe8b199cce7295eaea9282cacf24 Size/MD5: 576794 51814c281f84fe2e0650d3f8e029ac4a Size/MD5: 134016 3df0fd7a4ad96106e2f5143f1645b102 Size/MD5: 7514 5963503e765f0fe71ffa80fbc60c162f Size/MD5: 13286 3f3851bf7186b2d4450d35beeec0bb4d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 178640 086f9b0f2e83f879e323fd924f8a89f2 Size/MD5: 558202 b334310f53743de237845e24fcd911ec Size/MD5: 122160 95fd3e3346b8dce74e274239d00c018b Size/MD5: 4800 4a09138aa5f408d8fe49057f90cd0df1 Size/MD5: 10710 18641ce46b309baeb923165dd8e03158 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 37962 6c0956eecb7503bdb31a1bd4299efe47 Size/MD5: 1328 7548341cdd1a4a9bae7c793b6f677233 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334688 eff9827309f80a957196e9cd4da695d8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 250518 61fe3d4dd8def51dbd2b5d9b4159a9bc Size/MD5: 134084 c2adab0fb711634f47e695f3dd7447f8 Size/MD5: 6286 4b2563a3b767209061646fa6ae9ac85b Size/MD5: 11898 81a456c5d470799230c6a44f9cc8f9b9 Size/MD5: 191424 82a9fa8eb070e32116b0d8ecd5a22e0d i386 architecture (x86 compatibleIntel/AMD): Size/MD5: 233298 a01eb038a2ccbef8b6603525bc3f2f75 Size/MD5: 125878 4eda3acf59c21aba5e1cc89e96bfa8cc Size/MD5: 6272 a6ec88be551d729364d27af4863e1b11 Size/MD5: 11236 359d02f2dcdad53dcf72d0619aff697b Size/MD5: 176054 42b7f0efbbc73b45d6e69053ebf33671 lpia architecture (Low Power Intel Architecture): Size/MD5: 235774 ca05ad7d9e13ada710db91e738800eab Size/MD5: 127584 cf7c86c00c4a0e05cac37039288965f0 Size/MD5: 6132 a865f92bff1a6c22b927ee8af097c433 Size/MD5: 11282 733acc73b8be40399063ff28128525f5 Size/MD5: 178278 523c412323f658d260ae6a4d2ff40966 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 256510 d4b027ddeb929f3589956ba496cffba0 Size/MD5: 137148 e32d2bdd0d4a7cc71eec5e7daed52aa9 Size/MD5: 8724 cc701a74b724ca482b21a3dc321949c3 Size/MD5: 14234 cbff4f6e6faddfde029ff78ec9c48afb Size/MD5: 221040 f917935a1761ef9848e8c7c10e0ef06b sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 237666 5d6d33cc67ef0d14bd626ccb4dd9bcb6 Size/MD5: 123990 190cefef6ceb37c906aecaf1bf59b876 Size/MD5: 6006 6ec8001760781f1af9d8592866ff82fe Size/MD5: 12046 a2b4639c81cb79b31b0646657205fa35 Size/MD5: 183412 8ff9e8d6a32d80872131327e5203796c Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 37962 438146f23bcd7888fcc66c7b9d78098b Size/MD5: 1328 9ec573172e0fde174b56d0a3956ee35b Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334670 fa4a10e51620299585fa1642196f2887 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 191466 a61b82a3393f44e40cd2cc0f640eb6c6 Size/MD5: 250604 cd4538b261cc9003e7c131adda8b51ca Size/MD5: 134104 38fa2282b5e992c72a4ac79e0ece52b0 Size/MD5: 6286 401262f1a09831f0130f0db2872c97f6 Size/MD5: 11898 bdf96619188143fe417e8fa3bc5f780d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 176050 aa334ea8a28d5274741368d08b0f795d Size/MD5: 233334 2f3bfd25e51a9cca95f4c58646318d29 Size/MD5: 125970 3ceceb06c0b6b94fa508e008f19408b7 Size/MD5: 6272 35faf1e62dc2e57509ef98116b4c7cfb Size/MD5: 11228 0abf911853cdb7cd1020f5c43782ab92 lpia architecture (Low Power Intel Architecture): Size/MD5: 178280 db957830b08ec26fc211e78674f175c7 Size/MD5: 235772 146d7fbd61e3885873c2d884c3f289be Size/MD5: 127566 bec17756ac7d7c5c94fb4823b297b6df Size/MD5: 6126 36ebd0a2f1faaa2d67cdc9687377047b Size/MD5: 11276 efd0a2c2218bfbcd1a9211d85945fa43 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 221080 3ba1c50579c20918faaef6191ed041eb Size/MD5: 256338 eeb0f7815019f42674e3ed5fdfc72036 Size/MD5: 136980 638fb9b42c406d00b1510a926b5ed3ba Size/MD5: 8726 50665d1f710dba6dc2742e2bb57acf02 Size/MD5: 14228 3f0ee5ed9b9d24b19ec162f1c71127ce sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 183404 2852bdbf720008437395f7821c827fd4 Size/MD5: 237662 9da18282c48f96aabf98965c0717d9b2 Size/MD5: 123884 1600707f7478f01789738311510f598a Size/MD5: 5970 15efadc4f18985aa1fadc50bec55d099 Size/MD5: 12018 1475302ae62826aced512ca859a2c237 . An urgent security notice regarding a vulnerability in a TIFF image library across various Ubuntu distributions uncovers potential threats posed by harmful image files.. tiff library risk, ubuntu 797-1 advisory, denial of service, libtiff security issue, update instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 06, 2009 Critical Ubuntu
91

Gentoo: GLSA-200611-07 Normal: GraphicsMagick Buffer Overflow Threat

GraphicsMagick improperly handles PALM and DCM images, potentially resulting in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200611-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GraphicsMagick: PALM and DCM buffer overflows Date: November 13, 2006 Bugs: #152668 ID: 200611-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= GraphicsMagick improperly handles PALM and DCM images, potentially resulting in the execution of arbitrary code. Background ========= GraphicsMagick is a collection of tools and libraries which support reading, writing, and manipulating images in many major formats. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/graphicsmagick < 1.1.7-r3 > = 1.1.7-r3 Description ========== M. Joonas Pihlaja has reported that a boundary error exists within the ReadDCMImage() function of coders/dcm.c, causing the improper handling of DCM images. Pihlaja also reported that there are several boundary errors in the ReadPALMImage() function of coders/palm.c, similarly causing the improper handling of PALM images. Impact ===== An attacker could entice a user to open a specially crafted DCM or PALM image with GraphicsMagick, and possibly execute arbitrary code with the privileges of the user running GraphicsMagick. Workaround ========= There is no known workaround at this time. Resolution ========= All GraphicsMagick users should upgrade to the latest version: # emerge --sync # emerge--ask --oneshot --verbose "> =media-gfx/graphicsmagick-1.1.7-r3" References ========= [ 1 ] CVE-2006-5456 https://www.cve.org/CVERecord?id=CVE-2006-5456 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200611-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The vulnerability in GraphicsMagick poses a risk of remote code execution on Gentoo systems. It's imperative to update your software immediately to mitigate potential threats.. GraphicsMagick,Buffers,Image Processing. . LinuxSecurity.com Team

Calendar%202 Nov 13, 2006 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200