Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 439
Alerts This Week
Warning Icon 1 439

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
98

Red Hat 7.1-8.0: RHSA-2003:133-01 Critical: Man Code Execution

Versions of man before 1.51 have a bug where a malformed man file can cause a program named "unsafe" to be run. . `` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated man packages fix minor vulnerability Advisory ID: RHSA-2003:133-01 Issue date: 2003-05-01 Updated on: 2003-05-01 Product: Red Hat Linux Keywords: Cross references: Obsoletes: CVE Names: CAN-2003-0124 ---------------------------------------------------------------------1. Topic: Updated man packages fix a minor security vulnerability. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 3. Problem description: The man package includes tools for finding and displaying online documentation. Versions of man before 1.51 have a bug where a malformed man file can cause a program named "unsafe" to be run. To exploit this vulnerability a local attacker would need to be able to get a victim to run man on a carefully crafted man file, and for the attacker to be able to create a file called "unsafe" that will be on the victims default path. Red Hat Linux 7.1, 7.2, 7.3, and 8.0 are vulnerable to this issue. Users of man can upgrade to these erratum packages which contain a patch to correct this vulnerability. These erratum packages also contain fixes for a number of other bugs. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory*only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 83934 - man command needs Korean man pages support 82088 - Mark /etc/man.config as %config(noreplace) 81964 - man uses wrong config file 82684 - /usr/bin/whatis fails with a grep error 77847 - man in Red Hat 8.0 assumes groff 1.18, but doesn't require it 65467 - /etc/man.config should MANPATH_MAP /usr/local/share/man 79289 - man -k attempts to run 'unsafe' script 62606 - apropos (man -k) generating invalid grep arguments 65511 - makewhatis man page omitted from specfile. 6. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: 7. Verification: MD5 sum Package Name --------------------------------------------------------------------------73ec668993191b2f2324468faf9b6f66 7.1/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm 749524bab3e6baa60edbc71892e2bafd 7.1/en/os/i386/man-1.5j-7.7x.0.i386.rpm 73ec668993191b2f2324468faf9b6f66 7.2/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm 749524bab3e6baa60edbc71892e2bafd 7.2/en/os/i386/man-1.5j-7.7x.0.i386.rpm 7717002ab88fe9848ce67fe2cc670e6b 7.2/en/os/ia64/man-1.5j-7.7x.0.ia64.rpm 73ec668993191b2f2324468faf9b6f66 7.3/en/os/SRPMS/man-1.5j-7.7x.0.src.rpm 749524bab3e6baa60edbc71892e2bafd 7.3/en/os/i386/man-1.5j-7.7x.0.i386.rpm a682e5aad64a9dcdf54373b3870c2460 8.0/en/os/SRPMS/man-1.5k-0.8x.0.src.rpm c12cf9900a6952bb3739a374ad36aed1 8.0/en/os/i386/man-1.5k-0.8x.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available at All Red Hatproducts You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 8. References: http://marc.theaimsgroup.com/?l=bugtraq&m=104740927915154 CVE -CVE-2003-0124 9. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: `` . Updated man packages from Red Hat fix critical code execution issue. Learn steps to ensure secure patch implementations.. Red Hat Advisory, Man Package Patch, Code Execution Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 30, 2023 Critical Red Hat
89

Fedora Core 6: FEDORA-2007-143 Moderate: Kernel Security Improvements

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-219 2006-03-24 ---------------------------------------------------------------------Product : Fedora Core 5 Name : man Version : 1.6c Release : 2.fc5 Summary : A set of documentation tools: man, apropos and whatis. Description : The man package includes three tools for finding information and/or documentation about your Linux system: man, apropos, and whatis. The man system formats and displays on-line manual pages about commands or functions on your system. Apropos searches the whatis database (containing short descriptions of system commands) for a string. Whatis searches its own database for a complete word. The man package should be installed on your system because it is the primary way to find documentation on a Linux system. ---------------------------------------------------------------------* Mon Feb 27 2006 Ivana Varekova - 1.6c-2.fc5 - fix the encoding of the Bulgarian translation ---------------------------------------------------------------------This update can be downloaded from: b656d60ce3236309f673e8eaea115c5087356197 SRPMS/man-1.6c-2.fc5.src.rpm 5e12250be1b752faed32cfd131e40c47ff412cf9 ppc/man-1.6c-2.fc5.ppc.rpm 41d990d117a86ca82e9a3f698cb6b670a8294a28 ppc/debug/man-debuginfo-1.6c-2.fc5.ppc.rpm 19a19a31e5b43b74e6e083ba1526491560b789ff x86_64/man-1.6c-2.fc5.x86_64.rpm 59b292b08acb3caf0685b099a53bab75e0b71f03 x86_64/debug/man-debuginfo-1.6c-2.fc5.x86_64.rpm 542b91f29071bf7810f0aad00696f8f22b128981 i386/man-1.6c-2.fc5.i386.rpm 2b2ef782be4bc36e7ab5242b572ee2357e8c959d i386/debug/man-debuginfo-1.6c-2.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at. ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The man package on Fedora Core 5 has been updated to enhance the Bulgarian translation. To obtain the latest documentation tools, use the yum command for installation.. Fedora Core 5, Man Package, Documentation Tools. . LinuxSecurity.com Team

Calendar%202 Mar 24, 2006 Fedora
91

Gentoo Linux 200306-06: Local Format String Exploit for Man Package

man v1.5l, and below, contain a format string vulnerability.the vulnerability occurs when man uses an optional catalog file, suppliedby the NLSPATH/LANG environmental variables.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200306-06 - - --------------------------------------------------------------------- PACKAGE : man SUMMARY : format string exploit DATE : 2003-06-14 16:40 UTC EXPLOIT : local VERSIONS AFFECTED : =man-1.5l-r5 CVE : - - --------------------------------------------------------------------- from advisory: "man v1.5l, and below, contain a format string vulnerability. the vulnerability occurs when man uses an optional catalog file, supplied by the NLSPATH/LANG environmental variables." Read the full advisory at http://marc.theaimsgroup.com/?l=bugtraq&m=105474717920585&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running sys-apps/man upgrade to man-1.5l-r5 as follows emerge sync emerge man emerge clean - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - - --------------------------------------------------------------------- . Gentoo Linux has issued a critical alert about a serious format string vulnerability in the man package. Affected users should update their systems immediately to reduce security risks. Gentoo Linux, format string exploit, man package advisory, security update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 14, 2003 Important Gentoo
98

Red Hat: RHSA-2001:072-14 Critical: Local GID to Root Escalation

Updated man packages fixing a local GID man exploit and a potential GID man to root exploit, as well as a problem with the man paths of Red Hat Linux 5.x and 6.x.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated man package fixing GID security problems. Advisory ID: RHSA-2001:072-14 Issue date: 2001-05-28 Updated on: 2001-09-06 Product: Red Hat Linux Keywords: man setgid heap overflow path makewhatis root GID Cross references: Obsoletes: RHSA-2001:069 --------------------------------------------------------------------- 1. Topic: Updated man packages fixing a local GID man exploit and a potential GID man to root exploit, as well as a problem with the man paths of Red Hat Linux 5.x and 6.x. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 3. Problem description: Users could gain access to the GID man by overrunning a buffer in the ultimate_source() function. Users with GID man could get root access by creating man pages with filenames containing escape characters. Furthermore, the previous errata package hardcoded Red Hat Linux 7.x man paths even on Red Hat Linux 5.x and 6.x. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to applyupdates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 42450 - man-1.5i-4: local-> gid man-> root in update 42031 - /etc/man.config's new MANPATH's incompatible with rh62 42192 - New 'man' package disagrees with 'tmpwatch' 43318 - apropos and whatis broken by update to man-1.5i-4 43213 - Man didn't drop privs when adding user PATH as MANPATH 46405 - man-1.5i2-i has incorrect backslash escape in makewhatis awk script 45646 - Cron generated errors45827 - Troubles with data updates for 'apropos' 43134 - man RPM needs to depend on specific mktemp version 42915 - makewhatis only works for first element in manpath 42031 - /etc/man.config's new MANPATH's incompatible with rh62 48762 - man does not create cat files even if told to do 47784 - man problem after an update 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 7e707edd6c8662713b3e1de4e4991c91 5.2/en/os/SRPMS/man-1.5i2-0.5x.5.src.rpm b4ca74b38769909b6edf96ae15e4f93a 5.2/en/os/alpha/man-1.5i2-0.5x.5.alpha.rpm 7145d59cc271555cff82399758cc38c9 5.2/en/os/i386/man-1.5i2-0.5x.5.i386.rpm 0d49141004f0686a362ccb4e341cdc77 5.2/en/os/sparc/man-1.5i2-0.5x.5.sparc.rpm 6a5757ee96a7a647f0f78ca0a5c52d53 6.2/en/os/SRPMS/man-1.5i2-0.6x.5.src.rpm af4d18fd95636a764d785089d336aca1 6.2/en/os/alpha/man-1.5i2-0.6x.5.alpha.rpm 2eb2926fbe663135b5a766c510c4c593 6.2/en/os/i386/man-1.5i2-0.6x.5.i386.rpm 578a17ecc5ac2d3d3c8ec1d623ea22bd 6.2/en/os/sparc/man-1.5i2-0.6x.5.sparc.rpm 8f1975f0a01765c2e8ffb4dfca2fc3bf7.0/en/os/SRPMS/man-1.5i2-0.7x.5.src.rpm 4deee7f6f4203f4755d71d723caebfd0 7.0/en/os/alpha/man-1.5i2-0.7x.5.alpha.rpm 99245cb9189b9e7c91b2241b308ee488 7.0/en/os/i386/man-1.5i2-0.7x.5.i386.rpm 8f1975f0a01765c2e8ffb4dfca2fc3bf 7.1/en/os/SRPMS/man-1.5i2-0.7x.5.src.rpm 4deee7f6f4203f4755d71d723caebfd0 7.1/en/os/alpha/man-1.5i2-0.7x.5.alpha.rpm 99245cb9189b9e7c91b2241b308ee488 7.1/en/os/i386/man-1.5i2-0.7x.5.i386.rpm 2d45b52218b65a5801ea8eec3e060788 7.1/en/os/ia64/man-1.5i2-0.7x.5.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. A new update from Canonical details the fix for the local UID privilege escalation flaw, enhancing system protection and fortifying cybersecurity.. Red Hat Advisory, Local Exploit Fix, GID Access Update, Security Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 22, 2001 Critical Red Hat
98

Red Hat: RHSA-2001:069-02 Critical Man Setgid Heap Overrun

A heap overrun exists in the man packages shipped with Red Hat Linux5.x, 6.x and 7.0.Since man is setgid man, users could gain gid man privileges.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated man package fixing security problems available Advisory ID: RHSA-2001:069-02 Issue date: 2001-05-13 Updated on: 2001-05-21 Product: Red Hat Linux Keywords: man setgid heap overflow Cross references: RHSA-2001:070 Obsoletes: --------------------------------------------------------------------- 1. Topic: A heap overrun exists in the man packages shipped with Red Hat Linux 5.x, 6.x and 7.0. Since man is setgid man, users could gain gid man privileges. Red Hat Linux 7.1 is not affected by this problem. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 3. Problem description: A buffer size was calculated incorrectly in man.c 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. In particular, if you are running Red Hat Linux 5.x or 6.x, you need to install the mktemp errata (RHSA-2001:070) before applying this update. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in theappropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 40400 - man 1.5h1-10 has an exploitable overflow 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 2b1c01c9490c9ee006566846a05b821a 5.2/en/os/SRPMS/man-1.5i-0.5x.1.src.rpm 00cea1dcef91591260a88dc61db73906 5.2/en/os/alpha/man-1.5i-0.5x.1.alpha.rpm dc0a21f7dda3f05c8599842ffff01482 5.2/en/os/i386/man-1.5i-0.5x.1.i386.rpm 75deb2a4464b3f50c930ef7d446edfe2 5.2/en/os/sparc/man-1.5i-0.5x.1.sparc.rpm 3ecc37d89a50cce2fa11851efc553569 6.2/en/os/SRPMS/man-1.5i-0.6x.1.src.rpm a13e86df8c929f337eb7eb12741fb9d8 6.2/en/os/alpha/man-1.5i-0.6x.1.alpha.rpm f132f39491c84f14d6f4d9120d1be777 6.2/en/os/i386/man-1.5i-0.6x.1.i386.rpm d1f322960a60560c45519600caa0f801 6.2/en/os/sparc/man-1.5i-0.6x.1.sparc.rpm 539ecb24566c3c4994379f8114fd58a0 7.0/en/os/SRPMS/man-1.5i-4.src.rpm 5fa9f106dbe9eadc2c148f11d6a15c7c 7.0/en/os/alpha/man-1.5i-4.alpha.rpm 1f99c169b03c1a59c038d77481a6710d 7.0/en/os/i386/man-1.5i-4.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Heap overrun in Red Hat's man package urges immediate security update to prevent privilege escalation.. Heap Overflow, Red Hat Man, Security Patch, Privilege Escalation, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 22, 2001 Critical Red Hat
100

SuSE: man-2.3.10-42 Critical: zsoelim File Overwrite Issue

The zsoelim program, which is part of the man package, creates files in /tmp without security checkings. . ______________________________________________________________________________ SuSE Security Announcement Package: man-2.3.10-42 Date: Tue Jun 29 00:22:52 CEST 1999 Affected: all Linux distributions using man-2.3.10 ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that that we provide this information on as "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. ______________________________________________________________________________ 1. Problem Description The zsoelim program, which is part of the man package, creates files in /tmp without security checkings. 2. Impact By creating symbolic links an attacker could overwrite files with the permissions of the user executing man. 3. Solution Install the updated man package, which is available from our ftp server since some weeks. ______________________________________________________________________________ Here are the md5 checksums of the upgrade packages, please verify these before installing the new packages: d95cbd1e35924738c7e53226d2298a4b man-2.3.10-76.i386.rpm cc96fa227766d50001d2800349bccb52 man-2.3.10-76.src.rpm ______________________________________________________________________________ You will find the updates on our ftp-Server: (glibc) (Source) Webpage for patches: https://www.suse.com/de-de/ or try the following web pages for a list ofmirrors: https://www.suse.com/de-de/ ______________________________________________________________________________ . ______________________________________________________________________________ SuSE Security Announc. zsoelim, program, which, package, creates, files, without, security, checki. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 08, 1999 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200