Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
172

Ubuntu 23.04 LTS: USN-6271-1 Moderate: MaraDNS Denial of Service

Several security issues were fixed in MaraDNS.. ========================================================================== Ubuntu Security Notice USN-6271-1 August 03, 2023 maradns vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 23.04 - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: Several security issues were fixed in MaraDNS. Software Description: - maradns: A small open-source DNS server Details: Xiang Li discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to obtain sensitive information. (CVE-2022-30256) Huascar Tejeda discovered that MaraDNS incorrectly handled certain inputs. If a user or an automated system were tricked into opening a specially crafted input file, a remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-31137) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 23.04: duende 2.0.13-1.4+deb11u1build0.23.04.1 maradns 2.0.13-1.4+deb11u1build0.23.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.23.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.23.04.1 Ubuntu 22.04 LTS: duende 2.0.13-1.4+deb11u1build0.22.04.1 maradns 2.0.13-1.4+deb11u1build0.22.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.22.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.22.04.1 Ubuntu 20.04 LTS: duende 2.0.13-1.4+deb11u1build0.20.04.1 maradns 2.0.13-1.4+deb11u1build0.20.04.1 maradns-deadwood 2.0.13-1.4+deb11u1build0.20.04.1 maradns-zoneserver 2.0.13-1.4+deb11u1build0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): duende 2.0.13-1.2ubuntu0.1~esm1 maradns 2.0.13-1.2ubuntu0.1~esm1 maradns-deadwood 2.0.13-1.2ubuntu0.1~esm1 maradns-zoneserver 2.0.13-1.2ubuntu0.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): duende 2.0.13-1ubuntu0.1~esm1 maradns 2.0.13-1ubuntu0.1~esm1 maradns-deadwood 2.0.13-1ubuntu0.1~esm1 maradns-zoneserver 2.0.13-1ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6271-1 CVE-2022-30256, CVE-2023-31137 Package Information: https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.23.04.1 https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.22.04.1 https://launchpad.net/ubuntu/+source/maradns/2.0.13-1.4+deb11u1build0.20.04.1 . A number of vulnerabilities addressed in MaraDNS for Ubuntu, impacting various releases. Update suggestions issued.. MaraDNS Security Update, Ubuntu Security Notice, DNS Server Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 03, 2023 Important Ubuntu
87

Debian DSA-5441-1: Critical Security Update for Maradns Denial of Service

Brief introduction Two vulnerbilities were found in maradns, an open source domain name system (DNS) implementation, that may lead to denial of service and . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5441-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Aron Xu June 29, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : maradns CVE ID : CVE-2022-30256 CVE-2023-31137 Debian Bug : 1033252 1035936 Brief introduction Two vulnerbilities were found in maradns, an open source domain name system (DNS) implementation, that may lead to denial of service and unintended domain name resolution. For the oldstable distribution (bullseye), these problems have been fixed in version 2.0.13-1.4+deb11u1. We recommend that you upgrade your maradns packages. For the detailed security status of maradns please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/maradns Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-5800-1 concerns vulnerabilities in maradns that could lead to denial of service and domain resolution problems.. Debian Security, Maradns Update, Security Patch, Denial Of Service, Open Source DNS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 29, 2023 Critical Debian
89

Fedora 38: FEDORA-2023-0c012f6245 Critical: Maradns Integer Underflow

Security fix for CVE-2023-31137, CVE-2022-30256. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-0c012f6245 2023-05-25 01:10:39.287243 --------------------------------------------------------------------------------Name : maradns Product : Fedora 38 Version : 3.5.0036 Release : 1.fc38 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-31137, CVE-2022-30256 --------------------------------------------------------------------------------ChangeLog: * Tue May 16 2023 Tomasz Torcz - 3.5.0036-1 - new version 3.5.0036 (rhbz#2149110, rhbz#2180267) - fixes CVE-2023-31137 (rhbz#2207551) --------------------------------------------------------------------------------References: [ 1 ] Bug #2207550 - CVE-2023-31137 maradns: integer underflow in DNS packet decompression https://bugzilla.redhat.com/show_bug.cgi?id=2207550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-0c012f6245' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Critical Fedora notice regarding maradns pertaining to security resolutions for CVE-2023-31137 and CVE-2022-30256 vulnerabilities.. Fedora Update, Maradns Security, DNS Fix, Security Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 25, 2023 Critical Fedora
89

Fedora 37 Security Update 2023-cdce244fb8: Critical MaraDNS Issue

Security fix for CVE-2023-31137, CVE-2022-30256. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-cdce244fb8 2023-05-25 00:59:24.928504 --------------------------------------------------------------------------------Name : maradns Product : Fedora 37 Version : 3.5.0036 Release : 1.fc37 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2023-31137, CVE-2022-30256 --------------------------------------------------------------------------------ChangeLog: * Tue May 16 2023 Tomasz Torcz - 3.5.0036-1 - new version 3.5.0036 (rhbz#2149110, rhbz#2180267) - fixes CVE-2023-31137 (rhbz#2207551) --------------------------------------------------------------------------------References: [ 1 ] Bug #2207550 - CVE-2023-31137 maradns: integer underflow in DNS packet decompression https://bugzilla.redhat.com/show_bug.cgi?id=2207550 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-cdce244fb8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam, report it: . Important release for Fedora 37 tackling vulnerabilities in MaraDNS, boosting stability and protection of the DNS server.. Fedora 37 Update, MaraDNS Security, DNS Server Evasion, Open Source Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 25, 2023 Critical Fedora
89

Fedora 21: FEDORA-2015-14033 Critical: Maradns DoS Risk

This update fixes Denial-of-Service vulnerability in ”zoneserver” component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14033 2015-08-27 19:40:20.010620 -------------------------------------------------------------------------------- Name : maradns Product : Fedora 21 Version : 2.0.12 Release : 1.fc21 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. -------------------------------------------------------------------------------- Update Information: This update fixes Denial-of-Service vulnerability in ”zoneserver” component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update maradns' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- . Announcement Alert FEDORA-2015-14034 addresses a critical Denial-of-Service vulnerability in the maradns zoneserver module.. MaradnsUpdate, Fedora Security, Denial-of-Service Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 27, 2015 Critical Fedora
89

Fedora 22: 2015-14032 Critical: Zoneserver DoS Impacting MaraDNS

This update fixes Denial-of-Service vulnerability in ”zoneserver” component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2015-14032 2015-08-27 17:52:04.306247 -------------------------------------------------------------------------------- Name : maradns Product : Fedora 22 Version : 2.0.12 Release : 1.fc22 URL : https://maradns.samiam.org/ Summary : Authoritative and recursive DNS server made with security in mind Description : MaraDNS is a package that implements the Domain Name Service (DNS), an essential internet service. MaraDNS has the following advantages: * Secure. * Supported. * Easy to use. * Small. * Open Source. -------------------------------------------------------------------------------- Update Information: This update fixes Denial-of-Service vulnerability in ”zoneserver” component. By making the zoneserver daemon free an invalid memory location, it was possible to terminate the zoneserver process. It is not known whether or not this bug is remotely exploitable. More details: https://samiam.org/blog/2015-08-19.html -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update maradns' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- . This patch resolves a service interruption vulnerability found in the zoneserver module of Fedora 22'sMaraDNS software.. Fedora Update, Denial of Service, MaraDNS Security, Software Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 27, 2015 Critical Fedora
87

Debian: DSA-2196-1 Critical: MaraDNS Buffer Overflow Denial of Service

Witold Baryluk discovered that MaraDNS, a simple security-focused Domain Name Service server, may overflow an internal buffer when handling requests with a large number of labels, causing a server crash and the consequent denial of service. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2196-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Raphael Geissert March 19, 2011 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : maradns Vulnerability : buffer overflow Problem type : remote Debian-specific: no CVE ID : CVE-2011-0520 Debian Bug : 610834 Witold Baryluk discovered that MaraDNS, a simple security-focused Domain Name Service server, may overflow an internal buffer when handling requests with a large number of labels, causing a server crash and the consequent denial of service. For the oldstable distribution (lenny), this problem has been fixed in version 1.3.07.09-2.1. For the stable distribution (squeeze) and greater this problem had already been fixed in version 1.4.03-1.1. We recommend that you upgrade your maradns packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent advisory for MaraDNS highlights a severe buffer overflow vulnerability that has the potential to lead to server failures and service interruptions.. MaraDNS Security Update, Debian Security Advisory, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 19, 2011 Critical Debian
87

Debian 4.0 DSA-1445-1 Critical: Maradns Denial Of Service Threat

Michael Krieger and Sam Trenholme discovered a programming error in MaraDNS, a simple security-aware Domain Name Service server, which might to denial of service through malformed DNS packets.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1445-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff January 03, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : maradns Vulnerability : programming error Problem type : remote Debian-specific: no CVE Id(s) : CVE-2008-0061 Michael Krieger and Sam Trenholme discovered a programming error in MaraDNS, a simple security-aware Domain Name Service server, which might to denial of service through malformed DNS packets. For the stable distribution (etch), this problem has been fixed in version 1.2.12.04-1etch2. For the old stable distribution (sarge), this problem has been fixed in version 1.0.27-2. For the unstable distribution (sid), this problem has been fixed in version 1.2.12.08-1. We recommend that you upgrade your maradns package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian 3.1 (oldstable) - ----------------------Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, m68k, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 568 b211f2c8bb6f589b68e470dd3cbb7bf7 Size/MD5 checksum: 7060125fd4a3e8024a0a7561f09e3ff3955cf2 Size/MD5 checksum: 13750 5eec451105342d404680363cc55304d4 alpha architecture (DEC Alpha) Size/MD5 checksum: 334558 e9504463d1aeb92f2a9850f06731d37d amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 293844 0ae412e1fc143990be4c10c7c3ef27db arm architecture (ARM) Size/MD5 checksum: 279548 f73c92834aa322530dd7ac8a5b7987b8 hppa architecture (HP PA RISC) Size/MD5 checksum: 301566 7cd905a3e7c890b691e60acf8a4ad179 i386 architecture (Intel ia32) Size/MD5 checksum: 280286 fc8b498709e17b015e6f5d2daa7044ec ia64 architecture (Intel ia64) Size/MD5 checksum: 359728 adac044edb5a2062fd7e23f765c2b426 m68k architecture (Motorola Mc680x0) Size/MD5 checksum: 263496 6b0aca240a56ecd34b41136a07d99723 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 304440 72a10d56ada559dac2ef3d7d8ef5ba37 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 304524 7c7d31805416f4151e65c554e40bd5d5 powerpc architecture (PowerPC) Size/MD5 checksum: 290008 6be1203722742a5f04543e0b414b5fa1 s390 architecture (IBM S/390) Size/MD5 checksum: 288736 6d1f00a6dfffef9b48786b5d1f2dda86 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 277652 3aed2b89373691601c8e6daa88ea2758 Debian 4.0 (stable) - -------------------Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1323244 032465dca4842731ab78edb065d0caed Size/MD5 checksum: 503 024c6dfc89a28dd7113b10eadad124fa alpha architecture (DEC Alpha) Size/MD5 checksum: 550836 6fcf2d7f2652c098688d35e40a901b49 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 500544 2ca8d84ecc72ace553ab24b99ebb90e9 arm architecture (ARM) Size/MD5 checksum: 477186 2b6ba5db9a98ffdc38352d0a1b3cff84 hppa architecture (HP PA RISC) Size/MD5 checksum: 522826 f6a32d023392e55de5358fb6b98643e4 i386 architecture (Intel ia32) Size/MD5 checksum: 471410 7083cec7888c69efee3440ce59417dd8 ia64 architecture (Intel ia64) Size/MD5 checksum: 661664 be8d5c96b8400c17e7624bf754fdd5b4 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 528270 8eab540505b58fdb2c2f3dc72d284a14 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 529546 b72a7386b2ede6c4cfeb083ae43e5a4e powerpc architecture (PowerPC) Size/MD5 checksum: 487420 03cc439b6fdfc8dd222aba274ef4d539 s390 architecture (IBM S/390) Size/MD5 checksum: 499454 cf0db50276a245147f57a0c556900a56 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 462932 8d32c8dc463c073a9c5621e6b98ac125 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Uncover the ways in which the newest maradns updates tackle a coding flaw that leads to service interruptions in Debian environments.. maradns programming error, denial service fix, debian security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 03, 2008 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here