Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu: 1710-2 Urgent: libav Service Disruption and Remote Code Execution

Libav could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-1705-1 January 28, 2013 libav vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.10 - Ubuntu 12.04 LTS - Ubuntu 11.10 Summary: Libav could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - libav: Multimedia player, server, encoder and transcoder Details: It was discovered that Libav incorrectly handled certain malformed media files. If a user were tricked into opening a crafted media file, an attacker could cause a denial of service via application crash, or possibly execute arbitrary code with the privileges of the user invoking the program. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: libavcodec53 6:0.8.5-0ubuntu0.12.10.1 libavformat53 6:0.8.5-0ubuntu0.12.10.1 Ubuntu 12.04 LTS: libavcodec53 4:0.8.5-0ubuntu0.12.04.1 libavformat53 4:0.8.5-0ubuntu0.12.04.1 Ubuntu 11.10: libavcodec53 4:0.7.6-0ubuntu0.11.10.3 libavformat53 4:0.7.6-0ubuntu0.11.10.3 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1705-1 CVE-2012-2783, CVE-2012-2791, CVE-2012-2797, CVE-2012-2798, CVE-2012-2801, CVE-2012-2802, CVE-2012-2803, CVE-2012-2804, CVE-2012-5144 Package Information: https://launchpad.net/ubuntu/+source/libav/6:0.8.5-0ubuntu0.12.10.1 https://launchpad.net/ubuntu/+source/libav/4:0.8.5-0ubuntu0.12.04.1 https://launchpad.net/ubuntu/+source/libav/4:0.7.6-0ubuntu0.11.10.3 . The Ubuntu SecurityNotice USN-1705-1 discusses vulnerabilities in Libav, outlining their potential security risks and providing essential update instructions.. Libav Exploit, Ubuntu Security Advisory, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 28, 2013 Critical Ubuntu
98

Red Hat: RHSA-2009-0269-01 Important: Gstreamer-Plugins Security Issue

Updated gstreamer-plugins packages that fix one security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: gstreamer-plugins security update Advisory ID: RHSA-2009:0269-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:0269.html Issue date: 2009-02-06 CVE Names: CVE-2009-0398 ==================================================================== 1. Summary: Updated gstreamer-plugins packages that fix one security issue are now available for Red Hat Enterprise Linux 3. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux AS version 3 - i386, ia64, ppc, s390, s390x, x86_64 Red Hat Desktop version 3 - i386, x86_64 Red Hat Enterprise Linux ES version 3 - i386, ia64, x86_64 Red Hat Enterprise Linux WS version 3 - i386, ia64, x86_64 3. Description: The gstreamer-plugins package contains plug-ins used by the GStreamer streaming-media framework to support a wide variety of media types. An array indexing error was found in the GStreamer's QuickTime media file format decoding plug-in. An attacker could create a carefully-crafted QuickTime media .mov file that would cause an application using GStreamer to crash or, potentially, execute arbitrary code if played by a victim. (CVE-2009-0398) All users of gstreamer-plugins are advised to upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the update, all applications using GStreamer (such as nautilus-media) must be restarted for the changes to take effect. 4. Solution: Before applying this update, make sure that allpreviously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 483740 - CVE-2009-0398 gstreamer-plugins: Array index error while parsing malformed QuickTime media files 6. Package List: Red Hat Enterprise Linux AS version 3: Source: i386: gstreamer-plugins-0.6.0-19.i386.rpm gstreamer-plugins-debuginfo-0.6.0-19.i386.rpm gstreamer-plugins-devel-0.6.0-19.i386.rpm ia64: gstreamer-plugins-0.6.0-19.ia64.rpm gstreamer-plugins-debuginfo-0.6.0-19.ia64.rpm gstreamer-plugins-devel-0.6.0-19.ia64.rpm ppc: gstreamer-plugins-0.6.0-19.ppc.rpm gstreamer-plugins-debuginfo-0.6.0-19.ppc.rpm gstreamer-plugins-devel-0.6.0-19.ppc.rpm s390: gstreamer-plugins-0.6.0-19.s390.rpm gstreamer-plugins-debuginfo-0.6.0-19.s390.rpm gstreamer-plugins-devel-0.6.0-19.s390.rpm s390x: gstreamer-plugins-0.6.0-19.s390x.rpm gstreamer-plugins-debuginfo-0.6.0-19.s390x.rpm gstreamer-plugins-devel-0.6.0-19.s390x.rpm x86_64: gstreamer-plugins-0.6.0-19.x86_64.rpm gstreamer-plugins-debuginfo-0.6.0-19.x86_64.rpm gstreamer-plugins-devel-0.6.0-19.x86_64.rpm Red Hat Desktop version 3: Source: i386: gstreamer-plugins-0.6.0-19.i386.rpm gstreamer-plugins-debuginfo-0.6.0-19.i386.rpm gstreamer-plugins-devel-0.6.0-19.i386.rpm x86_64: gstreamer-plugins-0.6.0-19.x86_64.rpm gstreamer-plugins-debuginfo-0.6.0-19.x86_64.rpm gstreamer-plugins-devel-0.6.0-19.x86_64.rpm Red Hat Enterprise Linux ES version 3: Source: i386: gstreamer-plugins-0.6.0-19.i386.rpm gstreamer-plugins-debuginfo-0.6.0-19.i386.rpm gstreamer-plugins-devel-0.6.0-19.i386.rpm ia64: gstreamer-plugins-0.6.0-19.ia64.rpm gstreamer-plugins-debuginfo-0.6.0-19.ia64.rpm gstreamer-plugins-devel-0.6.0-19.ia64.rpm x86_64: gstreamer-plugins-0.6.0-19.x86_64.rpm gstreamer-plugins-debuginfo-0.6.0-19.x86_64.rpm gstreamer-plugins-devel-0.6.0-19.x86_64.rpm Red Hat Enterprise Linux WS version3: Source: i386: gstreamer-plugins-0.6.0-19.i386.rpm gstreamer-plugins-debuginfo-0.6.0-19.i386.rpm gstreamer-plugins-devel-0.6.0-19.i386.rpm ia64: gstreamer-plugins-0.6.0-19.ia64.rpm gstreamer-plugins-debuginfo-0.6.0-19.ia64.rpm gstreamer-plugins-devel-0.6.0-19.ia64.rpm x86_64: gstreamer-plugins-0.6.0-19.x86_64.rpm gstreamer-plugins-debuginfo-0.6.0-19.x86_64.rpm gstreamer-plugins-devel-0.6.0-19.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-0398 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFJjDQRXlSAg2UNWIIRAkybAJ9liCAEwGkN4wL1QkJn21lr1cdGfQCgxH/+ otEOgt31/GZaRjwle7mygJ8=MQig -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Crucial patch released for gstreamer-plugins resolving a significant vulnerability in Red Hat Enterprise Linux 3.. gstreamer, Red Hat Enterprise, security update, media framework, important patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 06, 2009 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200