Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 16.04 LTS: USN-4499-1 Critical: MilkyTracker Crash Risk

MilkyTracker could be made to crash or run programs as your login if it opened a specially crafted file.. =========================================================================Ubuntu Security Notice USN-4499-1 September 15, 2020 milkytracker vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS Summary: MilkyTracker could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - milkytracker: music creation tool inspired by Fast Tracker 2 Details: It was discovered that MilkyTracker did not properly handle certain input. If a user were tricked into opening a malicious file, an attacker could cause MilkyTracker to crash or potentially execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: milkytracker 0.90.85+dfsg-2.2+deb8u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4499-1 CVE-2019-14464, CVE-2019-14496, CVE-2019-14497 Package Information: https://launchpad.net/ubuntu/+source/milkytracker/0.90.85+dfsg-2.2+deb8u1build0.16.04.1 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . Ubuntu Security Advisory USN-4500-1 addresses vulnerabilities in MilkyTracker, highlighting associated threats and providing recommendations for updates.. milkytracker vulnerabilities, Ubuntu security updates, code execution risks, software vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 15, 2020 Critical Ubuntu
197

Debian: DLA-2292-1 Critical: MilkyTracker Buffer Overflow Issues

Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2292-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ July 27, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : milkytracker Version : 0.90.86+dfsg-2+deb9u1 CVE ID : CVE-2019-14464 CVE-2019-14496 CVE-2019-14497 CVE-2020-15569 Debian Bug : 933964 964797 Several vulnerabilities were fixed in MilkyTracker, a music tracker for composing music in the MOD and XM module file formats. CVE-2019-14464 Heap-based buffer overflow in XMFile::read CVE-2019-14496 Stack-based buffer overflow in LoaderXM::load CVE-2019-14497 Heap-based buffer overflow in ModuleEditor::convertInstrument CVE-2020-15569 Use-after-free in the PlayerGeneric destructor For Debian 9 stretch, these problems have been fixed in version 0.90.86+dfsg-2+deb9u1. We recommend that you upgrade your milkytracker packages. For the detailed security status of milkytracker please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/milkytracker Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS announcement DLA-2293-1 upgrades VLC Media Player to rectify various integer overflows and security vulnerabilities.. MilkyTracker, Debian LTS, security update, buffer overflow, music composing. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 27, 2020 Critical Debian LTS
197

Debian 8 LTS: DLA-1961-1 Critical: MilkyTracker Buffer Overflow Issues

Fredric discovered a couple of buffer overflows in MilkyTracker, of which, a brief description is given below. . Package : milkytracker Version : 0.90.85+dfsg-2.2+deb8u1 CVE ID : CVE-2019-14464 CVE-2019-14496 CVE-2019-14497 Debian Bug : 933964 Fredric discovered a couple of buffer overflows in MilkyTracker, of which, a brief description is given below. CVE-2019-14464 XMFile::read in XMFile.cpp in milkyplay in MilkyTracker had a heap-based buffer overflow. CVE-2019-14496 LoaderXM::load in LoaderXM.cpp in milkyplay in MilkyTracker had a stack-based buffer overflow. CVE-2019-14497 ModuleEditor::convertInstrument in tracker/ModuleEditor.cpp in MilkyTracker had a heap-based buffer overflow. For Debian 8 "Jessie", these problems have been fixed in version 0.90.85+dfsg-2.2+deb8u1. We recommend that you upgrade your milkytracker packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Strengthen the MilkyTracker software bundles by rectifying buffer overflow weaknesses present in Debian LTS distributions.. MilkyTracker Security Update, Debian LTS, Buffer Overflows, Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 21, 2019 Critical Debian LTS
89

Fedora 27 Milkytracker Update: RCE Fix and Upgrade Instructions

New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-2331a462fb 2018-02-25 21:13:42.652067 --------------------------------------------------------------------------------Name : milkytracker Product : Fedora 27 Version : 1.01.00 Release : 1.fc27 URL : https://milkytracker.org/ Summary : Module tracker software for creating music Description : MilkyTracker is an application for creating music in the .MOD and .XM formats. Its goal is to be free replacement for the popular Fasttracker II software. --------------------------------------------------------------------------------Update Information: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35 --------------------------------------------------------------------------------References: [ 1 ] Bug #1545501 - milkytracker: Multiple flaws in module loaders potentially leading to remote code execution https://bugzilla.redhat.com/show_bug.cgi?id=1545501 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade milkytracker' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 37 milkytracker vulnerability patch tacklesremote execution risks. Discover how to implement the update today!. Fedora 27 Update, MilkyTracker Security Fix, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 25, 2018 Critical Fedora
89

Fedora 26: 2018-7d90e269a4 Moderate: Milkytracker Remote Code Execution

New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-7d90e269a4 2018-02-25 20:51:53.201949 --------------------------------------------------------------------------------Name : milkytracker Product : Fedora 26 Version : 1.01.00 Release : 1.fc26 URL : https://milkytracker.org/ Summary : Module tracker software for creating music Description : MilkyTracker is an application for creating music in the .MOD and .XM formats. Its goal is to be free replacement for the popular Fasttracker II software. --------------------------------------------------------------------------------Update Information: New upstream version Security fix for upstream issue 35 https://github.com/milkytracker/MilkyTracker/issues/35 --------------------------------------------------------------------------------References: [ 1 ] Bug #1545501 - milkytracker: Multiple flaws in module loaders potentially leading to remote code execution https://bugzilla.redhat.com/show_bug.cgi?id=1545501 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade milkytracker' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Latest MilkyTracker security patch resolves severalvulnerabilities and improves overall functionality for Fedora users.. MilkyTracker Update, Fedora Security, Remote Code Execution, Software Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 25, 2018 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here