Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
89

Fedora 11: 2009-10171 Critical: Mimetex Buffer Overflow Patch

- Fixes a buffer-overflow as detailed in #511049. - Updates to 1.7.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-10170 2009-10-03 17:52:30 -------------------------------------------------------------------------------- Name : mimetex Product : Fedora 11 Version : 1.71 Release : 1.fc11 URL : Summary : Easily embed LaTeX math in web pages Description : MimeTeX lets you easily embed LaTeX math in your html pages. It parses a LaTeX math expression and immediately emits the corresponding gif image, rather than the usual TeX dvi. And mimeTeX is an entirely separate little program that doesn't use TeX or its fonts in any way. -------------------------------------------------------------------------------- Update Information: - Fixes a buffer-overflow as detailed in #511049. - Updates to 1.7. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 1 2009 Jorge Torres - 1.71-1 - Update to 1.71 * Sat Jul 25 2009 Fedora Release Engineering - 1.60-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #511049 - CVE-2009-1382 CVE-2009-2459 mimeTeX: various flaws https://bugzilla.redhat.com/show_bug.cgi?id=511049 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update mimetex' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The patch resolves a security flaw in mimetex on Fedora 11 and outlines the installation procedure.. Fedora Update, Mimetex Security, Buffer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 04, 2009 Critical Fedora
87

Debian: DSA-1917-1 Moderate: Mimetex Buffer Overflow Exploits

Several vulnerabilities have been discovered in mimetex, a lightweight alternative to MathML. The Common Vulnerabilities and Exposures project identifies the following problems: . - ------------------------------------------------------------------------ Debian Security Advisory DSA-1917-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano October 24, 2009 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : mimetex Vulnerability : several vulnerabilities Problem type : remote (local) Debian-specific: no Debian bug : 537254 CVE Ids : CVE-2009-1382 CVE-2009-2459 Several vulnerabilities have been discovered in mimetex, a lightweight alternative to MathML. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-1382 Chris Evans and Damien Miller, discovered multiple stack-based buffer overflow. An attacker could execute arbitrary code via a TeX file with long picture, circle, input tags. CVE-2009-2459 Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. A remote attacker can obtain sensitive information. For the oldstable distribution (etch), these problems have been fixed in version 1.50-1+etch1. Due to a bug in the archive system, the fix for the stable distribution (lenny) will be released as version 1.50-1+lenny1 once it is available. For the testing distribution (squeeze), and the unstable distribution (sid), these problems have been fixed in version 1.50-1.1. We recommend that you upgrade your mimetex packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Debian (oldstable) - ------------------ Oldstable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 584 4c4ac225a147438ea1bb7be1b0f65019 Size/MD5 checksum: 5318 5d3a2a06fecf83d573c8cbb9c778ddf0 Size/MD5 checksum: 401817 cdda954fc3a436daa8345ecbfdb084c3 alpha architecture (DEC Alpha) Size/MD5 checksum: 154406 b525a79c4c6e92ebe5d6853261edb7d9 amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 151848 b01a4cf79985dbc98aa468b27355c005 arm architecture (ARM) Size/MD5 checksum: 150546 8041ce35d9d2457999e217bd9ecff233 hppa architecture (HP PA RISC) Size/MD5 checksum: 148156 0f7d099d12f46f9c74a9d4863cacb676 i386 architecture (Intel ia32) Size/MD5 checksum: 143668 55db42c430e79ebd525679d72c8556f8 ia64 architecture (Intel ia64) Size/MD5 checksum: 188604 5f4c8c896998e82797bba6a0997d550c mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 155176 c080d72fef8acd63fa27b0a5cf7688bd mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 156068 96a3663cab62464f23ea747f679fbb57 powerpc architecture (PowerPC) Size/MD5 checksum: 145470 84ec68d2dcf0378f634f7cdc48c272d2 s390 architecture (IBM S/390) Size/MD5 checksum: 157512 493034d85d335c5c48358aac4fa5365f sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 146950 657d93204c670f44c337d85b5fa9a67b These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list:This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Upgrade the mimetex packages to address urgent security flaws that jeopardize Debian users, such as buffer overflows and information disclosures.. Debian Security,mimetex update,remote exploits,buffer overflow,info leak. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 24, 2009 Important Debian
172

Ubuntu 8.04, 8.10, 9.04 USN-844-1 Moderate: mimeTeX Code Execution Risk

Chris Evans discovered that mimeTeX incorrectly handled certain long tags. An attacker could exploit this with a crafted mimeTeX expression and cause a denial of service or possibly execute arbitrary code. (CVE-2009-1382) [More...]. ==========================================================Ubuntu Security Notice USN-844-1 October 08, 2009 mimetex vulnerabilities CVE-2009-1382, CVE-2009-2459 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: mimetex 1.50-1ubuntu0.8.04.1 Ubuntu 8.10: mimetex 1.50-1ubuntu0.8.10.1 Ubuntu 9.04: mimetex 1.50-1ubuntu0.9.04.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Chris Evans discovered that mimeTeX incorrectly handled certain long tags. An attacker could exploit this with a crafted mimeTeX expression and cause a denial of service or possibly execute arbitrary code. (CVE-2009-1382) Chris Evans discovered that mimeTeX contained certain directives that may be unsuitable for handling untrusted user input. This update fixed the issue by disabling the \input and \counter tags. (CVE-2009-2459) Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 5469 8ad9a9938ea88e8ee405cb4ad667d4ac Size/MD5: 683 4eed9863876f2366eabd726cd410d101 Size/MD5: 401817 cdda954fc3a436daa8345ecbfdb084c3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 153268 e62de978629895ea46b3a505c98cb99d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 146142 2cb087e9a9b2cf2f544849935f7a1515 lpia architecture(Low Power Intel Architecture): Size/MD5: 143960 7695d7a093fa724e889cc836c7ad10a4 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 146076 c45addd30e86bd71f3ba40ca0a22d446 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 151876 960eec8e54a45b14e6095231752da948 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 5474 7a491ab73b9fca19aa47465e69a8c95a Size/MD5: 1083 cd5e9dacab96573c0a636b787de405e7 Size/MD5: 401817 cdda954fc3a436daa8345ecbfdb084c3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 153886 123a3943c860774fbef8ab1bbd7a6b2d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 146906 b06c90066e821a422152a0eee6d99c8b lpia architecture (Low Power Intel Architecture): Size/MD5: 144780 28155fae4c79e9567c9f218e5a2b5dc0 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 145814 2c8cc371d38dca569ffc46bcdde1f16b sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 151790 ab0a37e033383d4299d8e2f1aa1e15ba Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 5472 b12e605f5aeaac50a3680c95ebe5a94e Size/MD5: 1083 c35754529c28839ef43b4419b2c850fb Size/MD5: 401817 cdda954fc3a436daa8345ecbfdb084c3 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 153886 12e2799a662c380aa9974fc20e5766fc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 146904 7094c07fec0a2324e143b671a9ae4fbb lpia architecture (Low Power Intel Architecture): Size/MD5: 144772 26369d7ec13ac18350aa1628304be27f powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 145810 d7bc985011692be4d4a00cb9114520a0 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 151730 8d105909cf098d9170e7ef00ed69c4e7 . Ubuntu security advisory844-1 highlights vulnerabilities in mimeTeX used for LaTeX rendering, emphasizing unauthorized access risks and urging updates to secure systems against attacks. mimeTeX Exploits, Ubuntu Patch, Security Notice. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Oct 08, 2009 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here