Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
89

Fedora 25 Minicom Update - Security Fix for Multiple Issues

Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-90cf7a82de 2017-07-27 14:25:19.487115 --------------------------------------------------------------------------------Name : minicom Product : Fedora 25 Version : 2.7.1 Release : 1.fc25 URL : Summary : A text-based modem control and terminal emulation program Description : Minicom is a simple text-based modem control and terminal emulation program somewhat similar to MSDOS Telix. Minicom includes a dialing directory, full ANSI and VT100 emulation, an (external) scripting language, and other features. --------------------------------------------------------------------------------Update Information: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade minicom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 minicom security patch addressed several vulnerabilities within the software, improving reliability and functionality.. Fedora 25 Minicom Update, Terminal Emulation Security, Minicom Version Upgrade. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jul 27, 2017 Important Fedora
89

Fedora 24: 2017-31af7a849d Moderate: Minicom Security Update

Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-31af7a849d 2017-07-27 14:24:45.247086 --------------------------------------------------------------------------------Name : minicom Product : Fedora 24 Version : 2.7.1 Release : 1.fc24 URL : Summary : A text-based modem control and terminal emulation program Description : Minicom is a simple text-based modem control and terminal emulation program somewhat similar to MSDOS Telix. Minicom includes a dialing directory, full ANSI and VT100 emulation, an (external) scripting language, and other features. --------------------------------------------------------------------------------Update Information: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade minicom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . This Fedora patch for the application netcat resolves vulnerabilities found in bugs rhbz#1450060 and rhbz#1450085 in release 1.12.. Fedora Update, Minicom Fix, Terminal Emulation. . LinuxSecurity.com Team

Calendar 2 Jul 27, 2017 Fedora
89

Fedora 26 Minicom 2.7.1 Moderate Severity Update Notification

Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-0642394b5a 2017-07-27 14:26:19.255151 --------------------------------------------------------------------------------Name : minicom Product : Fedora 26 Version : 2.7.1 Release : 1.fc26 URL : Summary : A text-based modem control and terminal emulation program Description : Minicom is a simple text-based modem control and terminal emulation program somewhat similar to MSDOS Telix. Minicom includes a dialing directory, full ANSI and VT100 emulation, an (external) scripting language, and other features. --------------------------------------------------------------------------------Update Information: Rebuilt to new upstream version 2.7.1 fixes rhbz#1443071 and rhbz#1443129 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade minicom' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora 26 introduces an updated Minicom package, addressing security vulnerabilities present in version 2.7.1 from upstream.. Fedora Security Update, Minicom Software Update, Terminal Emulator Fix. . LinuxSecurity.com Team

Calendar 2 Jul 27, 2017 Fedora
91

Gentoo: GLSA-201706-13 Normal: Minicom Remote Execution Risk

An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201706-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: minicom: Remote execution of arbitrary code Date: June 06, 2017 Bugs: #615996 ID: 201706-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= An out-of-bounds data access in minicom might allow remote attackers to execute arbitrary code. Background ========= Minicom is a text-based serial port communications program. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dialup/minicom < 2.7.1 > = 2.7.1 Description ========== In minicom before version 2.7.1, the escparms[] buffer in vt100.c is vulnerable to an overflow. Impact ===== A remote attacker, able to connect to a minicom port, could possibly execute arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All minicom users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dialup/minicom-2.7.1" References ========= [ 1 ] CVE-2017-7467 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7467 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201706-13 Concerns? ======== Security is a primary focus of Gentoo Linux andensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . Unauthorized memory access in minicom could potentially lead to remote code execution vulnerabilities. It is advisable to update to version 2.7.1 to reduce security risks.. Minicom Remote Execution, Gentoo Advisory, Out-of-Bounds Code, Security Update, Normal Severity. . LinuxSecurity.com Team

Calendar 2 Jun 06, 2017 Gentoo
197

Debian 7 Wheezy DLA-914-1 Critical Minicom Out Of Bounds Write

CVE-2017-7467 Out of bounds write in vt100.c For Debian 7 "Wheezy", these problems have been fixed in version . Hash: SHA512 Package : minicom Version : 2.6.1-1+deb7u1 CVE ID : CVE-2017-7467 Debian Bug : 860940 CVE-2017-7467 Out of bounds write in vt100.c For Debian 7 "Wheezy", these problems have been fixed in version 2.6.1-1+deb7u1. We recommend that you upgrade your minicom packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Hash: SHA512 Package : minicom Version : 2.6.1-1+deb7u1 CVE ID : CVE-2017-7467 Debian Bug : 860940 C. cve-2017-7467, bounds, write, vt100, debian, 'wheezy', these, problems. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 24, 2017 Critical Debian LTS
99

Slackware: 2023-204-05 Urgent: Minicom Remote Code Execution

New minicom packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] minicom (SSA:2017-108-01) New minicom packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/minicom-2.7.1-i586-1_slack14.2.txz: Upgraded. Fix an out of bounds data access that can lead to remote code execution. This issue was found by Solar Designer of Openwall during a security audit of the Virtuozzo 7 product, which contains derived downstream code in its prl-vzvncserver component. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-7467 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/minicom-2.7.1-i486-1_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/minicom-2.7.1-x86_64-1_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/minicom-2.7.1-i486-1_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/minicom-2.7.1-x86_64-1_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/minicom-2.7.1-i486-1_slack13.37.txz Updated package for Slackware x86_6413.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/minicom-2.7.1-x86_64-1_slack13.37.txz Updated package for Slackware 14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/minicom-2.7.1-i486-1_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/minicom-2.7.1-x86_64-1_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/minicom-2.7.1-i486-1_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/minicom-2.7.1-x86_64-1_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/minicom-2.7.1-i586-1_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/minicom-2.7.1-x86_64-1_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: b7197571bc25f6272a49e016e75260c0 minicom-2.7.1-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 5f90a004fd56dfde61e4edccc6600bf6 minicom-2.7.1-x86_64-1_slack13.0.txz Slackware 13.1 package: e719abf9c97fb624c2158d119b29a8e3 minicom-2.7.1-i486-1_slack13.1.txz Slackware x86_64 13.1 package: d096a62153dbca10477ce9c5b7f3e4cd minicom-2.7.1-x86_64-1_slack13.1.txz Slackware 13.37 package: 30b55c08506d65aeb34f788bcf92bbd2 minicom-2.7.1-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 366d9f36aa9126d561493c9c1ee59b8f minicom-2.7.1-x86_64-1_slack13.37.txz Slackware 14.0 package: e02ca4c7e052a60297487d54cea1563e minicom-2.7.1-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 9b6997e949b872e539d9e20be11c3824 minicom-2.7.1-x86_64-1_slack14.0.txz Slackware 14.1 package: 3ea4b0a6a5161670203b56b8aa0c091b minicom-2.7.1-i486-1_slack14.1.txz Slackware x86_64 14.1package: fb5e623fffc45aadf7fe97264e761fd9 minicom-2.7.1-x86_64-1_slack14.1.txz Slackware 14.2 package: 7de4ed4ba12b1868012b2a62365ca441 minicom-2.7.1-i586-1_slack14.2.txz Slackware x86_64 14.2 package: 86031667476f918e824257bbf6d5d05e minicom-2.7.1-x86_64-1_slack14.2.txz Slackware -current package: b41864d475ac9958efe9dd5e48dbddbe a/minicom-2.7.1-i586-1.txz Slackware x86_64 -current package: cba988ccb02f9f8772488928094ed297 a/minicom-2.7.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg minicom-2.7.1-i586-1_slack14.2.txz +-----+ . A security patch for Minicom affecting various Slackware releases tackles a vulnerability that allows for remote code execution. Please update immediately!. Minicom Security Update, Remote Code Execution Fix, Slackware Packages. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 19, 2017 Critical Slackware
98

Red Hat 6.2: RHSA-2001:068-04 Critical: Tmux Local Vulnerability

The minicom program allows any user with local shell access to obtaingroup uucp priveledges.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated minicom packages available Advisory ID: RHSA-2001:067-03 Issue date: 2001-05-03 Updated on: 2001-05-09 Product: Red Hat Linux Keywords: minicom security format string exploit Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: The minicom program allows any user with local shell access to obtain group uucp priveledges. It may also be possible for the malicious user to obtain root priveledges as well. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - i386 3. Problem description: Minicom contains a great number of format string abuses in it's usage of several printf-like varargs functions. The program was never written with security in mind, and as such even though many format strings bugs have been fixed in this release, there are many more lurking in the code. This release solves the security problem by disabling setgid uucp on the minicom binary. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red HatUpdate Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 35613 - SGID uucp from minicom = format string + setgid uucp + makewhatis.cron bug 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 5991bffcfbe2900f4522c03b981ae0bb 5.2/en/os/SRPMS/minicom-1.83.1-1.0.5x.src.rpm b0f31c02364c8fa9cc296eaa8e5e25d6 5.2/en/os/alpha/minicom-1.83.1-1.0.5x.alpha.rpm e7875eb52e0b1166be8b1dd7e540dfa1 5.2/en/os/i386/minicom-1.83.1-1.0.5x.i386.rpm 2b844a4be94f692973c5d8e8e1cd0eb9 5.2/en/os/sparc/minicom-1.83.1-1.0.5x.sparc.rpm d6ecd41e7df093ca62f8d1ab15a2d51c 6.2/en/os/SRPMS/minicom-1.83.1-1.0.6x.src.rpm b27358ca1604b2ca5fa8ec6a34fa6349 6.2/en/os/alpha/minicom-1.83.1-1.0.6x.alpha.rpm 158495648d2d3f8a2636d345249fc01a 6.2/en/os/i386/minicom-1.83.1-1.0.6x.i386.rpm ca9069a87bfa81fe730cb8f31378e57a 6.2/en/os/sparc/minicom-1.83.1-1.0.6x.sparc.rpm eb41cbef4946cccb1e1e388a88bf4e88 7.0/en/os/SRPMS/minicom-1.83.1-8.src.rpm 2da88e6d8479ccb35078ec1a469b3568 7.0/en/os/alpha/minicom-1.83.1-8.alpha.rpm 5567d943ad44b7f44e332576edabdb5e 7.0/en/os/i386/minicom-1.83.1-8.i386.rpm 599a686fa0598467f5ee451f934c8a28 7.1/en/os/SRPMS/minicom-1.83.1-8.src.rpm 5cfe67255b3ec7df6c3f1b274da3c7ad 7.1/en/os/i386/minicom-1.83.1-8.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: None. Copyright(c) 2000, 2001 Red Hat,Inc. `. Upgraded minicom application for Red Hat Linux addresses local elevation of privilege risks arising from format string flaws.. Red Hat Security, Local Escalation, Minicom Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 09, 2001 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here