Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian: DLA-2308-1 Moderate: libopenmpt Buffer Overflow Fix

In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2308-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta August 02, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : libopenmpt Version : 0.2.7386~beta20.3-3+deb9u4 CVE ID : CVE-2019-17113 In libopenmpt before 0.3.19 and 0.4.x before 0.4.9, ModPlug_InstrumentName and ModPlug_SampleName in libopenmpt_modplug.c do not restrict the lengths of libmodplug output-buffer strings in the C API, leading to a buffer overflow. For Debian 9 stretch, this problem has been fixed in version 0.2.7386~beta20.3-3+deb9u4. We recommend that you upgrade your libopenmpt packages. For the detailed security status of libopenmpt please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libopenmpt Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Best, Utkarsh . The Debian LTS Advisory DLA-2309-1 highlights a critical vulnerability in libopenmpt related to a stack overflow. Users are urged to update promptly to mitigate security risks.. libopenmpt security, buffer overflow fix, debian lts, modplug instruments, debian update. . LinuxSecurity.com Team

Calendar 2 Aug 02, 2020 Debian LTS
91

Gentoo: GLSA 201408-07 Normal: ModPlug XMMS Plugin Remote Access Threat

Multiple vulnerabilities have been found in ModPlug XMMS Plugin, worst of which allows remote attackers to execute arbitrary code. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201408-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ModPlug XMMS Plugin: Multiple vulnerabilities Date: August 16, 2014 Bugs: #480388 ID: 201408-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in ModPlug XMMS Plugin, worst of which allows remote attackers to execute arbitrary code. Background ========= ModPlug XMMS Plugin is a library for playing MOD-like music files Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libmodplug < 0.8.8.5 > = 0.8.8.5 Description ========== Multiple vulnerabilities have been discovered in ModPlug XMMS Plugin. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker could possibly execute arbitrary code with the privileges of the process, or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All ModPlug XMMS Plugin users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libmodplug-0.8.8.5" References ========= [ 1 ] CVE-2013-4233 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4233 [ 2 ] CVE-2013-4234 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4234 Availability =========== This GLSAand any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201408-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws identified in ModPlug XMMS Plugin could lead to remote code execution or trigger Denial of Service incidents; updating is strongly recommended.. ModPlug XMMS Plugin,Gentoo Advisory,Remote Execution,Security Update,Code Execution. . LinuxSecurity.com Team

Calendar 2 Aug 16, 2014 Gentoo
91

Gentoo: GLSA-200907-08 Normal: libX11 Local Denial of Service Vulnerability

ModPlug contains several buffer overflows that could lead to the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200907-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: ModPlug: User-assisted execution of arbitrary code Date: July 12, 2009 Bugs: #266913 ID: 200907-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= ModPlug contains several buffer overflows that could lead to the execution of arbitrary code. Background ========= ModPlug is a library for playing MOD-like music. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-libs/libmodplug < 0.8.7 > = 0.8.7 2 media-libs/gst-plugins-bad < 0.10.11 > = 0.10.11 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Two vulnerabilities have been reported in ModPlug: * dummy reported an integer overflow in the CSoundFile::ReadMed() function when processing a MED file with a crafted song comment or song name, which triggers a heap-based buffer overflow (CVE-2009-1438). * Manfred Tremmel and Stanislav Brabec reported a buffer overflow in the PATinst() function when processing a long instrument name (CVE-2009-1513). The GStreamer Bad plug-ins (gst-plugins-bad) before 0.10.11 built a vulnerable copy of ModPlug. Impact ===== A remote attacker couldentice a user to read specially crafted files, possibly resulting in the execution of arbitrary code with the privileges of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All ModPlug users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-libs/libmodplug-0.8.7" gst-plugins-bad 0.10.11 and later versions do not include the ModPlug plug-in (it has been moved to media-plugins/gst-plugins-modplug). All gst-plugins-bad users should upgrade to the latest version and install media-plugins/gst-plugins-modplug: # emerge --sync # emerge --ask --oneshot -v "> =media-libs/gst-plugins-bad-0.10.11" # emerge --ask --verbose "media-plugins/gst-plugins-modplug" References ========= [ 1 ] CVE-2009-1438 https://www.cve.org/CVERecord?id=CVE-2009-1438 [ 2 ] CVE-2009-1513 https://www.cve.org/CVERecord?id=CVE-2009-1513 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200907-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . ModPlug has vulnerabilities due to buffer overflow risks, enabling arbitrary code execution. Please update to the latest version to address this security concern on Gentoo platforms.. ModPlug, Buffer Overflow, Gentoo Security, Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar 2 Jul 12, 2009 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here