Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":2,"type":"x","order":1,"pct":25,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
217

Oracle Linux 7 ELSA-2025-9332 Significant: mpfr buffer overflow resolution

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-9332 http://linux.oracle.com/errata/ELSA-2025-9332.html The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network: x86_64: mpfr-3.1.1-4.0.1.el7.i686.rpm mpfr-3.1.1-4.0.1.el7.x86_64.rpm mpfr-devel-3.1.1-4.0.1.el7.i686.rpm mpfr-devel-3.1.1-4.0.1.el7.x86_64.rpm SRPMS: http://oss.oracle.com/ol7/SRPMS-updates/mpfr-3.1.1-4.0.1.el7.src.rpm Related CVEs: CVE-2014-9474 Description of changes: [3.1.1-4.0.1] - Fixes buffer overflow in mpfr_strtofr (CVE-2014-9474) [Orabug: 38103811] _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Red Hat Enterprise Linux 7 updates address urgent flaws in the gmp library. Discover the newest security enhancements here. Oracle Linux Updates, Buffer Overflow Fixes, MPFR Security Patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 10, 2025 Important Oracle
91

Gentoo: 202310-45 Critical: XYZ Library Buffer Overflow Risk

Multiple buffer overflows in MPFR might lead to a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: MPFR: Denial of Service Date: March 09, 2009 Bugs: #260968 ID: 200903-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple buffer overflows in MPFR might lead to a Denial of Service. Background ========= MPFR is a library for multiple-precision floating-point computations with exact rounding. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-libs/mpfr < 2.4.1 > = 2.4.1 Description ========== Multiple buffer overflows have been reported in the mpfr_snprintf() and mpfr_vsnprintf() functions. Impact ===== A remote user could exploit the vulnerability to cause a Denial of Service in an application using MPFR via unknown vectors. Workaround ========= There is no known workaround at this time. Resolution ========= All MPRF users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/mpfr-2.4.1" References ========= [ 1 ] CVE-2009-0757 https://www.cve.org/CVERecord?id=CVE-2009-0757 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200903-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is ofutmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2009 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several vulnerabilities found in MPFR may result in Denial of Service; Gentoo users are advised to upgrade.. MPFR Buffer Overflow, Denial of Service, Gentoo Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 09, 2009 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":2,"type":"x","order":1,"pct":25,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":4,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200