Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian 3.0 DSA 427-1 Critical: mremap Local Attack Exploit

A flaw in bounds checking in mremap() in the Linux kernel may allow a local attacker to gain root privileges.. Hash: SHA1 Debian Security Advisory DSA 427-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Martin Schulze January 19th, 2004 debian.org/security/faq - -------------------------------------------------------------------------- Package : kernel-patch-2.4.17-mips Vulnerability : mising boundary check Problem-Type : local Debian-specific: no CVE ID : CAN-2003-0985 Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux kernel (present in version 2.4.x and 2.6.x) which may allow a local attacker to gain root privileges. Version 2.2 is not affected by this bug. For the stable distribution (woody) this problem has been fixed in version 2.4.17-0.020226.2.woody3 the mips and mipsel architectures. For the unstable distribution (sid) this problem will be fixed soon with newly uploaded packages. We recommend that you upgrade your kernel packages. This problem has been fixed in the upstream version 2.4.24 as well. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 786 0ed0c82eae3f9bdea8b5643080f11231 Size/MD5 checksum: 1136013 b115834700679688144a44ba55554389 Architecture independent components: Size/MD5 checksum: 1138232 067fa128b07595b293b69c77093c1ceb Big endian MIPS architecture: Size/MD5 checksum: 3475612 d5ad56a3ed70e47a8da77a82e2736c82 Size/MD5 checksum: 2042408 9595b0545e466f8329b6c41df35bd817 Size/MD5 checksum: 2042232 70e9777c256a8cf0d0682bcc442467eb Little endian MIPS architecture: Size/MD5 checksum: 3474458 5cf03484bfbd5f6c9ea7fa44c87b5e41 Size/MD5 checksum: 2196262 6456cdf36e393a624f6155fb229d0364 Size/MD5 checksum: 2192656 96c8ca1f1a6b7e30ca7b114c075823c8 Size/MD5 checksum: 14928 30ee08d500482dbdea402ef23a52ca6c These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ table/updates main For dpkg-ftp: dists/stable/updates/main Mailing list:This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show` ' and packages.debian.org . A local attacker might capitalize on a weakness in the boundary checks of the mremap() function in the Debian OS kernel, resulting in heightened privileges; applying an update is recommended.. Debian Security Advisory,bounds checking,mremap kernel patch,local attack,security fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 19, 2004 Critical Debian
99

Slackware 8.1: 2004-008-01 Critical: Local Privilege Escalation Fix

New kernels are available for Slackware 8.1 containing a backported fix from a bounds-checking problem in the kernel's mremap() call which could be used by a local attacker to gain root privileges. This fix was previously issued for Slackware . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] Slackware 8.1 kernel security update (SSA:2004-008-01) New kernels are available for Slackware 8.1 containing a backported fix from a bounds-checking problem in the kernel's mremap() call which could be used by a local attacker to gain root privileges. This fix was previously issued for Slackware 9.0, 9.1, and -current (SSA:2004-006-01). Sites running Slackware 8.1 should upgrade to the new kernel. After installing the new kernel, be sure to run 'lilo'. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CVE-CAN-2003-0985 Here are the details from the Slackware 8.1 ChangeLog: +--------------------------+ Thu Jan 8 18:21:27 PST 2004 patches/kernels/*: These are 2.4.18 kernels containing a backported fix for a security problem with the kernel's mremap() function. A local user could exploit this hole to gain root privileges. For more details, see: https://www.cve.org/CVERecord?id=CVE-CAN-2003-0985 After installing the new kernel, be sure to run 'lilo'. (* Security fix *) patches/packages/kernel-ide-2.4.18-i386-5.tgz: Patched mremap(). (* Security fix *) patches/packages/kernel-source-2.4.18-noarch-6.tgz: This is the source code from kernel-source-2.4.18-noarch-5 with the fix for mremap(). (* Security fix *) +--------------------------+ WHERE TO FIND THE NEW PACKAGES: +-----------------------------+ Updated packages for Slackware 8.1: An alternate kernel may be installed. Those are found in this directory: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/kernels/ MD5 SIGNATURES: +-------------+ MD5 signatures may be downloaded from our FTP server: Slackware 8.1packages: ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/CHECKSUMS.md5 To verify authenticity, this file has been signed with the Slackware GPG key (use 'gpg --verify'): ftp://ftp.slackware.com/pub/slackware/slackware-8.1/patches/CHECKSUMS.md5.asc INSTALLATION INSTRUCTIONS: +------------------------+ Use upgradepkg to install the new kernel, kernel-modules, and alsa packages. After installing the kernel-ide package you will need to run lilo ('lilo' at a command prompt) or create a new system boot disk ('makebootdisk'), and reboot. If desired, a kernel from the kernels/ directory may be used instead. For example, to use the kernel in kernels/scsi.s/, you would copy it to the boot directory like this: cd kernels/scsi.s cp bzImage /boot/vmlinuz-scsi.s-2.4.18 Create a symbolic link: ln -sf /boot/vmlinuz-scsi.s-2.4.18 /boot/vmlinuz Then, run 'lilo' or create a new system boot disk and reboot. +-----+ . The recent patch for Debian 9.0 kernel fixes vulnerability related to copy_to_user() allowing local privilege escalation for unprivileged users.. Kernel Update, Local Privilege Escalation, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 09, 2004 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here