Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
198

Arch Linux: 202011-29 Medium: Musl Arbitrary Code Execution Risk

The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-202011-29 ========================================= Severity: Medium Date : 2020-11-26 CVE-ID : CVE-2020-28928 Package : musl Type : arbitrary code execution Remote : No Link : https://security.archlinux.org/AVG-1287 Summary ====== The package musl before version 1.2.1-2 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.2.1-2. # pacman -Syu "musl> =1.2.1-2" The problem has been fixed upstream but no release is available yet. Workaround ========= None. Description ========== The wcsnrtombs function in all musl libc versions up to 1.2.1 has been found to have multiple bugs in the handling of the destination buffer size when limiting the input character count, which can lead to an infinite loop with no progress (no overflow) or to writing past the end of the destination buffer. Impact ===== An attacker might be able to execute arbitrary code via crafted input content. References ========= https://bugs.archlinux.org/task/68685 https://www.openwall.com/lists/musl/2020/11/19/1 https://security.archlinux.org/CVE-2020-28928 . The musl library on Arch Linux contains a critical security vulnerability that enables arbitrary code execution. Upgrading to the latest version is vital for system protection. Arch Linux, Musl Execution Risk, Security Update. . Severity: Medium. LinuxSecurity.com Team

Calendar 2 Dec 05, 2020 Medium ArchLinux
198

Arch Linux: 201503-26 Critical Advisory for Musl Code Execution

The package musl before version 1.1.8-1 is vulnerable to arbitrary code execution. . Arch Linux Security Advisory ASA-201503-26 ========================================= Severity: Critical Date : 2015-03-31 CVE-ID : CVE-2015-1817 Package : musl Type : arbitrary code execution Remote : No Link : https://wiki.archlinux.org/title/CVE Summary ====== The package musl before version 1.1.8-1 is vulnerable to arbitrary code execution. Resolution ========= Upgrade to 1.1.8-1. # pacman -Syu "musl> =1.1.8-1" The problem has been fixed upstream in version 1.1.8. Workaround ========= None. Description ========== A stack-based buffer overflow has been found in musl libc's ipv6 address literal parsing code. Programs which call the inet_pton or getaddrinfo function with AF_INET6 or AF_UNSPEC and untrusted address strings are affected. Successful exploitation yields control of the return address. Having enabled stack protector at the application level does not mitigate the issue. Impact ===== An attacker can execute arbitrary code by submitting a carefully crafted IPv6 address to a program linked with musl calling inet_pton() or getaddrinfo() with AF_INET6 or AF_UNSPEC. References ========= https://www.openwall.com/lists/musl/2015/03/30/1 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-1817 . Arch Linux Security Announcement ASA-202310-42 Severity: High Date: 2023-10-05 CVE-ID: CVE-2023-4049. Arbitrary Code Execution, Musl Package Update, Arch Linux Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 31, 2015 Critical ArchLinux
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here