Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
98

Red Hat Powertools 7.1 RHSA-2001:061-02 Moderate: Nedit Symlink Issue

nedit creates temporary files in an insecure fashion. This version has been patched to use mkstemp().. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated nedit packages available Advisory ID: RHSA-2001:061-02 Issue date: 2001-04-27 Updated on: 2001-05-08 Product: Red Hat Powertools Keywords: nedit symlink tempfile temporary file Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Updated nedit packages fixing a security problem are available. 2. Relevant releases/architectures: Red Hat Powertools 5.2 - alpha, i386, sparc Red Hat Powertools 6.2 - alpha, i386, sparc Red Hat Powertools 7.0 - alpha, i386 Red Hat Powertools 7.1 - i386 3. Problem description: nedit creates temporary files in an insecure fashion. This version has been patched to use mkstemp(). 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Powertools 5.2: SRPMS: alpha: i386: sparc: Red Hat Powertools 6.2: SRPMS: alpha: i386: sparc: Red Hat Powertools7.0: SRPMS: alpha: i386: Red Hat Powertools 7.1: SRPMS: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 3c6f9f82781ba9ad21fa39a5059de6a6 5.2/en/powertools/SRPMS/nedit-5.1.1-0.5x.1.src.rpm f98e819337e278653b079de923127058 5.2/en/powertools/alpha/nedit-5.1.1-0.5x.1.alpha.rpm 58752b338c12bd277a699c02b3cd14c2 5.2/en/powertools/i386/nedit-5.1.1-0.5x.1.i386.rpm a71ec4cb26527dc38b9b27bb50911a5e 5.2/en/powertools/sparc/nedit-5.1.1-0.5x.1.sparc.rpm 5e9a3a4e1393894a78ed04b465e83a2f 6.2/en/powertools/SRPMS/nedit-5.1.1-0.6x.1.src.rpm a6074bc71a26cd277b779e6ef60eda33 6.2/en/powertools/alpha/nedit-5.1.1-0.6x.1.alpha.rpm 4dbebabde0161af23eb7062fec9371ee 6.2/en/powertools/i386/nedit-5.1.1-0.6x.1.i386.rpm efadb8e39c8ad9c4cbe7474557b0be47 6.2/en/powertools/sparc/nedit-5.1.1-0.6x.1.sparc.rpm cb4ce21be886e969583cbebaea7b9959 7.0/en/powertools/SRPMS/nedit-5.1.1-4.70.1.src.rpm ba2c570e51110ef1ec25713315426369 7.0/en/powertools/alpha/nedit-5.1.1-4.70.1.alpha.rpm 06b17468b8eea63b8fb4e0290cf944e0 7.0/en/powertools/i386/nedit-5.1.1-4.70.1.i386.rpm fce7698e1d33f4a61fb72ad63e19844d 7.1/en/powertools/SRPMS/nedit-5.1.1-6.src.rpm bdf0aea15e167f316edc17532cbad5c9 7.1/en/powertools/i386/nedit-5.1.1-6.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Recently published nedit enhancements for Red Hat fix issues pertaining to temporary file security flaws. It is advisable to apply the latest updates without delay.. Red Hat Powertools,nedit security,temporary file patch. . LinuxSecurity.com Team

Calendar 2 May 08, 2001 Red Hat
87

Debian: DSA-053-1 Critical: Nedit Insecure Temporary File Issue

When printing text it would create a temporary file with the to beprinted text and pass that on to the print system.. ------------------------------------------------------------------------ Debian Security Advisory DSA-053-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman April 27, 2001 ------------------------------------------------------------------------ Package : nedit Problem type : insecure temporary file Debian-specific: no The nedit (Nirvana editor) package as shipped in the non-free section accompanying Debian GNU/Linux 2.2/potato had a bug in its printing code: when printing text it would create a temporary file with the to be printed text and pass that on to the print system. The temporary file was not created safely, which could be exploited by an attacked to make nedit overwrite arbitrary files. This has been fixed in version 5.02-7.1. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 82b90eea8263fd3f6140b40737f1fc16 MD5 checksum: e14d25693dab3e329a93bdca10a45f03 MD5 checksum: 2d8d0a8ec173fde6d574ffef40bbc524 Alpha architecture: MD5 checksum: 18b921a22b20423e1e10ea599f8e98a3 ARM architecture: MD5 checksum: 748d639bc26e810a23fb4911b5a93da0 Intel ia32 architecture: MD5 checksum: 1ad6fee0f55443820817b6a7e702afbf Motorola 680x0 architecture: MD5 checksum: eecbe4dd085e4d3588d1b1e2ce394af7 PowerPC architecture: MD5 checksum: abb9cbbee1abf13ba7d7cbcc16caf07a Sun Sparc architecture: MD5 checksum: cc465ff49985a82cd150fb38f449f75b These packages will be moved into the stable distribution on its next revision. For not yet released architectures please refer tothe appropriate directory . -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Advisory DSA-053-1 highlights that nedit's insecure temporary files may cause file overwriting, risking data integrity; update nedit to the secure version. nedit Insecure File, Debian Security Advisory, File Overwrite Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 26, 2001 Critical Debian
100

SuSE: 2001:15 Moderate: nedit Privilege Escalation Risk

When printing a whole text or selected parts of a text, nedit(1) creates a temporary file in an insecure manner. This behavior could be exploited to gain access to other users privileges, even root.. ______________________________________________________________________________ SuSE Security Announcement Package: nedit Announcement-ID: SuSE-SA:2001:14 Date: Wednesday, April 18th, 2001 13.06 MEST Affected SuSE versions: [6.1, 6.2] 6.3, 6.4, 7.0, 7.1 Vulnerability Type: locoal privilege escalation Severity (1-10): 3 SuSE default package: no Other affected systems: all systems using nedit Content of this advisory: 1) security vulnerability resolved: nedit problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information The Nirvana Editor, NEdit, is a GUI-style text editor based on popular Macintosh and MS Windows editors. When printing a whole text or selected parts of a text, nedit(1) creates a temporary file in an insecure manner. This behavior could be exploited to gain access to other users privileges, even root. There is no workaround possible, because tmpnam(3) ignores the TMPDIR environment variable. Just install the new RPM to fix this problem. Download the update package from locations described below and install the package with the command `rpm -Uhv file.rpm'. The md5sum for each file is in the line below. You can verify the integrity of the rpm files using the command `rpm --checksig --nogpg file.rpm', independently from the md5 signatures below. i386 Intel Platform: SuSE-7.1 07efdf2fa5c475fcf40633d392d4ae1d source rpm: 27e52c3688082257d7f7ecf81c461ad9 SuSE-7.0 b9846658b0f9c8330b8f9c5732b9e115 source rpm: d2dc1c39dbad292326f953e1e84fe187 SuSE-6.4 c5c6eebe946463926583272690ca4d27 source rpm: 0a486fa81f4b84ab6f09bd5353b0fd4d SuSE-6.3 e1e0baeca49ce972df89a5bb5ebfc6c2 source rpm: 9a3328dc8fb8a4da343be20c10cb0c02 Sparc Platform: SuSE-7.1 2370e09571b1037270d34afb555cc408 source rpm: 0ac1364f6b97d503444e6fcb4a0b20df SuSE-7.0 a60e8f47d4ac4794f7ee472ef1d7ccb4 source rpm: 96c96dda6b1ba8b91bebbf3f1a9a56c6 AXP Alpha Platform: SuSE-6.4 cde274f25bec040ae289ef0fb8520b7e source rpm: 4cdff5d4836bf4f926298bb3b3a1c513 SuSE-6.3 fc7fc98267dc76ceec30633068d72533 source rpm: fc3ddc09f7c3383b01721e6462f77748 PPC PowerPC Platform: SuSE-7.1 1f413b9e77263ec37d0e42dde6cb55d1 source rpm: 403bcf64a6ba2824899316e3bd8ea41d SuSE-7.0 e771c3bcd7cbc0121a527089ad40a336 source rpm: f45e0786fefb5c92fbd61e8c4a36ab32 SuSE-6.4 7dcb7bf1110311063daac06df1f7cccb source rpm: 5f1d6da7f268b8c10f7ea8a4f7a1fab5 ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - New RPMs for HylaFax, a Fax Server, are currently being build, which fix a format bug in hfaxd, which could lead to local root privilege. - Updated man RPMs will be available in a few days. - In the past weeks, some security related bugs in the Linux kernel 2.2 and 2.4 were found. An announcement, that addresses this will be released this week. - Samba has serveral security problems, which could lead to local root access. Samba 2.0.8 fixes theseproblems. New RPMs are currently being build. ______________________________________________________________________________ 3) standard appendix: SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ============================================== SuSE's security contact is . ============================================== ______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. SuSE GmbH makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. . A nedit privilege escalation risk has been identified affecting multiple SuSE versions. Immediate action is advised.. Local Privilege Escalation,nedit Vulnerability,SuSE Security Announcement. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 19, 2001 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here