Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 18.04/16.04: USN-4621-1 Moderate: Netqmail Input Handling Issues

netqmail could be made to crash if it received specially crafted input.. =========================================================================Ubuntu Security Notice USN-4621-1 November 05, 2020 netqmail vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: netqmail could be made to crash if it received specially crafted input. Software Description: - netqmail: a secure, reliable, efficient, simple message transfer agent Details: It was discovered that netqmail did not properly handle certain input. Both remote and local attackers could use this vulnerability to cause netqmail to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514, CVE-2005-1515) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this to bypass email address validation. (CVE-2020-3811) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this vulnerability to cause netqmail to disclose sensitive information. (CVE-2020-3812) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: qmail 1.06-6.2~deb10u1build0.18.04.1 Ubuntu 16.04 LTS: qmail 1.06-6.2~deb10u1build0.16.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4621-1 CVE-2005-1513, CVE-2005-1514, CVE-2005-1515, CVE-2020-3811, CVE-2020-3812 Package Information: https://launchpad.net/ubuntu/+source/netqmail/1.06-6.2~deb10u1build0.18.04.1 https://launchpad.net/ubuntu/+source/netqmail/1.06-6.2~deb10u1build0.16.04.1 . The latest Ubuntu Security Notice USN-4621-1 highlights issues in netqmail, which could lead to system instability through speciallydesigned inputs.. netqmail vulnerabilities, email address validation, Ubuntu advisory. . LinuxSecurity.com Team

Calendar 2 Nov 06, 2020 Ubuntu
172

Ubuntu 20.04 LTS: USN-4556-1 Critical: Netqmail Input Issues

netqmail could be made to crash or run programs as any user (except root) if it received specially crafted network traffic.. =========================================================================Ubuntu Security Notice USN-4556-1 September 29, 2020 netqmail vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: netqmail could be made to crash or run programs as any user (except root) if it received specially crafted network traffic. Software Description: - netqmail: a secure, reliable, efficient, simple message transfer agent Details: It was discovered that netqmail did not properly handle certain input. Both remote and local attackers could use this vulnerability to cause netqmail to crash or execute arbitrary code. (CVE-2005-1513, CVE-2005-1514, CVE-2005-1515) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this to bypass email address validation. (CVE-2020-3811) It was discovered that netqmail did not properly handle certain input when validating email addresses. An attacker could use this vulnerability to cause netqmail to disclose sensitive information. (CVE-2020-3812) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: qmail 1.06-6.2~deb10u1build0.20.04.1 qmail-uids-gids 1.06-6.2~deb10u1build0.20.04.1 In general, a standard system update will make all the necessary changes. References: CVE-2005-1513, CVE-2005-1514, CVE-2005-1515, CVE-2020-3811, CVE-2020-3812 Package Information: https://launchpad.net/ubuntu/+source/netqmail/1.06-6.2~deb10u1build0.20.04.1 -- ubuntu-security-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce . Securityissues in netqmail may cause crashes and allow arbitrary code execution on Ubuntu 20.04 LTS. Immediate updates are advised!. netqmail vulnerabilities, arbitrary code execution, Ubuntu 20.04 LTS. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 29, 2020 Critical Ubuntu
91

Gentoo: GLSA-202007-01 Normal: netqmail Multiple Code Execution Issues

Multiple vulnerabilities have been found in netqmail, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202007-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: netqmail: Multiple vulnerabilities Date: July 26, 2020 Bugs: #721566 ID: 202007-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in netqmail, the worst of which could result in the arbitrary execution of code. Background ========= qmail is a secure, reliable, efficient, simple message transfer agent. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 mail-mta/netqmail < 1.06-r13 > = 1.06-r13 Description ========== Multiple vulnerabilities have been discovered in netqmail. Please review the CVE identifiers referenced below for details. Impact ===== In the default configuration, these vulnerabilities are only local. Please review the referenced CVE identifiers for details. Workaround ========= There is no known workaround at this time. Resolution ========= All netqmail users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =mail-mta/netqmail-1.06-r13" References ========= [ 1 ] CVE-2005-1513 https://nvd.nist.gov/vuln/detail/CVE-2005-1513 [ 2 ] CVE-2005-1514 https://nvd.nist.gov/vuln/detail/CVE-2005-1514 [ 3 ] CVE-2005-1515 https://nvd.nist.gov/vuln/detail/CVE-2005-1515 Availability =========== This GLSAand any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202007-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org . License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several security flaws identified in netqmail could potentially enable arbitrary code execution; it's advisable to update for protection.. netqmail vulnerabilities, arbitrary code execution, gentoo advisory, network security. . LinuxSecurity.com Team

Calendar 2 Jul 26, 2020 Gentoo
197

Debian LTS 8: DLA-2234-1 Moderate: Netqmail Denial Of Service

There were several CVE bugs reported against src:netqmail. CVE-2005-1513 . Package : netqmail Version : 1.06-6.2~deb8u1 CVE ID : CVE-2005-1513 CVE-2005-1514 CVE-2005-1515 CVE-2020-3811 CVE-2020-3812 Debian Bug : 961060 There were several CVE bugs reported against src:netqmail. CVE-2005-1513 Integer overflow in the stralloc_readyplus function in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large SMTP request. CVE-2005-1514 commands.c in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SMTP command without a space character, which causes an array to be referenced with a negative index. CVE-2005-1515 Integer signedness error in the qmail_put and substdio_put functions in qmail, when running on 64 bit platforms with a large amount of virtual memory, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large number of SMTP RCPT TO commands. CVE-2020-3811 qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. CVE-2020-3812 qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root and tests for the existence of files in the attacker's home directory, without dropping its privileges first. For Debian 8 "Jessie", these problems have been fixed in version 1.06-6.2~deb8u1. We recommend that you upgrade your netqmail packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at:https://wiki.debian.org/LTS Best, Utkarsh . Netqmail security notice highlighting CVE-2005-1513 and additional concerns for Debian LTS users. Update advised for enhanced security.. netqmail security advisory, Debian update, CVE resolution, software vulnerabilities. . LinuxSecurity.com Team

Calendar 2 Jun 04, 2020 Debian LTS
87

Debian: DSA-4692-1 Critical: netqmail Multiple Issues Detected

Georgi Guninski and the Qualys Research Labs discovered multiple vulnerabilities in qmail (shipped in Debian as netqmail with additional patches) which could result in the execution of arbitrary code, bypass of mail address verification and a local information leak whether a file . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4692-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 24, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : netqmail CVE ID : CVE-2005-1513 CVE-2005-1514 CVE-2005-1515 CVE-2020-3811 CVE-2020-3812 Debian Bug : 961060 Georgi Guninski and the Qualys Research Labs discovered multiple vulnerabilities in qmail (shipped in Debian as netqmail with additional patches) which could result in the execution of arbitrary code, bypass of mail address verification and a local information leak whether a file exists or not. For the oldstable distribution (stretch), these problems have been fixed in version 1.06-6.2~deb9u1. For the stable distribution (buster), these problems have been fixed in version 1.06-6.2~deb10u1. We recommend that you upgrade your netqmail packages. For the detailed security status of netqmail please refer to its security tracker page at: Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The Debian Security Advisory DSA-4693-1 addresses issues in the Apache HTTP Server, which may allow for access control bypass and exposure of sensitive data.. netqmail security update, Debian advisory, mail exploit, code execution, email verification. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 24, 2020 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here