Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo GLSA 200806-01 High: Mtr Stack-Based Buffer Overflow Threat

A stack-based buffer overflow was found in mtr, possibly resulting in the execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: mtr: Stack-based buffer overflow Date: June 03, 2008 Bugs: #223017 ID: 200806-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A stack-based buffer overflow was found in mtr, possibly resulting in the execution of arbitrary code. Background ========= mtr combines the functionality of the 'traceroute' and 'ping' programs in a single network diagnostic tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-analyzer/mtr < 0.73-r1 > = 0.73-r1 Description ========== Adam Zabrocki reported a boundary error within the split_redraw() function in the file split.c, possibly leading to a stack-based buffer overflow. Impact ===== A remote attacker could use a specially crafted resolved hostname to execute arbitrary code with root privileges. However, it is required that the attacker controls the DNS server used by the victim, and that the "-p" (or "--split") command line option is used. Workaround ========= There is no known workaround at this time. Resolution ========= All mtr users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-analyzer/mtr-0.73-r1" References ========= [ 1 ] CVE-2008-2357 https://www.cve.org/CVERecord?id=CVE-2008-2357 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200806-01 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Delve into the Gentoo Linux GLSA 200806-01 advisory on a critical buffer overflow vulnerability in mtr and identify effective strategies to mitigate potential risks associated with this issue. Gentoo Advisory, Mtr Overflow, High Severity Threat. . LinuxSecurity.com Team

Calendar 2 Jun 03, 2008 Gentoo
89

Fedora Core 4: mtr Update 0.71-0.FC4.1 Critical Network Tool Fix

Updated package.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-226 2006-03-27 ---------------------------------------------------------------------Product : Fedora Core 4 Name : mtr Version : 0.71 Release : 0.FC4.1 Summary : A network diagnostic tool. Description : Mtr is a network diagnostic tool that combines ping and traceroute into one program. Mtr provides two interfaces: an ncurses interface, useful for using Mtr from a telnet session; and a GTK+ interface for X (provided in the mtr-gtk package). ---------------------------------------------------------------------* Mon Mar 27 2006 Miroslav Lichvar - 2:0.71-0.FC4.1 - update to mtr-0.71 (fixes #162029, #165339) ---------------------------------------------------------------------This update can be downloaded from: b068a80943de18fe01fba49403c171b0a9bc7578 SRPMS/mtr-0.71-0.FC4.1.src.rpm 0b2484a42cad4a86fc990e8eb1ca0b5ba8baa07d ppc/mtr-0.71-0.FC4.1.ppc.rpm b74ee64188f42502e4a2c4f6b315cfa4e4a5c44a ppc/mtr-gtk-0.71-0.FC4.1.ppc.rpm 068c211ce3eca9c415281798dc677bcc7255cb2d ppc/debug/mtr-debuginfo-0.71-0.FC4.1.ppc.rpm 34b15276d0d804c823c737a48047325b7503a74c x86_64/mtr-0.71-0.FC4.1.x86_64.rpm 46a57a129920f878f724f7a53ec11e1aae7cdfad x86_64/mtr-gtk-0.71-0.FC4.1.x86_64.rpm 89addcbcdc49de3f1f4087b278ece5fba02894c8 x86_64/debug/mtr-debuginfo-0.71-0.FC4.1.x86_64.rpm e72d434c12ca0f5b20b6451c9d27ca5019e62564 i386/mtr-0.71-0.FC4.1.i386.rpm d9d805adedc81079ca7a20543b3d670c463e3d7a i386/mtr-gtk-0.71-0.FC4.1.i386.rpm d068fa52419b5003b7c314019a5f9eee6a6e83a8 i386/debug/mtr-debuginfo-0.71-0.FC4.1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailinglist This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhancements made to traceroute, a vital utility for diagnosing connectivity problems in Fedora Core 4.. Network Diagnostic Tool, Fedora Core 4, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 27, 2006 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here