The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet. (CVE-2023-1801) References: . MGASA-2023-0154 - Updated tcpdump packages fix security vulnerability Publication date: 24 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0154.html Type: security Affected Mageia releases: 8 CVE: CVE-2023-1801 The SMB protocol decoder in tcpdump version 4.99.3 can perform an out-of-bounds write when decoding a crafted network packet. (CVE-2023-1801) References: - https://bugs.mageia.org/show_bug.cgi?id=31782 - - https://www.cve.org/CVERecord?id=CVE-2023-1801 SRPMS: - 8/core/tcpdump-4.99.2-1.1.mga8 . Mageia 2023-0155 addresses a vulnerability in Wireshark's DNS protocol handler that involves an improper input validation error. Discover the details!. Network Security, Tcpdump Update, Mageia Advisory, Security Fixes. . Severity: Critical. LinuxSecurity.com Team
Moderate: qemu-kvm security fix update. Date: Tue, 15 Sep 2015 19:26:04 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Moderate: qemu-kvm on SL7.x x86_64 MIME-Version: 1.0 Message-ID: Synopsis: Moderate: qemu-kvm security fix update Advisory ID: SLSA-2015:1793-1 Issue Date: 2015-09-15 CVE Numbers: CVE-2015-5165 -- An information leak flaw was found in the way QEMU's RTL8139 emulation implementation processed network packets under RTL8139 controller's C+ mode of operation. An unprivileged guest user could use this flaw to read up to 65 KB of uninitialized QEMU heap memory. (CVE-2015-5165) After installing this update, shut down all running virtual machines. Once all virtual machines have shut down, start them again for this update to take effect. -- SL7 x86_64 libcacard-1.5.3-86.el7_1.6.i686.rpm libcacard-1.5.3-86.el7_1.6.x86_64.rpm qemu-img-1.5.3-86.el7_1.6.x86_64.rpm qemu-kvm-1.5.3-86.el7_1.6.x86_64.rpm qemu-kvm-common-1.5.3-86.el7_1.6.x86_64.rpm qemu-kvm-debuginfo-1.5.3-86.el7_1.6.i686.rpm qemu-kvm-debuginfo-1.5.3-86.el7_1.6.x86_64.rpm qemu-kvm-tools-1.5.3-86.el7_1.6.x86_64.rpm libcacard-devel-1.5.3-86.el7_1.6.i686.rpm libcacard-devel-1.5.3-86.el7_1.6.x86_64.rpm libcacard-tools-1.5.3-86.el7_1.6.x86_64.rpm - Scientific Linux Development Team . Scientific Linux users should take note of a new security advisory for qemu-kvm. A moderate fix is available to remedy a potential information leak, so update your systems to stay secure. qemu-kvm Update, Scientific Linux Security, Information Leak Fix, Security Advisory. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.