Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
100

Ubuntu: 2022:09 Critical: nkitb/nkitserv Remote Execution Vulnerability

Two parts of the nkitb/nkitserv package are vulnerable to security related bugs.. ______________________________________________________________________________ SuSE Security Announcement Package: nkitb/nkitserv Announcement-ID: SuSE-SA:2001:07 Date: Thursday, March 22th, 2001 19.06 MEST Affected SuSE versions: 6.1, 6.2, 6.3, 6.4, 7.0, 7.1 Vulnerability Type: remote denial-of-service Severity (1-10): 4 SuSE default package: yes: in.ftpd, no: timed Other affected systems: all system using in.ftpd (OpenBSD port) or timed Content of this advisory: 1) security vulnerability resolved: timed, in.ftpd problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information Two parts of the nkitb/nkitserv package are vulnerable to security related bugs. in.ftpd(8): A one-byte bufferoverflow was discovered in the OpenBSD port of the FTP daemon in.ftpd(8) several weeks ago. This bug could just be triggered by authenticated users, which have write access. This bug is believed to not be exploitable under Linux. However, we prefer to provide a fixed update package to make sure that the daemon is on the safe side. in.ftpd(8) will be invoked by inetd(8) and is activated by default. timed(8): The time server daemon timed(8), which is started at boot time, tries to synchronize the local host time with the time of other machines on the local area network. A bug in timed(8) was reported by the FreeBSD Security Officer, that could be triggered remotely to crash the time server daemon. For SuSE 6.1-6.4 in.ftpd and timed were part ofnkitb. Users of SuSE 7.0 need to download the nkitserv package for both in.ftpd and timed. The bug in in.ftpd is fixed in SuSE 7.1, so nkitserv for SuSE 7.1 just includes a new version of timed(8). Download the update package from locations desribed below and install the package with the command `rpm -Uhv file.rpm'. The md5sum for each file is in the line below. You can verify the integrity of the rpm files using the command `rpm --checksig --nogpg file.rpm', independently from the md5 signatures below. i386 Intel Platform: SuSE-7.1 c4313f92a36916f0eba0b8837c9c0c81 source rpm: ec452523fa25c8aed962fbd3349d1f3d SuSE-7.0 02772824805c6c4293bd1750d7bda6d3 source rpm: 5d301edc1b1ec9111572815aace33984 SuSE-6.4 842dea179cc449c4af25accf0c3f38ec source rpm: c099e7c1194b7706100453a89433b59c SuSE-6.3 768a636df4731cd8efd181aa2eaf2e60 source rpm: b705425c4c3cb70ebf9cd1345c92104a SuSE-6.2 cbae31148c79c91a1443f79ee1ba34d3 source rpm: d287c01d35d00756ecbf8da04556037c SuSE-6.1 5f45ade69a9e8c2756e671c4a6e3522a source rpm: 62b969c4e666f3ea71b6ce6b31762718 Sparc Platform: SuSE-7.1 142329dcae76a1603c0d84836192e357 source rpm: 5bd9123cecba6ddd42cc965c599f383e SuSE-7.0 07ed33c76c7ae2df5b877003b254944d source rpm: 66ba7b71624f636e24e2d628c8f06e81 AXP Alpha Platform: SuSE-7.0 5fcf177588788eb069bdb69332046d23 source rpm: c27ed3bf0c293eaa77fe5a8fa960e95d SuSE-6.4 385fa60c0c216f1d9e61afd52d37df93 source rpm: 5ba60084740c9be9f89a729e2d21a77c SuSE-6.3 8a9e207a77e3c7f954e8faa91954f7aa source rpm: 53f8a03feacc7fb81b92a726c8e81d21 SuSE-6.1 359a3432f73220cecd42ba0b365d5e06 sourcerpm: e0ccf6395312f9c33518f5f083c9d51f PPC PowerPC Platform: SuSE-7.1 37bf5a963bc93215084b5634e864479c source rpm: c31af637f58d9b43db542657b02bc772 SuSE-7.0 ddc1dcfb94ba90f3cbdf395f89dd3b84 source rpm: 2fa9c58b871248172285a64107e3be7c SuSE-6.4 1dc4c831b5f6bd344ab8f511497b3fa5 source rpm: 5529e5f63e2391ab1669efa0a8c33b57 ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - joe (configuration file vulnerability): The problem has been reported on multiple security-related mailing lists. We are about to provide fixed packages. - The game spaceboom (SVGA shoot'em up) has been found vulnerable to multiple vulnerabilities. As a reaction to these bugs, the spaceboom game has been dropped from the distribution. We recommend to deinstall the game from our 6.x and 7.x distribution by using the command `rpm -e space´, or to remove the suid bit from the file /usr/games/SpaceBoom/SpaceBoom using the command `chmod -s /usr/games/SpaceBoom/SpaceBoom´. (Note: removing the suid bit prevents the game from being used by non-root users and from being reinstalled after removal.) - We are in the process of preparing update packages for the man package which has been found vulnerable to a commandline format string bug. The man command is installed suid man on SuSE systems. When exploited, the bug can be used to install a different man binary to introduce a trojan into the system. As an interim workaround, we recommend to `chmod -s /usr/bin/man´ and ignore the warnings and errors when viewing manpages. - The file browser MidnightCommander (mc) is vulnerable to unwanted program execution. Updates are currently being built. - New RPMs, that fix' a vulnerbility in the eperl package for SuSE6.1-7.1 are currently being built. ______________________________________________________________________________ 3) standard appendix: SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ============================================== SuSE's security contact is . ============================================== ______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. SuSE GmbH makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. . Critical remote execution vulnerabilities in nkitb/nkitserv package require immediate updates in SuSE systems.. remote Denial Of Service, nkitb, nkitserv, SuSE Security, Package Updates. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 22, 2001 Critical SuSE
100

SuSE Linux Security Alert: Serious Risk of Remote Access Vulnerability

It may be possible for an attacker to modify his/her DNS record to execute abitrary machine code as root while connecting to the standard ftp daemon.. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SuSE Security Announcement Package: nkitb < 2000.7.11-0 Date: Fri Jul 14 14:38:37 CEST 2000 Affected SuSE versions: 6.1-6.4 Vulnerability Type: (possible) remote root compromise SuSE default package: yes Other affected systems: all linux systems using this package ______________________________________________________________________________ A security hole was discovered in the package mentioned above. Please update it as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note that we provide this information on an "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. _____________________________________________________________________________ 1. Problem Description The standard ftp server does directly pass untrusted data from a DNS server to the setproctitle() function in a unsecure manner. 2. Impact It may be possible for an attacker to modify his/her DNS record to execute abitrary machine code as root while connecting to the standard ftp daemon. 3. Solution Update the package from our FTP server. ______________________________________________________________________________ Please verify these md5 checksums of the updates before installing: (For SuSE 6.0, please use the 6.1 updates) AXP: 77ee118ac0790b775c08cecf28b3f5c3 5eac90efb3c82a948b7843a8d29b1c65 i386: c85b8c047395f87a61fe7ef1938facd6 /6.1/a1/nkitb-2000.7.11-0.i386.rpm 9fec7f48504f7c4134ac1ae78ee99060 /6.2/a1/nkitb-2000.7.11-0.i386.rpm 34540a50d4a562b02fbb4bc56f23e1b6 118075b7fc295be86b3659bf9b3fa778 /6.4/a1/nkitb-2000.7.11-0.i386.rpm PPC: 9ab22ed85cf0efb875c0c4f8fc878c3d 61608e1f8e8bd4f20d9f47bea6a70740 ______________________________________________________________________________ You can find updates on our ftp-Server: for Intel processors for Alpha processors or try the following web pages for a list of mirrors: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE Our webpage for patches: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE Our webpage for security announcements: SUSE – Open-Source-Lösungen für Enterprise Server und Cloud | SUSE If you want to report vulnerabilities, please contact This email address is being protected from spambots. You need JavaScript enabled to view it. ______________________________________________________________________________ SuSE runs two free security mailing list services to which any interested party may subscribe: suse- This email address is being protected from spambots. You need JavaScript enabled to view it. - moderated and for general/linux/SuSE security discussions. All SuSE security announcements are sent to this list. suse-security- This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe to the list, send a message to: To remove your address from the list, send a message to: Send mail to the following for info and FAQ for this list: _____________________________________________________________________________ This information is provided freely to everyone interested and may be redistributed provided that it is not altered in any way. Type Bits/KeyID Date User ID pub 2048/3D25D3D9 1999/03/06 SuSE Security Team - ------BEGIN PGP PUBLIC KEY BLOCK----- Version:2.6.3i mQENAzbhLQQAAAEIAKAkXHe0lWRBXLpn38hMHy03F0I4Sszmoc8aaKJrhfhyMlOA BqvklPLE2f9UrI4Xc860gH79ZREwAgPt0pi6+SleNFLNcNFAuuHMLQOOsaMFatbz JR9i4m/lf6q929YROu5zB48rBAlcfTm+IBbijaEdnqpwGib45wE/Cfy6FAttBHQh 1Kp+r/jPbf1mYAvljUfHKuvbg8t2EIQz/5yGp+n5trn9pElfQO2cRBq8LFpf1l+U P7EKjFmlOq+Gs/fF98/dP3DfniSd78LQPq5vp8RL8nr/o2i7jkAQ33m4f1wOBWd+ cZovrKXYlXiR+Bf7m2hpZo+/sAzhd7LmAD0l09kABRG0JVN1U0UgU2VjdXJpdHkg VGVhbSA8c2VjdXJpdHlAc3VzZS5kZT6JARUDBRA24S1H5Fiyh7HKPEUBAVcOB/9b yHYji1/+4Xc2GhvXK0FSJN0MGgeXgW47yxDL7gmR4mNgjlIOUHZj0PEpVjWepOJ7 tQS3L9oP6cpj1Fj/XxuLbkp5VCQ61hpt54coQAvYrnT9rtWEGN+xmwejT1WmYmDJ xG+EGBXKr+XP69oIUl1E2JO3rXeklulgjqRKos4cdXKgyjWZ7CP9V9daRXDtje63 Om8gwSdU/nCvhdRIWp/Vwbf7Ia8iZr9OJ5YuQl0DBG4qmGDDrvImgPAFkYFzwlqo choXFQ9y0YVCV41DnR+GYhwl2qBd81T8aXhihEGPIgaw3g8gd8B5o6mPVgl+nJqI BkEYGBusiag2pS6qwznZiQEVAwUQNuEtBHey5gA9JdPZAQFtOAf+KVh939b0J94u v/kpg4xs1LthlhquhbHcKNoVTNspugiC3qMPyvSX4XcBr2PC0cVkS4Z9PY9iCfT+ x9WM96g39dAF+le2CCx7XISk9XXJ4ApEy5g4AuK7NYgAJd39PPbERgWnxjxir9g0 Ix30dS30bW39D+3NPU5Ho9TD/B7UDFvYT5AWHl3MGwo3a1RhTs6sfgL7yQ3U+mvq MkTExZb5mfN1FeaYKMopoI4VpzNVeGxQWIz67VjJHVyUlF20ekOz4kWVgsxkc8G2 saqZd6yv2EwqYTi8BDAduweP33KrQc4KDDommQNDOXxaKOeCoESIdM4p7Esdjq1o L0oixF12Cg==pIeS - ------END PGP PUBLIC KEY BLOCK----- -----BEGIN PGP SIGNATURE----- Version: 2.6.3i Charset: noconv iQEVAwUBOXKe1Hey5gA9JdPZAQGmNwf/Tlpj/I+38kI21SiBAzt+ggX9YRFzCjO6 B6/lPpm5BenPwDDusqs3K1a2y1bn2W30dAyuZiC4cWnmoAT0JE3liP1gqvmt6pXS IY3XfH3qrd6SXpyD9fOfixrGzNTLvzaK+AcOFiZcOBoHXOaLGlmZeS3eu1h8dSwm 3hWoEfVaQuVGCJg/0REnJkD/B+hHCmmld7iMrslbRFvtNCMld/J8UV+aeMwbQUNw tCxzWzfPckuxdUhBqtkMfNIBH/zaEF3U7idtewgrdXo1TkNCQTCD+qPYwHGo8QM9 6Onaev9bhOLi/Znn/gZsP1f2lfbn4StelWSLrNMs80181RRNt9eMCw==nw86 -----END PGP SIGNATURE----- . This bulletin highlights serious vulnerabilities in Ubuntu's pkgb package that may enable unauthorized access. Timely updates and protective measures are vital for system security. SuSE Linux Security,nkitb vulnerability,DNS exploitation,remote root access,software patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 17, 2000 Critical SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here