Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat OpenShift 2.0.6 RHSA-2014:0763-01 Critical Command Injection Issue

An updated rubygem-openshift-origin-node package that fixes one security issue is now available for Red Hat OpenShift Enterprise 2.0.6. The Red Hat Security Response Team has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Critical: rubygem-openshift-origin-node security update Advisory ID: RHSA-2014:0763-01 Product: Red Hat OpenShift Enterprise Advisory URL: https://access.redhat.com/errata/RHSA-2014:0763.html Issue date: 2014-06-18 CVE Names: CVE-2014-3496 ==================================================================== 1. Summary: An updated rubygem-openshift-origin-node package that fixes one security issue is now available for Red Hat OpenShift Enterprise 2.0.6. The Red Hat Security Response Team has rated this update as having Critical security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHOSE Node 2.0 - noarch 3. Description: The rubygem-openshift-origin-node package provides basic OpenShift node functionality. A command injection flaw was found in rubygem-openshift-origin-node. A remote, authenticated user permitted to install cartridges via the web interface could use this flaw to execute arbitrary code with root privileges on the Red Hat OpenShift Enterprise node server. (CVE-2014-3496) This issue was discovered by Jeremy Choi of the Red Hat HSS Pen-test Team. All rubygem-openshift-origin-node users are advised to upgrade to this updated package, which contains a backported patch to correct this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available viathe Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/site/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1110470 - CVE-2014-3496 OpenShift Origin: Command execution as root via downloadable cartridge source-url 6. Package List: RHOSE Node 2.0: Source: rubygem-openshift-origin-node-1.17.5.17-1.el6op.src.rpm noarch: rubygem-openshift-origin-node-1.17.5.17-1.el6op.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/#package 7. References: https://access.redhat.com/security/cve/CVE-2014-3496 https://access.redhat.com/security/updates/classification/#critical 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFTofdhXlSAg2UNWIIRAh9pAJ9AHfCJAyBO5p7TLUT+guMi58LxAACgp96/ 8BQXq/vJk9N2H9HOL8HMQLw=ce4G -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Important alert for rubygem-openshift-origin-node highlights a serious command execution vulnerability, necessitating prompt user intervention.. rubygem-openshift-origin-node, command injection exploit, red hat security advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 18, 2014 Critical Red Hat
87

Ubuntu 4.0 DSA 201-2 Severe: JSON Parsing Vulnerability Exploit

Morgan alias SM6TKY discovered and fixed several security relatedproblems in LinuxNode, an Amateur Packet Radio Node program. Thebuffer overflow he discovered can be used to gain unauthorised rootaccess and can be remotely triggered.. -------------------------------------------------------------------------- Debian Security Advisory DSA 274-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze August 29th, 2003 Debian -- Debian security FAQ -------------------------------------------------------------------------- Package : node Vulnerability : buffer overflow, format string Problem-Type : remote Debian-specific: no Morgan alias SM6TKY discovered and fixed several security related problems in LinuxNode, an Amateur Packet Radio Node program. The buffer overflow he discovered can be used to gain unauthorised root access and can be remotely triggered. For the stable distribution (woody) this problem has been fixed in version 0.3.0a-2woody1. For the unstable distribution (sid) this problem has been fixed in version 0.3.2-1. We recommend that you upgrade your node packages immediately. Upgrade Instructions -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 588 1efa176d975c1e05370f8ba964516797 Size/MD5 checksum: 6480 188fb0de8bf4e0befe24381e0dae20de Size/MD5 checksum: 53547 8aff48a8744aa6ee6eaf1daa7c3b92f8 Alpha architecture: Size/MD5 checksum: 64240520c82abc8809f56870724351ed6de39 ARM architecture: Size/MD5 checksum: 47708 7f7955e0159549de75ec925f2237b7c9 Intel IA-32 architecture: Size/MD5 checksum: 47484 dbf928e7f52f5194fea6a03d2d3fdf01 Intel IA-64 architecture: Size/MD5 checksum: 67634 71cc9de2aa3c9ad0145ff0aa3e0a29b3 HP Precision architecture: Size/MD5 checksum: 52174 57c6db7ca08a02988fc0fb2b8bbe23eb Motorola 680x0 architecture: Size/MD5 checksum: 45790 7089cd0cb435322faed03e167a6e7dc7 Big endian MIPS architecture: Size/MD5 checksum: 52166 c6918f854b286a0b1fe46c1a4a2e0853 Little endian MIPS architecture: Size/MD5 checksum: 52240 3e214a4217e6fee4c7aa32f84770c02a PowerPC architecture: Size/MD5 checksum: 49514 a599cf448a4c2bc3618aa0a404742c3f IBM S/390 architecture: Size/MD5 checksum: 48998 7cc2ae72a9c975d78be45cd82f115116 Sun Sparc architecture: Size/MD5 checksum: 49524 e086b527ec73a28d9ac2109249c71691 These files will probably be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Addressing critical data integrity vulnerability in Debian Node software. Implement updates immediately to boost protection.. Debian Node, Buffer Overflow, Critical Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 29, 2003 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here