Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian 3.0: DSA 527-1 Urgent: Pavuk Memory Overflow Vulnerability

An oversized HTTP 305 response sent by a malicious server could cause arbitrary code to be executed with the privileges of the pavuk process.. Debian Security Advisory DSA 527-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman July 3rd, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : pavuk Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE Ids : CAN-2004-0456 Ulf Härnhammar discovered a vulnerability in pavuk, a file retrieval program, whereby an oversized HTTP 305 response sent by a malicious server could cause arbitrary code to be executed with the privileges of the pavuk process. For the current stable distribution (woody), this problem has been fixed in version 0.9pl28-1woody1. pavuk is no longer included in the unstable distribution of Debian. We recommend that you update your pavuk package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 707 8c039288254bd756409cab54b6ca7cfc Size/MD5 checksum: 13610 c824a2921a9791a8d840447062643d0b Size/MD5 checksum: 968336 d0f7b77bd11322add1f7d52d62afbf78 Alpha architecture: Size/MD5 checksum: 630654 9d0d364a20448a4113e07d0e40745d63 ARM architecture: Size/MD5 checksum: 568730 8dcb6be6111bab1194bb70b668659a6a Intel IA-32 architecture: Size/MD5 checksum: 562284 eb47253f87db9ade4748d5e2d01bd701 Intel IA-64 architecture: Size/MD5 checksum: 700588 0a76ba2d4d8aa4db408bf3546a7c4775 HP Precision architecture: Size/MD5 checksum: 608290 5858310a6a9902a6d796c6bbcb527e83 Motorola 680x0 architecture: Size/MD5 checksum: 540248 9b5e9a7d2a98f7aacb5dbefeb2ac5f81 Big endian MIPS architecture: Size/MD5 checksum: 565172 134a4284c713a2faca228ca0086fffd0 Little endian MIPS architecture: Size/MD5 checksum: 560950 ea00112b42beec9797c7cac4125541c7 PowerPC architecture: Size/MD5 checksum: 577756 d6a276f698025c5d2851c0f2d256082f IBM S/390 architecture: Size/MD5 checksum: 556910 3a8f996cc7123dfb8d789ebcfa3b8026 Sun Sparc architecture: Size/MD5 checksum: 573834 f0473eea31b3d870e54649431867c9c4 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian DSA 527-1 issued for pavuk addressing urgent memory overflow risks due to oversized HTTP responses.. Debian Security, Pavuk Exploit, Buffer Overflow Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 08, 2004 Critical Debian
91

Gentoo: 200406-22 High: Pavuk Remote Code Execution Threat

Pavuk contains a bug potentially allowing an attacker to run arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200406-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Pavuk: Remote buffer overflow Date: June 30, 2004 ID: 200406-22 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Pavuk contains a bug potentially allowing an attacker to run arbitrary code. Background ========= Pavuk is web spider and website mirroring tool. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-misc/pavuk = 0.9.28-r2 Description ========== When Pavuk connects to a web server and the server sends back the HTTP status code 305 (Use Proxy), Pavuk copies data from the HTTP Location header in an unsafe manner. Impact ===== An attacker could cause a stack-based buffer overflow which could lead to arbitrary code execution with the rights of the user running Pavuk. Workaround ========= There is no known workaround at this time. All users are encouraged to upgrade to the latest available version. Resolution ========= All Pavuk users should upgrade to the latest stable version: # emerge sync # emerge -pv "> =net-misc/pavuk-0.9.28-r2" # emerge "> ="net-misc/pavuk-0.9.28-r2 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200406-22 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our usersmachines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Technologies, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ . The Gentoo GLSA 200406-24 addresses a critical buffer overrun in the application Avidan, which could permit attackers to execute arbitrary code remotely.. Gentoo Security Advisory, Buffer Overflow, Remote Code Execution, Pavuk, Upgrade. . LinuxSecurity.com Team

Calendar 2 Jun 30, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here