Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA 1066-1 Critical: phpbb2 Input Flaw Code Execution

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1066-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff May 20th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : phpbb2 Vulnerability : missing input sanitising Problem-Type : local Debian-specific: no CVE ID : CVE-2006-1896 Debian Bug : 365533 It was discovered that phpbb2, a web based bulletin board, does insufficiently sanitise values passed to the "Font Colour 3" setting, which might lead to the execution of injected code by admin users. The old stable distribution (woody) does not contain phpbb2 packages. For the stable distribution (sarge) this problem has been fixed in version 2.0.13+1-6sarge3. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your phpbb2 package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 719 517bf7f4c266f26f3ef9a9be6d7c571f Size/MD5 checksum: 65253 01f4762f95f68fb8c1681ee9d4d6faa1 Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78 Architecture independent components: Size/MD5 checksum: 37594 ab27da20ca8360e5ea735ee02664ecb5 Size/MD5 checksum: 2873158 31ea4f9837234335e35cc42fbc906ec1 Size/MD5 checksum: 525642 702da4887fbdc27a06cc519c9f02363f These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling phpbb2's poor input validation which permits script penetration. Upgrade advisable for all Debian installations.. phpbb2 security, Debian package update, input sanitization, code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 20, 2006 Critical Debian
87

Debian Sarge Advisory DSA 768-1: Critical phpBB2 Cross-Site Scripting Risk

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 768-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze July 27th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : phpbb2 Vulnerability : missing input validation Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-2161 Debian Bug : 317739 A cross-site scripting vulnerability has been detected in phpBB2, a fully featured and skinneable flat webforum software, that allows remote attackers to inject arbitrary web script or HTML via nested tags. The old stable distribution (woody) does not contain phpbb2. For the stable distribution (sarge) this problem has been fixed in version 2.0.13-6sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.0.13-6sarge1. We recommend that you upgrade your phpbb2 packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 783 a2192409bb6c743be83d87529e00ebcc Size/MD5 checksum: 61579 e5a598478e4f01a3e8981b72c1356445 Size/MD5 checksum: 3340445 678d0cb0372e46402a472c510fb90d78 Architecture independent components: Size/MD5 checksum: 36996 9d27f1ba0c529544447be2537a2e427c Size/MD5 checksum: 28683628de633213b53ff0c2029b0b3e28aa847 Size/MD5 checksum: 525020 2e0d83079efc4321532e062a4c746598 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 768-1 http://www.debian.org/security/ Martin Schulze July 27th, 2005 ht. updated, package, --------------------------------------------------------------------------debian. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 27, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here