Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
172

Ubuntu 20.04: 6353-1 High: PLIB Arbitrary Code Execution Threat

PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file.. ========================================================================== Ubuntu Security Notice USN-6353-1 September 07, 2023 plib vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS (Available with Ubuntu Pro) - Ubuntu 16.04 LTS (Available with Ubuntu Pro) Summary: PLIB could be made to execute arbitrary code if it opens a specially crafted TGA file. Software Description: - plib: Portability Libraries: Development package Details: Wooseok Kang discovered that PLIB did not properly manage memory under certain circumstances. If a user were tricked into opening a specially crafted TGA file, an attacker could possibly use this issue to cause applications using PLIB to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: libplib1 1.8.5-8ubuntu0.20.04.1 Ubuntu 18.04 LTS (Available with Ubuntu Pro): libplib1 1.8.5-8ubuntu0.18.04.1~esm1 Ubuntu 16.04 LTS (Available with Ubuntu Pro): libplib1 1.8.5-7ubuntu0.1~esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6353-1 CVE-2021-38714 Package Information: https://launchpad.net/ubuntu/+source/plib/1.8.5-8ubuntu0.20.04.1 . Critical vulnerability in the networking stack of Fedora enables remote code execution via maliciously designed BMP images. Ensure your system is updated immediately.. Ubuntu Security, PLIB Exploit, Code Execution Risk. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 07, 2023 Important Ubuntu
89

Fedora 34: FEDORA-2022-2d8e3f9c2b Important: plib Memory Management Patch

Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-1cf3c9578f 2022-05-25 01:28:35.280227 --------------------------------------------------------------------------------Name : plib Product : Fedora 34 Version : 1.8.5 Release : 30.fc34 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) * Fri Jan 21 2022 Fedora Release Engineering - 1.8.5-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild * Fri Jul 23 2021 Fedora Release Engineering - 1.8.5-28 - Rebuilt for https://fedoraproject.org/wiki/Fedora_35_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-1cf3c9578f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the FedoraProject GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Important update issued for CVE-2021-38714 concerning Fedora 34's plib, dealing with vulnerabilities and necessary software enhancements.. Fedora 34, plib, integer overflow fix, software advisory, security updates. . Severity: Important. LinuxSecurity.com Team

Calendar 2 May 24, 2022 Important Fedora
89

Fedora 35 FEDORA-2022-bcc0df5180 Critical: plib Integer Overflow Issue

Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-bcc0df5180 2022-05-25 01:23:53.566442 --------------------------------------------------------------------------------Name : plib Product : Fedora 35 Version : 1.8.5 Release : 30.fc35 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) * Fri Jan 21 2022 Fedora Release Engineering - 1.8.5-29 - Rebuilt for https://fedoraproject.org/wiki/Fedora_36_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-bcc0df5180' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Essential security update for plib in Fedora 35 resolving possible unauthorized code execution due to integer overflow vulnerabilities.. Fedora 35, plib security, security patch, code execution risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 24, 2022 Critical Fedora
89

Fedora 36: 2022-08022e9452 Critical: plib Integer Overflow

Security fix for CVE-2021-38714. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-08022e9452 2022-05-25 01:03:47.532310 --------------------------------------------------------------------------------Name : plib Product : Fedora 36 Version : 1.8.5 Release : 30.fc36 URL : Summary : Set of portable libraries especially useful for games Description : This is a set of OpenSource (LGPL) libraries that will permit programmers to write games and other realtime interactive applications that are 100% portable across a wide range of hardware and operating systems. Here is what you need - it's all free and available with LGPL'ed source code on the web. All of it works well together. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2021-38714 --------------------------------------------------------------------------------ChangeLog: * Fri May 13 2022 Hans de Goede - 1.8.5-30 - Add 3 patches from Debian - Fixes CVE-2021-38714 (rhbz#1997815) --------------------------------------------------------------------------------References: [ 1 ] Bug #1997814 - CVE-2021-38714 plib: integer overflow could lead to arbitrary code execution https://bugzilla.redhat.com/show_bug.cgi?id=1997814 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-08022e9452' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Fedora 36 plib update resolves CVE-2021-38714, correcting integer overflow vulnerabilities and strengthening application security.. Fedora Update, plib Security Fix, Arbitrary Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 24, 2022 Critical Fedora
203

Mageia 8: 2021-0476 Critical Integer Overflow in Plib Packages

Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. References: . MGASA-2021-0476 - Updated plib packages fix security vulnerability Publication date: 13 Oct 2021 URL: https://advisories.mageia.org/MGASA-2021-0476.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-38714 Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. References: - https://bugs.mageia.org/show_bug.cgi?id=29528 - https://lists.debian.org/debian-lts-announce/2021/10/msg00000.html - https://www.cve.org/CVERecord?id=CVE-2021-38714 SRPMS: - 8/core/plib-1.8.5-13.1.mga8 . Integer overflow flaw identified in Mageia's plib libraries may permit execution of arbitrary code. Urgent patch needed.. Mageia Security Update, Integer Overflow, Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 13, 2021 Critical Mageia
197

Debian 9 Stretch DLA-2775-1 Critical: Plib Integer Overflow Risk

One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2775-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Anton Gladky October 02, 2021 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : plib Version : 1.8.5-7+deb9u1 CVE ID : CVE-2021-38714 One security issue has been discovered in plib. Integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file. For Debian 9 stretch, this problem has been fixed in version 1.8.5-7+deb9u1. We recommend that you upgrade your plib packages. For the detailed security status of plib please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/plib Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance plib to address the integer overflow vulnerability that results in unpredictable code execution.. Debian LTS, plib Update, Integer Overflow Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 02, 2021 Critical Debian LTS
202

openSUSE 11.4: 2013:0146-1 Important: Plib Stack Overflow Fix

An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available. An update that fixes two vulnerabilities is now available.. openSUSE Security Update: update for plib ______________________________________________________________________________ Announcement ID: openSUSE-SU-2013:0146-1 Rating: important References: #738207 #787305 Cross-References: CVE-2011-4620 CVE-2012-4552 Affected Products: openSUSE 11.4/standard/i586/patchinfo.11 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update of plib fixed two stack-based buffer overflows. Patch Instructions: To install this openSUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - openSUSE 11.4/standard/i586/patchinfo.11: zypper in -t patch 2012-5 To bring your system up-to-date, use "zypper patch". Package List: - openSUSE 11.4/standard/i586/patchinfo.11 (i586 x86_64): plib-1.8.5-70.1 plib-debuginfo-1.8.5-70.1 plib-debugsource-1.8.5-70.1 plib-devel-1.8.5-70.1 References: https://www.suse.com/security/cve/CVE-2011-4620.html https://www.suse.com/security/cve/CVE-2012-4552.html . The recent release for plib on openSUSE addresses critical stack-related buffer overflow vulnerabilities. Safeguard your system by applying this advisory promptly.. openSUSE Security, Plib Updates, Important Patches. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jan 23, 2013 Important OpenSUSE
87

Debian: DSA-2425-1 Critical: PLIB Buffer Overflow Remote Code Execution

It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2425-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Florian Weimer March 04, 2012 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : plib Vulnerability : buffer overflow Problem type : remote Debian-specific: no CVE ID : CVE-2011-4620 Debian Bug : 654785 It was discovered that PLIB, a library used by TORCS, contains a buffer overflow in error message processing, which could allow remote attackers to execute arbitrary code. For the stable distribution (squeeze), this problem has been fixed in version 1.8.5-5+squeeze1. For the testing distribution (wheezy) and the unstable distribution (sid), this problem has been fixed in version 1.8.5-5.1. We recommend that you upgrade your plib packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A critical vulnerability in PLIB allows remote arbitrary code execution within Debian's TORCS framework. Immediate patching suggested.. Debian Security, PLIB Risk, TORCS Library Flaw, Remote Code Execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 04, 2012 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here