Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
87

Debian: DSA-2063-1 Local Denial Of Service In Pmount Package

Dan Rosenberg discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-2063-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Giuseppe Iuculano June 17, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : pmount Vulnerability : insecure temporary file Problem type : local Debian-specific: no CVE Id : CVE-2010-2192 Dan Rosenberg discovered that pmount, a wrapper around the standard mount program which permits normal users to mount removable devices without a matching /etc/fstab entry, creates files in /var/lock insecurely. A local attacker could overwrite arbitrary files utilising a symlink attack. For the stable distribution (lenny), this problem has been fixed in version 0.9.18-2+lenny1 For the unstable distribution (sid), this problem has been fixed in version 0.9.23-1, and will migrate to the testing distribution (squeeze) shortly. We recommend that you upgrade your pmount package. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 andsparc. Source archives: Size/MD5 checksum: 436009 d04973bde34edac7dd2e50bfe8f10700 Size/MD5 checksum: 1202 d2a121965c3af232694c8df63821d713 Size/MD5 checksum: 8778 96ad2faddf78f80b104a4b9d883507d5 alpha architecture (DEC Alpha) Size/MD5 checksum: 119610 b8734d5a360b76e0c8dc7e7d97ee2f9d amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 117680 5ef3870410e876fbc7bdd0e092f08eef arm architecture (ARM) Size/MD5 checksum: 100718 b04cb703b30df4605d9d121ee2c89c16 armel architecture (ARM EABI) Size/MD5 checksum: 101628 1ecb1c7cc49eda6d31de2165327dac99 hppa architecture (HP PA RISC) Size/MD5 checksum: 113350 189516bd992b63efaa489067cc9f6449 i386 architecture (Intel ia32) Size/MD5 checksum: 102034 5070f1a0a8a9d617c710bc2820bf65e9 ia64 architecture (Intel ia64) Size/MD5 checksum: 133204 747d5be1ca278b8bac08522d72282923 mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 114712 661bf288a4790a6c99f826a9d23ed584 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 115204 e5fc95107322fa23317ac413b9d0dac5 powerpc architecture (PowerPC) Size/MD5 checksum: 124538 684de19e8f8df5ae941849b1b0298e33 s390 architecture (IBM S/390) Size/MD5 checksum: 116318 a80c45d4dbd5a7fb666f4926e5deac59 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 102488 96c8d0f14087b1036c70bd500da2b032 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Enhance your pmount installation to rectify a local denial of service vulnerability on Debian, following guidelines outlined in security notice DSA-2063-1.. DebianSecurity Advisory, Pmount Issue, Local Attack Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Jun 17, 2010 Important Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":552,"type":"x","order":1,"pct":78.63,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.27,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.84,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here