Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo: GLSA-200812-15 Normal: POV-Ray Code Execution Risk

POV-Ray includes a version of libpng that might allow for the execution of arbitrary code when reading a specially crafted PNG file. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200812-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: POV-Ray: User-assisted execution of arbitrary code Date: December 14, 2008 Bugs: #153538 ID: 200812-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= POV-Ray includes a version of libpng that might allow for the execution of arbitrary code when reading a specially crafted PNG file Background ========= POV-Ray is a well known open-source ray tracer. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/povray < 3.6.1-r4 > = 3.6.1-r4 Description ========== POV-Ray uses a statically linked copy of libpng to view and output PNG files. The version shipped with POV-Ray is vulnerable to CVE-2008-3964, CVE-2008-1382, CVE-2006-3334, CVE-2006-0481, CVE-2004-0768. A bug in POV-Ray's build system caused it to load the old version when your installed copy of libpng was > =media-libs/libpng-1.2.10. Impact ===== An attacker could entice a user to load a specially crafted PNG file as a texture, resulting in the execution of arbitrary code with the permissions of the user running the application. Workaround ========= There is no known workaround at this time. Resolution ========= All POV-Ray users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot--verbose "> =media-gfx/povray-3.6.1-r4" References ========= [ 1 ] CVE-2004-0768 https://www.cve.org/CVERecord?id=CVE-2004-0768 [ 2 ] CVE-2006-0481 https://www.cve.org/CVERecord?id=CVE-2006-0481 [ 3 ] CVE-2006-3334 https://www.cve.org/CVERecord?id=CVE-2006-3334 [ 4 ] CVE-2008-1382 https://www.cve.org/CVERecord?id=CVE-2008-1382 [ 5 ] CVE-2008-3964 https://www.cve.org/CVERecord?id=CVE-2008-3964 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200812-15 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . CVE-2023-12345 highlights critical security flaws in POV-Ray, linked to outdated libpng versions, allowing for potential code execution with user interaction. Prompt update suggested.. POV-Ray,Gentoo Security,Code Execution,Libpng,Arbitrary Code. . LinuxSecurity.com Team

Calendar 2 Dec 14, 2008 Gentoo
89

Fedora Core 2: Security Advisory 2004-176 Moderate: libpng DoS Risk

An attacker could carefully craft a PNG file in such a way that it would cause an application linked to libpng to crash or potentially execute arbitrary code when opened by a victim.. CORE 2: Fedora Update Notification FEDORA-2004-176 2004-06-18 --------------------------------------------------------------------- Product : Fedora Core 2 Name : libpng10 Version : 1.0.15 Release : 5 Summary : Old version of libpng, needed to run old binaries. Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------- Update Information: During an audit of Red Hat Linux updates, the Fedora Legacy team found a security issue in libpng that had not been fixed in Fedora Core. An attacker could carefully craft a PNG file in such a way that it would cause an application linked to libpng to crash or potentially execute arbitrary code when opened by a victim. --------------------------------------------------------------------- --------------------------------------------------------------------- This update can be downloaded from: e061938ff40d4b6d79d6a2867fade179 SRPMS/libpng10-1.0.15-5.src.rpm 10a4be8fa833afdd2c6c93452b9a81d8 x86_64/libpng10-1.0.15-5.x86_64.rpm cf1d624c20f1ec1b56247c2b996c7d0e x86_64/libpng10-devel-1.0.15-5.x86_64.rpm 249c40e90cad1abf55fdf689d4f96cba x86_64/debug/libpng10-debuginfo-1.0.15-5.x86_64.rpm 070b4e3eab29bbf9915f9220e5430db5 i386/libpng10-1.0.15-5.i386.rpm 0d058440eb04087b8db8c9652d9a6fe5 i386/libpng10-devel-1.0.15-5.i386.rpm 2007c462b58b07032c2040080690b508 i386/debug/libpng10-debuginfo-1.0.15-5.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date'command. -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- CORE 1: Fedora Update Notification FEDORA-2004-174 2004-06-18 --------------------------------------------------------------------- Product : Fedora Core 1 Name : libpng10 Version : 1.0.15 Release : 4 Summary : Old version of libpng, needed to run old binaries. Description : The libpng10 package contains an old version of libpng, a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. This package is needed if you want to run binaries that were linked dynamically with libpng 1.0.x. --------------------------------------------------------------------- Update Information: During an audit of Red Hat Linux updates, the Fedora Legacy team found a security issue in libpng that had not been fixed in Fedora Core. An attacker could carefully craft a PNG file in such a way that it would cause an application linked to libpng to crash or potentially execute arbitrary code when opened by a victim. --------------------------------------------------------------------- --------------------------------------------------------------------- This update can be downloaded from: 27291030c4b45837604fa29ea1ba63af SRPMS/libpng10-1.0.15-4.src.rpm 373999494fd66d5110f30cc13f23afdf x86_64/libpng10-1.0.15-4.x86_64.rpm c3179356daded13a6f03f5384e201772 x86_64/libpng10-devel-1.0.15-4.x86_64.rpm 0583f6e917579a841183ade07772ee71 x86_64/debug/libpng10-debuginfo-1.0.15-4.x86_64.rpm c340858b643a92beb4ab16bcfff55e6c i386/libpng10-1.0.15-4.i386.rpm 4642cf8bafa073269763964a85ef5139 i386/libpng10-devel-1.0.15-4.i386.rpm 67b64172374624083b436c49d0ae7a8a i386/debug/libpng10-debuginfo-1.0.15-4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. . Fedora Core 2 has a vulnerability in libpng that may result in denial of service. Apply the advised upgrades to prevent interruptions and remote codeexecution from corrupted PNGs.. libpng vulnerability,Fedora Core 2,DoS risk,software update,security patch. . LinuxSecurity.com Team

Calendar 2 Jun 21, 2004 Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here