Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
203

Mageia 9 MGASA-2024-0036 Critical Quictls Security Threat

The updated packages fix security vulnerabilities: Excessive time spent in DH check / generation with large Q parameter value. (CVE-2023-5678) POLY1305 MAC implementation corrupts vector registers on PowerPC. (CVE-2023-6129) . MGASA-2024-0036 - Updated quictls packages fix security vulnerabilities Publication date: 14 Feb 2024 URL: https://advisories.mageia.org/MGASA-2024-0036.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-5678, CVE-2023-6129, CVE-2023-6237, CVE-2024-0727 The updated packages fix security vulnerabilities: Excessive time spent in DH check / generation with large Q parameter value. (CVE-2023-5678) POLY1305 MAC implementation corrupts vector registers on PowerPC. (CVE-2023-6129) Excessive time spent checking invalid RSA public keys. (CVE-2023-6237) PKCS12 Decoding crashes. (CVE-2024-0727) References: - https://bugs.mageia.org/show_bug.cgi?id=32794 - https://bugs.mageia.org/show_bug.cgi?id=32498 - https://openssl-library.org/news/secadv/20231106.txt - https://openssl-library.org/news/secadv/20240109.txt - https://openssl-library.org/news/secadv/20240115.txt - https://openssl-library.org/news/secadv/20240125.txt - https://www.cve.org/CVERecord?id=CVE-2023-5678 - https://www.cve.org/CVERecord?id=CVE-2023-6129 - https://www.cve.org/CVERecord?id=CVE-2023-6237 - https://www.cve.org/CVERecord?id=CVE-2024-0727 SRPMS: - 9/core/quictls-3.0.12-1.1.mga9 . Recent updates to quictls packages tackle vulnerabilities that lead to prolonged computation durations and problems with vector registers on PowerPC architectures.. Mageia Security Update, Quictls Fix, PowerPC Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 14, 2024 Critical Mageia
89

Fedora Core 5: 2006-297 Moderate: Xorg X11 Buffer Overflow on PowerPC

This update fixes a small buffer overflow that causes crashes on vt switches on powerpc.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-297 2006-04-13 ---------------------------------------------------------------------Product : Fedora Core 5 Name : xorg-x11-server Version : 1.0.1 Release : 9.fc5 Summary : X.Org X11 X server Description : X.Org X11 X server ---------------------------------------------------------------------Update Information: This update fixes a small buffer overflow that causes crashes on vt switches on powerpc. ---------------------------------------------------------------------* Sun Apr 9 2006 Ray Strode - 1.0.1-9.fc5 - Fix small overflow that causes crash on vt switch on ppc. Patch by David Woodhouse (bug 187083). ---------------------------------------------------------------------This update can be downloaded from: fbd32e6d1614398bae4f2843e815414750eea1e3 SRPMS/xorg-x11-server-1.0.1-9.fc5.src.rpm 1afb53923a8b3888151a5b477d188c32f3c4cff9 ppc/xorg-x11-server-Xorg-1.0.1-9.fc5.ppc.rpm ec945ca1ef375fcbe998a832bf3c1ce59761aa25 ppc/xorg-x11-server-Xnest-1.0.1-9.fc5.ppc.rpm f0f31a93b058fc340c54d7365bc60490baae505a ppc/xorg-x11-server-Xdmx-1.0.1-9.fc5.ppc.rpm 46f1d3f2535cc889b74bb9715b8d87b4578c1493 ppc/xorg-x11-server-Xvfb-1.0.1-9.fc5.ppc.rpm ba87a3e59fffeb7f97f8905465bd157b81e1fff9 ppc/xorg-x11-server-sdk-1.0.1-9.fc5.ppc.rpm 927817d0f9ff0848d63d29ceebadf09f1bb96043 ppc/debug/xorg-x11-server-debuginfo-1.0.1-9.fc5.ppc.rpm 3ace0e18373f43615cd144c3b30f55ab0af63730 x86_64/xorg-x11-server-Xorg-1.0.1-9.fc5.x86_64.rpm 78be2c943844b91a05951146fc65821f90a50c68 x86_64/xorg-x11-server-Xnest-1.0.1-9.fc5.x86_64.rpm e47d7f692077cbf9ef5c09590e0612afa071205d x86_64/xorg-x11-server-Xdmx-1.0.1-9.fc5.x86_64.rpm 581277e126d410f5f0bf1ae75f0c6174f46ae33e x86_64/xorg-x11-server-Xvfb-1.0.1-9.fc5.x86_64.rpm 9e2c43767c36759a0eed1fe5caefac9371d4736c x86_64/xorg-x11-server-sdk-1.0.1-9.fc5.x86_64.rpm e1dc18fa309b7120be7982acce7ada62f34c6e25 x86_64/debug/xorg-x11-server-debuginfo-1.0.1-9.fc5.x86_64.rpm 0583f35a6ec525ab9f0fde9278415376fb3a6d2c i386/xorg-x11-server-Xorg-1.0.1-9.fc5.i386.rpm c664d97673fd620b88269c3c6394dabf818efb4c i386/xorg-x11-server-Xnest-1.0.1-9.fc5.i386.rpm 9f0c8c150f7bf35b0689c91c2507d333ef89041a i386/xorg-x11-server-Xdmx-1.0.1-9.fc5.i386.rpm 0d4340119097eebb6ee6ca8cc6f4aa016b132859 i386/xorg-x11-server-Xvfb-1.0.1-9.fc5.i386.rpm 38d068fbf6e69af806dcec0dcae2589600311aa0 i386/xorg-x11-server-sdk-1.0.1-9.fc5.i386.rpm eceac5dfc885126dd599366538a9fb8ffafe5416 i386/debug/xorg-x11-server-debuginfo-1.0.1-9.fc5.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Fedora Core 5 has issued a patch addressing a buffer overflow vulnerability impacting the powerpc architecture during vt switching, enhancing security and stability. Fedora Core, Buffer Overflow, X.Org X Server, PowerPC Update. . LinuxSecurity.com Team

Calendar 2 Apr 13, 2006 Fedora
87

Debian 2.2.x Critical: Local Root Exploit and Upgrade Instructions

This patch corrects a root exploit specifically for the 2.2.x kernel on the PowerPC platform.. Debian Security Advisory DSA 466-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 18th, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : kernel-source-2.2.10, kernel-image-2.2.10-powerpc-apus Vulnerability : failing function and TLB flush Problem-Type : local Debian-specific: no CVE ID : CAN-2004-0077 CERT advisory : VU#981222 Paul Starzetz and Wojciech Purczynski of isec.pl discovered a critical security vulnerability in the memory management code of Linux inside the mremap(2) system call. Due to flushing the TLB (Translation Lookaside Buffer, an address cache) too early it is possible for an attacker to trigger a local root exploit. The attack vectors for 2.4.x and 2.2.x kernels are exclusive for the respective kernel series, though. We formerly believed that the exploitable vulnerability in 2.4.x does not exist in 2.2.x which is still true. However, it turned out that a second (sort of) vulnerability is indeed exploitable in 2.2.x, but not in 2.4.x, with a different exploit, of course. For the stable distribution (woody) this problem has been fixed in version 2.2.10-13woody1 of 2.2 kernel images for the powerpc/apus architecture and in version 2.2.10-2 of Linux 2.2.10 source. For the unstable distribution (sid) this problem will be fixed soon with the 2.4.20 kernel-image package for powerpc/apus. The old 2.2.10 kernel image will be removed from Debian unstable. You are strongly advised to switch to the fixed 2.4.17 kernel-image package for powerpc/apus from woody until the 2.4.20 kernel-image package is fixed in the unstable distribution. We recommend that you upgrade your Linux kernel package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 602 c30270ed0bb5a9b99775aefaff4b5037 Size/MD5 checksum: 13862 b0dec7f7611601b2aab69d2117298641 Size/MD5 checksum: 13902979 e3e865f9103dfcea4a3715d66d89dad1 Size/MD5 checksum: 614 f6f2c6563e5eed7ff97d19551a1117fb Size/MD5 checksum: 453378 865a8125d959621697b045edc210e200 Architecture independent components: Size/MD5 checksum: 866978 74d85ee7a1f5855710b3201b907967dd Size/MD5 checksum: 11302672 7a66220ced59920d2cc50eff7003108f PowerPC architecture: Size/MD5 checksum: 1575772 03558d9d86b2c08194088cf5cece6811 Size/MD5 checksum: 1303764 2a3c5a6a45c3978ae45c4572ddc0547b These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Addressing a significant kernel vulnerability on Debian PowerPC architectures is essential. Updating the kernel ensures vital security enhancements are included. More details follow. Debian Kernel Exploit, Local Root Exploit, PowerPC Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 18, 2004 Critical Debian
87

Debian 2.2 DSA-031-2 Critical: Sudo Buffer Overflow in PowerPC

The most recent advisory covering sudo missed one architecture that was released with 2.2. Therefore this advisory is only an addition to DSA 031-1 and only adds the relevant package for the powerpc architecture.. ---------------------------------------------------------------------------- Debian Security Advisory DSA-031-2 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze March 6, 2001 ---------------------------------------------------------------------------- Package : sudo Vulnerability : buffer overflow Debian-specific: no Todd Miller announced a new version of sudo which corrects a buffer overflow that could potentially be used to gain root privilages on the local system. This bugfix has been backported to the version which was used in Debian GNU/Linux 2.2. The most recent advisory covering sudo missed one architecture that was released with 2.2. Therefore this advisory is only an addition to DSA 031-1 and only adds the relevant package for the powerpc architecture. We recommend you upgrade your sudo packages for powerpc immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. PowerPC architecture: MD5 checksum: aed5d9d437b614ab8495cbafe2d421ac These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . ---------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian addresses a critical buffer overflow risk in sudo affecting PowerPC architecture through advisory DSA-031-2.. Debian Advisory, Buffer Overflow, Sudo Security, PowerPC Architecture, DSA-031-2. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 05, 2001 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here