Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 6.06 LTS USN-459-2 Critical: PPTP Denial of Service Fix

USN-459-1 fixed vulnerabilities in pptpd. However, a portion of the fix caused a regression in session establishment under Dapper for certain PPTP clients. This update fixes the problem. We apologize for the inconvenience. . =========================================================== Ubuntu Security Notice USN-459-2 May 21, 2007 pptpd vulnerabilities https://bugs.launchpad.net/ubuntu/+source/pptpd/+bug/115448 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: bcrelay 1.2.3-1ubuntu0.2 pptpd 1.2.3-1ubuntu0.2 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: USN-459-1 fixed vulnerabilities in pptpd. However, a portion of the fix caused a regression in session establishment under Dapper for certain PPTP clients. This update fixes the problem. We apologize for the inconvenience. Original advisory details: A flaw was discovered in the PPTP tunnel server. Remote attackers could send a specially crafted packet and disrupt established PPTP tunnels, leading to a denial of service. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 9454 2d77f7325b22f11bc934caae910d6235 Size/MD5: 597 99180d1dd8b3fb5d18f200bcec669beb Size/MD5: 185721 a521e40ca304b0c125cc25f9b9d03324 amd64 architecture (Athlon64, Opteron, EM64T Xeon) Size/MD5: 20470 3f21f2728e3ea23ee38316f5441d6d8d Size/MD5: 56676 b87a21300d9010e1a4bd38dfcc72963d i386 architecture (x86 compatible Intel/AMD) Size/MD5: 19702 79dec9218e4c44ce9ab75ceb609494ff Size/MD5: 54228 0801f14c705396544b024417a9edd53a powerpc architecture (Apple Macintosh G3/G4/G5) Size/MD5: 20368 d2e318aa804d06c3a9fa84f17d0a582c Size/MD5: 58308 52095cfefa517a7e6fa22bdf4d6a148e sparc architecture (Sun SPARC/UltraSPARC) Size/MD5: 20142 61d2f4e9a005ab87646006fc12fe9d72 Size/MD5: 54602 d6ff36cf5d38e0c453941f89559b09f2 . Ubuntu Security Notice USN-459-3 addresses a vulnerability in OpenSSH affecting specific client systems. It is advised to update immediately.. PPTPD Update, Ubuntu Security Advisory, Regression Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 21, 2007 Critical Ubuntu
91

RedHat: 202310-25 Critical: OpenSSH Remote Execution Risk

A vulnerability has been reported in PPTPD which could lead to a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200705-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: PPTPD: Denial of Service attack Date: May 20, 2007 Bugs: #176936 ID: 200705-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been reported in PPTPD which could lead to a Denial of Service. Background ========= PPTPD is a Point-to-Point Tunnelling Protocol Daemon for Linux. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-dialup/pptpd < 1.3.4 > = 1.3.4 Description ========== James Cameron from HP has reported a vulnerability in PPTPD caused by malformed GRE packets. Impact ===== A remote attacker could exploit this vulnerability to cause a Denial of Service on the PPTPD connection. Workaround ========= There is no known workaround at this time. Resolution ========= All PPTPD users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-dialup/pptpd-1.3.4" References ========= [ 1 ] CVE-2007-0244 https://www.cve.org/CVERecord?id=CVE-2007-0244 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200705-18 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance tous. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2007 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . A routine severity alert for Gentoo pertaining to a PPTPD Denial of Service security flaw. Update advised.. PPTPD Security Advisory,Gentoo Denial of Service,PPTPD Threat,Upgrade Recommendation. . LinuxSecurity.com Team

Calendar 2 May 20, 2007 Gentoo
87

Debian 4.0 DSA 1288-1 Critical: pptpd Denial Of Service Attack

It was discovered that the PoPToP Point to Point Tunneling Server contains a programming error, which allows the tear-down of a PPTP connection through a malformed GRE packet, resulting in denial of service.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1288-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff May 8th, 2007 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : pptpd Vulnerability : programming error Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-0244 It was discovered that the PoPToP Point to Point Tunneling Server contains a programming error, which allows the tear-down of a PPTP connection through a malformed GRE packet, resulting in denial of service. The oldstable distribution (sarge) is not affected by this problem. For the stable distribution (etch) this problem has been fixed in version 1.3.0-2etch1. For the unstable distribution (sid) this problem has been fixed in version 1.3.4-1. We recommend that you upgrade your pptpd packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - ------------------------------- Source archives: Size/MD5 checksum: 599 0363621f77d0364e4f58bd834d33b4ad Size/MD5 checksum: 11297 419d853dca942c8a0067f498105cb23e Size/MD5 checksum: 204099 75d494e881f7027f4e60b114163f6b67 Alphaarchitecture: Size/MD5 checksum: 21554 5da1231c95624aebe45151934ada6d8e Size/MD5 checksum: 64740 d6521d5ac703126cc34159150a0e2d52 AMD64 architecture: Size/MD5 checksum: 20428 70a4c0df307f0945aa314f86df7f2702 Size/MD5 checksum: 59290 6bc5e608d384ffbd41405a92e97f647a ARM architecture: Size/MD5 checksum: 20176 d6ce1ef85e3fafdc8cb32d04d6ae98c8 Size/MD5 checksum: 58408 96844eb323113add2816a8f2e8ca1142 HP Precision architecture: Size/MD5 checksum: 21004 912a261ede698514104c8fbc93b1b6bf Size/MD5 checksum: 59894 5c4ca1daa388f43cc7b3972fc76da82a Intel IA-32 architecture: Size/MD5 checksum: 20166 c085606c87a9905a2c72e6dcd7305525 Size/MD5 checksum: 57490 942bd5e1e6e928a841f4d95fd7bf71ee Intel IA-64 architecture: Size/MD5 checksum: 23648 ed22bf531fe2b9711208df4e4e3389c6 Size/MD5 checksum: 74040 c2d7c1c250b89d9403a7c0199f5fae34 Big endian MIPS architecture: Size/MD5 checksum: 20720 798efba0ced288d3833e2e7b18965ca1 Size/MD5 checksum: 59772 7d974663a724e5a3ff9f777ceb6ff839 Little endian MIPS architecture: Size/MD5 checksum: 20858 cd09139e896c5c11e160b6c10833a786 Size/MD5 checksum: 60398 6a36307f4c7b3e13f85969ffb54e0e65 PowerPC architecture: Size/MD5 checksum: 20540 1dca71d4ff863840bfea87c61456f084 Size/MD5 checksum: 61312 1f19e449701c0f8dae0ea3463893b593 IBM S/390 architecture: Size/MD5 checksum: 20490 8c50aa09194d05221750645eccfad15a Size/MD5 checksum: 58254 2c1c0e98d8e7ad0ab85fe0e5374d8dec Sun Sparc architecture: Size/MD5 checksum: 20146 7c4b0159f15c3dd61bc0c3e067a019b1 Size/MD5 checksum: 56976 657c5b4daf375eab89e13259c52e41b7 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A flaw in the pptpd implementation enables exploitation of GRE packets, resulting in service interruption; updates can be obtained for Debian.. pptp denial service,debian fix,pptpd security issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 08, 2007 Critical Debian
91

Gentoo: 202107-14 Critical: pptpd Remote Buffer Overflow Advisory

A buffer overflow has been fixed in pptpd. It is recommended that all Gentoo Linux users who are runningnet-dialup/pptpd upgrade to pptpd-1.1.3.20030409. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200304-08 - - --------------------------------------------------------------------- PACKAGE : pptpd SUMMARY : buffer overflow DATE : 2003-04-28 09:22 UTC EXPLOIT : remote VERSIONS AFFECTED : =pptpd-1.1.3.20030429 CVE : CAN-2003-0213 - - --------------------------------------------------------------------- - From advisory: "PPTP packet header contain 16bit length which specifies the full size of the packet: bytes_this = read(clientFd, packet + bytes_ttl, 2 - bytes_ttl); // ... bytes_ttl += bytes_this; // ... length = htons(*(u_int16_t *) packet); if (length > PPTP_MAX_CTRL_PCKT_SIZE) { // abort } Looks good so far, except: bytes_this = read(clientFd, packet + bytes_ttl, length - bytes_ttl); If given length was 0 or 1, the "length - bytes_ttl" result is -1 or -2, which means that it reads unlimited amount of data from client into "packet", which is a buffer located in stack. The exploitability only depends on if libc allows the size parameter to be larger than SSIZE_MAX bytes. GLIBC does, Solaris and *BSD don't." Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104994375011406&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running net-dialup/pptpd upgrade to pptpd-1.1.3.20030409 as follows: emerge sync emerge pptpd emerge clean . Important security flaw resolved in Gentoo's pptpd. Users must upgrade to the latest version to maintain safety.. Gentoo Security,PPTP Exploit,Remote Buffer Overflow,Linux Security Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 28, 2003 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here