Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 455
Alerts This Week
Warning Icon 1 455

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 22 articles for you...
202

openSUSE: 2019:2135-1 Important: rdesktop Denial of Service Fixes

An update that fixes 19 vulnerabilities is now available.. openSUSE Security Update: Security update for rdesktop ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:2135-1 Rating: important References: #1121448 Cross-References: CVE-2018-20174 CVE-2018-20175 CVE-2018-20176 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8794 CVE-2018-8795 CVE-2018-8796 CVE-2018-8797 CVE-2018-8798 CVE-2018-8799 CVE-2018-8800 Affected Products: openSUSE Leap 15.1 openSUSE Backports SLE-15-SP1 ______________________________________________________________________________ An update that fixes 19 vulnerabilities is now available. Description: This update for rdesktop fixes the following issues: rdesktop was updated to 1.8.6: * Fix protocol code handling new licenses rdesktop was updated to 1.8.5: * Add bounds checking to protocol handling in order to fix many security problems when communicating with a malicious server. rdesktop was updated to 1.8.4 (fix for boo#1121448): * Add rdp_protocol_error function that is used in several fixes * Refactor of process_bitmap_updates * Fix possible integer overflow in s_check_rem() on 32bit arch * Fix memory corruption in process_bitmap_data - CVE-2018-8794 * Fix remote code execution in process_bitmap_data - CVE-2018-8795 * Fix remote code execution in process_plane - CVE-2018-8797 * Fix Denial of Service in mcs_recv_connect_response - CVE-2018-20175 * Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175 * Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176 * Fix Denial of Service in sec_recv - CVE-2018-20176 * Fix minor information leak in rdpdr_process -CVE-2018-8791 * Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792 * Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793 * Fix Denial of Service in process_bitmap_data - CVE-2018-8796 * Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798 * Fix Denial of Service in process_secondary_order - CVE-2018-8799 * Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800 * Fix major information leak in ui_clip_handle_data - CVE-2018-20174 * Fix memory corruption in rdp_in_unistr - CVE-2018-20177 * Fix Denial of Service in process_demand_active - CVE-2018-20178 * Fix remote code execution in lspci_process - CVE-2018-20179 * Fix remote code execution in rdpsnddbg_process - CVE-2018-20180 * Fix remote code execution in seamless_process - CVE-2018-20181 * Fix remote code execution in seamless_process_line - CVE-2018-20182 * Fix building against OpenSSL 1.1 - remove obsolete patches * rdesktop-Fix-OpenSSL-1.1-compability-issues.patch * rdesktop-Fix-crash-in-rdssl_cert_to_rkey.patch - update changes file * add missing info about bugzilla 1121448 - Added rdesktop-Fix-decryption.patch Patch from https://github.com/rdesktop/rdesktop/pull/334 to fix connections to VirtualBox. - update to 1.8.6 * Fix protocol code handling new licenses - update to 1.8.5 * Add bounds checking to protocol handling in order to fix many security problems when communicating with a malicious server. - Trim redundant wording from description. - Use %make_install. - update to 1.8.4 (fix for boo#1121448) * Add rdp_protocol_error function that is used in several fixes * Refactor of process_bitmap_updates * Fix possible integer overflow in s_check_rem() on 32bit arch * Fix memory corruption in process_bitmap_data - CVE-2018-8794 * Fix remote code execution in process_bitmap_data - CVE-2018-8795 * Fix remote code execution in process_plane - CVE-2018-8797 * Fix Denial of Service inmcs_recv_connect_response - CVE-2018-20175 * Fix Denial of Service in mcs_parse_domain_params - CVE-2018-20175 * Fix Denial of Service in sec_parse_crypt_info - CVE-2018-20176 * Fix Denial of Service in sec_recv - CVE-2018-20176 * Fix minor information leak in rdpdr_process - CVE-2018-8791 * Fix Denial of Service in cssp_read_tsrequest - CVE-2018-8792 * Fix remote code execution in cssp_read_tsrequest - CVE-2018-8793 * Fix Denial of Service in process_bitmap_data - CVE-2018-8796 * Fix minor information leak in rdpsnd_process_ping - CVE-2018-8798 * Fix Denial of Service in process_secondary_order - CVE-2018-8799 * Fix remote code execution in in ui_clip_handle_data - CVE-2018-8800 * Fix major information leak in ui_clip_handle_data - CVE-2018-20174 * Fix memory corruption in rdp_in_unistr - CVE-2018-20177 * Fix Denial of Service in process_demand_active - CVE-2018-20178 * Fix remote code execution in lspci_process - CVE-2018-20179 * Fix remote code execution in rdpsnddbg_process - CVE-2018-20180 * Fix remote code execution in seamless_process - CVE-2018-20181 * Fix remote code execution in seamless_process_line - CVE-2018-20182 * Fix building against OpenSSL 1.1 Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-2135=1 - openSUSE Backports SLE-15-SP1: zypper in -t patch openSUSE-2019-2135=1 Package List: - openSUSE Leap 15.1 (x86_64): rdesktop-1.8.6-lp151.2.3.1 rdesktop-debuginfo-1.8.6-lp151.2.3.1 rdesktop-debugsource-1.8.6-lp151.2.3.1 - openSUSE Backports SLE-15-SP1 (aarch64 ppc64le s390x x86_64): rdesktop-1.8.6-bp151.2.3.1 References: https://www.suse.com/security/cve/CVE-2018-20174.html https://www.suse.com/security/cve/CVE-2018-20175.html https://www.suse.com/security/cve/CVE-2018-20176.html https://www.suse.com/security/cve/CVE-2018-20177.html https://www.suse.com/security/cve/CVE-2018-20178.html https://www.suse.com/security/cve/CVE-2018-20179.html https://www.suse.com/security/cve/CVE-2018-20180.html https://www.suse.com/security/cve/CVE-2018-20181.html https://www.suse.com/security/cve/CVE-2018-20182.html https://www.suse.com/security/cve/CVE-2018-8791.html https://www.suse.com/security/cve/CVE-2018-8792.html https://www.suse.com/security/cve/CVE-2018-8793.html https://www.suse.com/security/cve/CVE-2018-8794.html https://www.suse.com/security/cve/CVE-2018-8795.html https://www.suse.com/security/cve/CVE-2018-8796.html https://www.suse.com/security/cve/CVE-2018-8797.html https://www.suse.com/security/cve/CVE-2018-8798.html https://www.suse.com/security/cve/CVE-2018-8799.html https://www.suse.com/security/cve/CVE-2018-8800.html https://bugzilla.suse.com/1121448 -- . Essential patch for rdesktop on openSUSE addresses 19 security flaws, highlighting serious remote execution threats.. openSUSE,rdesktop,security update,Denial of Service,remote code execution. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 14, 2019 Important OpenSUSE
203

Mageia: 2020-0365 Moderate: Risk of Information Disclosure in OpenSSL

Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. References: - https://bugs.mageia.org/show_bug.cgi?id=25274 . MGASA-2019-0247 - Updated rdesktop packages fix security vulnerabilities Publication date: 06 Sep 2019 URL: https://advisories.mageia.org/MGASA-2019-0247.html Type: security Affected Mageia releases: 6, 7 Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. References: - https://bugs.mageia.org/show_bug.cgi?id=25274 SRPMS: - 7/core/rdesktop-1.8.6-1.mga7 - 6/core/rdesktop-1.8.6-1.mga6 . Significant vulnerabilities in rdesktop RDP client patched in Mageia's update, crucial exploitation threats mitigated.. Mageia Security Advisory, Rdesktop Update, Denial of Service Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 06, 2019 Important Mageia
89

Fedora 29 rdesktop: FEDORA-2019-a457303ffc Moderate: Buffer Overflow Threat

Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-a457303ffc 2019-09-06 12:57:51.121029 --------------------------------------------------------------------------------Name : rdesktop Product : Fedora 29 Version : 1.8.6 Release : 1.fc29 URL : http://www.rdesktop.org/ Summary : X client for remote desktop into Windows Terminal Server Description : rdesktop is an open source client for Windows NT Terminal Server and Windows 2000 & 2003 Terminal Services, capable of natively speaking Remote Desktop Protocol (RDP) in order to present the user's NT desktop. Unlike Citrix ICA, no server extensions are required. --------------------------------------------------------------------------------Update Information: Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Charles R. Anderson - 1.8.6-1 - Update to 1.8.6 release which fixes a bug in 1.8.5. - 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. * Fri Jul 26 2019 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild * Sat Feb 2 2019 Fedora Release Engineering - 1.8.4-3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_30_Mass_Rebuild * Tue Jan 29 2019 Charles R. Anderson - 1.8.4-2 - Escape macros in comments - 1.8.4 release security fixes rhbz#1670427: CVE-2018-8794 CVE-2018-8795 CVE-2018-8797 CVE-2018-20175 CVE-2018-20176 CVE-2018-8791 CVE-2018-8792 CVE-2018-8793 CVE-2018-8796 CVE-2018-8798 CVE-2018-8799CVE-2018-8800 CVE-2018-20174 CVE-2018-20177 CVE-2018-20178 CVE-2018-20179 CVE-2018-20180 CVE-2018-20181 CVE-2018-20182 * Sat Jan 26 2019 Charles R. Anderson - 1.8.4-1 - Update to 1.8.4 release * Fri Nov 30 2018 Charles R. Anderson - 1.8.4-0.1 - Update to git master * Sat Jul 14 2018 Fedora Release Engineering - 1.8.3-8 - Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild * Fri Feb 9 2018 Fedora Release Engineering - 1.8.3-7 - Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-a457303ffc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The release of rdesktop 1.8.6 addresses critical buffer overflow vulnerabilities, enhancing the security of remote desktop connections in Fedora 29.. Fedora Update, Remote Desktop Security, rdesktop Protocol Fixes. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 06, 2019 Important Fedora
89

Fedora 30: FEDORA-2019-baff775841 Moderate: rdesktop Buffer Overflow

Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-baff775841 2019-09-06 12:30:29.164027 --------------------------------------------------------------------------------Name : rdesktop Product : Fedora 30 Version : 1.8.6 Release : 1.fc30 URL : http://www.rdesktop.org/ Summary : X client for remote desktop into Windows Terminal Server Description : rdesktop is an open source client for Windows NT Terminal Server and Windows 2000 & 2003 Terminal Services, capable of natively speaking Remote Desktop Protocol (RDP) in order to present the user's NT desktop. Unlike Citrix ICA, no server extensions are required. --------------------------------------------------------------------------------Update Information: Update to 1.8.6 release which fixes a bug in 1.8.5. 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. --------------------------------------------------------------------------------ChangeLog: * Fri Aug 16 2019 Charles R. Anderson - 1.8.6-1 - Update to 1.8.6 release which fixes a bug in 1.8.5. - 1.8.5 is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling. * Fri Jul 26 2019 Fedora Release Engineering - 1.8.4-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-baff775841' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . The upgrade to rdesktop version 1.8.6 resolves multiple bugs and security vulnerabilities present in Fedora 30, specifically targeting buffer overflow issues.. rdesktop Update, Fedora Security, Remote Desktop Fix, Buffer Issues. . LinuxSecurity.com Team

Calendar%202 Sep 06, 2019 Fedora
203

Mageia: 2019-0209 Moderate: rdesktop Buffer Overflow and Overrun Issues

This is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling identified by Kaspersky Lab and National Cyber Security Centre. rdesktop will now detect any attempts to access invalid areas and refuse . MGASA-2019-0209 - Updated rdesktop packages fix security issues Publication date: 21 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0209.html Type: security Affected Mageia releases: 6 This is a security release to address various buffer overflow and overrun issues in the rdesktop protocol handling identified by Kaspersky Lab and National Cyber Security Centre. rdesktop will now detect any attempts to access invalid areas and refuse to continue. References: - https://bugs.mageia.org/show_bug.cgi?id=24797 - https://github.com/rdesktop/rdesktop/releases/tag/v1.8.5 SRPMS: - 6/core/rdesktop-1.8.5-1.mga6 . The update MGASA-2021-0412 from Mageia tackles critical vulnerabilities in gedit, improving protection against unauthorized data manipulations.. rdesktop Security Update,Mageia Security Advisory,Buffer Overflow Fix,rdesktop Protocol Issues,Mageia Releases. . LinuxSecurity.com Team

Calendar%202 Jul 21, 2019 Mageia
197

Debian Jessie: DLA-1837-2 Critical rdesktop Regression Fix Released

The update for rdesktop released as 1.8.6-0+deb8u1 introduced a regression which broke RDP protocol negotiation. Updated rdesktop packages are now available to correct this issue. . Package : rdesktop Version : 1.8.6-0+deb8u2 Debian Bug : 930511 The update for rdesktop released as 1.8.6-0+deb8u1 introduced a regression which broke RDP protocol negotiation. Updated rdesktop packages are now available to correct this issue. For Debian 8 "Jessie", this problem has been fixed in version 1.8.6-0+deb8u2. We recommend that you upgrade your rdesktop packages. For the detailed security status of rdesktop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rdesktop Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Jonas Meurer . The recent rdesktop revision addresses a flaw in RDP protocol coordination on Debian. Please update to version 1.8.6-0+deb8u2 immediately.. rdesktop update, Debian security, regression fix, protocol issue, Jessie updates. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 01, 2019 Critical Debian LTS
87

Ubuntu: DSA-4450-1 Urgent: VNC Server Security Vulnerability

Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4473-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso June 28, 2019 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : rdesktop Debian Bug : 930387 Multiple security issues were found in the rdesktop RDP client, which could result in denial of service and the execution of arbitrary code. For the stable distribution (stretch), this problem has been fixed in version 1.8.6-2~deb9u1. We recommend that you upgrade your rdesktop packages. For the detailed security status of rdesktop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rdesktop Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest rdesktop update addresses critical security vulnerabilities that may allow unauthorized code execution and disrupt services, ensuring system safety against threats. Debian Security, Rdesktop Update, Denial Of Service, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 28, 2019 Important Debian
197

Debian 8: DLA-1837-1 Critical: Rdesktop Buffer Overflow Fix

Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code. . Package : rdesktop Version : 1.8.6-0+deb8u1 Debian Bug : 930387 Several security vulnerabilities were discovered in the rdesktop RDP client, which could result in buffer overflows and execution of arbitrary code. For Debian 8 "Jessie", this problem has been fixed in version 1.8.6-0+deb8u1. We recommend that you upgrade your rdesktop packages. For the detailed security status of rdesktop please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rdesktop Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS - -- Jonas Meurer . Enhance rdesktop to address numerous security vulnerabilities, including potential buffer overflow issues and the risk of arbitrary code execution within Debian 8.. rdesktop security update, Debian LTS, buffer overflow fix, security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 25, 2019 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200