Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 442
Alerts This Week
Warning Icon 1 442

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
98

Red Hat Powertools: RHSA-2002:107-11 Critical: Gaim Buffer Overflow

Updated gaim packages are now available for Red Hat Powertools 7.These updates fix a buffer overflow in the Jabber plug-in module.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated gaim client fixes Jabber plug-in vulnerability (Powertools) Advisory ID: RHSA-2002:107-11 Issue date: 2002-06-04 Updated on: 2002-08-05 Product: Red Hat Powertools Keywords: gaim jabber irc Cross references: RHSA-2002:098 Obsoletes: CVE Names: CAN-2002-0384 --------------------------------------------------------------------- 1. Topic: Updated gaim packages are now available for Red Hat Powertools 7. These updates fix a buffer overflow in the Jabber plug-in module. 2. Relevant releases/architectures: Red Hat Powertools 7.0 - alpha, i386 3. Problem description: Gaim is an instant messaging client written in GTK and is based on the published TOC messaging protocol from AOL. Versions of gaim prior to 0.58 contained a buffer overflow in the Jabber plug-in module. Users of gaim should update to these errata packages containing gaim 0.59 which is not vulnerable to this issue. Please note that gaim version 0.57 had an additional security problem which has been fixed in version 0.58 (CAN-2002-0377), however Red Hat Powertools did not ship with version 0.57 and was not vulnerable to this issue. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red HatNetwork. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 65263 - security issues in gaim 0.57 6. RPMs required: Red Hat Powertools 7.0: SRPMS: alpha: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 6bbebd4e3d3eb89e40def52921c6c064 7.0/en/powertools/SRPMS/gaim-0.59-0.7.0.src.rpm ad0f3b17d7c6e642dd04fb2f8f245fc9 7.0/en/powertools/alpha/gaim-0.59-0.7.0.alpha.rpm 06f4568fc44680bbcf1f171e26897fe6 7.0/en/powertools/i386/gaim-0.59-0.7.0.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: CVE -CVE-2002-0384 Copyright(c) 2000, 2001, 2002 Red Hat, Inc. `. Recent enhancements to gaim on CentOS address significant security vulnerabilities concerning the Jabber feature, which may permit buffer overflow exploits, as outlined in this notice.. Red Hat Powertools, Jabber Plug-in, gaim Update, Critical Security Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Aug 06, 2002 Critical Red Hat
98

Red Hat Powertools 7 RHSA-2002:100-03 Critical: XSS in Mailman

Updated mailman packages are now available for Red Hat Power Tools 7 and7.1. These updates resolve a cross-site scripting vulnerability present inversions of Mailman prior to 2.0.1. `` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated mailman packages available Advisory ID: RHSA-2002:100-03 Issue date: 2002-05-22 Updated on: 2002-06-06 Product: Red Hat Powertools Keywords: mailman cross-site scripting Cross references: RHSA-2002:099 RHSA-2002:101 Obsoletes: --------------------------------------------------------------------- 1. Topic: Updated mailman packages are now available for Red Hat Power Tools 7 and 7.1. These updates resolve a cross-site scripting vulnerability present in versions of Mailman prior to 2.0.1 2. Relevant releases/architectures: Red Hat Powertools 7.0 - alpha, i386 Red Hat Powertools 7.1 - alpha, i386 3. Problem description: Two cross-site scripting vulnerabilities have been discovered in versions of Mailman prior to version 2.0.11. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMsrequired: Red Hat Powertools 7.0: SRPMS: alpha: i386: Red Hat Powertools 7.1: SRPMS: alpha: i386: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- a4b1884a70fbba7789d061c7c74fc238 7.0/en/powertools/SRPMS/mailman-2.0.11-0.7.src.rpm ccb0fb6a094d32dffdf40ec8e6d2a471 7.0/en/powertools/alpha/mailman-2.0.11-0.7.alpha.rpm 837c0a7fb1b96aa44220107d2a6c8da2 7.0/en/powertools/i386/mailman-2.0.11-0.7.i386.rpm 057093443e34f55c7c32a0c499672b5f 7.1/en/powertools/SRPMS/mailman-2.0.11-0.7.1.src.rpm e408809a6ed99cdc6b3289fe71683b4f 7.1/en/powertools/alpha/mailman-2.0.11-0.7.1.alpha.rpm 7741cc4b43b2bca2ed4d6ddc0bbc229e 7.1/en/powertools/i386/mailman-2.0.11-0.7.1.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: [Mailman-Announce] RELEASED Mailman 2.0.11 Copyright(c) 2000, 2001, 2002 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: ``. The Blue Shield Toolkit update resolves a critical CSRF flaw in WordPress versions before 5.5.2. Implement security measures to protect your infrastructure without delay.. Mailman Update, Red Hat Powertools, Security Fix, Software Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 11, 2002 Critical Red Hat
98

Red Hat Powertools 6.2 RHSA-2001:011-03 Critical: XEmacs Buffer Overflow

The XEmacs package as shipped with Red Hat PowerTools 6.2 has a securityproblem with gnuserv and gnuclient, due to a buffer overflow and weaksecurity.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated XEmacs packages available for Red Hat Powertools 6.2 Advisory ID: RHSA-2001:011-03 Issue date: 2001-02-02 Updated on: 2001-02-06 Product: Red Hat Powertools Keywords: xemacs gnuserv gnuclient Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: 2. Relevant releases/architectures: Red Hat Powertools 6.2 - alpha, i386, sparc 3. Problem description: The XEmacs package as shipped with Red Hat PowerTools 6.2 has a security problem with gnuserv and gnuclient, due to a buffer overflow and weak security. Note that this package obsoletes xemacs-mule (this is now compiled into the main binary), xemacs-static, xemacs-extras and xemacs-noX, as this is a backport of a newer xemacs package. 4. Solution: To update all RPMs for your particular architecture, run: rpm -Fvh where is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Powertools 6.2: alpha: i386: sparc: 7. Verification: MD5 sum PackageName -------------------------------------------------------------------------- 963901255ab8377baf92bcc8f3ec30b3 6.2/alpha/xemacs-21.1.14-2.62.alpha.rpm c1fa617399ff85af31c5d31e314249a8 6.2/alpha/xemacs-el-21.1.14-2.62.alpha.rpm e190d32da1a92132d53ee734a93b43cb 6.2/alpha/xemacs-info-21.1.14-2.62.alpha.rpm 661aae1be3097c403df3d38eb5f6ae80 6.2/i386/xemacs-21.1.14-2.62.i386.rpm 03fab61adb2f874f95dfc895e1ede878 6.2/i386/xemacs-el-21.1.14-2.62.i386.rpm bae82e4622a0b4b810eaa690446442b5 6.2/i386/xemacs-info-21.1.14-2.62.i386.rpm 5c4a36734b54ebd3be33e9404bbcb8e6 6.2/sparc/xemacs-21.1.14-2.62.sparc.rpm ef99cb1d6d1d2a0f90f034d4a3a0697f 6.2/sparc/xemacs-el-21.1.14-2.62.sparc.rpm e4a34278881cc1ec29f817bbcfc8f52b 6.2/sparc/xemacs-info-21.1.14-2.62.sparc.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Updated XEmacs patches for Red Hat Powertools 6.2 released to address critical buffer overflow vulnerabilities. Apply patches without delay!. XEmacs Security, Package Update, Buffer Overflow. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 06, 2001 Critical Red Hat
98

CentOS Security Advisory: CESA-2021:0482 Important: Zope Access Control Fix

Vulnerabilities exist with all Zope-2.0 releases.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: Zope update Advisory ID: RHSA-2000:052-02 Issue date: 2000-08-11 Updated on: 2000-08-11 Product: Red Hat Powertools Keywords: Zope Cross references: N/A --------------------------------------------------------------------- 1. Topic: Vulnerabilities exist with all Zope-2.0 releases. 2. Relevant releases/architectures: Red Hat Powertools 6.1 - noarch Red Hat Powertools 6.2 - noarch 3. Problem description: This HotFix corrects issues in the getRoles method of user objects contained in the default UserFolder implementation. Users with the ability to edit DTML could arrange to give themselves extra roles for the duration of a single request by mutating the roles list as a part of the request processing. 4. Solution: Users of Red Hat Powertools 6.1 who have not upgraded Zope to the version of Zope released in Red Hat Powertools 6.2 (2.1.2-5) need to do so prior to installing this Zope update. The Zope packages from 6.2 are located at: Hat/powertools/6.2/ After you have upgraded to Zope-2.1.2-5 install the Zope-Hotfix package. To install the update, use this command: rpm -Uvh Zope-Hotfix-DTML-08_09_2000-1.noarch.rpm Once the Zope-Hotfix package is installed, restart Zope. 5. Bug IDs fixed ( for more info): N/A 6. RPMs required: Red Hat Powertools 6.2: noarch: sources: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- d008c975cec06c552172659ffb14a3a1 6.2/SRPMS/Zope-Hotfix-DTML-08_09_2000-1.src.rpm 61e9f5fed71cbb784f2e1352cb98fb1a 6.2/noarch/Zope-Hotfix-DTML-08_09_2000-1.noarch.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish toverify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000 Red Hat, Inc. `. The guidance issued by Canonical regarding Django security flaws emphasizes essential updates and improvements for developers utilizing Powerstack.. Zope Update, Red Hat Hotfix, Critical Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 12, 2000 Important Red Hat
98

Red Hat Powertools 6.2 RHSA-2000:049-02 High: ntop Remote Access

The version of ntop which was included in Red Hat Powertools 6.2 has aremote exploit in which arbitrary files can be read on the host machine.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: Remote file access vulnerability in ntop Advisory ID: RHSA-2000:049-02 Issue date: 2000-08-07 Updated on: 2000-08-08 Product: Red Hat Powertools Keywords: N/A Cross references: N/A --------------------------------------------------------------------- 1. Topic: The version of ntop which was included in Red Hat Powertools 6.2 has a remote exploit in which arbitrary files can be read on the host machine. 2. Relevant releases/architectures: Red Hat Powertools 6.2 - i386, alpha, sparc 3. Problem description: If ntop is run with the Web interface it allows any user to connect and access all files on the host machine. 4. Solution: For the Alpha architecture please remove ntop by running: rpm -e ntop For Sparc and i386 run: rpm -Fvh [filename] where filename is the name of the RPM. 5. Bug IDs fixed ( for more info): N/A 6. RPMs required: Red Hat Powertools 6.2: sparc: i386: sources: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 8620607a310e28385cfc4961b3c909a9 6.2/SRPMS/ntop-1.3.1-1.src.rpm 188636458d73d66ea6e7d61aec64fc5b 6.2/i386/ntop-1.3.1-1.i386.rpm e6415fc286119023f321ce7e5bdbfce9 6.2/sparc/ntop-1.3.1-1.sparc.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: N/A Copyright(c) 2000 Red Hat, Inc. `. Serious security vulnerability uncovered in ntop for Red HatPowertools 6.2. Urgent advisory actions are advised.. Red Hat Powertools, ntop exploit, remote access exploit. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Aug 08, 2000 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200