Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
197

Debian 9 DLA-2683-1 Severe Rxvt Code Execution Vulnerability Alert

rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2683-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta June 09, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : rxvt Version : 1:2.7.10-7+deb9u2 CVE ID : CVE-2017-7483 CVE-2021-33477 Debian Bug : 861694 rxvt, VT102 terminal emulator for the X Window System, allowed (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). For Debian 9 stretch, this problem has been fixed in version 1:2.7.10-7+deb9u2. We recommend that you upgrade your rxvt packages. For the detailed security status of rxvt please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . The Debian LTS Advisory DLA-2683-1 highlights a vulnerability in rxvt concerning its mishandling of escape codes, potentially enabling remote code execution.. Debian Security,Rxvt Terminal,Code Execution Risk. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 09, 2021 Critical Debian LTS
98

Red Hat 6.0 RHSA-1999:014-01 Critical: Secure Package Updates

New dev, rxvt, and screen packages are available that fix a security issue with the packages that originally shipped with Red Hat Linux 6.0. Please read the 'Solution' section for special action needed to complete this upgrade. red hat corp/contact.html . Red Hat, Inc. Security Advisory Package dev, rxvt, screen Synopsis New dev, rxvt, screen packages for Red Hat Linux 6.0 Advisory ID RHSA-1999:014-01 Issue Date 1999-06-15 Keywords dev rxvt screen pts devpts tty 1. Topic: New dev, rxvt, and screen packages are available that fix a security issue with the packages that originally shipped with Red Hat Linux 6.0. Please read the 'Solution' section for special action needed to complete this upgrade. 2. Bug IDs fixed: 2611 3025 3324 3. Relevant releases/architectures: Red Hat Linux 6.0, all architectures 4. Obsoleted by: None 5. Conflicts with: None 6. RPMs required: Intel: dev-2.7.7- 2.i386.rpm rxvt-2.6.0- 2.i386.rpm screen- 3.7.6-9.i386.rpm Alpha: dev-2.7.7- 2.alpha.rpm rxvt-2.6.0- 2.alpha.rpm screen- 3.7.6-9.alpha.rpm SPARC: dev-2.7.7- 2.sparc.rpm rxvt-2.6.0- 2.sparc.rpm screen- 3.7.6-9.sparc.rpm 7. Problem description: The /dev/pts filesystem was mounted with options 'mode=0622' in Red Hat Linux 6.0, instead of the correct 'gid=5,mode=0620'. This could lead to users being able to write to affected ttys. Additionally, once this was corrected, screen and rxvt would still chmod the tty devices to potentially insecure modes. 8. Solution: Upgrade to the latest errata releases of dev, screen and rxvt for Red Hat Linux 6.0 on your particular platform. While the post-install script for the dev package will add the correct permissions for the /dev/pts file system in the /etc/fstab file, you will have to manually unmount and remount the /dev/pts filesystem with the following commands, once the correct permissions have been set in the /etc/fstab file: umount /dev/pts mount /dev/pts If you get the error message "umount: /dev/pts: device is busy" when trying to unmount the filesystem, you will have to close all connections using the filesystem, such as screen, xterm (and other such X terminal programs), and some remote connections. 9. Verification: MD5 sum Package Name ------------------------------------------------------------------------- 34c8c9f6ae3bcb74e63fd67bb785b560 dev-2.7.7-2.i386.rpm 3f0ad6893bdbde6dc9c1a357e555a13b rxvt-2.6.0-2.i386.rpm fc48d9c63ebe02b0fa1741f468f4ccea screen-3.7.6-9.i386.rpm 06777bc610b46490de200cd066c5687b dev-2.7.7-2.alpha.rpm 67bc34923cd2b2a4504fcb14ed735bf8 rxvt-2.6.0-2.alpha.rpm f3c2f2c5867d3bca4a5751fcc8652105 screen-3.7.6-9.alpha.rpm e43914909f7151ef525a6f4b9b1ad461 dev-2.7.7-2.sparc.rpm fe677d3c7d188e204162d4694739639b rxvt-2.6.0-2.sparc.rpm 8e793294d01c9a8f7ded1c563cb0ab92 screen-3.7.6-9.sparc.rpm b25e4de59a00270bb6acd85c8dc901ad dev-2.7.7-2.src.rpm eed32f9b8d67c58d62989758beb7320d rxvt-2.6.0-2.src.rpm f6b51e57e68c9f1e32dd58ef45c76797 screen-3.7.6-9.src.rpm These packages are also PGP signed by Red Hat Inc. for security. Our key is available at: red hat corp/contact.html 10. References: . Bolster system protection through the advancement of secure-shell, terminator, and multiplex packages within Red Hat Linux 6.0 to mitigate potential access risks.. Red Hat Packages, Security Advisory, Linux Updates, Access Control, Linux Compliance. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 03, 2020 Critical Red Hat
99

Slackware 14.2: 2017-121-01 Critical Rxvt Integer Overflow Fix

New rxvt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] rxvt (SSA:2017-121-01) New rxvt packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix a security issue. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/rxvt-2.7.10-i586-5_slack14.2.txz: Rebuilt. Patched an integer overflow that can crash rxvt with an escape sequence, or possibly have unspecified other impact. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-7483 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/rxvt-2.7.10-i486-5_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/rxvt-2.7.10-x86_64-5_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/rxvt-2.7.10-i486-5_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/rxvt-2.7.10-x86_64-5_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/rxvt-2.7.10-i486-5_slack13.37.txz Updated package for Slackware x86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/rxvt-2.7.10-x86_64-5_slack13.37.txz Updated package for Slackware14.0: ftp://ftp.slackware.com/pub/slackware/slackware-14.0/patches/packages/rxvt-2.7.10-i486-5_slack14.0.txz Updated package for Slackware x86_64 14.0: ftp://ftp.slackware.com/pub/slackware/slackware64-14.0/patches/packages/rxvt-2.7.10-x86_64-5_slack14.0.txz Updated package for Slackware 14.1: ftp://ftp.slackware.com/pub/slackware/slackware-14.1/patches/packages/rxvt-2.7.10-i486-5_slack14.1.txz Updated package for Slackware x86_64 14.1: ftp://ftp.slackware.com/pub/slackware/slackware64-14.1/patches/packages/rxvt-2.7.10-x86_64-5_slack14.1.txz Updated package for Slackware 14.2: ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/rxvt-2.7.10-i586-5_slack14.2.txz Updated package for Slackware x86_64 14.2: ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/rxvt-2.7.10-x86_64-5_slack14.2.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: a15c10264ce5765477432de13579b48f rxvt-2.7.10-i486-5_slack13.0.txz Slackware x86_64 13.0 package: f55562b1a1d6fdc15a9a4f2890238f1d rxvt-2.7.10-x86_64-5_slack13.0.txz Slackware 13.1 package: db90840841f04887dabc377259cd36fb rxvt-2.7.10-i486-5_slack13.1.txz Slackware x86_64 13.1 package: 825608858631aa0be24a1f42a1d9b70d rxvt-2.7.10-x86_64-5_slack13.1.txz Slackware 13.37 package: 4b047b92b11a2cd26b6128c14fa56702 rxvt-2.7.10-i486-5_slack13.37.txz Slackware x86_64 13.37 package: f19b7075fbb0e0bbab9f0856307c2735 rxvt-2.7.10-x86_64-5_slack13.37.txz Slackware 14.0 package: 3f1eac3d0b82ae20f291558899970c02 rxvt-2.7.10-i486-5_slack14.0.txz Slackware x86_64 14.0 package: 807e723ab1e3e339570f30a56c81809c rxvt-2.7.10-x86_64-5_slack14.0.txz Slackware 14.1 package: b08b3976772f322e34c37241efa0d92c rxvt-2.7.10-i486-5_slack14.1.txz Slackware x86_64 14.1 package: 883a5e61212c9bd6a501eaa2f26cc537 rxvt-2.7.10-x86_64-5_slack14.1.txz Slackware 14.2 package: 9c911a2d3ce544504001a6126f05ed1e rxvt-2.7.10-i586-5_slack14.2.txz Slackware x86_6414.2 package: 259ddfb7572a413baacc281e951bba9b rxvt-2.7.10-x86_64-5_slack14.2.txz Slackware -current package: 762750b7b19257fa85a5b333ea3ce4af xap/rxvt-2.7.10-i586-5.txz Slackware x86_64 -current package: 1fb40762cda1489ecb04798184d941ed xap/rxvt-2.7.10-x86_64-5.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg rxvt-2.7.10-i586-5_slack14.2.txz +-----+ . Latest rxvt updates have been released for various Slackware editions to tackle a serious integer overflow vulnerability.. Rxvt Security, Slackware Update, Integer Overflow Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 02, 2017 Critical Slackware
91

Gentoo: 200303-20 Important: Xterm Security Update Advisory

There are multiple vulnerabilites in rxvt.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200303-16 - - --------------------------------------------------------------------- PACKAGE : rxvt SUMMARY : dangerous interception of escape sequences DATE : 2003-03-20 09:57 UTC EXPLOIT : remote VERSIONS AFFECTED : =2.7.8-r6 CVE : CAN-2003-0021 CAN-2003-0068 - - --------------------------------------------------------------------- - From advisory: "Many of the features supported by popular terminal emulator software can be abused when un-trusted data is displayed on the screen. The impact of this abuse can range from annoying screen garbage to a complete system compromise. All of the issues below are actually documented features, anyone who takes the time to read over the man pages or source code could use them to carry out an attack." Read the full advisory at: http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 SOLUTION It is recommended that all Gentoo Linux users who are running x11-terms/rxvt upgrade to rxvt-2.7.8-r6 as follows: emerge sync emerge rxvt emerge clean - - --------------------------------------------------------------------- This email address is being protected from spambots. You need JavaScript enabled to view it. - GnuPG key is available at - - --------------------------------------------------------------------- . Upgrade your xterm package to version 1.1.0-r3 to fix significant security flaws affecting Arch Linux. Learn additional information!. Rxvt Security,Gentoo Advisory,Remote Exploitation,Software Vulnerability,Terminal Emulator Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 20, 2003 Important Gentoo
98

Red Hat Linux RHSA-2003:054-00 Critical: Rxvt Escape Sequence Threat

Updated rxvt packages are available which fix a number of vulnerabilities in the handling of escape sequences.. ` --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated rxvt packages fix various vulnerabilites Advisory ID: RHSA-2003:054-00 Issue date: 2003-03-17 Updated on: 2003-03-17 Product: Red Hat Linux Keywords: trojan escape reporting Cross references: Obsoletes: CVE Names: CAN-2003-0022 CAN-2003-0023 CAN-2003-0066 --------------------------------------------------------------------- 1. Topic: Updated rxvt packages are available which fix a number of vulnerabilities in the handling of escape sequences. 2. Relevant releases/architectures: Red Hat Linux 6.2 - i386 Red Hat Linux 7.0 - i386 Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 3. Problem description: Rxvt is a color VT102 terminal emulator for the X Window System. A number of issues have been found in the escape sequence handling of Rxvt. These could be potentially exploited if an attacker can cause carefully crafted escape sequences to be displayed on a rxvt terminal being used by their victim. One of the features which most terminal emulators support is the ability for the shell to set the title of the window using an escape sequence. Certain xterm variants, including rxvt, also provide an escape sequence for reporting the current window title. This essentially takes the current title and places it directly on the command line. Since it is not possible to embed a carriage return into the window title itself, the attacker would have to convince the victim to hit enter for it to process the title as a command, although the attacker can perform a number of actions to increase the likelyhood of this happening. The "screen dump" feature in rxvt 2.7.8 allows attackers to overwrite arbitrary files via a certain character escape sequence when it is echoed to auser's terminal, e.g. when the user views a file containing the malicious sequence. The menuBar feature in rxvt 2.7.8 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the menu. Users of Rxvt are advised to upgrade to these errata packages which contain a patch to disable the title reporting functionality and patches to correct the other issues. Red Hat would like to thank H D Moore for bringing these issues to our attention. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. RPMs required: Red Hat Linux 6.2: SRPMS: i386: Red Hat Linux 7.0: SRPMS: i386: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: 6. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 356e4148537e1e522cdcbedfb735ef80 6.2/en/os/SRPMS/rxvt-2.7.8-3.6.2.1.src.rpm 8ce644f8e66b473ef91ea5baa70066ea 6.2/en/os/i386/rxvt-2.7.8-3.6.2.1.i386.rpm 08bc3ef32e1bc77836dc266af8ef2fa1 7.0/en/os/SRPMS/rxvt-2.7.8-3.7.0.1.src.rpm b93bc19a8403c72943b33779b44b28fe7.0/en/os/i386/rxvt-2.7.8-3.7.0.1.i386.rpm cf99378c595e06eed1ff0c2a493d0472 7.1/en/os/SRPMS/rxvt-2.7.8-3.7.1.1.src.rpm f973a30d1f45f561a1e15d4c58615526 7.1/en/os/i386/rxvt-2.7.8-3.7.1.1.i386.rpm f5b4712eeb3c941b9b5f2cf3ab6d6dc4 7.2/en/os/SRPMS/rxvt-2.7.8-4.src.rpm 94a3cbbf0dbd8739e9b1b2cc716a326e 7.2/en/os/i386/rxvt-2.7.8-4.i386.rpm 781b84624dda1114d74d09814438c54a 7.2/en/os/ia64/rxvt-2.7.8-4.ia64.rpm f5b4712eeb3c941b9b5f2cf3ab6d6dc4 7.3/en/os/SRPMS/rxvt-2.7.8-4.src.rpm 94a3cbbf0dbd8739e9b1b2cc716a326e 7.3/en/os/i386/rxvt-2.7.8-4.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at About You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920 CVE -CVE-2003-0022 CVE -CVE-2003-0023 CVE -CVE-2003-0066 8. Contact: The Red Hat security contact is . More contact details at All Red Hat products Copyright 2003 Red Hat, Inc. _______________________________________________ Red Hat-watch-list mailing list To unsubscribe, visit: `. A security notice concerning recent rxvt updates rectifying various escape sequence vulnerabilities in Red Hat Linux.. Red Hat Linux, Rxvt Terminal Update, Escape Sequence Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 17, 2003 Critical Red Hat
87

Debian 2.2 DSA-062-1 Moderate: rxvt Buffer Overflow Threat

Since rxvt is installed sgid utmp an attacker could use thisto gain utmp which would allow him to modify the utmp file.. ------------------------------------------------------------------------ Debian Security Advisory DSA-062-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman June 16, 2001 ------------------------------------------------------------------------ Package : rxvt Problem type : buffer overflow Debian-specific: no Samuel Dralet reported on bugtraq that version 2.6.2 of rxvt (a VT102 terminal emulator for X) have a buffer overflow in the tt_printf() function. A local user could abuse this making rxvt print a special string using that function, for example by using the -T or -name command-line options. That string would cause a stack overflow and contain code which rxvt will execute. Since rxvt is installed sgid utmp an attacker could use this to gain utmp which would allow him to modify the utmp file. This has been fixed in version 2.6.2-2.1, and we recommend that you upgrade your rxvt package. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 2f0bc5f6be93de9058b70aa798e3107b MD5 checksum: cb15b91b306310b3a14b2530bedb45ce MD5 checksum: f1866fd8d7c6b92d0f5b11ccbe348f73 Alpha architecture: MD5 checksum: ea3b35ff253c79b3a83ecfe837fe0189 MD5 checksum: 4d4bce3b3632b2391ce282c67034d558 ARM architecture: MD5 checksum: 94e13605d75cf071ef22e320c2a841d6 MD5 checksum: 3f45cc0c414874c9065b2c21e174ef3c Intel IA-32 architecture: MD5 checksum: 1d6ad4bcaca88243f83a9cfa0b5d6753 MD5 checksum: 30c7114e67c17a47c4ac8abf15ded74e Motorola 680x0 architecture: MD5 checksum:9fd344e418b551535facc6ae7a9484ba MD5 checksum: bded59c5b4061dab92c907a9df2db259 PowerPC architecture: MD5 checksum: c5f20b67ceb084d1e1226f52a1a8cda1 MD5 checksum: 48566b5a60f937bfd0b1a54ac09dd081 Sun Sparc architecture: MD5 checksum: 29074cfb3a849199500192eca0fc650b MD5 checksum: d501d5de8283d33a1915c0b52dd33c28 These packages will be moved into the stable distribution on its next revision. For not yet released architectures please refer to the appropriate directory . -- ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian's rxvt buffer overflow threat requires immediate attention to prevent unauthorized modifications.. rxvt Terminal, Buffer Overflow Risk, Debian 2.2, Security Advisory. . LinuxSecurity.com Team

Calendar 2 Jun 18, 2001 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here