Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
203

Mageia 8: 2023-0015 Critical: Net-SNMP Denial Of Service

handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. (CVE-2022-44792) . MGASA-2023-0015 - Updated net-snmp packages fix security vulnerability Publication date: 24 Jan 2023 URL: https://advisories.mageia.org/MGASA-2023-0015.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-44792, CVE-2022-44793 handle_ipDefaultTTL in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.8 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker (who has write access) to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. (CVE-2022-44792) handle_ipv6IpForwarding in agent/mibgroup/ip-mib/ip_scalars.c in Net-SNMP 5.4.3 through 5.9.3 has a NULL Pointer Exception bug that can be used by a remote attacker to cause the instance to crash via a crafted UDP packet, resulting in Denial of Service. (CVE-2022-44793) References: - https://bugs.mageia.org/show_bug.cgi?id=31388 - https://ubuntu.com/security/notices/USN-5795-1 - https://www.cve.org/CVERecord?id=CVE-2022-44792 - https://www.cve.org/CVERecord?id=CVE-2022-44793 SRPMS: - 8/core/net-snmp-5.9-1.2.mga8 . Updated net-snmp packages address a severe NULL Pointer Exception issue that can lead to Denial of Service vulnerabilities in Mageia.. Mageia Security, Net-SNMP Update, UDP Threat, NULL Pointer Error. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 24, 2023 Critical Mageia
87

Debian Buster: DSA-4714-3 Moderate: Chromium Service Worker Flaw

The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4714-3 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Michael Gilbert July 13, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : chromium Debian Bug : 963548 The previous update for chromium released as DSA 4714-2 contained a flaw in the service worker implementation. This problem causes the browser to crash when a connection error occurs. Updated chromium packages are now available that correct this issue. For the stable distribution (buster), this problem has been fixed in version 83.0.4103.116-1~deb10u3. We recommend that you upgrade your chromium packages. For the detailed security status of chromium please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/chromium Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Newly released chromium updates address service worker issues leading to system crashes on Debian Buster.. Debian Chromium Update, Service Worker Issue, Security Fixes. . LinuxSecurity.com Team

Calendar 2 Jul 13, 2020 Debian
89

Fedora 27: Security Advisory for Community-MySQL Critical Flaws

A quarter year regular dose of fixed CVE's. https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-20.html . rhbz#1497694: Fix owner and perms on log file in post script CVE fixes: rhbz#1503701 CVE-2017-10155 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276 CVE-2017-10279 CVE-2017-10283 CVE-2017-10286 CVE-2017-10294 CVE-2017-10314. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-9e28c78e07 2017-11-11 13:29:22.452704 --------------------------------------------------------------------------------Name : community-mysql Product : Fedora 27 Version : 5.7.20 Release : 1.fc27 URL : https://www.mysql.com/ Summary : MySQL client programs and shared libraries Description : MySQL is a multi-user, multi-threaded SQL database server. MySQL is a client/server implementation consisting of a server daemon (mysqld) and many different client programs and libraries. The base package contains the standard MySQL client programs and generic MySQL files. --------------------------------------------------------------------------------Update Information: A quarter year regular dose of fixed CVE's. https://dev.mysql.com/doc/relnotes/mysql/5.7/en/news-5-7-20.html . rhbz#1497694: Fix owner and perms on log file in post script CVE fixes: rhbz#1503701 CVE-2017-10155 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276 CVE-2017-10279 CVE-2017-10283 CVE-2017-10286 CVE-2017-10294 CVE-2017-10314 CVE-2017-10378 CVE-2017-10379 CVE-2017-10384 Others: Move all test binaries to -test package Dont ship unneeded man pages on systemd platforms Remove mysql_config_editor from -devel package, shipped in client --------------------------------------------------------------------------------References: [ 1 ] Bug #1503701 - CVE-2017-10155 CVE-2017-10227 CVE-2017-10268 CVE-2017-10276 CVE-2017-10279 CVE-2017-10283 CVE-2017-10286 CVE-2017-10294 CVE-2017-10314 CVE-2017-10378 CVE-2017-10379CVE-2017-10384 community-mysql: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1503701 [ 2 ] Bug #1497694 - mysqld service not working by default after bd72127 https://bugzilla.redhat.com/show_bug.cgi?id=1497694 [ 3 ] Bug #1503357 - community-mysql-5.7.20 is available https://bugzilla.redhat.com/show_bug.cgi?id=1503357 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade community-mysql' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Recent community-mysql updates in Fedora 27 introduce vital security enhancements, addressing vulnerabilities to protect users from exploits and unauthorized access. Fedora Security, MySQL Patch, Community Update, Service Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 11, 2017 Critical Fedora
98

Red Hat: RHSA-2013-0942-01 Moderate: krb5 Authentication Service Flaw

Updated krb5 packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: krb5 security update Advisory ID: RHSA-2013:0942-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2013:0942.html Issue date: 2013-06-12 CVE Names: CVE-2002-2443 ==================================================================== 1. Summary: Updated krb5 packages that fix one security issue are now available for Red Hat Enterprise Linux 5 and 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: RHEL Desktop Workstation (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node (v. 6) - x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: Kerberos is a network authentication system which allows clients and servers to authenticate to each other using symmetric encryption and a trusted third-party, the Key Distribution Center (KDC). It was found that kadmind's kpasswd service did not perform any validation on incoming network packets, causing it to reply toall requests. A remote attacker could use this flaw to send spoofed packets to a kpasswd service that appear to come from kadmind on a different server, causing the services to keep replying packets to each other, consuming network bandwidth and CPU. (CVE-2002-2443) All krb5 users should upgrade to these updated packages, which contain a backported patch to correct this issue. After installing the updated packages, the krb5kdc and kadmind daemons will be restarted automatically. 4. Solution: Before applying this update, make sure all previously-released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (http://bugzilla.redhat.com/): 962531 - CVE-2002-2443 krb5: UDP ping-pong flaw in kpasswd 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-workstation-1.6.1-70.el5_9.2.i386.rpm x86_64: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.x86_64.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.x86_64.rpm krb5-workstation-1.6.1-70.el5_9.2.x86_64.rpm RHEL Desktop Workstation (v. 5 client): Source: i386: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-server-1.6.1-70.el5_9.2.i386.rpm krb5-server-ldap-1.6.1-70.el5_9.2.i386.rpm x86_64: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.x86_64.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-ldap-1.6.1-70.el5_9.2.x86_64.rpm Red Hat Enterprise Linux (v. 5server): Source: i386: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-server-1.6.1-70.el5_9.2.i386.rpm krb5-server-ldap-1.6.1-70.el5_9.2.i386.rpm krb5-workstation-1.6.1-70.el5_9.2.i386.rpm ia64: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.ia64.rpm krb5-devel-1.6.1-70.el5_9.2.ia64.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.ia64.rpm krb5-server-1.6.1-70.el5_9.2.ia64.rpm krb5-server-ldap-1.6.1-70.el5_9.2.ia64.rpm krb5-workstation-1.6.1-70.el5_9.2.ia64.rpm ppc: krb5-debuginfo-1.6.1-70.el5_9.2.ppc.rpm krb5-debuginfo-1.6.1-70.el5_9.2.ppc64.rpm krb5-devel-1.6.1-70.el5_9.2.ppc.rpm krb5-devel-1.6.1-70.el5_9.2.ppc64.rpm krb5-libs-1.6.1-70.el5_9.2.ppc.rpm krb5-libs-1.6.1-70.el5_9.2.ppc64.rpm krb5-server-1.6.1-70.el5_9.2.ppc.rpm krb5-server-ldap-1.6.1-70.el5_9.2.ppc.rpm krb5-workstation-1.6.1-70.el5_9.2.ppc.rpm s390x: krb5-debuginfo-1.6.1-70.el5_9.2.s390.rpm krb5-debuginfo-1.6.1-70.el5_9.2.s390x.rpm krb5-devel-1.6.1-70.el5_9.2.s390.rpm krb5-devel-1.6.1-70.el5_9.2.s390x.rpm krb5-libs-1.6.1-70.el5_9.2.s390.rpm krb5-libs-1.6.1-70.el5_9.2.s390x.rpm krb5-server-1.6.1-70.el5_9.2.s390x.rpm krb5-server-ldap-1.6.1-70.el5_9.2.s390x.rpm krb5-workstation-1.6.1-70.el5_9.2.s390x.rpm x86_64: krb5-debuginfo-1.6.1-70.el5_9.2.i386.rpm krb5-debuginfo-1.6.1-70.el5_9.2.x86_64.rpm krb5-devel-1.6.1-70.el5_9.2.i386.rpm krb5-devel-1.6.1-70.el5_9.2.x86_64.rpm krb5-libs-1.6.1-70.el5_9.2.i386.rpm krb5-libs-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-1.6.1-70.el5_9.2.x86_64.rpm krb5-server-ldap-1.6.1-70.el5_9.2.x86_64.rpm krb5-workstation-1.6.1-70.el5_9.2.x86_64.rpm Red Hat Enterprise Linux Desktop (v.6): Source: i386: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.i686.rpm krb5-workstation-1.10.3-10.el6_4.3.i686.rpm x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-server-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm Red Hat Enterprise Linux HPC Node (v. 6): Source: x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.i686.rpm krb5-server-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-workstation-1.10.3-10.el6_4.3.i686.rpm ppc64: krb5-debuginfo-1.10.3-10.el6_4.3.ppc.rpm krb5-debuginfo-1.10.3-10.el6_4.3.ppc64.rpm krb5-devel-1.10.3-10.el6_4.3.ppc.rpm krb5-devel-1.10.3-10.el6_4.3.ppc64.rpm krb5-libs-1.10.3-10.el6_4.3.ppc.rpm krb5-libs-1.10.3-10.el6_4.3.ppc64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.ppc64.rpm krb5-server-1.10.3-10.el6_4.3.ppc64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.ppc.rpm krb5-server-ldap-1.10.3-10.el6_4.3.ppc64.rpm krb5-workstation-1.10.3-10.el6_4.3.ppc64.rpm s390x: krb5-debuginfo-1.10.3-10.el6_4.3.s390.rpm krb5-debuginfo-1.10.3-10.el6_4.3.s390x.rpm krb5-devel-1.10.3-10.el6_4.3.s390.rpm krb5-devel-1.10.3-10.el6_4.3.s390x.rpm krb5-libs-1.10.3-10.el6_4.3.s390.rpm krb5-libs-1.10.3-10.el6_4.3.s390x.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.s390x.rpm krb5-server-1.10.3-10.el6_4.3.s390x.rpm krb5-server-ldap-1.10.3-10.el6_4.3.s390.rpm krb5-server-ldap-1.10.3-10.el6_4.3.s390x.rpm krb5-workstation-1.10.3-10.el6_4.3.s390x.rpm x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm Red Hat Enterprise Linux Workstation (v.6): Source: i386: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.i686.rpm krb5-server-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-workstation-1.10.3-10.el6_4.3.i686.rpm x86_64: krb5-debuginfo-1.10.3-10.el6_4.3.i686.rpm krb5-debuginfo-1.10.3-10.el6_4.3.x86_64.rpm krb5-devel-1.10.3-10.el6_4.3.i686.rpm krb5-devel-1.10.3-10.el6_4.3.x86_64.rpm krb5-libs-1.10.3-10.el6_4.3.i686.rpm krb5-libs-1.10.3-10.el6_4.3.x86_64.rpm krb5-pkinit-openssl-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-1.10.3-10.el6_4.3.x86_64.rpm krb5-server-ldap-1.10.3-10.el6_4.3.i686.rpm krb5-server-ldap-1.10.3-10.el6_4.3.x86_64.rpm krb5-workstation-1.10.3-10.el6_4.3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2002-2443 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2013 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4 (GNU/Linux) iD8DBQFRuKhxXlSAg2UNWIIRAuEZAJ9YgFoyhp++XuH+PFVXD9/8MupERACgs2eM AUTouQ1hh+B4Rsoskma2QtM=2IZt -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Keep informed about Red Hat's announcement regarding a krb5 security patch addressing a critical vulnerability impacting corporate Linux customers.. krb5 update, Red Hat advisory, network security. . LinuxSecurity.com Team

Calendar 2 Jun 12, 2013 Red Hat
98

Red Hat: RHSA-2011:1102-01 Moderate: libsoup Directory Traversal Flaw

Updated libsoup packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate [More...]. ==================================================================== Red Hat Security Advisory Synopsis: Moderate: libsoup security update Advisory ID: RHSA-2011:1102-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2011:1102.html Issue date: 2011-07-28 CVE Names: CVE-2011-2524 ==================================================================== 1. Summary: Updated libsoup packages that fix one security issue are now available for Red Hat Enterprise Linux 6. The Red Hat Security Response Team has rated this update as having moderate security impact. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available from the CVE link in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 6) - i386, x86_64 Red Hat Enterprise Linux Desktop Optional (v. 6) - i386, x86_64 Red Hat Enterprise Linux HPC Node Optional (v. 6) - x86_64 Red Hat Enterprise Linux Server (v. 6) - i386, ppc64, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 6) - i386, x86_64 3. Description: libsoup is an HTTP client/library implementation for GNOME. A directory traversal flaw was found in libsoup's SoupServer. If an application used SoupServer to implement an HTTP service, a remote attacker who is able to connect to that service could use this flaw to access any local files accessible to that application via a specially-crafted request. (CVE-2011-2524) All users of libsoup should upgrade to these updated packages, which contain a backported patch to resolve this issue. All running applications using libsoup's SoupServer must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure all previously-releasederrata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/kb/docs/DOC-11259 5. Bugs fixed (http://bugzilla.redhat.com/): 720509 - CVE-2011-2524 libsoup: SoupServer directory traversal flaw 6. Package List: Red Hat Enterprise Linux Desktop (v. 6): Source: i386: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm x86_64: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-2.28.2-1.el6_1.1.x86_64.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.x86_64.rpm Red Hat Enterprise Linux Desktop Optional (v. 6): Source: i386: libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm x86_64: libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.x86_64.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.x86_64.rpm Red Hat Enterprise Linux HPC Node Optional (v. 6): Source: x86_64: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-2.28.2-1.el6_1.1.x86_64.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.x86_64.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.x86_64.rpm Red Hat Enterprise Linux Server (v.6): Source: i386: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm ppc64: libsoup-2.28.2-1.el6_1.1.ppc.rpm libsoup-2.28.2-1.el6_1.1.ppc64.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.ppc.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.ppc64.rpm libsoup-devel-2.28.2-1.el6_1.1.ppc.rpm libsoup-devel-2.28.2-1.el6_1.1.ppc64.rpm s390x: libsoup-2.28.2-1.el6_1.1.s390.rpm libsoup-2.28.2-1.el6_1.1.s390x.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.s390.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.s390x.rpm libsoup-devel-2.28.2-1.el6_1.1.s390.rpm libsoup-devel-2.28.2-1.el6_1.1.s390x.rpm x86_64: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-2.28.2-1.el6_1.1.x86_64.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.x86_64.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 6): Source: i386: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm x86_64: libsoup-2.28.2-1.el6_1.1.i686.rpm libsoup-2.28.2-1.el6_1.1.x86_64.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.i686.rpm libsoup-debuginfo-2.28.2-1.el6_1.1.x86_64.rpm libsoup-devel-2.28.2-1.el6_1.1.i686.rpm libsoup-devel-2.28.2-1.el6_1.1.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://access.redhat.com/security/cve/CVE-2011-2524 https://access.redhat.com/security/updates/classification#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2011 Red Hat, Inc. . Critical libsoup security patch for CentOS 6 mitigating path traversal vulnerability. Update strongly advised.. Red Hat Enterprise Linux, Libsoup Service Flaw, Security Patch. . LinuxSecurity.com Team

Calendar 2 Jul 28, 2011 Red Hat
98

Red Hat: RHSA-2009-1238 Important: Dnsmasq TFTP Service Issues

An updated dnsmasq package that fixes two security issues is now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ==================================================================== Red Hat Security Advisory Synopsis: Important: dnsmasq security update Advisory ID: RHSA-2009:1238-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2009:1238.html Issue date: 2009-08-31 CVE Names: CVE-2009-2957 CVE-2009-2958 ==================================================================== 1. Summary: An updated dnsmasq package that fixes two security issues is now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team. 2. Relevant releases/architectures: Red Hat Enterprise Linux Desktop (v. 5 client) - i386, x86_64 Red Hat Enterprise Linux (v. 5 server) - i386, ia64, ppc, s390x, x86_64 3. Description: Dnsmasq is a lightweight and easy to configure DNS forwarder and DHCP server. Core Security Technologies discovered a heap overflow flaw in dnsmasq when the TFTP service is enabled (the "--enable-tftp" command line option, or by enabling "enable-tftp" in "/etc/dnsmasq.conf"). If the configured tftp-root is sufficiently long, and a remote user sends a request that sends a long file name, dnsmasq could crash or, possibly, execute arbitrary code with the privileges of the dnsmasq service (usually the unprivileged "nobody" user). (CVE-2009-2957) A NULL pointer dereference flaw was discovered in dnsmasq when the TFTP service is enabled. This flaw could allow a malicious TFTP client to crash the dnsmasq service. (CVE-2009-2958) Note: The default tftp-root is "/var/ftpd", which is short enough to make it difficult to exploit the CVE-2009-2957 issue; if a longer directory name is used, arbitrarycode execution may be possible. As well, the dnsmasq package distributed by Red Hat does not have TFTP support enabled by default. All users of dnsmasq should upgrade to this updated package, which contains a backported patch to correct these issues. After installing the updated package, the dnsmasq service must be restarted for the update to take effect. 4. Solution: Before applying this update, make sure that all previously-released errata relevant to your system have been applied. This update is available via Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at 5. Bugs fixed (http://bugzilla.redhat.com/): 519020 - CVE-2009-2957, CVE-2009-2958 dnsmasq: multiple vulnerabilities in TFTP server 6. Package List: Red Hat Enterprise Linux Desktop (v. 5 client): Source: i386: dnsmasq-2.45-1.1.el5_3.i386.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.i386.rpm x86_64: dnsmasq-2.45-1.1.el5_3.x86_64.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.x86_64.rpm Red Hat Enterprise Linux (v. 5 server): Source: i386: dnsmasq-2.45-1.1.el5_3.i386.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.i386.rpm ia64: dnsmasq-2.45-1.1.el5_3.ia64.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.ia64.rpm ppc: dnsmasq-2.45-1.1.el5_3.ppc.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.ppc.rpm s390x: dnsmasq-2.45-1.1.el5_3.s390x.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.s390x.rpm x86_64: dnsmasq-2.45-1.1.el5_3.x86_64.rpm dnsmasq-debuginfo-2.45-1.1.el5_3.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key#package 7. References: https://www.cve.org/CVERecord?id=CVE-2009-2957 https://www.cve.org/CVERecord?id=CVE-2009-2958 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2009 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.4(GNU/Linux) iD8DBQFKnGj+XlSAg2UNWIIRAqlbAJ4obBBc7erzPdu46+OD7GpyjNLnswCcCjii r+XXPtJj1i9ZsL+6ADBu2tQ=YGeD -----END PGP SIGNATURE----- -- Enterprise-watch-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Red Hat's latest package addresses two major dnsmasq vulnerabilities, enhancing overall service reliability.. Dnsmasq Updates, TFTP Security Flaws, Red Hat Fixes, Critical Security Issues. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 01, 2009 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here