Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 418
Alerts This Week
Warning Icon 1 418

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
89

Fedora 41: FEDORA-2024-5d6c951b0b moderate: iwd signal handling issues

iwd 2.22: Fix issue with handling the Affinities property. Fix issue with handling ConnectedAccessPoint signal when roaming.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5d6c951b0b 2024-09-23 00:15:17.969906 -------------------------------------------------------------------------------- Name : iwd Product : Fedora 41 Version : 2.22 Release : 1.fc41 URL : https://archive.kernel.org/oldwiki/iwd.wiki.kernel.org/ Summary : Wireless daemon for Linux Description : The daemon and utilities for controlling and configuring the Wi-Fi network hardware. -------------------------------------------------------------------------------- Update Information: iwd 2.22: Fix issue with handling the Affinities property. Fix issue with handling ConnectedAccessPoint signal when roaming. -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 14 2024 Peter Robinson - 2.22-1 - Update to 2.22 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2311767 - iwd-2.22 is available https://bugzilla.redhat.com/show_bug.cgi?id=2311767 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5d6c951b0b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: . iwd 2.22 enhancements in Fedora 41 tackle critical signal processing challenges to boost Wi-Fi connectivity reliability and efficiency.. iwd updates,Fedora 41,Wi-Fi daemon,softwrare fixes. . LinuxSecurity.com Team

Calendar%202 Sep 23, 2024 Fedora
87

Debian Jessie DSA-3793-2: Critical Shadow Signal Handling Update

The update for the shadow suite issued as DSA-3793-1 introduced a regression in su signal handling. If su receives a signal like SIGTERM, it is not propagated to the child. Updated packages are now available to correct this issue. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3793-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso May 17, 2017 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : shadow Debian Bug : 862806 The update for the shadow suite issued as DSA-3793-1 introduced a regression in su signal handling. If su receives a signal like SIGTERM, it is not propagated to the child. Updated packages are now available to correct this issue. For the stable distribution (jessie), this problem has been fixed in version 1:4.2-3+deb8u4. We recommend that you upgrade your shadow packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian's shadow package has been revised to rectify signal management regression concerns. Upgrade now to improve overall security and system resilience.. Debian security, Shadow package update, Signal handling, Software fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 17, 2017 Critical Debian
172

Ubuntu 17.04 USN-3276-2 Moderate: Shadow Signal Handling Regression

USN-3276-1 introduced a regression in su.. =========================================================================Ubuntu Security Notice USN-3276-2 May 17, 2017 shadow regression ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 17.04 - Ubuntu 16.10 - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: USN-3276-1 introduced a regression in su. Software Description: - shadow: system login tools Details: USN-3276-1 intended to fix a vulnerability in su. The solution introduced a regression in su signal handling. This update modifies the security fix. We apologize for the inconvenience. Original advisory details: Sebastian Krahmer discovered integer overflows in shadow utilities. A local attacker could possibly cause them to crash or potentially gain privileges via crafted input. (CVE-2016-6252) Tobias Stöckmann discovered a race condition in su. A local attacker could cause su to send SIGKILL to other processes with root privileges. (CVE-2017-2616) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 17.04: login 1:4.2-3.2ubuntu1.17.04.2 passwd 1:4.2-3.2ubuntu1.17.04.2 uidmap 1:4.2-3.2ubuntu1.17.04.2 Ubuntu 16.10: login 1:4.2-3.2ubuntu1.16.10.2 passwd 1:4.2-3.2ubuntu1.16.10.2 uidmap 1:4.2-3.2ubuntu1.16.10.2 Ubuntu 16.04 LTS: login 1:4.2-3.1ubuntu5.3 passwd 1:4.2-3.1ubuntu5.3 uidmap 1:4.2-3.1ubuntu5.3 Ubuntu 14.04 LTS: login 1:4.1.5.1-1ubuntu9.5 passwd 1:4.1.5.1-1ubuntu9.5 uidmap 1:4.1.5.1-1ubuntu9.5 In general, a standard system update will make allthe necessary changes. References: https://ubuntu.com/security/notices/USN-3276-2 https://ubuntu.com/security/notices/USN-3276-1 https://bugs.launchpad.net/ubuntu/+source/shadow/+bug/1690820 Package Information: https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.2ubuntu1.17.04.2 https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.2ubuntu1.16.10.2 https://launchpad.net/ubuntu/+source/shadow/1:4.2-3.1ubuntu5.3 https://launchpad.net/ubuntu/+source/shadow/1:4.1.5.1-1ubuntu9.5 . Ubuntu Advisory: USN-3276-3 resolves a hidden regression in su signal processing impacting various versions.. shadow security, Ubuntu advisory, su issue, local privilege attack, Ubuntu update. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 May 17, 2017 Medium Ubuntu
98

Red Hat Linux: RHSA-2003:296-01 Critical Update for Stunnel Signal Handling

Updated stunnel packages are now available for Red Hat Linux 7.1, 7.2, 7.3,and 8.0 systems. These updates address problems stemming from improper useof non-reentrant functions in signal handlers.. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - --------------------------------------------------------------------- Red Hat Security Advisory Synopsis: Updated stunnel packages available Advisory ID: RHSA-2003:296-01 Issue date: 2003-11-24 Updated on: 2003-11-24 Product: Red Hat Linux Keywords: stunnel signal Cross references: RHSA-2003:297 Obsoletes: RHSA-2003:221 CVE Names: CAN-2002-1563 CAN-2003-0740 - --------------------------------------------------------------------- 1. Topic: Updated stunnel packages are now available for Red Hat Linux 7.1, 7.2, 7.3, and 8.0 systems. These updates address problems stemming from improper use of non-reentrant functions in signal handlers. 2. Relevant releases/architectures: Red Hat Linux 7.1 - i386 Red Hat Linux 7.2 - i386, ia64 Red Hat Linux 7.3 - i386 Red Hat Linux 8.0 - i386 3. Problem description: Stunnel is a wrapper for network connections. It can be used to tunnel an unencrypted network connection over an encrypted connection (encrypted using SSL or TLS) or to provide an encrypted means of connecting to services that do not natively support encryption. A previous advisory provided updated packages to address re-entrancy problems in stunnel's signal-handling routines. These updates did not address other bugs that were found by Steve Grubb, and introduced an additional bug, which was fixed in stunnel 3.26. All users should upgrade to these errata packages, which address these issues by updating stunnel to version 3.26. NOTE: After upgrading, any instances of stunnel configured to run in daemon mode should be restarted, and any active network connections that are currently being serviced by stunnel should be terminated and reestablished. 4. Solution: Before applying thisupdate, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. If up2date fails to connect to Red Hat Network due to SSL Certificate Errors, you need to install a version of the up2date client with an updated certificate. The latest version of up2date is available from the Red Hat FTP site and may also be downloaded directly from the RHN website: 5. RPMs required: Red Hat Linux 7.1: SRPMS: i386: Red Hat Linux 7.2: SRPMS: i386: ia64: Red Hat Linux 7.3: SRPMS: i386: Red Hat Linux 8.0: SRPMS: i386: 6. Verification: MD5 sum Package Name - -------------------------------------------------------------------------- cfd2b7c9519812d58a945d4b5e189fdd 7.1/en/os/SRPMS/stunnel-3.26-1.7.1.src.rpm f05723a19a2990ce17ded0ce817890b5 7.1/en/os/i386/stunnel-3.26-1.7.1.i386.rpm f1c75122248f440e96adff582de64520 7.2/en/os/SRPMS/stunnel-3.26-1.7.3.src.rpm e307840b930fc50e4bb2b61a0578af5a 7.2/en/os/i386/stunnel-3.26-1.7.3.i386.rpm cd223922c7a690d7dfcfdd2e49c49e24 7.2/en/os/ia64/stunnel-3.26-1.7.3.ia64.rpm f1c75122248f440e96adff582de64520 7.3/en/os/SRPMS/stunnel-3.26-1.7.3.src.rpm e307840b930fc50e4bb2b61a0578af5a 7.3/en/os/i386/stunnel-3.26-1.7.3.i386.rpm 071ab6a4091737a4292e631bd74909758.0/en/os/SRPMS/stunnel-3.26-1.8.0.src.rpm d3718eebbd8b921de713c4914da22dec 8.0/en/os/i386/stunnel-3.26-1.8.0.i386.rpm These packages are GPG signed by Red Hat for security. Our key is available from https://access.redhat.com/security/team/key You can verify each package with the following command: rpm --checksig -v If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: md5sum 7. References: http://marc.theaimsgroup.com/?l=stunnel-users&m=105980139926784 http://marc.theaimsgroup.com/?l=stunnel-users&m=106221975232250 http://marc.theaimsgroup.com/?l=bugtraq&m=106260760211958 CVE -CVE-2002-1563 CVE -CVE-2003-0740 8. Contact: The Red Hat security contact is . More contact details at https://www.redhat.com/en/technologies/all-products Copyright 2003 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQE/wcV5XlSAg2UNWIIRAnw4AJ9u7klajUMumofqL1o9vU6/uhjTGACeIRIC ehS8TWOZF6fd+owIpBhNSwE=69GI -----END PGP SIGNATURE----- . The latest stunnel patches for Fedora tackle issues concerning signal handling. Users are encouraged to update to improve system security.. Signal Handling Update, Red Hat, Stunnel Packages, Security Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Nov 24, 2003 Critical Red Hat
87

Debian: DSA 083-1 Critical: Procmail Local Root Exploit

Using older versions of procmail it was possible to make procmail crash by sending it signals. On systems where procmail is installed setuid this could be exploited to obtain unauthorized privileges.. -------------------------------------------------------------------------- Debian Security Advisory DSA 083-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze October 18th, 2001 -------------------------------------------------------------------------- Package : procmail Vulnerability : insecure signal handling Problem-Type : local root exploit Debian-specific: no Using older versions of procmail it was possible to make procmail crash by sending it signals. On systems where procmail is installed setuid this could be exploited to obtain unauthorized privileges. This problem has been fixed in version 3.20 by the upstream maintainer, included in Debian unstable, and was ported back to version 3.15.2 which is available for for the stable Debian GNU/Linux 2.2. We recommend that you upgrade your procmail package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato ------------------------------------ Source archives: MD5 checksum: 0cb94b0c0d122a01f40f121ea0ec6ade MD5 checksum: 0c197e2629dc5aca44f08a97b94751ad MD5 checksum: 933c8f378082048f2d7f598dff9b760c Alpha architecture: MD5 checksum: daf60f1b098153e852f2e8404acbf037 ARM architecture: MD5 checksum: 2e1b96787ccb90724db0b0dc97574a9a Intel ia32 architecture: MD5 checksum:d7245b21110faf119e77705eaf724218 Motorola 680x0 architecture: MD5 checksum: f9bf3d4630d57abc6ff876d01174493f PowerPC architecture: MD5 checksum: e2713f8a2862ddab38774a1708b85018 Sun Sparc architecture: MD5 checksum: 80635f04bd2bbfc991176438307d7371 These files will be moved into the stable distribution on its next revision. --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Upgrade your procmail setup swiftly to address vulnerable signal handling that allows unpermitted access privileges.. Procmail Security Update, Debian Protection, Signal Handling Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 18, 2001 Critical Debian
98

Red Hat 5.2, 6.2, 7.0, 7.1: RHSA-2001:093-03 Critical Update for Procmail

Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2,6.2, 7, and 7.1, handles signals unsafely.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated procmail packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 Advisory ID: RHSA-2001:093-03 Issue date: 2001-07-03 Updated on: 2001-07-13 Product: Red Hat Linux Keywords: procmail Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 3. Problem description: Procmail was not handling signals properly. This has been fixed in procmail 3.21. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- c07f1a3eb5360143ea51afa401ae6639 5.2/en/os/SRPMS/procmail-3.21-0.52.src.rpm 1bc3b9acbf67118fa21fa7cb7ca2c14b 5.2/en/os/alpha/procmail-3.21-0.52.alpha.rpm b4a99c68a9141f2448709afd0c84ff60 5.2/en/os/i386/procmail-3.21-0.52.i386.rpm 86fe4d853a65dea9d892dfc7042fd12e 5.2/en/os/sparc/procmail-3.21-0.52.sparc.rpm 82ece26660bcfdd51aeea2b906737e6b 6.2/en/os/SRPMS/procmail-3.21-0.62.src.rpm dde2aa93f0b6dc5379ea77112478f16f 6.2/en/os/alpha/procmail-3.21-0.62.alpha.rpm 07c080d1d6f09138203a68cac57b8ca8 6.2/en/os/i386/procmail-3.21-0.62.i386.rpm e1a7a7103705463fd89fb09c002c84a4 6.2/en/os/sparc/procmail-3.21-0.62.sparc.rpm aee4c233f3f81a090379f903113a8212 7.0/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.0/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.0/en/os/i386/procmail-3.21-0.71.i386.rpm aee4c233f3f81a090379f903113a8212 7.1/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.1/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.1/en/os/i386/procmail-3.21-0.71.i386.rpm f1e8da53ad57d95a2ad108f30bab476a 7.1/en/os/ia64/procmail-3.21-0.71.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Critical vulnerability in Procmail resolved through Red Hat update, fixing an issue with signal handling affecting versions 5.2, 6.2, 7, and 7.1 of Red Hat.. RedHat Procmail SignalHandling SecurityUpdate. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jul 20, 2001 Critical Red Hat
98

Red Hat Linux: RHSA-2001:093-03 Critical: Procmail Signal Handling Issue

Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Updated procmail packages available for Red Hat Linux 5.2, 6.2, 7 and 7.1 Advisory ID: RHSA-2001:093-03 Issue date: 2001-07-03 Updated on: 2001-07-13 Product: Red Hat Linux Keywords: procmail Cross references: Obsoletes: --------------------------------------------------------------------- 1. Topic: Procmail, an autonomous mail processor, as shipped in Red Hat Linux 5.2, 6.2, 7, and 7.1, handles signals unsafely. 2. Relevant releases/architectures: Red Hat Linux 5.2 - alpha, i386, sparc Red Hat Linux 6.2 - alpha, i386, sparc Red Hat Linux 7.0 - alpha, i386 Red Hat Linux 7.1 - alpha, i386, ia64 3. Problem description: Procmail was not handling signals properly. This has been fixed in procmail 3.21. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desired RPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 6. RPMs required: Red Hat Linux 5.2: SRPMS: alpha: i386: sparc: Red Hat Linux 6.2: SRPMS: alpha: i386: sparc: Red Hat Linux 7.0: SRPMS: alpha: i386: Red Hat Linux 7.1: SRPMS: alpha: i386: ia64: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- c07f1a3eb5360143ea51afa401ae6639 5.2/en/os/SRPMS/procmail-3.21-0.52.src.rpm 1bc3b9acbf67118fa21fa7cb7ca2c14b 5.2/en/os/alpha/procmail-3.21-0.52.alpha.rpm b4a99c68a9141f2448709afd0c84ff60 5.2/en/os/i386/procmail-3.21-0.52.i386.rpm 86fe4d853a65dea9d892dfc7042fd12e 5.2/en/os/sparc/procmail-3.21-0.52.sparc.rpm 82ece26660bcfdd51aeea2b906737e6b 6.2/en/os/SRPMS/procmail-3.21-0.62.src.rpm dde2aa93f0b6dc5379ea77112478f16f 6.2/en/os/alpha/procmail-3.21-0.62.alpha.rpm 07c080d1d6f09138203a68cac57b8ca8 6.2/en/os/i386/procmail-3.21-0.62.i386.rpm e1a7a7103705463fd89fb09c002c84a4 6.2/en/os/sparc/procmail-3.21-0.62.sparc.rpm aee4c233f3f81a090379f903113a8212 7.0/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.0/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.0/en/os/i386/procmail-3.21-0.71.i386.rpm aee4c233f3f81a090379f903113a8212 7.1/en/os/SRPMS/procmail-3.21-0.71.src.rpm 5d378a8ae5599cac04802e3de254804e 7.1/en/os/alpha/procmail-3.21-0.71.alpha.rpm 51ad4ad3241887e2eb631e1799c94972 7.1/en/os/i386/procmail-3.21-0.71.i386.rpm f1e8da53ad57d95a2ad108f30bab476a 7.1/en/os/ia64/procmail-3.21-0.71.ia64.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: Copyright(c) 2000, 2001 Red Hat, Inc. `. Critical security alert for Red Hat: Upgrade procmail to resolve issues with incorrect signal management impacting multiple versions.. Red Hat Linux Update, Procmail Security Fix, Signal Handling Flaw. . Severity: Critical.LinuxSecurity.com Team

Calendar%202 Jul 19, 2001 Critical Red Hat
87

Debian 2.2 Moderate: Symlink Attack in Joe Editor Advisory

When joe dies to a signal instead of a normal exit it is vulnerable to a symlink attack.. - ------------------------------------------------------------------------ Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman November 22, 2000 - ------------------------------------------------------------------------ Package : joe Problem type : symlink attack Debian-specific: no When joe (Joe's Own Editor) dies due to a signal instead of a normal exit it saves a list of the files it is editing to a file called `DEADJOE' in its current directory. Unfortunately this wasn't done safely which made joe vulnerable to a symlink attack. This has been fixed in version 2.8-15.1 . wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 94131d7638b028e6bd6f529747b9d318 MD5 checksum: 5ad45a1fa1a293bef03786f9258bf846 MD5 checksum: 84c1aebfce7876b8639945da3c29f204 Alpha architecture: MD5 checksum: defbc5c39a2ae8ed000b7b302ecd339f ARM architecture: MD5 checksum: bcb70726840c2cf11cba068ce2a826be Intel ia32 architecture: MD5 checksum: 21444255b240be01132208e5cb1d3439 Motorola 680x0 architecture: MD5 checksum: a4b275c324956489bf7558d42a80f22f PowerPC architecture: MD5 checksum: 689d54abe039ded6e82bf60115737631 Sun Sparc architecture: MD5 checksum: 8846236e9158cf3f3d7f1b8edce73d40 These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - -- - ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . - ------------------------------------------------------------------------ Debian Security Advisory . signal, instead, normal, vulnerable, symlink, attack, ---------. . LinuxSecurity.com Team

Calendar%202 Nov 22, 2000 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200