Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
99

Slackware 12.1 Security Advisory: Slocate Moderate Information Leak Fix

New slocate packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] slocate (SSA:2012-244-05) New slocate packages are available for Slackware 12.1, 12.2, 13.0, 13.1, 13.37, and -current to fix a security issue. Here are the details from the Slackware 13.37 ChangeLog: +--------------------------+ Patched to use lstat64 and -D_LARGEFILE64_SOURCE. Thanks to Mancha+. Patched to fix information leak of filenames in protected directories. For more information, see: https://www.cve.org/CVERecord?id=CVE-2007-0227 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 12.1: ftp://ftp.slackware.com/pub/slackware/slackware-12.1/patches/packages/slocate-3.1-i486-2_slack12.1.tgz Updated package for Slackware 12.2: ftp://ftp.slackware.com/pub/slackware/slackware-12.2/patches/packages/slocate-3.1-i486-2_slack12.2.tgz Updated package for Slackware 13.0: ftp://ftp.slackware.com/pub/slackware/slackware-13.0/patches/packages/slocate-3.1-i486-4_slack13.0.txz Updated package for Slackware x86_64 13.0: ftp://ftp.slackware.com/pub/slackware/slackware64-13.0/patches/packages/slocate-3.1-x86_64-4_slack13.0.txz Updated package for Slackware 13.1: ftp://ftp.slackware.com/pub/slackware/slackware-13.1/patches/packages/slocate-3.1-i486-4_slack13.1.txz Updated package for Slackware x86_64 13.1: ftp://ftp.slackware.com/pub/slackware/slackware64-13.1/patches/packages/slocate-3.1-x86_64-4_slack13.1.txz Updated package for Slackware 13.37: ftp://ftp.slackware.com/pub/slackware/slackware-13.37/patches/packages/slocate-3.1-i486-4_slack13.37.txz Updated package for Slackwarex86_64 13.37: ftp://ftp.slackware.com/pub/slackware/slackware64-13.37/patches/packages/slocate-3.1-x86_64-4_slack13.37.txz Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 12.1 package: 294638d315522d39a548320f8ecb8dfe slocate-3.1-i486-2_slack12.1.tgz Slackware 12.2 package: 314118b4aa53120c98049c3979a91bd9 slocate-3.1-i486-2_slack12.2.tgz Slackware 13.0 package: c355a02276b1dd619d4097aff1f6deaa slocate-3.1-i486-4_slack13.0.txz Slackware x86_64 13.0 package: d81b496d4d5eeb64b6d58e006a671019 slocate-3.1-x86_64-4_slack13.0.txz Slackware 13.1 package: de3ac5c264fcc7e0916d603ca6f11e41 slocate-3.1-i486-4_slack13.1.txz Slackware x86_64 13.1 package: df3c40f8666d2d1bf9c4aa9b383c87ff slocate-3.1-x86_64-4_slack13.1.txz Slackware 13.37 package: 83670d384a248f24e3a8e2bfdfebb14f slocate-3.1-i486-4_slack13.37.txz Slackware x86_64 13.37 package: df0cf00f72804b549283e4c719eff4ec slocate-3.1-x86_64-4_slack13.37.txz Slackware -current package: 5c32ada3968815e063e5abd8cef507b4 a/slocate-3.1-i486-4.txz Slackware x86_64 -current package: 69e300421110474e99fcce4d6dcbe6a3 a/slocate-3.1-x86_64-4.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg slocate-3.1-i486-4_slack13.37.txz +-----+ . Recent updates to slocate packages for Slackware address a critical information disclosure vulnerability. Please upgrade to maintain your system's security.. slocate packages, Slackware update, security patches. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 31, 2012 Important Slackware
87

Debian 2.2 Potato DSA-005-1 Critical Slocate Local Exploit Advisory

Michel Kaempf reported a security problem in slocate on bugtraqwhich was originally discovered by zorgon.. - ------------------------------------------------------------------------ Debian Security Advisory DSA-005-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman December 17, 2000 - ------------------------------------------------------------------------ Package : slocate Problem type : local exploit Debian-specific: no Michel Kaempf reported a security problem in slocate (a secure version of locate, a tool to quickly locate files on a filesystem) on bugtraq which was originally discovered by zorgon. He discovered there was a bug in the database reading code which made it overwrite a internal structure with some input. He then showed this could be exploited to trick slocate into executing arbitrary code by pointing it to a carefully crafted database. This has been fixed in version 2.4-2potato1 and we recommend that you upgrade your slocate package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Source archives: MD5 checksum: 9d15a0e95b501427f697e9031d8e62e8 MD5 checksum: 7effe675baba70e3b30ce41e9d231835 MD5 checksum: 185520e64e7b194b6d448f034e2f1c7a Alpha architecture: MD5 checksum: 90888e9f21437c6a3e7c7addbd244fdc ARM architecture: MD5 checksum: 8904b89a14f7a91f6c205fa37ad67466 Motorola 680x0 architecture: MD5 checksum: 09bd79672ac452a5c10618a368a4b40a Intel ia32 architecture: MD5 checksum: ff79ebacf5cfa910608f3cdaff043255 PowerPC architecture: MD5 checksum: 1f117700d339fa8acb8de938dab95cfa Sun Sparc architecture: MD5 checksum: 3059fe27465a9bc8738ea8e7a6f8f3e2 These files will bemoved into soon. For not yet released architectures please refer to the appropriate directory . . Ubuntu Security Notice USN-1234-1 exposes a vulnerability in locate that could be exploited by local users, making upgrades essential to prevent unauthorized command execution. Debian Security, Slocate Vulnerability, Local Exploit Fix, Package Upgrade. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 16, 2000 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here