Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA-1500-2 Urgent: Libxslt Security Flaw Detected

Mike Ashton discovered that splitvt, a utility to run two programs in a split screen, did not drop group privileges prior to executing 'xprop'. This could allow any local user to gain the privileges of group utmp.. - ------------------------------------------------------------------------Debian Security Advisory DSA-1500-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steve Kemp February 21, 2008 http://www.debian.org/security/faq - ------------------------------------------------------------------------Package : splitvt Vulnerability : privilege escalation Problem type : local Debian-specific: no CVE Id(s) : CVE-2008-0162 Mike Ashton discovered that splitvt, a utility to run two programs in a split screen, did not drop group privileges prior to executing 'xprop'. This could allow any local user to gain the privileges of group utmp. For the stable distribution (etch), this problem has been fixed in version 1.6.5-9etch1. For the unstable distribution (sid), this problem has been fixed in version 1.6.6-4. We recommend that you upgrade your splitvt package. Upgrade instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 4.0 alias etch - -------------------------------Source archives: Size/MD5 checksum: 602 38c5d340fe95abbd78edfa806618fce8 Size/MD5 checksum: 10746 ea95a61da623237d715e5b1fdce9e92a alpha architecture (DEC Alpha) Size/MD5 checksum: 41314 06622ad249f48ee2009f03ef1b4ba1ad amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 37754 dd591bff5b03378ab225dbf41648e037 hppa architecture (HP PA RISC) Size/MD5 checksum: 38398 f9c5dc35197dcd1b8a2843a29c200bbb i386 architecture (Intel ia32) Size/MD5 checksum: 34754 70d76970fb5017197c78861c4d070cab ia64 architecture (Intel ia64) Size/MD5 checksum: 50166 d2328ca3f1d1114cc9a2497d59e0ff9a mips architecture (MIPS (Big Endian)) Size/MD5 checksum: 39434 3205ddfd371fd0edd5175333a5c94c1b powerpc architecture (PowerPC) Size/MD5 checksum: 37800 7c8d9c7f20e4a4fc92531f0a5cd7bb26 s390 architecture (IBM S/390) Size/MD5 checksum: 37854 9c39d0109f6600022862c3ee6d1fb0c8 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Updated splitvt packages address vulnerabilities related to privilege escalation in Debian environments, safeguarding local user permissions associated with the utmp group.. Debian Security Update, Privilege Escalation Fix, Splitvt Update. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Feb 21, 2008 Important Debian
87

Debian 2.2: DSA-014-2 Critical: Splitvt Buffer Overflow Threat

Numerous buffer overflow and a format string attacks exist in previous versions.. - ---------------------------------------------------------------------------- Debian Security Advisory DSA-014-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze January 23, 2001 - ---------------------------------------------------------------------------- Package : splitvt Vulnerability : buffer overflow and format string attack Debian-specific: no This advisory is only a corrected security advisory for DSA 014-1 since I wasn't careful enough last night and files from an older advisory back from June 2000 slipped through. To keep confusion to a minimum this advisory contains all relevant URLs - and only these. It was reported recently that splitvt is vulnerable to numerous buffer overflow attack and a format string attack. An attacker was able to gain access to the tty group. We recommend you upgrade your splitvt package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 2.2 alias potato - ------------------------------------ Potato was released for the alpha, arm, i386, m68k, powerpc and sparc architectures. Source archives: MD5 checksum: 475d1066c013102625c79757b3615d9b MD5 checksum: dcfd3f56c5f7a3686e35a2de47614944 MD5 checksum: f93974daa4f39945b3d5b9cc39bb1b0f Intel ia32 architecture: MD5 checksum: ccb41228b11505bb25dc2f09830b3964 Motorola 680x0 architecture: MD5 checksum: fae77f348ae28c89de0e51965cbafd35 Sun Sparc architecture: MD5 checksum: 7bfd098f4a8f884a63805ae13c1e9cea Alpha architecture: MD5 checksum: e960372181b65e167c41f36707ef48cf PowerPC architecture: MD5 checksum: d0d3b36c20b2999c7c7610a48866167e ARM architecture: MD5checksum: 1d697bed936476ae88fd478aba112be8 These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - ---------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Immediate update issued for splitvt tackling severe security flaws concerning buffer overflow and format string attacks in Debian systems.. splitvt, buffer overflow, format string, Debian security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jan 22, 2001 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here