Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -8 articles for you...
99

Slackware: 2017-223-01 Critical: Git Command Injection Threat

New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] git (SSA:2017-223-01) New git packages are available for Slackware 13.0, 13.1, 13.37, 14.0, 14.1, 14.2, and -current to fix security issues. Here are the details from the Slackware 14.2 ChangeLog: +--------------------------+ patches/packages/git-2.14.1-i586-1_slack14.2.txz: Upgraded. Fixes security issues: A "ssh://..." URL can result in a "ssh" command line with a hostname that begins with a dash "-", which would cause the "ssh" command to instead (mis)treat it as an option. This is now prevented by forbidding such a hostname (which should not impact any real-world usage). Similarly, when GIT_PROXY_COMMAND is configured, the command is run with host and port that are parsed out from "ssh://..." URL; a poorly written GIT_PROXY_COMMAND could be tricked into treating a string that begins with a dash "-" as an option. This is now prevented by forbidding such a hostname and port number (again, which should not impact any real-world usage). For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-1000117 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-) Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you. Updated package for Slackware 13.0: Updated package for Slackware x86_64 13.0: Updated package for Slackware 13.1: Updated package for Slackware x86_64 13.1: Updated package for Slackware 13.37: Updated package for Slackware x86_64 13.37: Updated package for Slackware 14.0: Updated package for Slackware x86_64 14.0: Updated package for Slackware 14.1: Updated package for Slackware x86_64 14.1: Updated package forSlackware 14.2: Updated package for Slackware x86_64 14.2: Updated package for Slackware -current: Updated package for Slackware x86_64 -current: MD5 signatures: +-------------+ Slackware 13.0 package: eb09b59fc1bb219e829caa8fc3619bd6 git-2.14.1-i486-1_slack13.0.txz Slackware x86_64 13.0 package: 1a31cef1c6c5a81a09635d25ea3090ff git-2.14.1-x86_64-1_slack13.0.txz Slackware 13.1 package: 77c2adf3715328fd28a075d19b636fc1 git-2.14.1-i486-1_slack13.1.txz Slackware x86_64 13.1 package: b382a2bde0bad0f83e13788c4e2dd9b2 git-2.14.1-x86_64-1_slack13.1.txz Slackware 13.37 package: 7858189706b9da7a8822b43fcc57038e git-2.14.1-i486-1_slack13.37.txz Slackware x86_64 13.37 package: 951d45486e41bfca03a99b52dbe82f2c git-2.14.1-x86_64-1_slack13.37.txz Slackware 14.0 package: e1d681ce44de2459fcd2e1f06b83fb7e git-2.14.1-i486-1_slack14.0.txz Slackware x86_64 14.0 package: 6eb717a73dc54f4c5dcdad9710636a38 git-2.14.1-x86_64-1_slack14.0.txz Slackware 14.1 package: 211e9d242f3044bc2f3920d978c148d1 git-2.14.1-i486-1_slack14.1.txz Slackware x86_64 14.1 package: 4e0d3510b71bf1e5a0ede2b6f41e330e git-2.14.1-x86_64-1_slack14.1.txz Slackware 14.2 package: f065edb1ef108a8cefe74292441ad77b git-2.14.1-i586-1_slack14.2.txz Slackware x86_64 14.2 package: c29b1e8d760661c0c1cb62cccb316f55 git-2.14.1-x86_64-1_slack14.2.txz Slackware -current package: e7765505e32c34d6b23160dc207932af d/git-2.14.1-i586-1.txz Slackware x86_64 -current package: 9659eaf46710b5514ca804f44b451910 d/git-2.14.1-x86_64-1.txz Installation instructions: +------------------------+ Upgrade the package as root: # upgradepkg git-2.14.1-i586-1_slack14.2.txz +-----+ . Latest git versions made available for Slackware aimed at fixing significant security vulnerabilities and improving comprehensive system safeguarding.. Slackware Security Update, Git Package, Security Fixes. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 11, 2017 Critical Slackware
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here