Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 8 MGASA-2023-0150 Critical: Squirrel Code Execution Risk

sqclass.cpp in Squirrel 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An . MGASA-2023-0150 - Updated squirrel/supertux packages fix security vulnerability Publication date: 24 Apr 2023 URL: https://advisories.mageia.org/MGASA-2023-0150.html Type: security Affected Mageia releases: 8 CVE: CVE-2021-41556 sqclass.cpp in Squirrel 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script sandbox even if all dangerous functionality such as File System functions has been disabled. An attacker might abuse this bug to target (for example) Cloud services that allow customization via SquirrelScripts, or distribute malware through video games that embed a Squirrel Engine. (CVE-2021-41556) supertux has been rebuilt as it uses a bundled copy of squirrel. References: - https://bugs.mageia.org/show_bug.cgi?id=30742 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/M3FQILX7UUEERSDPMZP3MKGTMY2E7ESU/ - - https://www.cve.org/CVERecord?id=CVE-2021-41556 SRPMS: - 8/core/squirrel-3.2-1.mga8 - 8/core/supertux-0.6.2-4.2.mga8 . MGASA-2023-0151 tackles a significant buffer overflow vulnerability in Acorn that could enable arbitrary code execution.. Squirrel Security Update, Mageia 2023 Advisory, Supertux Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 24, 2023 Critical Mageia
203

Mageia 8 MGASA-2022-0204 Critical: Supertux Buffer Overflow

squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call (CVE-2022-30292) References: - https://bugs.mageia.org/show_bug.cgi?id=30430 . MGASA-2022-0204 - Updated supertux packages fix security vulnerability Publication date: 25 May 2022 URL: https://advisories.mageia.org/MGASA-2022-0204.html Type: security Affected Mageia releases: 8 CVE: CVE-2022-30292 squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call (CVE-2022-30292) References: - https://bugs.mageia.org/show_bug.cgi?id=30430 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./thread/WBUYGYXDQX3OSAYHP4TCG3JS7PJTIE75/ - https://www.cve.org/CVERecord?id=CVE-2022-30292 SRPMS: - 8/core/supertux-0.6.2-4.1.mga8 . Revised supertux versions tackle a vital security concern linked to threading operations discovered in Mageia version 8.. Supertux Security Patch, Mageia Update, Software Vulnerability Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 25, 2022 Critical Mageia
89

Fedora 35: 2022-88e3257aef Critical: Fix for SuperTux Issue

Fix CVE-2022-30292. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-88e3257aef 2022-05-16 02:04:05.714253 --------------------------------------------------------------------------------Name : supertux Product : Fedora 35 Version : 0.6.3 Release : 2.fc35 URL : https://www.supertux.org Summary : Jump'n run like game Description : SuperTux is a jump'n run like game, Run and jump through multiple worlds, fighting off enemies by jumping on them or bumping them from below. Grabbing power-ups and other stuff on the way. --------------------------------------------------------------------------------Update Information: Fix CVE-2022-30292 --------------------------------------------------------------------------------ChangeLog: * Thu May 5 2022 David King - 0.6.3-2 - Fix CVE-2022-30292 (#2082179) --------------------------------------------------------------------------------References: [ 1 ] Bug #2082179 - CVE-2022-30292 supertux: squirrel: thread_call in sqbaselib.cpp lacks a certain sq_reservestack call [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2082179 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-88e3257aef' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure . Patch addressing CVE-2022-30292 in SuperTux game for Fedora 35 issued on May 16, 2022, improving both security measures and overall performance.. Fedora Updates, SuperTux Game, Security Patches. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 15, 2022 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here