Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA 682-1 Urgent: Illusionary Access Elevation Risk

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 681-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze February 14th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : synaesthesia Vulnerability : privilege escalation Problem-Type : local Debian-specific: no CVE ID : CAN-2005-0070 Erik Sjölund and Devin Carraway discovered that synaesthesia, a program for representing sounds visually, accesses user-controlled configuration and mixer files with elevated privileges. Thus, it is possible to read arbitrary files. For the stable distribution (woody) this problem has been fixed in version 2.1-2.1woody3. For the testing (sarge) and unstable (sid) distribution this problem does not exist since synaesthesia is not installed setuid root anymore. We recommend that you upgrade your synaesthesia package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 635 10d25969579c0c47a7b129ad01da7484 Size/MD5 checksum: 4016 be2f05ddbb3313c695e4eff731c680ef Size/MD5 checksum: 129209 5bc166deb369a3c71efd61e1ad5e5475 Alpha architecture: Size/MD5 checksum: 78042 d9e3e8349ea6f271de6a8285a8dfe495 ARM architecture: Size/MD5 checksum: 783485337592249f592cb0862203a6fca1159 Intel IA-32 architecture: Size/MD5 checksum: 70848 bb1224e1dffc6bf0a44a3bba534a4bc0 Intel IA-64 architecture: Size/MD5 checksum: 85912 68d1397f3599f6274580b15b9e7dc844 HP Precision architecture: Size/MD5 checksum: 77738 441992d64a1297a1c2aad0595de3ae71 Motorola 680x0 architecture: Size/MD5 checksum: 67484 ec838c58184804de2ab10c0586f818dc Big endian MIPS architecture: Size/MD5 checksum: 75892 a67edbec6ff9516e0a890cff2756a678 Little endian MIPS architecture: Size/MD5 checksum: 75580 0c1402c43656f76f61dc096a231991bf PowerPC architecture: Size/MD5 checksum: 72232 1bca4dfe5d5b27b6329b885b3c5f1350 IBM S/390 architecture: Size/MD5 checksum: 70430 f001c092c3f05099942db6b699fa0029 Sun Sparc architecture: Size/MD5 checksum: 71944 bb5f8638ecf6746521ab960433587735 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu notification outlines steps to resolve unapproved data access issues in perceptual software packages.. Debian Security, Synaesthesia Package, Privilege Escalation Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 14, 2005 Critical Debian
87

Debian 446-1 Critical: Synaesthesia Insecure File Creation Threat

This type of vulnerability can usually be easily exploited to execute arbitary code with root privileges by various means.. Debian Security Advisory DSA 446-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Matt Zimmerman February 21st, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : synaesthesia Vulnerability : insecure file creation Problem-Type : local Debian-specific: no CVE Ids : CAN-2004-0160 During an audit, Ulf Harnhammar discovered a vulnerability in synaesthesia, a program which represents sounds visually. synaesthesia created its configuration file while holding root privileges, allowing a local user to create files owned by root and writable by the user's primary group. This type of vulnerability can usually be easily exploited to execute arbitary code with root privileges by various means. For the current stable distribution (woody) this problem has been fixed in version 2.1-2.1woody1. The unstable distribution (sid) is not affected by this problem, because synaesthesia is no longer setuid. We recommend that you update your synaesthesia package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 635 ca8bc25afbb982dd10c40e5923c2e3c3 Size/MD5 checksum: 3443 f62b934ffb45a01c0c54fa02c76ea68b Size/MD5 checksum: 129209 5bc166deb369a3c71efd61e1ad5e5475 Alphaarchitecture: Size/MD5 checksum: 77836 7526ae1261ebb7c9ce6113e5e5ff0e00 ARM architecture: Size/MD5 checksum: 78138 e4a4770c9cb604e1f53b7f273acef38c Intel IA-32 architecture: Size/MD5 checksum: 70656 e56242f5bd2639ae8ab6eed5c0f9a4f1 Intel IA-64 architecture: Size/MD5 checksum: 85918 63f85dde186643f4ade2d28a8e0a9b1c HP Precision architecture: Size/MD5 checksum: 77528 529d8f398a586c2da550d1f6516c3dd9 Motorola 680x0 architecture: Size/MD5 checksum: 67276 fd6dfc3edc2006c9ec5a6b7c178edbc0 Big endian MIPS architecture: Size/MD5 checksum: 75688 7ec5526fa01d8fd8d89e30132528e796 PowerPC architecture: Size/MD5 checksum: 72086 8450c5664bc45e3ba415a4ae7dbfe04a IBM S/390 architecture: Size/MD5 checksum: 70246 04d89911bd4a830d10f09f67ff5215e2 Sun Sparc architecture: Size/MD5 checksum: 72078 a14d6100f23836795db0f3440e8f3c64 These files will probably be moved into the stable distribution on its next revision. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . A vulnerability in the Synaesthesia package allows improper file creation, risking unauthorized access.. Debian Security, Insecure File Creation, Synaesthesia Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 23, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here