Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian DSA-2009-1: Moderate Tdiary Cross-Site Scripting Threat

It was discovered that tdiary, a communication-friendly weblog system, is prone to a cross-site scripting vulnerability due to insuficient input sanitising in the TrackBack transmission plugin. . - ------------------------------------------------------------------------ Debian Security Advisory DSA-2009-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Steffen Joeris March 09, 2010 http://www.debian.org/security/faq - ------------------------------------------------------------------------ Package : tdiary Vulnerability : insufficient input sanitising Problem type : remote Debian-specific: no CVE Id : CVE-2010-0726 Debian Bug : 572417 It was discovered that tdiary, a communication-friendly weblog system, is prone to a cross-site scripting vulnerability due to insuficient input sanitising in the TrackBack transmission plugin. For the stable distribution (lenny), this problem has been fixed in version 2.2.1-1+lenny1. For the testing distribution (squeeze), this problem will be fixed soon. For the unstable distribution (sid), this problem has been fixed in version 2.2.1-1.1. We recommend that you upgrade your tdiary packages. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updates are available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1083 3256337487cc7177ac6a20a5815c2e5e Size/MD5 checksum: 2884847109a3e807f5595fb580a3eed3ce2a6 Size/MD5 checksum: 4207143 41bd634fc4a8a6ffe93f70d33c826865 Architecture independent packages: Size/MD5 checksum: 3671582 e23890cfcdbd50cf8edd68dea769f8ec Size/MD5 checksum: 209268 4425e9c291d09015b1d89eba2d345155 Size/MD5 checksum: 270084 c27fa1b2a89f4bc7edb08332aa0270ab Size/MD5 checksum: 36916 9fee97c0332c554040f646660c22b54d Size/MD5 checksum: 201722 cf6df3658938bc5df5839f29cd51d34e These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian Security Notice DSA-2020-5: Xwidget vulnerability patched for potential cross-origin exploits caused by inadequate filtering. Update immediately!. tdiary updates, debian security, cross-site scripting, input sanitization, remote threat. . LinuxSecurity.com Team

Calendar 2 Mar 09, 2010 Debian
87

Debian: DSA 809-1 Moderate: Tdiary Cross-Site Scripting Vulnerability

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 808-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze September 12th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : tdiary Vulnerability : design error Problem type : remote Debian-specific: no CVE ID : CAN-2005-2411 The tdiary Development Team has discovered a Cross-Site Request Forgery (CSRF) vulnerability in tdiary, a new generation weblog that can be exploited by remote attackers to alter the users information. The old stable distribution (woody) does not contain tdiary packages. For the stable distribution (sarge) this problem has been fixed in version 2.0.1-1sarge1. For the unstable distribution (sid) this problem has been fixed in version 2.0.2-1. We recommend that you upgrade your tdiary packages. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 698 725575945a14b3ff9ff776e4254b6e54 Size/MD5 checksum: 24611 df8afbbc86e0f1a9f365a1b8271e7a12 Size/MD5 checksum: 1840990 eaec0d3c00e1605d5cefad4119718183 Architecture independent components: Size/MD5 checksum: 109264 b3de14edff72c292002d68b4f6c5234c Size/MD5 checksum: 27768 632e5ed6bb82fce0d1f787aea0b25cf4 Size/MD5checksum: 155066 6100fce2dbe0a8acc5a365766b2b8b84 Size/MD5 checksum: 1506732 6a77d569ef301bc299ee4fe8e4f929f5 Size/MD5 checksum: 171434 b31846dc0632acdb13787a5ec28e8bc5 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Protect your Ubuntu system by patching susceptible tdiary software from CSRF threats.. Debian Security,Tdiary Update,CSRF Fix,Package Management. . LinuxSecurity.com Team

Calendar 2 Sep 12, 2005 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here