Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
172

Ubuntu 24.04: USN-6997-1 Critical: LibTIFF Denial of Service

LibTIFF could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6997-1 September 09, 2024 tiff vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: LibTIFF could be made to crash if it received specially crafted input. Software Description: - tiff: Tag Image File Format (TIFF) library Details: It was discovered that LibTIFF incorrectly handled memory. An attacker could possibly use this issue to cause the application to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libtiff6 4.5.1+git230720-4ubuntu2.2 Ubuntu 22.04 LTS libtiff5 4.3.0-6ubuntu0.10 Ubuntu 20.04 LTS libtiff5 4.1.0+git191117-2ubuntu0.20.04.14 Ubuntu 18.04 LTS libtiff5 4.0.9-5ubuntu0.10+esm7 Available with Ubuntu Pro Ubuntu 16.04 LTS libtiff5 4.0.6-1ubuntu0.8+esm17 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6997-1 CVE-2024-7006 Package Information: https://launchpad.net/ubuntu/+source/tiff/4.5.1+git230720-4ubuntu2.2 https://launchpad.net/ubuntu/+source/tiff/4.3.0-6ubuntu0.10 https://launchpad.net/ubuntu/+source/tiff/4.1.0+git191117-2ubuntu0.20.04.14 . Modified input may lead to LibTIFFfailure. Make sure your Ubuntu installations are current for improved reliability.. LibTIFF Security Advisory, Ubuntu Update, Denial of Service. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 09, 2024 Critical Ubuntu
202

openSUSE: 2018:3948-1 Moderate: tiff Issues Addressed in Update

An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for tiff ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:3948-1 Rating: moderate References: #1099257 #1113094 #1113672 Cross-References: CVE-2018-12900 CVE-2018-18557 CVE-2018-18661 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for tiff fixes the following issues: Security issues fixed: - CVE-2018-12900: Fixed heap-based buffer overflow in the cpSeparateBufToContigBuf (bsc#1099257). - CVE-2018-18661: Fixed NULL pointer dereference in the function LZWDecode in the file tif_lzw.c (bsc#1113672). - CVE-2018-18557: Fixed JBIG decode can lead to out-of-bounds write (bsc#1113094). Non-security issues fixed: - asan_build: build ASAN included - debug_build: build more suitable for debugging This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2018-1480=1 Package List: - openSUSE Leap 15.0 (i586 x86_64): libtiff-devel-4.0.9-lp150.4.9.1 libtiff5-4.0.9-lp150.4.9.1 libtiff5-debuginfo-4.0.9-lp150.4.9.1 tiff-4.0.9-lp150.4.9.1 tiff-debuginfo-4.0.9-lp150.4.9.1 tiff-debugsource-4.0.9-lp150.4.9.1 - openSUSE Leap 15.0 (x86_64): libtiff-devel-32bit-4.0.9-lp150.4.9.1 libtiff5-32bit-4.0.9-lp150.4.9.1 libtiff5-32bit-debuginfo-4.0.9-lp150.4.9.1 References: https://www.suse.com/security/cve/CVE-2018-12900.html https://www.suse.com/security/cve/CVE-2018-18557.html https://www.suse.com/security/cve/CVE-2018-18661.html https://bugzilla.suse.com/1099257 https://bugzilla.suse.com/1113094 https://bugzilla.suse.com/1113672 -- . Tackling significant vulnerabilities in the openSUSE Security Upgrade through vital fix procedures for users.. openSUSE Update,tiff Patch,tiff Security Fix,Moderate Issues,Security Updates. . LinuxSecurity.com Team

Calendar 2 Nov 30, 2018 OpenSUSE
172

Ubuntu: 797-1 Critical: TIFF Library Denial Of Service Risk

It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service. [More...]. ==========================================================Ubuntu Security Notice USN-797-1 July 06, 2009 tiff vulnerability CVE-2009-2285 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: libtiff4 3.7.4-1ubuntu3.4 Ubuntu 8.04 LTS: libtiff4 3.8.2-7ubuntu3.2 Ubuntu 8.10: libtiff4 3.8.2-11ubuntu0.8.10.1 Ubuntu 9.04: libtiff4 3.8.2-11ubuntu0.9.04.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that the TIFF library did not correctly handle certain malformed TIFF images. If a user or automated system were tricked into processing a malicious image, a remote attacker could cause an application linked against libtiff to crash, leading to a denial of service. Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 19878 69684a7a9c033fb40c755d2bb4dffaa2 Size/MD5: 764 2a6cbe50d507d9c402ad4e92fa1a66b8 Size/MD5: 1280113 02cf5c3820bda83b35bb35b45ae27005 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 220708 159dcfd51cf69df380ea71620b922f04 Size/MD5: 282354 541c2a6b0fe97743b984dd97c20395fd Size/MD5: 475612 4cb99e064c4547553f0edb081c529809 Size/MD5: 446624f662fbcf9fa548ab4f8b8754306c69b Size/MD5: 49846 953651334379bbaca92baf34950e2405 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 205896 f5ca6a96e1d3dedb3daea18094d65ac3 Size/MD5: 258978 6f612fbbf5ef115b4dcce981dcacf46f Size/MD5: 461822 ccb6e0322690b9e0f4064ee72813bd1f Size/MD5: 44646 fedd7054ff09c4a761f0bf052adc9dbb Size/MD5: 49176 4b422744db9046b2e6c24e2eeb8d0863 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 239714 2c126df7fad173e8e8facfbfe70d96bf Size/MD5: 288002 38a94eccdd4d769d5c833a4c18861a66 Size/MD5: 475924 aae7d86246008c63a0ef95a08b5f4eb2 Size/MD5: 46874 da98b514589753068801921dc68ceae6 Size/MD5: 51514 80ac11ceaaffc8f848967b0811b7f5e2 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 208520 4abc2ee74c41ba87917b975a7cb758ed Size/MD5: 269972 3cdfd7084bf54d17643e2f00793fb3a5 Size/MD5: 466632 b2c1bfb026aac831ced2ce4dafebf860 Size/MD5: 44594 f97d5668dd1b3deeb9992be92e1ffc7f Size/MD5: 49728 c4ce31f33d03dc294f40ada0bc955887 Updated packages for Ubuntu 8.04 LTS: Source archives: Size/MD5: 18378 450fcf81a838b9c67637987a2b39088b Size/MD5: 860 92cf9f6d3136c5b6fb52e4d123c0fdd5 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 186242 28dff44adbabe76ab7e85ff2da365f9d Size/MD5: 570796 315cdea73e2f4c28c891848d7e7e4fc0 Size/MD5: 130702 854535fab48a5f2a37a9256f61a38ab5 Size/MD5: 5064 4097c51386aaaafbfeae9eabaeb997c9 Size/MD5: 10494 49c45bed31e28bcd9d5e706f1c8db3cc i386 architecture (x86 compatible Intel/AMD): Size/MD5: 175048 01226d438f325312684575560d86d93b Size/MD5: 552280 36c3a1e37d12f1992346a057e4dab075 Size/MD5: 12240044cb0efa99a513084835be466da2cb7d Size/MD5: 5048 db565d6e40fa1b15e6ff9b87a599c0d7 Size/MD5: 9942 c7f799a523da81cee7c90ade65be2ccd lpia architecture (Low Power Intel Architecture): Size/MD5: 177116 df191c9d5e2f48103589d92a59b902d1 Size/MD5: 554842 2d10224badec0434fbb9d21d432df89d Size/MD5: 123556 534d8b03274794d0563a3b48001143c7 Size/MD5: 4920 264e617e42f1c8972cb1b2bb18a91574 Size/MD5: 9976 e5940f1dbb7d090a4e5d47cca0daeca2 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 223238 2385fe8b199cce7295eaea9282cacf24 Size/MD5: 576794 51814c281f84fe2e0650d3f8e029ac4a Size/MD5: 134016 3df0fd7a4ad96106e2f5143f1645b102 Size/MD5: 7514 5963503e765f0fe71ffa80fbc60c162f Size/MD5: 13286 3f3851bf7186b2d4450d35beeec0bb4d sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 178640 086f9b0f2e83f879e323fd924f8a89f2 Size/MD5: 558202 b334310f53743de237845e24fcd911ec Size/MD5: 122160 95fd3e3346b8dce74e274239d00c018b Size/MD5: 4800 4a09138aa5f408d8fe49057f90cd0df1 Size/MD5: 10710 18641ce46b309baeb923165dd8e03158 Updated packages for Ubuntu 8.10: Source archives: Size/MD5: 37962 6c0956eecb7503bdb31a1bd4299efe47 Size/MD5: 1328 7548341cdd1a4a9bae7c793b6f677233 Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334688 eff9827309f80a957196e9cd4da695d8 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 250518 61fe3d4dd8def51dbd2b5d9b4159a9bc Size/MD5: 134084 c2adab0fb711634f47e695f3dd7447f8 Size/MD5: 6286 4b2563a3b767209061646fa6ae9ac85b Size/MD5: 11898 81a456c5d470799230c6a44f9cc8f9b9 Size/MD5: 191424 82a9fa8eb070e32116b0d8ecd5a22e0d i386 architecture (x86 compatibleIntel/AMD): Size/MD5: 233298 a01eb038a2ccbef8b6603525bc3f2f75 Size/MD5: 125878 4eda3acf59c21aba5e1cc89e96bfa8cc Size/MD5: 6272 a6ec88be551d729364d27af4863e1b11 Size/MD5: 11236 359d02f2dcdad53dcf72d0619aff697b Size/MD5: 176054 42b7f0efbbc73b45d6e69053ebf33671 lpia architecture (Low Power Intel Architecture): Size/MD5: 235774 ca05ad7d9e13ada710db91e738800eab Size/MD5: 127584 cf7c86c00c4a0e05cac37039288965f0 Size/MD5: 6132 a865f92bff1a6c22b927ee8af097c433 Size/MD5: 11282 733acc73b8be40399063ff28128525f5 Size/MD5: 178278 523c412323f658d260ae6a4d2ff40966 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 256510 d4b027ddeb929f3589956ba496cffba0 Size/MD5: 137148 e32d2bdd0d4a7cc71eec5e7daed52aa9 Size/MD5: 8724 cc701a74b724ca482b21a3dc321949c3 Size/MD5: 14234 cbff4f6e6faddfde029ff78ec9c48afb Size/MD5: 221040 f917935a1761ef9848e8c7c10e0ef06b sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 237666 5d6d33cc67ef0d14bd626ccb4dd9bcb6 Size/MD5: 123990 190cefef6ceb37c906aecaf1bf59b876 Size/MD5: 6006 6ec8001760781f1af9d8592866ff82fe Size/MD5: 12046 a2b4639c81cb79b31b0646657205fa35 Size/MD5: 183412 8ff9e8d6a32d80872131327e5203796c Updated packages for Ubuntu 9.04: Source archives: Size/MD5: 37962 438146f23bcd7888fcc66c7b9d78098b Size/MD5: 1328 9ec573172e0fde174b56d0a3956ee35b Size/MD5: 1333780 e6ec4ab957ef49d5aabc38b7a376910b Architecture independent packages: Size/MD5: 334670 fa4a10e51620299585fa1642196f2887 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 191466 a61b82a3393f44e40cd2cc0f640eb6c6 Size/MD5: 250604 cd4538b261cc9003e7c131adda8b51ca Size/MD5: 134104 38fa2282b5e992c72a4ac79e0ece52b0 Size/MD5: 6286 401262f1a09831f0130f0db2872c97f6 Size/MD5: 11898 bdf96619188143fe417e8fa3bc5f780d i386 architecture (x86 compatible Intel/AMD): Size/MD5: 176050 aa334ea8a28d5274741368d08b0f795d Size/MD5: 233334 2f3bfd25e51a9cca95f4c58646318d29 Size/MD5: 125970 3ceceb06c0b6b94fa508e008f19408b7 Size/MD5: 6272 35faf1e62dc2e57509ef98116b4c7cfb Size/MD5: 11228 0abf911853cdb7cd1020f5c43782ab92 lpia architecture (Low Power Intel Architecture): Size/MD5: 178280 db957830b08ec26fc211e78674f175c7 Size/MD5: 235772 146d7fbd61e3885873c2d884c3f289be Size/MD5: 127566 bec17756ac7d7c5c94fb4823b297b6df Size/MD5: 6126 36ebd0a2f1faaa2d67cdc9687377047b Size/MD5: 11276 efd0a2c2218bfbcd1a9211d85945fa43 powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 221080 3ba1c50579c20918faaef6191ed041eb Size/MD5: 256338 eeb0f7815019f42674e3ed5fdfc72036 Size/MD5: 136980 638fb9b42c406d00b1510a926b5ed3ba Size/MD5: 8726 50665d1f710dba6dc2742e2bb57acf02 Size/MD5: 14228 3f0ee5ed9b9d24b19ec162f1c71127ce sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 183404 2852bdbf720008437395f7821c827fd4 Size/MD5: 237662 9da18282c48f96aabf98965c0717d9b2 Size/MD5: 123884 1600707f7478f01789738311510f598a Size/MD5: 5970 15efadc4f18985aa1fadc50bec55d099 Size/MD5: 12018 1475302ae62826aced512ca859a2c237 . An urgent security notice regarding a vulnerability in a TIFF image library across various Ubuntu distributions uncovers potential threats posed by harmful image files.. tiff library risk, ubuntu 797-1 advisory, denial of service, libtiff security issue, update instructions. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jul 06, 2009 Critical Ubuntu
91

Gentoo: 200412-17 Normal Advisory - kfax Buffer Overflow Risk

kfax contains several buffer overflows potentially leading to execution of arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200412-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: kfax: Multiple overflows in the included TIFF library Date: December 19, 2004 Bugs: #73795 ID: 200412-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= kfax contains several buffer overflows potentially leading to execution of arbitrary code. Background ========= KDE is a feature-rich graphical desktop environment for Linux and Unix-like Operating Systems. kfax (part of kdegraphics) is the KDE fax file viewer. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdegraphics < 3.3.1 Vulnerable! ------------------------------------------------------------------- NOTE: Certain packages are still vulnerable. See Workaround. Description ========== Than Ngo discovered that kfax contains a private copy of the TIFF library and is therefore subject to several known vulnerabilities (see References). Impact ===== A remote attacker could entice a user to view a carefully-crafted TIFF image file with kfax, which would potentially lead to execution of arbitrary code with the rights of the user running kfax. Workaround ========= The KDE Team recommends to remove the kfax binary as well as the kfaxpart.la KPart: rm /usr/kde/3.*/lib/kde3/kfaxpart.la rm /usr/kde/3.*/bin/kfax Note: This will render the kfax functionality useless, ifkfax functionality is needed you should upgrade to the KDE 3.3.2 which is not stable at the time of this writing. Resolution ========= All kfax users should use the workaround as no patches are available yet. References ========= [ 1 ] KDE Security Advisory: kfax libtiff vulnerabilities https://kde.org/info/security/advisory-20041209-2.txt [ 2 ] GLSA 200410-11 https://security.gentoo.org/glsa/200410-11 [ 3 ] CAN-2004-0803 https://www.cve.org/CVERecord?id=CVE-CAN-2004-0803 [ 4 ] CAN-2004-0804 https://www.cve.org/CVERecord?id=CVE-CAN-2004-0804 [ 5 ] CAN-2004-0886 https://www.cve.org/CVERecord?id=CVE-CAN-2004-0886 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200412-17 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Explore Gentoo GLSA 200412-17 regarding kfax, a buffer overflow issue leading to possible arbitrary code execution.. Gentoo Security,kfax Overflows,TIFF Vulnerability,KDE Security Advisory. . LinuxSecurity.com Team

Calendar 2 Dec 19, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here