Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 477
Alerts This Week
Warning Icon 1 477

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
200

SciLinux: tk Security Update For SL4.x and SL5.x Moderate Buffer Overflow

Moderate: tk security update. Date: Mon, 25 Feb 2008 11:57:45 -0600 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for tk on SL4.x, SL5.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Moderate: tk security update Issue date: 2008-02-21 CVE Names: CVE-2008-0553 CVE-2007-5137 CVE-2007-5378 An input validation flaw was discovered in Tk's GIF image handling. A code-size value read from a GIF image was not properly validated before being used, leading to a buffer overflow. A specially crafted GIF file could use this to cause a crash or, potentially, execute code with the privileges of the application using the Tk graphical toolkit. (CVE-2008-0553) A buffer overflow flaw was discovered in Tk's animated GIF image handling. An animated GIF containing an initial image smaller than subsequent images could cause a crash or, potentially, execute code with the privileges of the application using the Tk library. (CVE-2007-5137) A buffer overflow flaw was discovered in Tk's animated GIF image handling. An animated GIF containing an initial image smaller than subsequent images could cause a crash or, potentially, execute code with the privileges of the application using the Tk library. (CVE-2007-5378) SL 4.x SRPMS: tk-8.4.7-3.el4_6.1.src.rpm i386: tk-8.4.7-3.el4_6.1.i386.rpm tk-devel-8.4.7-3.el4_6.1.i386.rpm x86_64: tk-8.4.7-3.el4_6.1.i386.rpm tk-8.4.7-3.el4_6.1.x86_64.rpm tk-devel-8.4.7-3.el4_6.1.x86_64.rpm SL 5.x SRPMS: tk-8.4.13-5.el5_1.1.src.rpm i386: tk-8.4.13-5.el5_1.1.i386.rpm tk-devel-8.4.13-5.el5_1.1.i386.rpm x86_64: tk-8.4.13-5.el5_1.1.i386.rpm tk-8.4.13-5.el5_1.1.x86_64.rpm tk-devel-8.4.13-5.el5_1.1.i386.rpm tk-devel-8.4.13-5.el5_1.1.x86_64.rpm -Connie Sieh -Troy Dawson . Critical tk security enhancement fixing input vulnerabilities within GIF processing for SL4.x and SL5.x systems.. tk security update, SL4.x vulnerabilities, SL5.x security fixes. . LinuxSecurity.com Team

Calendar%202 Feb 25, 2008 Scientific Linux
89

Fedora 8 2008-1142 Moderate: Tk Memory Leak in PNG Handling

Fixed security issue - buffer overflow in gif parsing.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2008-1131 2008-02-05 23:10:30 --------------------------------------------------------------------------------Name : tk Product : Fedora 7 Version : 8.4.13 Release : 7.fc7 URL : Summary : The graphical toolkit for the Tcl scripting language Description : When paired with the Tcl scripting language, Tk provides a fast and powerful way to create cross-platform GUI applications. --------------------------------------------------------------------------------Update Information: Fixed security issue - buffer overflow in gif parsing. --------------------------------------------------------------------------------ChangeLog: * Mon Jan 28 2008 Marcela Maslanova - 1:8.4.13-7 - attached upstream patch - similar to CVE-2006-4484, problem with GIF again #430100 * Mon Oct 15 2007 Marcela Maslanova - 1:8.4.13-6 - CVE-2007-5137 gif buffer overflow --------------------------------------------------------------------------------References: [ 1 ] Bug #431518 - CVE-2008-0553 tk: GIF handling buffer overflow https://bugzilla.redhat.com/show_bug.cgi?id=431518 --------------------------------------------------------------------------------This update can be installed with the "yum" update program. Use su -c 'yum update tk' at the command line. For more information, refer to "Managing Software with yum", available at . All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ Fedora-package-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Thelatest Fedora update addresses a critical buffer overflow issue found in gif parsing within tk applications, thereby bolstering system security.. Fedora Update, Tk Security Patch, Buffer Overflow Fix, GIF Parsing Issue. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 07, 2008 Important Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":1,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":50,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200