Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
98

Red Hat Powertools: RHSA-2002:054-09 Moderate: Race Condition in Logwatch

Updated LogWatch packages are available that fix tmp file race conditionswhich can cause a local user to gain root privileges.. ` --------------------------------------------------------------------- Red Hat, Inc. Red Hat Security Advisory Synopsis: Race conditions in logwatch Advisory ID: RHSA-2002:054-09 Issue date: 2002-03-28 Updated on: 2002-04-04 Product: Red Hat Powertools Keywords: logwatch tmp race Cross references: RHSA-2002:053 Obsoletes: --------------------------------------------------------------------- 1. Topic: Updated LogWatch packages are available that fix tmp file race conditions which can cause a local user to gain root privileges. 2. Relevant releases/architectures: Red Hat Powertools 6.2 - noarch Red Hat Powertools 7.0 - noarch Red Hat Powertools 7.1 - noarch 3. Problem description: LogWatch is a customizable log analysis system which was available in Red Hat Powertools. Versions of LogWatch 2.1.1 and earlier have a vulnerability due to a race condition during the creation of a temporary directory. This vulnerability can allow a local user to gain root privileges. An additional race condition was found in versions of LogWatch 2.5 and earlier. Users should update to the errata packages containing Logwatch 2.6, which is not vulnerable to these issues. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CAN-2002-0162 and CAN-2002-0165 to these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. To update all RPMs for your particular architecture, run: rpm -Fvh [filenames] where [filenames] is a list of the RPMs you wish to upgrade. Only those RPMs which are currently installed will be updated. Those RPMs which are not installed but included in the list will not be updated. Note that you can also use wildcards (*.rpm) if your current directory *only* contains the desiredRPMs. Please note that this update is also available via Red Hat Network. Many people find this an easier way to apply updates. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date This will start an interactive process that will result in the appropriate RPMs being upgraded on your system. 5. Bug IDs fixed ( for more info): 62055 - A /tmp race condition leads to root 46371 - Handle accepted packets, not just reject and deny 56191 - logwatch is too noisy 58578 - Problem with RPM dependance 61202 - Logwatch logs appear to have emerged themselves with other logfiles. They are semi-unreadable 61829 - logwatch's sshd filter should scan secure logs 61831 - logwatch modprobe filter should allow dashes in module names 61832 - secure filter should ignore sshd messages 6. RPMs required: Red Hat Powertools 6.2: SRPMS: noarch: Red Hat Powertools 7.0: SRPMS: noarch: Red Hat Powertools 7.1: SRPMS: noarch: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- bb75f22ed70447d6a46d5d5b2a7ec7aa 6.2/en/powertools/SRPMS/logwatch-2.6-1.src.rpm ac8ea7498a2d6b14bb325a511cf8ba6b 6.2/en/powertools/noarch/logwatch-2.6-1.noarch.rpm bb75f22ed70447d6a46d5d5b2a7ec7aa 7.0/en/powertools/SRPMS/logwatch-2.6-1.src.rpm ac8ea7498a2d6b14bb325a511cf8ba6b 7.0/en/powertools/noarch/logwatch-2.6-1.noarch.rpm bb75f22ed70447d6a46d5d5b2a7ec7aa 7.1/en/powertools/SRPMS/logwatch-2.6-1.src.rpm ac8ea7498a2d6b14bb325a511cf8ba6b 7.1/en/powertools/noarch/logwatch-2.6-1.noarch.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: About You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: CVE -CVE-2002-0162 CVE -CVE-2002-0165 Copyright(c)2000, 2001, 2002 Red Hat, Inc. `. LogWatch update addresses a race condition vulnerability allowing local users to gain root privileges. Immediate actions recommended.. Logwatch Update, Red Hat Advisory, Race Condition Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Apr 05, 2002 Important Red Hat
98

Red Hat Linux 6.1, 6.2, 7.0 RHSA-2000:072-08 Critical: Local Exploit

A significant number of bugs, including tmp file creation vulnerabilities have been fixed. . ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: Updated gnorpm packages are available for Red Hat Linux 6.1, 6.2, and 7.0 Advisory ID: RHSA-2000:072-08 Issue date: 2000-10-04 Updated on: 2000-11-27 Product: Red Hat Linux Keywords: security tmp rpm Cross references: N/A --------------------------------------------------------------------- 1. Topic: (This is a re-release of the previous errata caused by a missing patch). A locally-exploitable security hole was found where a normal user could trick root running GnoRPM into writing to arbitrary files due to a bug in the gnorpm tmp file handling. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha 2. Relevant releases/architectures: Red Hat Linux 6.1 - i386, alpha, sparc Red Hat Linux 6.2 - i386, alpha, sparc Red Hat Linux 7.0 - i386, alpha 3. Problem description: While fixing other problems with the gnorpm package, a locally-exploitable security hole was found where a normal user could trick root running GnoRPM into writing to arbitrary files due to a bug in the gnorpm tmp file handling. A new release of GnoRPM (0.95.1) is now available. This fixes a significant number of bugs in the gnorpm package, including this security hole. Administrators who use this program on multi-user machines should update it, and anyone who uses it regularly will notice vast improvements. All versions of GnoRPM before 0.95 are believed to be vulnerable. 4. Solution: For each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. PLEASE NOTE: Due to library compatibility issues, this release of GnoRPM 0.95.1 cannot be used on a Red Hat Linux 6.0 system. If you are running Red Hat Linux 6.0, to close this security hole you shouldabstain from using GnoRPM until packages are available for that release. Alternatively you may upgrade to a later version of Red Hat Linux. Packages that function properly on a Red Hat Linux 6.0 system are in development. 5. Bug IDs fixed ( for more info): 6611 - GNORPM crashes when changing filter in the install window 6657 - gnorpm crashes 6659 - need summary 7678 - Corrupted .gnome/gnorpm.d/resources/fullIndex.rdf.gz 9254 - GnoRPM dies behind firewall 10162 - "Query" button in toolbar doesn't work properly 14327 - Querying RPMs after drag'n'drop crashes gnorpm 6. RPMs required: Red Hat Linux 6.2: alpha: sparc: i386: sources: Red Hat Linux 7.0: alpha: i386: sources: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 3d77624520a703638658134218018331 6.2/SRPMS/gnorpm-0.95.1-5.6x.src.rpm b265bbbe50bb057ca0b8a5e33dca4017 6.2/alpha/gnorpm-0.95.1-5.6x.alpha.rpm 5e447c0cc6cd363531d2ed58534daae2 6.2/i386/gnorpm-0.95.1-5.6x.i386.rpm 0de5eea58096827c3f3c3382088d6115 6.2/sparc/gnorpm-0.95.1-5.6x.sparc.rpm fd7d7e3bd554b4dcd3e13632906f27e9 7.0/SRPMS/gnorpm-0.95.1-5.src.rpm 48f5f0dc6a0b17cd204a9bc6ab6c2a86 7.0/alpha/gnorpm-0.95.1-5.alpha.rpm 1df97ee9659fc0f10c2f06ef69954228 7.0/i386/gnorpm-0.95.1-5.i386.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: N/A Copyright(c) 2000 Red Hat, Inc. ` . Critical update for Red Hat Linux addressing local exploitable bug in GnoRPM's tmp file handling. Immediate action advised.. GnoRPM, Red Hat Linux, Local Exploit, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 27, 2000 Critical Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":549,"type":"x","order":1,"pct":78.54,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.29,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.86,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.3,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here