Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
197

Debian 10: DLA-3762-1 Moderate: unadf Arbitrary Code Execution

Two vulnerabilities have been fixed in unADF, a tool to extract files from an Amiga Disk File dump. CVE-2016-1243 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3762-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk March 15, 2024 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : unadf Version : 0.7.11a-4+deb11u1~deb10u1 CVE ID : CVE-2016-1243 CVE-2016-1244 Debian Bug : 838248 Two vulnerabilities have been fixed in unADF, a tool to extract files from an Amiga Disk File dump. CVE-2016-1243 arbitrary code execution via long pathname CVE-2016-1244 arbitrary code execution via shell metacharacters in directory names For Debian 10 buster, these problems have been fixed in version 0.7.11a-4+deb11u1~deb10u1. We recommend that you upgrade your unadf packages. For the detailed security status of unadf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/unadf Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance unadf to address security concerns such as arbitrary code execution risks affecting Debian LTS environments.. Debian LTS Security Update, unadf Tool Security, File Extraction Vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Mar 15, 2024 Important Debian LTS
91

Gentoo: GLSA-201804-20 Normal: unADF Remote Execution Risk

Multiple vulnerabilities have been found in unADF that may allow a remote attacker to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201804-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: unADF: Remote code execution Date: April 22, 2018 Bugs: #636388 ID: 201804-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in unADF that may allow a remote attacker to execute arbitrary code. Background ========= An unzip like for .ADF files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/unadf < 0.7.12-r1 > = 0.7.12-r1 Description ========== Multiple vulnerabilities were discovered in unADF that can lead to remote code execution. Please review the CVE identifiers referenced below for details. Impact ===== A remote attacker, by enticing a user to process a specially crafted file, could execute arbitrary code. Workaround ========= There is no known workaround at this time. Resolution ========= All unADF users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/unadf-0.7.12-r1" References ========= [ 1 ] CVE-2016-1243 https://nvd.nist.gov/vuln/detail/CVE-2016-1243 [ 2 ] CVE-2016-1244 https://nvd.nist.gov/vuln/detail/CVE-2016-1244 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201804-20 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2018 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Several flaws in unADF could enable distant adversaries to run unauthorized code. Update to the most recent version.. Gentoo Security, unADF Threat, Remote Execution. . LinuxSecurity.com Team

Calendar 2 Apr 22, 2018 Gentoo
87

Debian 0.7.11a-3 Critical: unADF Buffer Overflow and Code Execution

Tuomas Räsänen discovered two vulnerabilities in unADF, a tool to extract files from an Amiga Disk File dump (.adf): CVE-2016-1243 . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3676-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Luciano Bello September 24, 2016 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : unadf CVE ID : CVE-2016-1243 CVE-2016-1244 Debian Bug : 838248 Tuomas Räsänen discovered two vulnerabilities in unADF, a tool to extract files from an Amiga Disk File dump (.adf): CVE-2016-1243 A stack buffer overflow in the function extractTree() might allow an attacker, with control on the content of a ADF file, to execute arbitrary code with the privileges of the program execution. CVE-2016-1244 The unADF extractor creates the path in the destination via a mkdir in a system() call. Since there was no sanitization on the input of the filenames, an attacker can directly inject code in the pathnames of archived directories in an ADF file. For the oldstable distribution (wheezy), these problems have been fixed in version 0.7.11a-3+deb7u1. For the stable distribution (jessie), these problems have been fixed in version 0.7.11a-3+deb8u1. For the unstable distribution (sid), these problems have been fixed in version 0.7.11a-4. We recommend that you upgrade your unadf packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA-3677-1 addresses issues found in libXYZ which affect system integrity and data management.. unadf vulnerabilities, debian security update, buffer overflow, code execution, code injection. . Severity:Critical. LinuxSecurity.com Team

Calendar 2 Sep 24, 2016 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here