Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian Security Advisory DSA-2757-1: WordPress Remote Threats Alert

Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from releases announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2757-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Yves-Alexis Perez September 14, 2013 http://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wordpress Vulnerability : several Problem type : remote Debian-specific: no CVE ID : CVE-2013-4338 CVE-2013-4339 CVE-2013-4340 CVE-2013-5738 CVE-2013-5739 Debian Bug : 722537 Several vulnerabilities were identified in Wordpress, a web blogging tool. As the CVEs were allocated from releases announcements and specific fixes are usually not identified, it has been decided to upgrade the Wordpress package to the latest upstream version instead of backporting the patches. This means extra care should be taken when upgrading, especially when using third-party plugins or themes, since compatibility may have been impacted along the way. We recommend that users check their install before doing the upgrade. CVE-2013-4338 Unsafe PHP unserialization in wp-includes/functions.php could cause arbitrary code execution. CVE-2013-4339 Insufficient input validation could result in redirecting or leading a user to another website. CVE-2013-4340 Privilege escalation allowing an user with an author role to create an entry appearing as written by another user. CVE-2013-5738 Insufficient capabilities were required for uploading .html/.html files, making it easier for authenticated users to conduct cross-site scripting attacks (XSS) usingcrafted html file uploads. CVE-2013-5739 Default Wordpress configuration allowed file upload for .swf/.exe files, making it easier for authenticated users to conduct cross-site scripting attacks (XSS). For the oldstable distribution (squeeze), these problems have been fixed in version 3.6.1+dfsg-1~deb6u1. For the stable distribution (wheezy), these problems have been fixed in version 3.6.1+dfsg-1~deb7u1. For the testing distribution (jessie), these problems have been fixed in version 3.6.1+dfsg-1. For the unstable distribution (sid), these problems have been fixed in version 3.6.1+dfsg-1. We recommend that you upgrade your wordpress packages. Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: http://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A number of weaknesses discovered in Joomla have resulted in urgent security patch advisories for Ubuntu users.. Wordpress Security, Debian Advisory, Remote Threats, Upgrade Guidance. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 14, 2013 Important Debian
87

Debian 3.0: DSA 502-1 Moderate: Exim-TLS Buffer Overflow Risk

These can not be exploited with the default configuration from the Debian system.. Debian Security Advisory DSA 502-1 This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Martin Schulze May 11th, 2004 Debian -- Debian security FAQ - -------------------------------------------------------------------------- Package : exim-tls Vulnerability : buffer overflow Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0399 CAN-2004-0400 Georgi Guninski discovered two stack-based buffer overflows in exim and exim-tls. They can not be exploited with the default configuration from the Debian system, though. The Common Vulnerabilities and Exposures project identifies the following problems that are fixed with this update: CAN-2004-0399 When "sender_verify = true" is configured in exim.conf a buffer overflow can happen during verification of the sender. This problem is fixed in exim 4. CAN-2004-0400 When headers_check_syntax is configured in exim.conf a buffer overflow can happen during the header check. This problem does also exist in exim 4. For the stable distribution (woody) these problems have been fixed in version 3.35-3woody2. The unstable distribution (sid) does not contain exim-tls anymore. The functionality has been incorporated in the main exim versions which have these problems fixed in version 3.36-11 for exim 3 and in version 4.33-1 for exim 4. We recommend that you upgrade your exim-tls package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux3.0 alias woody - -------------------------------- Source archives: Size/MD5 checksum: 677 992f537ab952a5dc72ca5dbc81a84fbc Size/MD5 checksum: 80179 3f0742c775c071b21c0b09527dad75ec Size/MD5 checksum: 1271057 42d362e40a21bd7ffc298f92c8bd986a Alpha architecture: Size/MD5 checksum: 873574 7430b4927e9c2078c59eafe17bae5165 ARM architecture: Size/MD5 checksum: 783982 06a82a303c171107d2f1688b482377bd Intel IA-32 architecture: Size/MD5 checksum: 759420 ea3302d15ec0d601c5019d45c8c0b096 Intel IA-64 architecture: Size/MD5 checksum: 973922 e3ac0d7664959623d55b597c8aa56572 HP Precision architecture: Size/MD5 checksum: 814182 1c943be21bc25358690ac086c2a45994 Motorola 680x0 architecture: Size/MD5 checksum: 736562 71dec71d4ec85be81886484d00bd1e3c Big endian MIPS architecture: Size/MD5 checksum: 824300 c9fca04199e8fd78a4b96de92098957a Little endian MIPS architecture: Size/MD5 checksum: 824960 6d51d7fbad04d5aa80503ee0ded41c4d PowerPC architecture: Size/MD5 checksum: 792588 5a51bcc85377381bfbcb03ebdfe22eb8 IBM S/390 architecture: Size/MD5 checksum: 779108 e625ab3a0334821727ec96462e048532 Sun Sparc architecture: Size/MD5 checksum: 782712 f2ec2bbe42fc7ee482d4707443cc83fc These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb Debian -- Security Information stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Key instructions to address buffer overflow risks in Exim-TLS on Debian, ensuring system security and stability.. Debian Security, Exim TLS, Buffer Overflow, Update Guidance,Security Advisory. . LinuxSecurity.com Team

Calendar 2 May 12, 2004 Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here