Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo: GLSA-202012-10 Normal: WebkitGTK+ Code Execution Risk

Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202012-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: WebkitGTK+: Multiple vulnerabilities Date: December 23, 2020 Bugs: #755947 ID: 202012-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in WebKitGTK+, the worst of which could result in the arbitrary execution of code. Background ========= WebKitGTK+ is a full-featured port of the WebKit rendering engine, suitable for projects requiring any kind of web integration, from hybrid HTML/CSS applications to full-fledged web browsers. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/webkit-gtk < 2.30.3 > = 2.30.3 Description ========== Multiple vulnerabilities have been discovered in WebKitGTK+. Please review the CVE identifiers referenced below for details. Impact ===== An attacker, by enticing a user to visit maliciously crafted web content, may be able to execute arbitrary code or cause memory corruption. Workaround ========= There is no known workaround at this time. Resolution ========= All WebkitGTK+ users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-libs/webkit-gtk-2.30.3" References ========= [ 1 ] CVE-2020-13543 https://nvd.nist.gov/vuln/detail/CVE-2020-13543 [ 2 ] CVE-2020-13584 https://nvd.nist.gov/vuln/detail/CVE-2020-13584 [ 3 ] CVE-2020-9948 https://nvd.nist.gov/vuln/detail/CVE-2020-9948 [ 4 ] CVE-2020-9951 https://nvd.nist.gov/vuln/detail/CVE-2020-9951 [ 5 ] CVE-2020-9952 https://nvd.nist.gov/vuln/detail/CVE-2020-9952 [ 6 ] CVE-2020-9983 https://nvd.nist.gov/vuln/detail/CVE-2020-9983 [ 7 ] WSA-2020-0008 https://webkitgtk.org/security/WSA-2020-0008.html [ 8 ] WSA-2020-0009 https://webkitgtk.org/security/WSA-2020-0009.html Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202012-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2020 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Examine the Gentoo notice regarding vulnerabilities in WebKitGTK+ that could permit remote code execution. It's crucial to upgrade your installations to maintain a secure environment.. WebKitGTK+, Gentoo Security Advisory, Code Execution Risk, Upgrade Instructions. . LinuxSecurity.com Team

Calendar 2 Dec 23, 2020 Gentoo
87

Debian 5.0 DSA-2029-1 Critical: Imlib2 Buffer Overflow Exploit

It was discovered that imlib2, a library to load and process several image formats, did not properly process various image file types. Several heap and stack based buffer overflows - partly due to integer overflows - in the ARGB, BMP, JPEG, LBM, PNM, TGA and XPM loaders can . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory DSA-2029-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Nico Golde April 5th, 2010 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : imlib2 Vulnerability : several Problem type : local Debian-specific: no Debian bug : 576469 CVE ID : CVE-2008-6079 It was discovered that imlib2, a library to load and process several image formats, did not properly process various image file types. Several heap and stack based buffer overflows - partly due to integer overflows - in the ARGB, BMP, JPEG, LBM, PNM, TGA and XPM loaders can lead to the execution of arbitrary code via crafted image files. For the stable distribution (lenny), this problem has been fixed in version 1.4.0-1.2+lenny1. For the testing distribution (squeeze), this problem has been fixed in version 1.4.2-1. For the unstable distribution (sid), this problem has been fixed in version 1.4.2-1. Upgrade instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 5.0 alias lenny - -------------------------------- Debian (stable) - --------------- Stable updatesare available for alpha, amd64, arm, armel, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc. Source archives: Size/MD5 checksum: 1152 b7cae77599a1ea2301395e18937d7788 Size/MD5 checksum: 845017 1f7f497798e06085767d645b0673562a Size/MD5 checksum: 58816 01418de90dce3c411ff6794b5d9e06cd alpha architecture (DEC Alpha) Size/MD5 checksum: 238740 5d728b77bdaf3ad6c9b7ec58d6e0348f Size/MD5 checksum: 430388 688de8efff4ab7f8612e46ab68febd5e amd64 architecture (AMD x86_64 (AMD64)) Size/MD5 checksum: 374282 62e14bee1f8870b98bf76c04e3e7145f Size/MD5 checksum: 220686 9d34ec5aa25ea6b531923d3db2553a4c arm architecture (ARM) Size/MD5 checksum: 340058 1e256f1b506e43e0c2d296fa6ea138ec Size/MD5 checksum: 206844 ce0402a348fb8dba20940c71ddde04f2 armel architecture (ARM EABI) Size/MD5 checksum: 342736 a9411677d132fbb85d89e0fae6edb22f Size/MD5 checksum: 215890 c80a62ed059ffd37d759e9192a22f220 hppa architecture (HP PA RISC) Size/MD5 checksum: 389348 7800351accb00c01d81b7bf5a99b88d7 Size/MD5 checksum: 227236 5b4a108161ef87f6907d35895bba46b9 i386 architecture (Intel ia32) Size/MD5 checksum: 208152 ae8a6d6ac41ea4969133270f73dae53f Size/MD5 checksum: 334920 1fa233439d1346ff20e637648d9e878d ia64 architecture (Intel ia64) Size/MD5 checksum: 461632 27e0586a22c9232dc7d878bc242b391b Size/MD5 checksum: 298746 133afe4b754ba5c17142e06afdfff6a1 mipsel architecture (MIPS (Little Endian)) Size/MD5 checksum: 372840 0acfa48bcf0b171c1eaee35a11669e76 Size/MD5 checksum: 210698 a15c7f21dd022c23f295a31c79073680 powerpc architecture (PowerPC) Size/MD5 checksum: 231286 10da4a38fe608c515dbc82b89fc6a3e4 Size/MD5 checksum: 366434 69765dba5758c6c1235beb51718107e0 s390 architecture (IBM S/390) Size/MD5 checksum: 379098 af33c3c32c9052bbbebf758d50a22f0a Size/MD5 checksum: 222936 6c18d6389154cde30f4b671d596d9fc3 sparc architecture (Sun SPARC/UltraSPARC) Size/MD5 checksum: 199142 c24cd7954c44b0cf3b76f3e737d111a9 Size/MD5 checksum: 338746 18ad88d5de59424416762f1ce448caa6 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . The Debian advisory points out vulnerabilities in imlib2 concerning buffer overflows that may permit arbitrary code execution. Updating your system is recommended for enhanced security.. debian imlib2 buffer overflow exploit code execution. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 05, 2010 Critical Debian
91

Gentoo: GLSA-200709-07:02 Normal: Eggdrop Buffer Overflow Threat

The unaffected ebuild, as reported in the original version of this Security Advisory, did not properly address all vulnerabilities. All Eggdrop users should upgrade to net-irc/eggdrop-1.6.18-r3. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [ERRATA UPDATE] GLSA 200709-07:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Eggdrop: Buffer overflow Date: September 15, 2007 Updated: September 26, 2007 Bugs: #179354 ID: 200709-07:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Errata ===== The unaffected ebuild, as reported in the original version of this Security Advisory, did not properly address all vulnerabilities. All Eggdrop users should upgrade to net-irc/eggdrop-1.6.18-r3. The corrected sections appear below. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-irc/eggdrop < 1.6.18-r3 > = 1.6.18-r3 Resolution ========= All Eggdrop users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =net-irc/eggdrop-1.6.18-r3" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200709-07 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, youmay file a bug at https://bugs.gentoo.org/. License ====== Copyright 2008 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Eggdrop clients advised to update immediately due to potential buffer overflow vulnerabilities highlighted in Gentoo's recent security advisory.. Gentoo Security, Eggdrop Upgrade, Buffer Overflow Fix, Net-irc, GLSA Advisory. . LinuxSecurity.com Team

Calendar 2 Jan 08, 2008 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here