Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
99

Slackware 10.2: 2006-130-01 Moderate: Apache Wildcard Bug Fix

New Apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix a bug with Apache 1.3.35 and glibc that breaks wildcards in Include directives. It may not occur with all versions of glibc, but it has been verified on -current (using an Include . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] Apache httpd redux (SSA:2006-130-01) New Apache packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, and -current to fix a bug with Apache 1.3.35 and glibc that breaks wildcards in Include directives. It may not occur with all versions of glibc, but it has been verified on -current (using an Include within a file already Included causes a crash), so better to patch it and reissue these packages just to be sure. My apologies if the last batch of updates caused anyone undue grief... they worked here with my (too simple?) config files. Note that if you use mod_ssl, you'll also require the mod_ssl package that was part of yesterday's release, and on -current you'll need the newest PHP package (if you use PHP). Thanks to Francesco Gringoli for bringing this issue to my attention. Here are the details from the Slackware 10.2 ChangeLog: +--------------------------+ patches/packages/apache-1.3.35-i486-2_slack10.2.tgz: Patched to fix totally broken Include behavior. Thanks to Francesco Gringoli for reporting this bug. +--------------------------+ Where to find the new packages: +-----------------------------+ Updated package for Slackware 8.1: Updated package for Slackware 9.0: Updated package for Slackware 9.1: Updated package for Slackware 10.0: Updated package for Slackware 10.1: Updated package for Slackware 10.2: Updated package for Slackware -current: MD5 signatures: +-------------+ Slackware 8.1 package: 3affa50debe634e148d8cfed98733a47 apache-1.3.35-i386-2_slack8.1.tgz Slackware 9.0 package: d3d5c446c6b16c84d17a43c0e836071c apache-1.3.35-i386-2_slack9.0.tgz Slackware 9.1 package: daa91eb34cd487f7621301f95ac931ce apache-1.3.35-i486-2_slack9.1.tgz Slackware 10.0 package: d4031f1dc80659091c9b83a9bfed2a9e apache-1.3.35-i486-2_slack10.0.tgz Slackware 10.1 package: a1239458270ae312f4d7f510cbd9785b apache-1.3.35-i486-2_slack10.1.tgz Slackware 10.2 package: 78130e24c739ea5c3569a0ab6647a7df apache-1.3.35-i486-2_slack10.2.tgz Slackware -current packages: 4b961ce755054c1820988ff0192922ad apache-1.3.35-i486-2.tgz Installation instructions: +------------------------+ First, stop apache: # apachectl stop Then, upgrade the apache package: # upgradepkg apache-1.3.35-i486-2_slack10.2.tgz Finally, restart apache: # apachectl start Or, if you use mod_ssl: # apachectl startssl +-----+ . Recent updates to Apache for Slackware resolve a wildcard issue found in Include directives spanning various versions.. Apache Patch, Slackware Security, Include Bug Fix. . LinuxSecurity.com Team

Calendar 2 May 10, 2006 Slackware
87

Debian: DSA 782-1 Critical: Bluez-Utils Command Execution Risk

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 782-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze August 23rd, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : bluez-utils Vulnerability : missing input sanitising Problem-Type : local Debian-specific: no CVE ID : CAN-2005-2547 Debian Bug : 323365 Henryk Plötz discovered a vulnerability n bluez-utils, tools and daemons for Bluetooth. Due to missing input sanitising it is possible for an attacker to execute arbitrary commands supplied as device name from the remote device. The old stable distribution (woody) is not affected by this problem since it doesn't contain bluez-utils packages. For the stable distribution (sarge) this problem has been fixed in version 2.15-1.1. For the unstable distribution (sid) this problem has been fixed in version 2.19-1. We recommend that you upgrade your bluez-utils package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 714 2491914f1cbc13f0ab28dec7e837e424 Size/MD5 checksum: 21489 43758255ed6bf5a46a3958f19cc083de Size/MD5 checksum: 299709 4e86dfd4449ff49e82696d8a3b254002 Alpha architecture: Size/MD5 checksum: 17100ad86005f878483c8cd5ea2593604c9b6 Size/MD5 checksum: 19900 816b04f618adbe2ba4ea7bb79a8d7157 Size/MD5 checksum: 13908 fa9bd6ebdbd4704f2cdc58a23776ce1d Size/MD5 checksum: 191032 3ab7545f8baf93b0f1d0c37b03fd60d0 AMD64 architecture: Size/MD5 checksum: 16614 a12b51e1eeef5c00d7979fccb6347556 Size/MD5 checksum: 18440 524a61c61424bb8878a4d481a4f96639 Size/MD5 checksum: 163404 f1de25ec8a42140ff0fd5981f106b446 ARM architecture: Size/MD5 checksum: 16350 7f5b07579302c70fe368a8fe879baf64 Size/MD5 checksum: 18020 410fa646ed25f2e4bf769b80627b8319 Size/MD5 checksum: 13908 75eca9861302d04cfa3030bcc6cc2e8d Size/MD5 checksum: 149058 de5dd73485032ba33405681e38019bd2 Intel IA-32 architecture: Size/MD5 checksum: 16294 e95efa30d455f23acc78913f46f8754b Size/MD5 checksum: 18006 339294a5b115f1df8460657c044f82a0 Size/MD5 checksum: 13890 5751fcbe540495b01a2888586a144617 Size/MD5 checksum: 149220 43e516a0d3a73e11de96a3293ab99e26 Intel IA-64 architecture: Size/MD5 checksum: 17742 5372690843eaed6b19925710c48ad440 Size/MD5 checksum: 20610 38b221b3769bb7567d85ff88fd8eb00b Size/MD5 checksum: 13904 38d8f9c631776fdf07befbc8010b51d7 Size/MD5 checksum: 213568 14322f997ac251b5c19663d9c8f8aafb HP Precision architecture: Size/MD5 checksum: 17000 1e61a7ef4218ebf09854b28d6f281573 Size/MD5 checksum: 18800 396815069f599b99b1fc45b75f32a2cd Size/MD5 checksum: 13908 9b30a8217fcd43466139c1487532e3a8 Size/MD5 checksum: 165964 42c6010d54d86b92aa550b3299423098 Motorola 680x0 architecture: Size/MD5 checksum: 16320 25bf3588642aa1040fd39f22c12f5697 Size/MD5 checksum: 17706 797c282ecdaa447fa9082b7406eee5ff Size/MD5 checksum: 13924 8d35a46404b9ee45d2a0aab68f48d3e1 Size/MD5checksum: 140002 c665c81408c4022e81d7132e4e7a3522 Big endian MIPS architecture: Size/MD5 checksum: 17070 2f3f4dc62239a17b174bf057e7d2dcf2 Size/MD5 checksum: 18746 d4e753008478ff9501fdd7b39efcb3ce Size/MD5 checksum: 13914 05fe887d123e34eab6843adb3d808c51 Size/MD5 checksum: 173706 fe02dcad2eb60b6db3032dc14e138342 Little endian MIPS architecture: Size/MD5 checksum: 17092 ecb402ed2303d3e68fedc7f23fb47bb2 Size/MD5 checksum: 18762 282f97232f45e0dadb904d881e1d24c8 Size/MD5 checksum: 13908 60ab63b402731440a44d6b9dc756d4f2 Size/MD5 checksum: 173960 abb2d7193c2698b703a56b71890531f6 PowerPC architecture: Size/MD5 checksum: 18160 7ed57b2c8f87e9dfdcc5401ce96d5028 Size/MD5 checksum: 19714 da7edeba354bec413084b310805f2277 Size/MD5 checksum: 13908 c2c98f3732799d08c29f2c8fe048b47f Size/MD5 checksum: 170292 db67afaaccde1cb6f5ac6de30527634d IBM S/390 architecture: Size/MD5 checksum: 16796 003612d4408414aad7028aca96a076e7 Size/MD5 checksum: 18246 ac2b0a2ce0099e60adf1adebf38092e8 Size/MD5 checksum: 157826 a54bb7d77b422d1cdd66fb647bfa2198 Sun Sparc architecture: Size/MD5 checksum: 16400 8f3da8e4a00cb7c1986a3c5bf06946ad Size/MD5 checksum: 17792 e1ef13fe1345cf554a65490430605040 Size/MD5 checksum: 13908 5863ca5e69542f659f30e4623abf07bf Size/MD5 checksum: 146742 7e7a54e5b793f702e9432480c1a4bdfe These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance your Debian system by updating the bluez-utils packages to mitigate risks associated witharbitrary command execution vulnerabilities and bolster your security.. Debian Security, Bluez-Utils Upgrade, Security Patch. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 23, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here