Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -3 articles for you...
87

Debian 3.1: DSA 1279-1 Moderate: WebCalendar Input Sanitization Issue

It was discovered that WebCalendar, a PHP-based calendar application, performs insufficient sanitising in the exports handler, which allows injection of web script.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1279-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff April 22nd, 2007 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : missing input sanitising Problem-Type : remote Debian-specific: no CVE ID : CVE-2006-6669 It was discovered that WebCalendar, a PHP-based calendar application, performs insufficient sanitising in the exports handler, which allows injection of web script. For the old stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge7. The stable distribution (etch) no longer contains WebCalendar packages. For the unstable distribution (sid) this problem has been fixed in version 1.0.5-2. We recommend that you upgrade your webcalendar package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 608 0c12e6c6307413350af264045a4df964 Size/MD5 checksum: 13013 ced8d9c6f7d52a42c3297a685547cb06 Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent components: Size/MD5checksum: 629712 39fca1d949580d18e1e293a1c181b1a8 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Addressing cross-site scripting risks in WebCalendar software for Debian installations. Recommended to update now.. WebCalendar Security Package, Debian Cross-Site Scripting, Input Sanitization Fix. . LinuxSecurity.com Team

Calendar%202 Apr 22, 2007 Debian
87

Debian DSA 1267-1: Webcalendar Remote File Inclusion Moderate Threat

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1267-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 15th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : missing input sanitising Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-1343 It was discovered that WebCalendar, a PHP-based calendar application, insufficiently protects an internal variable, which allows remote file inclusion. For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge6. The upcoming stable distribution (etch) no longer contains webcalendar packages. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your webcalendar package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 608 98123f7302a7b8f90beb5100f6922ad5 Size/MD5 checksum: 12730 17a8a7a4aebf500e71e00314786c4b1c Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent components: Size/MD5 checksum: 628890 1ac0d19d172483c9045997532d2b5e68 These files will probably be moved into the stable distribution on its next update. ----------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 1267-1 http://www.debian.org/security/ Moritz Muehlenhoff March 15th, 2. updated, package, --------------------------------------------------------------------------debian. . LinuxSecurity.com Team

Calendar%202 Mar 15, 2007 Debian
87

Debian 3.1 DSA 1096-1 Moderate: Webcalendar Remote Execution Issue

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1096-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze June 13th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : uninitialised variable Problem type : remote Debian-specific: no CVE ID : CVE-2006-2762 A vulnerability has been discovered in webcalendar, a PHP-based multi-user calendar, that allows a remote attacker to execute arbitrary PHP code when register_globals is turned on. The old stable distribution (woody) does not contain a webcalendar package. For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge5. For the unstable distribution (sid) this problem has been fixed in version 1.0.4-1 We recommend that you upgrade your webcalendar package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 608 216c1f9f764169fa877f1717f37dd73a Size/MD5 checksum: 12569 3a996902a10791fe764548728885d812 Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent components: Size/MD5 checksum: 629442 f918fe96d26d5cbfa99efe2b2e938d2f These files will probably be moved into the stabledistribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 1096-1 http://www.debian.org/security/ Martin Schulze June 13th, 2006 h. updated, package, --------------------------------------------------------------------------debian. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 13, 2006 Important Debian
87

Debian 4.0: DSA 1200-1 Important: Remote Information Leak in Webcalendar

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1056-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze May 15th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : verbose error message Problem type : remote Debian-specific: no CVE ID : CVE-2006-2247 Debian Bug : 366927 David Maciejak noticed that webcalendar, a PHP-Based multi-user calendar, returns different error messages on login attempts for an invalid password and a non-existing user, allowing remote attackers to gain information about valid usernames. The old stable distribution (woody) does not contain a webcalendar package For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge4. For the unstable distribution (sid) this problem will be fixed soon. We recommend that you upgrade your webcalendar package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 610 1a88e45355b0ca1a474eba42ac6c8eb4 Size/MD5 checksum: 12135 a518268d52b8a4744dd31ae9a7b60d0c Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent components: Size/MD5 checksum: 629232 c83c6d64bf495a79cc6fad26b68708e0 These fileswill probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . A recent security alert has been issued for the Debian webcalendar package, addressing a vulnerability that could lead to the exposure of sensitive information during remote login sessions.. Debian Security, Webcalendar Update, Remote Vulnerability, Security Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2006 Important Debian
87

Debian 3.1: DSA 798-1 Critical Remote Code Execution in Webcalendar

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 798-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Stone September 2, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : remote code execution Problem-Type : input validation Debian-specific: no CVE ID : CAN-2005-2717 A trivially-exploitable bug was discovered in webcalendar that allows an attacker to execute arbitrary code with the privileges of the HTTP daemon on a system running a vulnerable version. The old stable distribution (woody) does not contain the webcalendar package. For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge2. For the unstable distribution (sid) this problem will be fixed shortly. We recommend that you upgrade your webcalendar package immediately. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 9908 ae927afd627778637759df5f2e4e8336 Size/MD5 checksum: 725 0e765e2795bba3a7ccaedea569f2475c Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent packages: Size/MD5 checksum: 627470 1206a45774cad65c0b2b85bdc48a2d53 These files will probably be moved into the stable distributionon its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Ubuntu Security Notice USN-4234-1 addresses a vulnerability in OpenSSH, improving overall system protection.. remote code execution, Debian advisory, webcalendar fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 02, 2005 Critical Debian
87

Debian: DSA 766-1 Critical: Webcalendar Information Leak Advisory

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 766-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze July 26th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : webcalendar Vulnerability : authorisation failure Problem-Type : remote Debian-specific: no CVE ID : CAN-2005-2320 BugTraq ID : 14072 Debian Bug : 315671 A vulnerability has been discovered in webcalendar, a PHP based multi-user calendar, that can lead to the disclosure of sensitive information to unauthorised parties. the old stable distribution (woody) does not contain the webcalendar package. For the stable distribution (sarge) this problem has been fixed in version 0.9.45-4sarge1. For the unstable distribution (sid) this problem has been fixed in version 0.9.45-6. We recommend that you upgrade your webcalendar package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 607 d5030eb9186aa90e841a4ca395da6a3a Size/MD5 checksum: 9808 80408685999e6f85c279a187697d194d Size/MD5 checksum: 612360 a6a66dc54cd293429b604fe6da7633a6 Architecture independent components: Size/MD5 checksum: 628586 4d2edb921316272f6ad043153bf1757a These files will probably be moved into thestable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Enhance the webcalendar module on Debian to address the information exposure problem. Acquire the newest patches for better protection.. Debian Security, Webcalendar Update, Package Vulnerabilities, Information Disclosure. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 27, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":555,"type":"x","order":1,"pct":78.72,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.26,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.82,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.2,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here