Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 521
Alerts This Week
Warning Icon 1 521

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
100

SUSE: 2011:002 Critical: Buffer Overflow Resolutions Overview

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2011:002 Date: Tue, 25 Jan 2011 11:00:00 +0000 Cross-References: CVE-2008-3916, CVE-2009-0945, CVE-2009-1681 CVE-2009-1684, CVE-2009-1685, CVE-2009-1686 CVE-2009-1687, CVE-2009-1688, CVE-2009-1689 CVE-2009-1690, CVE-2009-1691, CVE-2009-1692 CVE-2009-1693, CVE-2009-1694, CVE-2009-1695 CVE-2009-1696, CVE-2009-1697, CVE-2009-1698 CVE-2009-1699, CVE-2009-1700, CVE-2009-1701 CVE-2009-1702, CVE-2009-1703, CVE-2009-1709 CVE-2009-1710, CVE-2009-1711, CVE-2009-1712 CVE-2009-1713, CVE-2009-1714, CVE-2009-1715 CVE-2009-1718, CVE-2009-1724, CVE-2009-1725 CVE-2009-2195, CVE-2009-2199, CVE-2009-2200 CVE-2009-2419, CVE-2009-2797, CVE-2009-2816 CVE-2009-2841, CVE-2009-3272, CVE-2009-3384 CVE-2009-3933, CVE-2009-3934, CVE-2009-4134 CVE-2010-0046, CVE-2010-0047, CVE-2010-0048 CVE-2010-0049, CVE-2010-0050, CVE-2010-0051 CVE-2010-0052,CVE-2010-0053, CVE-2010-0054 CVE-2010-0315, CVE-2010-0647, CVE-2010-0650 CVE-2010-0651, CVE-2010-0656, CVE-2010-0659 CVE-2010-0661, CVE-2010-1029, CVE-2010-1126 CVE-2010-1163, CVE-2010-1233, CVE-2010-1236 CVE-2010-1386, CVE-2010-1387, CVE-2010-1388 CVE-2010-1389, CVE-2010-1390, CVE-2010-1391 CVE-2010-1392, CVE-2010-1393, CVE-2010-1394 CVE-2010-1395, CVE-2010-1396, CVE-2010-1397 CVE-2010-1398, CVE-2010-1399, CVE-2010-1400 CVE-2010-1401, CVE-2010-1402, CVE-2010-1403 CVE-2010-1404, CVE-2010-1405, CVE-2010-1406 CVE-2010-1407, CVE-2010-1408, CVE-2010-1409 CVE-2010-1410, CVE-2010-1412, CVE-2010-1413 CVE-2010-1414, CVE-2010-1415, CVE-2010-1416 CVE-2010-1417, CVE-2010-1418, CVE-2010-1419 CVE-2010-1421, CVE-2010-1422, CVE-2010-1449 CVE-2010-1450, CVE-2010-1455, CVE-2010-1634 CVE-2010-1646, CVE-2010-1729, CVE-2010-1749 CVE-2010-1757, CVE-2010-1758, CVE-2010-1759 CVE-2010-1760, CVE-2010-1761, CVE-2010-1762 CVE-2010-1763, CVE-2010-1764, CVE-2010-1766 CVE-2010-1767, CVE-2010-1769, CVE-2010-1770 CVE-2010-1771, CVE-2010-1772, CVE-2010-1773 CVE-2010-1774, CVE-2010-1780, CVE-2010-1781 CVE-2010-1782, CVE-2010-1783, CVE-2010-1784 CVE-2010-1785, CVE-2010-1786, CVE-2010-1787 CVE-2010-1788, CVE-2010-1789, CVE-2010-1790 CVE-2010-1791, CVE-2010-1792, CVE-2010-1793 CVE-2010-1807, CVE-2010-1812, CVE-2010-1813 CVE-2010-1814, CVE-2010-1815, CVE-2010-1822 CVE-2010-1823, CVE-2010-1824, CVE-2010-1825 CVE-2010-2089, CVE-2010-2264, CVE-2010-2283 CVE-2010-2284, CVE-2010-2285, CVE-2010-2286 CVE-2010-2287, CVE-2010-2295, CVE-2010-2297 CVE-2010-2300, CVE-2010-2301, CVE-2010-2302 CVE-2010-2441, CVE-2010-2640, CVE-2010-2643 CVE-2010-2761, CVE-2010-2891, CVE-2010-2992 CVE-2010-2993, CVE-2010-2994, CVE-2010-2995 CVE-2010-3116, CVE-2010-3257, CVE-2010-3259 CVE-2010-3312, CVE-2010-3445, CVE-2010-3493 CVE-2010-3803, CVE-2010-3804, CVE-2010-3805 CVE-2010-3808, CVE-2010-3809, CVE-2010-3810 CVE-2010-3811, CVE-2010-3812, CVE-2010-3813 CVE-2010-3816, CVE-2010-3817, CVE-2010-3818 CVE-2010-3819, CVE-2010-3820, CVE-2010-3821 CVE-2010-3822, CVE-2010-3823, CVE-2010-3824 CVE-2010-3826, CVE-2010-3829, CVE-2010-3900 CVE-2010-4040, CVE-2010-4267, CVE-2010-4300 CVE-2010-4301, CVE-2010-4341, CVE-2010-4410 CVE-2010-4411, CVE-2010-4523, CVE-2011-0010 Content of this advisory: 1) Solved Security Vulnerabilities: - ed - evince - hplip - libopensc2/opensc - libsmi - libwebkit - perl - python - sssd - sudo - wireshark 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - ed This update fixes a heap-based buffer overflow in ed which can be exploited remotely only with user-assistance. CVE-2008-3916: CVSS v2 Base Score: 9.3 (HIGH) (AV:N/AC:M/Au:N/C:C/I:C/A:C): Buffer Errors (CWE-119) Affected products: SLE10-SP3, SLE11-SP1 - evince Multiple font parser vulnerabilities in the DVI backend of evince have been fixed. CVE-2010-2640 - CVE-2010-2643 have been assigned to these issues. Affected products: openSUSE 11.2-11.3, SLE11-SP1 - hplip Specially crafted SNMP replies could cause a buffer overflow in hplip's sane backend (CVE-2010-4267). Affected products: openSUSE 11.2-11.3, SLE11-SP1 - libopensc2/opensc Specially crafted smart cards could cause a buffer overflow in opensc (CVE-2010-4523). Affected products: openSUSE 11.1-11.3 - libsmi This update fixes a buffer overflow the smiGetNode() function in libsmi. It allowed context-dependent attackers to execute arbitrary code via an Object Identifier. CVE-2010-2891: CVSS v2 Base Score: 7.5 (HIGH) (AV:N/AC:L/Au:N/C:P/I:P/A:P): Buffer Errors (CWE-119) Affected products: SLE10-SP3, SLE11-SP1 - libwebkit Various bugs in webkit have beenfixed. The CVE id's are: CVE-2009-0945, CVE-2009-1681, CVE-2009-1684, CVE-2009-1685, CVE-2009-1686, CVE-2009-1687, CVE-2009-1688, CVE-2009-1689, CVE-2009-1691, CVE-2009-1690, CVE-2009-1692, CVE-2009-1693, CVE-2009-1694, CVE-2009-1695, CVE-2009-1696, CVE-2009-1697, CVE-2009-1698, CVE-2009-1699, CVE-2009-1700, CVE-2009-1701, CVE-2009-1702, CVE-2009-1703, CVE-2009-1709, CVE-2009-1710, CVE-2009-1711, CVE-2009-1712, CVE-2009-1713, CVE-2009-1714, CVE-2009-1715, CVE-2009-1718, CVE-2009-1724, CVE-2009-1725, CVE-2009-2195, CVE-2009-2199, CVE-2009-2200, CVE-2009-2419, CVE-2009-2797, CVE-2009-2816, CVE-2009-2841, CVE-2009-3272, CVE-2009-3384, CVE-2009-3933, CVE-2009-3934, CVE-2010-0046, CVE-2010-0047, CVE-2010-0048, CVE-2010-0049, CVE-2010-0050, CVE-2010-0052, CVE-2010-0053, CVE-2010-0054, CVE-2010-0315, CVE-2010-0647, CVE-2010-0051, CVE-2010-0650, CVE-2010-0651, CVE-2010-0656, CVE-2010-0659, CVE-2010-0661, CVE-2010-1029, CVE-2010-1126, CVE-2010-1233, CVE-2010-1236, CVE-2010-1386, CVE-2010-1387, CVE-2010-1388, CVE-2010-1389, CVE-2010-1390, CVE-2010-1391, CVE-2010-1392, CVE-2010-1393, CVE-2010-1394, CVE-2010-1395, CVE-2010-1396, CVE-2010-1397, CVE-2010-1398, CVE-2010-1399, CVE-2010-1400, CVE-2010-1401, CVE-2010-1402, CVE-2010-1403, CVE-2010-1404, CVE-2010-1405, CVE-2010-1406, CVE-2010-1407, CVE-2010-1408, CVE-2010-1409, CVE-2010-1410, CVE-2010-1412, CVE-2010-1413, CVE-2010-1414, CVE-2010-1415, CVE-2010-1416, CVE-2010-1417, CVE-2010-1418, CVE-2010-1419, CVE-2010-1421, CVE-2010-1422, CVE-2010-1729, CVE-2010-1749, CVE-2010-1757, CVE-2010-1758, CVE-2010-1759, CVE-2010-1760, CVE-2010-1761, CVE-2010-1762, CVE-2010-1763, CVE-2010-1764, CVE-2010-1766, CVE-2010-1767, CVE-2010-1769, CVE-2010-1770, CVE-2010-1771, CVE-2010-1772, CVE-2010-1773, CVE-2010-1774, CVE-2010-1780, CVE-2010-1781, CVE-2010-1782, CVE-2010-1783, CVE-2010-1784, CVE-2010-1785, CVE-2010-1786, CVE-2010-1787, CVE-2010-1788, CVE-2010-1789, CVE-2010-1790, CVE-2010-1791, CVE-2010-1792, CVE-2010-1793, CVE-2010-1807, CVE-2010-1812, CVE-2010-1813, CVE-2010-1814, CVE-2010-1815, CVE-2010-1822, CVE-2010-1823, CVE-2010-1824, CVE-2010-1825, CVE-2010-2264, CVE-2010-2295, CVE-2010-2297, CVE-2010-2300, CVE-2010-2301, CVE-2010-2302, CVE-2010-2441, CVE-2010-3116, CVE-2010-3257, CVE-2010-3259, CVE-2010-3312, CVE-2010-3803, CVE-2010-3804, CVE-2010-3805, CVE-2010-3808, CVE-2010-3809, CVE-2010-3810, CVE-2010-3811, CVE-2010-3812, CVE-2010-3813, CVE-2010-3816, CVE-2010-3817, CVE-2010-3818, CVE-2010-3819, CVE-2010-3820, CVE-2010-3821, CVE-2010-3822, CVE-2010-3823, CVE-2010-3824, CVE-2010-3826, CVE-2010-3829, CVE-2010-3900, CVE-2010-4040 Affected products: openSUSE 11.2-11.3 - perl Multiple header injection problems in the CGI module of perl have been fixed. They allowed to inject HTTP headers in responses. CVE-2010-2761, CVE-2010-4410 and CVE-2010-4411 have been assigned to this issue. Affected products: openSUSE 11.2-11.3, SLE10-SP3, SLE11-SP1 - python With this update of python: - a race condition in the accept() implementation of smtpd.py could lead to a denial of service (CVE-2010-3493). - integer overflows and insufficient size checks could crash the audioop and rgbimg modules (CVE-2010-2089, CVE-2010-1634, CVE-2009-4134,CVE-2010-1449,CVE-2010-1450). Affected products: SLE10-SP3 - sssd This update fixes a local denial-of-service attack that stops other users from logging in. The bug existed in the pam_parse_in_data_v2() function. (CVE-2010-4341: CVSS v2 Base Score: 2.1) Affected products: openSUSE 11.3 - sudo This update of sudo fixes: - CVE-2011-0010: Does ask for the user password for GID changes now. - CVE-2010-1646: CVSS v2 Base Score: 6.6 (CWE-264): The secure environment option can handle multiple occurrence of PATH now. - CVE-2010-1163: CVSS v2 Base Score: 6.9(CWE-20): Improved command matching. Affected products: openSUSE 11.2-11.3 - wireshark Wireshark version 1.4.2 fixes several security issues that allowed attackers to crash wireshark or potentially even execute arbitrary code (CVE-2010-1455, CVE-2010-2283, CVE-2010-2284, CVE-2010-2285, CVE-2010-2286, CVE-2010-2287, CVE-2010-2992, CVE-2010-2993, CVE-2010-2994, CVE-2010-2995, CVE-2010-3445, CVE-2010-4300, CVE-2010-4301) Affected products: openSUSE 11.2-11.3 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE publishes a weekly digest that focuses on subtle security concerns, highlighting vulnerabilities like improper input validations and essential updates.. SUSE Security, Buffer Overflow, Security Patch, Weekly Report. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jan 25, 2011 Critical SuSE
100

SUSE: 2010:023 Moderate: Application Fixes and Security Issues

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2010:023 Date: Wed, 08 Dec 2010 14:00:00 +0000 Cross-References: CVE-2010-0542, CVE-2010-1323, CVE-2010-1324 CVE-2010-1748, CVE-2010-2941, CVE-2010-3073 CVE-2010-3074, CVE-2010-3312, CVE-2010-3702 CVE-2010-3710, CVE-2010-3860, CVE-2010-3870 CVE-2010-4005, CVE-2010-4008, CVE-2010-4020 CVE-2010-4021 Content of this advisory: 1) Solved Security Vulnerabilities: - libxml2 - tomboy - krb5 - php5 - cups - java-1_6_0-openjdk - epiphany - encfs 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are alreadyavailable on our FTP server and via the YaST Online Update. - libxml2 Specially crafted xml documents could crash applications linked against libxml2 (CVE-2010-4008). Affected Products: SLE10-SP3, SLE11, SLE11-SP1, openSUSE 11.1, 11.2, 11.3 - tomboy The tomboy startup scripts put empty elements in LD_LIBRARY_PATH causing tomboy to load shared libraries from the current directory (CVE-2010-4005). Affected Products: openSUSE 11.3 - krb5 krb5 did no properly check messages. Remote attackers could exploit that to modify or forge messages (CVE-2010-1323, CVE-2010-1324, CVE-2010-4020, CVE-2010-4021) Affected Products: SLE11, SLE11-SP1 - php5 Insufficient handling of certain character sequences in the utf8_decode() function could be leveraged to conduct cross-site-scripting (XSS) attacks (CVE-2010-3870). php5 could also consume large amounts of memory and crash if a long mail address was passed to filter_var() with parmeter FILTER_VALIDATE_EMAIL (CVE-2010-3710). Affected Products: SLE10-SP3, SLE11, SLE11-SP1, openSUSE 11.1, 11.2, 11.3 - cups - CVE-2010-3702: Specially crafted PDF files could crash pdftops or potentially even cause execution of arbitrary code. - CVE-2010-2941: Specially crafted IPP requests could crash cupsd - CVE-2010-0542: A NULL pointer dereference in the _WriteProlog() function of the texttops image filter. - CVE-2010-1748: An attacker with access to the web-interface may be able to read some bytes of uninitialized memory. Affected Products: SLES9, SLE10-SP3, SLE11, SLE11-SP1, openSUSE 11.1, 11.2, 11.3 - java-1_6_0-openjdk Untrusted applets could read values of restricted system properties (CVE-2010-3860). Affected Products: openSUSE 11.1, 11.2, 11.3 - epiphany Epiphany does not support verification of ssl certificates. It nevertheless displayed all httpsconnections as secure (CVE-2010-3312). Affected Products: SLE11-SP1, openSUSE 11.2 - encfs - CVE-2010-3073: encfs only used 32bits for the IV - CVE-2010-3074: encfs was prone to a watermarking attack Affected Products: openSUSE 11.1, 11.2, 11.3 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Overview Document for Notification ID:SUSE-SR:2010:024 outlines addressed vulnerabilities and security notifications.. SUSE Security Report, Low Profile Fixes, Weekly Summary. . LinuxSecurity.com Team

Calendar%202 Dec 08, 2010 SuSE
100

SUSE: 2010:014 Moderate: Multiple Software Security Risks

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2010:014 Date: Mon, 02 Aug 2010 15:00:00 +0000 Cross-References: CVE-2009-2625, CVE-2009-2663, CVE-2009-3560 CVE-2009-3700, CVE-2009-3720, CVE-2009-3826 CVE-2009-4270, CVE-2010-0211, CVE-2010-0212 CVE-2010-0395, CVE-2010-0438, CVE-2010-0547 CVE-2010-0653, CVE-2010-0731, CVE-2010-0733 CVE-2010-0787, CVE-2010-0926, CVE-2010-1166 CVE-2010-1169, CVE-2010-1170, CVE-2010-1321 CVE-2010-1325, CVE-2010-1411, CVE-2010-1459 CVE-2010-1507, CVE-2010-1512, CVE-2010-1628 CVE-2010-1639, CVE-2010-1640, CVE-2010-1869 CVE-2010-1975, CVE-2010-1993, CVE-2010-2023 CVE-2010-2024, CVE-2010-2055, CVE-2010-2059 CVE-2010-2063, CVE-2010-2067, CVE-2010-2074 CVE-2010-2077, CVE-2010-2228, CVE-2010-2229 CVE-2010-2230, CVE-2010-2231, CVE-2010-2251 CVE-2010-2451, CVE-2010-2452, CVE-2010-2480 CVE-2010-2494, CVE-2010-2532, CVE-2010-2713 CVE-2010-2785 Content of this advisory: 1) Solved Security Vulnerabilities: - OpenOffice_org - apache2-slms - aria2 - bogofilter - cifs-mount/samba - clamav - exim - ghostscript-devel - gnutls - krb5 - kvirc - lftp - libpython2_6-1_0 - libtiff - libvorbis - lxsession - mono-addon-bytefx-data-mysql/bytefx-data-mysql - moodle - openldap2 - opera - otrs - popt - postgresql - python-mako - squidGuard - vte - w3m - xmlrpc-c - XFree86/xorg-x11 - yast2-webclient 2) Pending Vulnerabilities, Solutions, and Work-Arounds: none 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - OpenOffice_org This update of OpenOffice_org does not allow macros written in Python to be executed without permission, CVE-2010-0395. This also provides the maintenance update to OpenOffice.org-3.2.1. Details about all upstream changes can be found at http://www.openoffice.org/development/releases/3.2.1.html Affected Products: SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - apache2-slms Insufficient quoting of parameters in SLMS could allow for cross-site-request-forgery (CSRF) attacks (CVE-2010-1325). Affected Products: SLE11 - aria2 This aria2 update to 1.9.3 fixes a metalink name Directory Traversal issue (CVE-2010-1512). Affected Products: openSUSE 11.2 - bogofilter This update of bogofilter/bogolexer fixes a heap based buffer underflow vulnerability which could be exploited to cause a denial of service or potentially execute arbitrary code (CVE-2010-2494). Affected Products: SLE11, openSUSE 11.0, 11.1, 11.2 - cifs-mount/samba This update of the Samba server package fixes security issues and bugs. Following security issues were fixed: - CVE-2010-2063: A buffer overrun was possible in chain_reply code in 3.3.x and below, which could be used to crash the samba server or potentially execute code. - CVE-2010-0787: Take extra care that a mount point of mount.cifs is not changed during mount. - CVE-2010-0926: With enabled "wide links" samba follows symbolic links on the server side, therefore allowing clients to overwrite arbitrary files. This update changes the default setting to have "wide links" disabled by default. The new default only works if "wide links" is not set explicitly in smb.conf. - CVE-2010-0547: Due to a race condition in mount.cifs a local attacker could corrupt /etc/mtab if mount.cifs is installed setuid root. mount.cifs is not setuid root by default and it is not recommended to change that. Affected Products: SLES9, SLE10-SP3, SLE11, openSUSE 11.0, 11.1 - clamav This update fixes a off-by-one buffer overflow (CVE-2010-1640) and a crash while parsing PDFs (CVE-2010-1639, CVE-2010-2077) in clamav that can be used as a remote denial of service attack. Affected Products: SLES9,SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - exim Two local vulnerabilities have been fixed in the exim MTA which allowed attackers to create arbitrary files or to change ownership of arbitrary files. CVE-2010-2023 and CVE-2010-2024 have been assigned to these issues. Affected Products: openSUSE 11.1, 11.2, 11.3 - ghostscript Specially crafted postscript (.ps) files could cause buffer overflows in ghostscript that could potentially be exploited to execute arbitrary code (CVE-2010-1628, CVE-2010-1869, CVE-2009-4270) Additionally ghostscript, by default, reads some initialization files from the current working directory. Local attackers could potentially exploit that to have other users execute arbitrary commands by placing such files e.g. in /tmp (CVE-2010-2055). Affected Products: SLE11, openSUSE 11.0, 11.1, 11.2, 11.3 - gnutls The ASN.1 parser for X.509 certificates used a wrong integer type for extracting a certficiate's serial number. On 64bit big-endian architectures this could result in bypassing CRL checks (CVE-2010-0731). Affected Products: SLES9 - krb5 This update fixes a denial-of-service vulnerability in kadmind. A remote attack can send a malformed GSS-API token that triggers a NULL pointer dereference. (CVE-2010-1321: CVSS v2 Base Score: 6.8 (MEDIUM) (AV:N/AC:L/Au:S/C:N/I:N/A:C)) Affected Products: SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - kvirc This update of KVirc fixes a remotely exploitable format string and directory traversal vulnerability (CVE-2010-2451, CVE-2010-2452). Additionally KVirc does not further allow remote client to send arbitrary CTCP commands. (CVE-2010-2785) Affected Products: openSUSE 11.1, 11.2, 11.3 - lftp This update of lftp improves the filename handling of downloaded files to avoid downloading arbitrary content to unexpected locations (like .login). (CVE-2010-2251) Affected Products: openSUSE11.0, 11.1, 11.2 - libpython2_6-1_0 This update of python has a copy of libxmlrpc that is vulnerable to denial of service bugs that can occur while processing malformed XML input. - CVE-2009-2625: CVSS v2 Base Score: 5.0: Permissions, Privileges, and Access Control (CWE-264) - CVE-2009-3720: CVSS v2 Base Score: 5.0: Insufficient Information - CVE-2009-3560: CVSS v2 Base Score: 5.0: Buffer Errors (CWE-119) Affected Products: SLES9, SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - libtiff This update of libtiff fixes several integer overflows that could lead to a corrupted heap memory. This bug can be exploited remotely with a crafted TIFF file to cause an application crash or probably to execute arbitrary code. (CVE-2010-1411) Affected Products: SLES9, SLE10-SP3, openSUSE 11.0, 11.1, 11.2 - libvorbis This update of libvorbis fixes a memory corruption while parsing OGG files. This bug was exploitable by remote attackers to cause an application crash and could probably be exploited to execute arbitrary code. CVE-2009-2663: CVSS v2 Base Score: 6.8: Resource Management Errors (CWE-399) Affected Products: SLES9, SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - lxsession lxsession-logout did not properly lock the screen before suspending, hibernating and switching between users which could allow attackers with physical access to take control of the system to obtain sensitive infor- mation and / or execute arbitrary code in the context of the user who is currently logged in (CVE-2010-2532). Affected Products: openSUSE 11.3 - mono-addon-bytefx-data-mysql/bytefx-data-mysql Mono's ASP.NET implementation did not set the 'EnableViewStateMac' property by default. Attackers could exploit that to conduct cross- site-scripting (XSS) attacks. (CVE-2010-1459) Affected Products: SLE10-SP2, SLE11, openSUSE 11.0, 11.1, 11.2 - moodle Moodle was prone toseveral Cross-Site Scripting (XSS) vulnerabilities (CVE-2010-2228, CVE-2010-2229, CVE-2010-2230, CVE-2010-2231). Affected Products: openSUSE 11.0, 11.1 - openldap2 Specially crafted MODRDN operations can crash the OpenLDAP server. (CVE-2010-0211 and CVE-2010-0212) Affected Products: openSUSE 11.0 - opera Opera was upgraded to the 10.60 release. - CVE-2010-0653: Opera permits cross-origin loading of CSS style sheets even when the style sheet download has an incorrect MIME type and the style sheet document is malformed, which allows remote HTTP servers to obtain sensitive information via a crafted document. - CVE-2010-1993: Opera 9.52 does not properly handle an IFRAME element with a mailto: URL in its SRC attribute, which allows remote attackers to cause a denial of service (resource consumption) via an HTML document with many IFRAME elements. Affected Products: openSUSE 11.0, 11.1, 11.2, 11.3 - otrs OTRS was prone to multiple SQL-injection vulnerabilities which could allow remote authenticated attackers to execute arbitrary SQL code via unspecified vectors. (CVE-2010-0438) Affected Products: openSUSE 11.0, 11.1, 11.2 - popt This update fixes the problem where RPM misses to clear the SUID/SGID bit of old files during package updates. (CVE-2010-2059) Affected Products: openSUSE 11.0 - postgresql This update of postgresql was pblished to fix several minor security vulnerabilities: - CVE-2010-1975: postgresql does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings. - CVE-2010-1170: The PL/Tcl implementation in postgresql loads Tcl code from thepltcl_modules table regardless of the table's ownership and permissions, which allows remote authenticated users, with database-creation privileges, to execute arbitrary Tcl code. - CVE-2010-1169: Postgresql does not properly restrict PL/perl procedures, which allows remote authenticated users, with database- creation privileges, to execute arbitrary Perl code via a crafted script. - CVE-2010-0733: An integer overflow in postgresql allows remote authen- ticated users to crash the daemon via a SELECT statement. Affected Products: SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - python-mako Python-mako was prone to a Cross-Site Scripting flaw due to improperly escaped single quotes (CVE-2010-2480). Affected Products: openSUSE 11.2, 11.3 - squidGuard Two buffer overflows in squidGard were fixed: - CVE-2009-3700: Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode." - CVE-2009-3826: Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL. Affected Products: openSUSE 11.1, 11.2, 11.3 - vte VTE was vulnerable to an old title set+query attack which could be used by remote attackers to execute arbitrary code (CVE-2010-2713). Affected Products: openSUSE 11.2, 11.3 - w3m w3m did not handle embedded nul characters in the common name and in subject alternative names of x509 certificates. CVE-2010-2074 has been assigned to this issue. This update also turns on verification of x509 certificates by default which was not the case before. Affected Products: SLE10-SP3, SLE11, openSUSE 11.0, 11.1, 11.2 - xmlrpc-c This update of libxmlrpc is not vulnerable to denial of service bugs that can occur while processing malformed XML input. - CVE-2009-2625: CVSS v2 Base Score: 5.0: Permissions, Privileges, and Access Control (CWE-264) - CVE-2009-3720: CVSS v2 Base Score: 5.0: Insufficient Information - CVE-2009-3560: CVSS v2 Base Score: 5.0: Buffer Errors (CWE-119) Affected Products: SLES9, SLE11 - XFree86/xorg-x11 X clients could cause a memory corruption in the X Render extension which crashes the X server (CVE-2010-1166). Affected Products: SLES9, SLE10-SP3 - yast2-webclient WebYaST generates the secret key used to create session cookies after package installation. Since WebYaST appliances use pre-installed images all such instances end up using the same secret key (CVE-2010-1507). Affected Products: SLE11 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify the signature of the announcement, save it as text into a file and run the command gpg --verify replacing with thename of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . Debian releases a biweekly security overview detailing minor corrections alongside significant vulnerabilities and patches.. SUSE Linux Security, Weekly Security Summary, Software Security Updates. . LinuxSecurity.com Team

Calendar%202 Aug 02, 2010 SuSE
100

SUSE: 2009:001 moderate: Low Profile Fixes and Vulnerable Software

To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________ SUSE Security Summary Report Announcement ID: SUSE-SR:2009:001 Date: Mon, 12 Jan 2009 13:00:00 +0000 Cross-References: CVE-2008-2380, CVE-2008-3933, CVE-2008-3934 CVE-2008-3963, CVE-2008-4097, CVE-2008-4098 CVE-2008-4225, CVE-2008-4314, CVE-2008-4552 CVE-2008-4575, CVE-2008-4639, CVE-2008-4640 CVE-2008-4641, CVE-2008-4680, CVE-2008-4681 CVE-2008-4682, CVE-2008-4683, CVE-2008-4684 CVE-2008-4685, CVE-2008-4864, CVE-2008-5006 CVE-2008-5031, CVE-2008-5285, CVE-2008-5514 CVE-2008-5517, CVE-2008-5617 Content of this advisory: 1) Solved Security Vulnerabilities: - ethereal, wireshark - mysql - imap - rsyslog - courier-authlib - nfs-utils - libxml2 - python - jhead - git - samba - vinagre - opera 2) Pending Vulnerabilities, Solutions, and Work-Arounds: 3) Authenticity Verification and Additional Information ______________________________________________________________________________ 1) Solved Security Vulnerabilities To avoid flooding mailing lists with SUSE SecurityAnnouncements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. Fixed packages for the following incidents are already available on our FTP server and via the YaST Online Update. - ethereal, wireshark An update of wireshark/ethereal was released to fix various vulnerabili- ties: CVE-2008-3933 (crash when processing compressed data), CVE-2008-3934 (crash when processing rf5 files), CVE-2008-4680 (USB dissector crash), CVE-2008-4681 (Bluetooth RFCOMM dissector crash), CVE-2008-4682 (Tamos CommView dissector crash), CVE-2008-4683 (Bluetooth ACL dissector crash), CVE-2008-4684 (PRP and MATE dissector crash) and CVE-2008-4685 (Q.931 dissector crash). CVE-2008-5285 (SMTP dissector infinite loop) and an infinite loop problem in the WLCCP dissector Affected products: openSUSE 10.3-11.1, NLD 9 SDK, Novell Linux POS 9, Open Enterprise Server, SLES 9, SLE SDK 10 SP2, SLED 10 SP2, SLES 10 SP2 - mysql Due a flaw users could access tables of other users (CVE-2008-4097, CVE-2008-4098); additionally empty bit-strings in a query could crash the MySQL server (CVE-2008-3963) Affected products: openSUSE 10.3-11.0, NLD 9 SDK, Novell Linux Desktop 9, Novell Linux POS 9, Open Enterprise Server, SLES 9, SLES SDK 9 - imap Insufficient buffer length checks in the imap client library may crash applications that use the library to print formatted email addresses. The imap daemon itself is not affected but certain versions of e.g. the php imap module are (CVE-2008-5514). The client library could also crash when a rogue server unexpectedly closes the connection (CVE-2008-5006). Affected products: openSUSE 10.3-11.1 - rsyslog rsyslog ignored the$AllowedSender configuration directive, therefore accepting log messages from anyone (CVE-2008-5617). Additionally imudp logged a message when unauthorized senders tried to send to it, therefore allowing attackers to flood the log CVE-2008-5618). Affected products: openSUSE 11.1 - courier-authlib Insufficient quoting allowed attackers to inject SQL statements when using the pgsql backend (CVE-2008-2380). Affected products: openSUSE 10.3-11.1 - nfs-utils This update of nfs-utils fixes the handling of the tcp wrapper ACLs. (CVE-2008-4552) Affected products: Novell Linux Desktop 9, Novell Linux POS 9, Open Enterprise Server, SLE 10 DEBUGINFO SP2, SLED 10 SP2, SLES 10 SP2, SLES 9 - libxml2 libxml2 could run into an endless loop when processing specially crafted XML files (CVE-2008-4225) Affected products: NLD 9 SDK, Novell Linux Desktop 9, Novell Linux POS 9, Open Enterprise Server, SLES 9, SLES SDK 9, SuSE Linux Enterprise Server 8 for IBM S/390 and IBM zSeries, SuSE Linux Enterprise Server 8 for x86, SLE 10 DEBUGINFO SP2, SLED 10 SP1, SLED 10 SP2, SLES 10 SP1, SLES 10 SP2 - python Integer Overflows in the python imageop module and in the expandtabs method potentially allowed attackers to execute arbitrary code (CVE-2008-4864, CVE-2008-5031) Affected products: openSUSE 10.3-11.0, Novell Linux Desktop 9, Novell Linux POS 9, Open Enterprise Server, SLES 9, SLE SDK 10 SP2, SLED 10 SP2, SLES 10 SP2 - jhead An update of jhead fixes several security problems: - CVE-2008-4575: buffer overflow in DoCommand() - CVE-2008-4639: local symlink attack - CVE-2008-4640: DoCommand() allowed deletion of arbitrary files - CVE-2008-4641: execution of arbitrary shell commands in DoCommand() Affected products: openSUSE 10.3-11.1 - git Insufficient quoting of shell characters allowed remote attackers to execute arbitrary commands via the git webinterface (CVE-2008-5517) Affected products: openSUSE 10.3 - samba This update of samba fixes a bug that allowed the client to retrieve arbitrary memory content from the server process. (CVE-2008-4314) Additionally another bug was fixed that affects environments that enabled registry shares by setting "registry shares = yes". In this case an authenticated user is accidently allowed to access the root file- system "/". (CVE-2009-0022) Affected products: openSUSE 10.3-11.1 - vinagre A format string problem in vinagre potentially allowed malicious VNC servers to have a vinagre client that connects to the server execute arbitrary code. (CVE-2008-5660) Affected products: openSUSE 11.0-11.1 - opera Opera 9.63 fixes the following security problems: - Manipulating text input contents can allow execution of arbitrary code - HTML parsing flaw can cause Opera to execute arbitrary code. - Long hostnames in file: URLs can cause execution of arbitrary code. - Script injection in feed preview can reveal contents of unrelated news feeds. - Built-in XSLT templates can allow cross-site scripting. - Fixed an issue that could reveal random data. - SVG images embedded using tags can no longer execute Java or plugin content. Affected products: openSUSE 10.3-11.1 ______________________________________________________________________________ 2) Pending Vulnerabilities, Solutions, and Work-Arounds none ______________________________________________________________________________ 3) Authenticity Verification and Additional Information - Announcement authenticity verification: SUSE security announcements are published via mailing lists and on Web sites. The authenticity and integrity of a SUSE security announcement is guaranteed by a cryptographic signature in each announcement. All SUSE security announcements are published with a valid signature. To verify thesignature of the announcement, save it as text into a file and run the command gpg --verify replacing with the name of the file containing the announcement. The output for a valid signature looks like: gpg: Signature made using RSA key ID 3D25D3D9 gpg: Good signature from "SuSE Security Team " where is replaced by the date the document was signed. If the security team's key is not contained in your key ring, you can import it from the first installation CD. To import the key, use the command gpg --import gpg-pubkey-3d25d3d9-36e12d04.asc - Package authenticity verification: SUSE update packages are available on many mirror FTP servers all over the world. While this service is considered valuable and important to the free and open source software community, the authenticity and integrity of a package needs to be verified to ensure that it has not been tampered with. The internal RPM package signatures provide an easy way to verify the authenticity of an RPM package. Use the command rpm -v --checksig to verify the signature of the package, replacing with the filename of the RPM package downloaded. The package is unmodified if it contains a valid signature from This email address is being protected from spambots. You need JavaScript enabled to view it. with the key ID 9C800ACA. This key is automatically imported into the RPM database (on RPMv4-based distributions) and the gpg key ring of 'root' during installation. You can also find it on the first installation CD and included at the end of this announcement. - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - General Linux and SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an e-mail to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements aresent to this list. To subscribe, send an e-mail to . ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Report on Low Profile Fixes and Vulnerabilities Revealed in 2009 Announcements.. SUSE Announcement, Security Fixes, Vulnerability Management. . LinuxSecurity.com Team

Calendar%202 Jan 12, 2009 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200