Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
91

Gentoo: GLSA-201701-40 Normal: Xdelta Arbitrary Code Execution Risk

A buffer overflow in xdelta might allow remote attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201701-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: xdelta: User-assisted execution of arbitrary code Date: January 17, 2017 Bugs: #574408 ID: 201701-40 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in xdelta might allow remote attackers to execute arbitrary code. Background ========= Xdelta is a C library and command-line tool for delta compression using VCDIFF/RFC 3284 streams. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-util/xdelta < 3.0.10 > = 3.0.10 Description ========== A buffer overflow can be triggered within xdelta when ran against a malicious input file. Impact ===== A remote attacker could coerce the victim to run xdelta against a malicious input file. This may be leveraged by an attacker to crash xdelta and gain control of program execution. Workaround ========= There is no known workaround at this time. Resolution ========= All xdelta users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/xdelta-3.0.10" References ========= [ 1 ] CVE-2014-9765 https://www.cve.org/CVERecord?id=CVE-2014-9765 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201701-40 Concerns? ======== Security is a primaryfocus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2017 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The Gentoo Linux Security Advisory GLSA 202301-15 warns of a critical vulnerability in the libjpeg library, recommending immediate updates to protect systems.. Gentoo Security,xdelta Buffer Overflow,Remote Code Execution,Arbitrary Code Execution. . LinuxSecurity.com Team

Calendar 2 Jan 17, 2017 Gentoo
89

Fedora Core 4: FEDORA-2005-876 Critical: xdelta Large File Fix

xdelta shipped with FC4 isn't compiled with large file support and uses obsolete glib-1.2 library. The libedsio symbols are missing from the installed libxdelta library. This release introduces xdelta ported to glib-2 and fixes the noted issues.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2005-876 2005-09-12 ---------------------------------------------------------------------Product : Fedora Core 4 Name : xdelta Version : 1.1.3 Release : 17.fc4 Summary : A binary file delta generator and an RCS replacement library. Description : Xdelta (X for XCF: the eXperimental Computing Facility at Berkeley) is a binary delta generator (like a diff program for binaries) and an RCS version control replacement library. The Xdelta library performs its work independently of the actual format used to encode the file and is intended to be used by various higher-level programs such as XCF's Project Revision Control System (PRCS). PRCS is a front end for a version control toolset. Xdelta uses a binary file delta algorithm to replace the standard diff program used by RCS. ---------------------------------------------------------------------Update Information: xdelta shipped with FC4 isn't compiled with large file support and uses obsolete glib-1.2 library. The libedsio symbols are missing from the installed libxdelta library. This release introduces xdelta ported to glib-2 and fixes the noted issues. ---------------------------------------------------------------------* Mon Sep 12 2005 Jindrich Novy 1.1.3-17.fc4 - link libxdelta against libedsio (#165978) - add support for large files (#155524) - port to use glib2 instead of obsolete glib1.2 (#136221) - convert spec to UTF-8 ---------------------------------------------------------------------This update can be downloaded from: 3a94b7bd642960731f6e38d7d4b5d05f SRPMS/xdelta-1.1.3-17.fc4.src.rpm 9306247120f496282ebb9f42bed3a069 ppc/xdelta-1.1.3-17.fc4.ppc.rpm 08ca1c6f1216955556405c35ec879743 ppc/xdelta-devel-1.1.3-17.fc4.ppc.rpm c00e6bc5915c87caae03555f3613ed55 ppc/debug/xdelta-debuginfo-1.1.3-17.fc4.ppc.rpm 48c7d5107da7dbc2ac6f690ac7f1243c x86_64/xdelta-1.1.3-17.fc4.x86_64.rpm 4b80e426540aa645644965eb17878e48 x86_64/xdelta-devel-1.1.3-17.fc4.x86_64.rpm 931c1025795e9086fea8f55fa5f569ce x86_64/debug/xdelta-debuginfo-1.1.3-17.fc4.x86_64.rpm 2a8a7a78139b5d88988536099a6bad3a i386/xdelta-1.1.3-17.fc4.i386.rpm 0b895d6b960689c02711100dc1df2e19 i386/xdelta-devel-1.1.3-17.fc4.i386.rpm acef04ad4519a2ceb57a992289442f9b i386/debug/xdelta-debuginfo-1.1.3-17.fc4.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. ----------------------------------------------------------------------- fedora-announce-list mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . An upgrade for xdelta on Fedora Core 4 addresses concerns regarding support for sizable files and the deprecated glib library.. xdelta Update, Fedora Core 4, Library Fix, Delta Generator. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 12, 2005 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here