Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo: GLSA-201309-03 normal: xlockmore denial of service

A buffer overflow in Xlockmore might allow remote attackers to cause a Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201309-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Xlockmore: Denial of Service Date: September 02, 2013 Bugs: #255229, #440776, #477328 ID: 201309-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A buffer overflow in Xlockmore might allow remote attackers to cause a Denial of Service. Background ========= Xlockmore is just another screensaver application for X. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 x11-misc/xlockmore < 5.43 > = 5.43 Description ========== A Denial of Service flaw was found in the way Xlockmore performed the passing of arguments to the underlying localtime() call, when the 'dlock' mode was used. Impact ===== A local attacker could possibly cause a Denial of Service condition and potentially obtain unauthorized access to the graphical session, previously locked by another user. Workaround ========= There is no known workaround at this time. Resolution ========= All Xlockmore users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =x11-misc/xlockmore-5.43" References ========= [ 1 ] CVE-2012-4524 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-4524 [ 2 ] CVE-2013-4143 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4143 Availability =========== This GLSA and any updates to it are available for viewing at theGentoo Security Website: https://security.gentoo.org/glsa/201309-03 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org. License ====== Copyright 2013 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . The Gentoo security advisory GLSA 201401-02 highlights a critical vulnerability in Gnumeric that could lead to arbitrary code execution.. Xlockmore Denial Of Service,Gentoo Security Advisory,Buffer Overflow. . LinuxSecurity.com Team

Calendar 2 Sep 02, 2013 Gentoo
99

Slackware: Critical xlockmore Root Access Threat Advisory

A root exploit has been found in xlockmore packaged with Slackware.. A root exploit has been found in xlockmore packaged with Slackware. By providing a carefully crafted display variable to xlock, it is possible for a local attacker to gain root access. Anyone running xlock on a public machine should upgrade to this version of xlock (or disable xlock altogether) immediately. The package described below will work for users of Slackware 7.0, 7.1, and -current. ========================================== xlockmore 4.17.2 AVAILABLE - (x1/xlock.tgz) ========================================== A root exploit has been fixed in this release of xlockmore. The new xlock.tgz package is available from: For verification purposes, we provide the following checksums: 16-bit "sum" checksum: 53857 762 x1/xlock.tgz 128-bit MD5 message digest: ca171919342cd7a3e18a3ac3cd91e252 x1/xlock.tgz INSTALLATION INSTRUCTIONS FOR THE xlock.tgz PACKAGE: --------------------------------------------------- Disable any running xlockmore processes and issue this command: # upgradepkg xlock.tgz Remember, it's also a good idea to backup configuration files before upgrading packages. - Slackware Linux Security Team The Slackware Linux Project . A critical flaw has been discovered in xlockmore bundled with Slackware. Users are urged to update immediately or disable the application.. root Access,xlockmore,slackware,critical Update,software Importance. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 24, 2000 Critical Slackware
87

Debian 2.1: Security Advisory on Xlockmore Local Exploit

There is a format string bug in all versions of xlockmore/xlockmore-gl.. -----BEGIN PGP SIGNED MESSAGE----- - ------------------------------------------------------------------------ Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Michael Stone August 16, 2000 - ------------------------------------------------------------------------ Package: xlockmore, xlockmore-gl Vulnerability type: local exploit Debian-specific: no There is a format string bug in all versions of xlockmore/xlockmore-gl. Debian 2.1 (slink) installs xlock setgid by default, and this exploit can be used to gain read access to the shadow file. We recommend upgrading immediately. xlockmore is normally installed as an unprivileged program in Debian 2.2 (potato) and is not vulnerable in that configuration. xlockmore may be setuid/setgid for historical reasons or after upgrading from a previous Debian release; consult README.Debian in /usr/doc/xlockmore or /usr/doc/xlockmore-gl for information about xlock privileges and how to disable them. If your local environment requires xlock to be setgid, or if in doubt, you should upgrade to a fixed package immediately. Fixed packages are available in xlockmore/xlockmore-gl 4.12-5 for Debian 2.1 (slink) and xlockmore/xlockmore-gl 4.15-9 for Debian 2.2 (potato). wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink - -------------------------------- Source archives: MD5 checksum: e253bee3472f835e71e23994ead85dcf MD5 checksum: acbf3f3310edca9ce20f5d4e720f3227 MD5 checksum: 110a594d89f3a2758255d0bba0e48217 Alpha architecture: MD5 checksum: d51723c04362213ca6f43d12db479a07 MD5 checksum: 41878e3ba49152c5049cb9a394a41d14 Intel ia32 architecture: MD5 checksum: 0d5c32ed8a834bb810ba421520f81dea MD5 checksum: ca34fd0732d82f2e4d176eb80f828cd8 Motorola 680x0 architecture: will be available shortly Sun Sparc architecture: MD5 checksum: 3ccfd6b2893e0e183eb1118c75fd57e4 MD5 checksum: 002d7712d7be3a943e0b88f9263092b2 Debian GNU/Linux 2.2 alias potato - --------------------------------- Source archives: MD5 checksum: 02f86bd315558ca32ca5a777d009c85f MD5 checksum: 377a392b2f6c711b5252fbfff822ce99 MD5 checksum: eceda376ee0a336063a46ec018c83d94 Alpha architecture: MD5 checksum: e620c4e0d3f4ecc7167b9f9897cd3971 MD5 checksum: 15e4be9f504873789c42ce0f283da707 Arm architecture: MD5 checksum: bb0f9cfb7a90f73a870ed529b51ef258 MD5 checksum: e78be3e33bbc1ee68c01bef39be8997d Intel ia32 architecture: MD5 checksum: aed3a97f49cd0ea1464cefb6ef94b9ac MD5 checksum: 7a8ac4b5725bf3117b029ba31568817f Motorola 680x0 architecture: Will be available shortly PowerPC architecture: Will be available shortly Sun Sparc architecture: MD5 checksum: 3507476bbf9e625c06a4f52ffa81a1e8 MD5 checksum: 9ce55111c3a93744b62eb5f2d2291511 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.2 (GNU/Linux) Comment: For info see The GNU Privacy Guard iQCVAwUBOZtlzQ0hVr09l8FJAQGhqAQArn11m6LbQxYxvrt1VmrrEpCYpSKcCeQd LptDP6MkaD/8CvQHm7qYDyG/BD90UxkocLEmiRf53DvYYfaKEskyLXfKEoafMJAt /q4V6PslIP98sz0Q1ddLIq4x+mHgJpmsD69XqjxqNMhK9sqLXpJuSLA1HE08JOD5 LjEL+J5ISSo=qN72 -----END PGP SIGNATURE----- . Important notice issued: mitigate recent risk found in xlockmore affecting Debian systems. Contact Debian security support for assistance.. Debian, Local Exploit, xlockmore Exploit. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 17, 2000 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here