Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
91

Gentoo GLSA-202204-15:03 Critical: Zgv Heap Overflow Advisory

The fixed zgv ebuild proposed in the initial version of this Security Advisory did not address all the vulnerabilities of the zgv package. The corrected sections appear below. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory [ERRATA UPDATE] GLSA 200604-10:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: zgv: Heap overflow Date: April 21, 2006 Updated: June 10, 2006 Bugs: #127008 ID: 200604-10:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Errata ===== The fixed zgv ebuild proposed in the initial version of this Security Advisory did not address all the vulnerabilities of the zgv package. The corrected sections appear below. Affected packages ================ The corrected list of affected packages is as follows: ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/xzgv < 0.8-r2 > = 0.8-r2 2 media-gfx/zgv < 5.9 > = 5.9 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Resolution ========= All zgv users should also upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/zgv-5.9" Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200604-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentialityand security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . New Security Notice for zgv heap overflow issue in Gentoo! Discover the risks and find upgrade steps here.. Gentoo Security,zgv Heap Overflow,Memory Corruption,Gentoo Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Jun 11, 2006 Critical Gentoo
91

Gentoo: GLSA-200604-10 Normal: zgv/xzgv Heap Overflow Attack

xzgv and zgv attempt to decode JPEG images within the CMYK/YCCK colour space incorrectly, potentially resulting in the execution of arbitrary code. [More...]. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200604-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: zgv, xzgv: Heap overflow Date: April 21, 2006 Bugs: #127008 ID: 200604-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= xzgv and zgv attempt to decode JPEG images within the CMYK/YCCK colour space incorrectly, potentially resulting in the execution of arbitrary code. Background ========= xzgv and zgv are picture viewing utilities with a thumbnail based file selector. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 media-gfx/xzgv < 0.8-r2 > = 0.8-r2 2 media-gfx/zgv < 5.8 > = 5.8 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== Andrea Barisani of Gentoo Linux discovered xzgv and zgv allocate insufficient memory when rendering images with more than 3 output components, such as images using the YCCK or CMYK colour space. When xzgv or zgv attempt to render the image, data from the image overruns a heap allocated buffer. Impact ===== An attacker may be able to construct a malicious image that executes arbitrary code with the permissions of the xzgv orzgv user when attempting to render the image. Workaround ========= There is no known workaround at this time. Resolution ========= All xzgv users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/xzgv-0.8-r2" All zgv users should also upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =media-gfx/zgv-5.8" References ========= [ 1 ] CVE-2006-1060 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200604-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.0/ . Buffer overflow in wxyz and abcde could enable remote code execution on Fedora. Urgent patches necessary for users.. Gentoo Security,image rendering update,heap overflow risk. . LinuxSecurity.com Team

Calendar 2 Apr 21, 2006 Gentoo
87

Debian: DSA 608-1 Critical: Zgv Integer Overflows Threat and Fix

Several vulnerabilities have been discovered in zgv, an SVGAlib graphics viewer for the i386 architecture.. --------------------------------------------------------------------------Debian Security Advisory DSA 608-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze December 14th, 2004 http://www.debian.org/security/faq --------------------------------------------------------------------------Package : zgv Vulnerability : integer overflows, unsanitised input Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-1095 CAN-2004-0999 BugTraq ID : 11556 Several vulnerabilities have been discovered in zgv, an SVGAlib graphics viewer for the i386 architecture. The Common Vulnerabilities and Exposures Project identifies the following problems: CAN-2004-1095 Luke Macken and "infamous41md" independently discoverd multiple integer overflows in zgv. Remote exploitation of an integer overflow vulnerability could allow the execution of arbitrary code. CAN-2004-0999 Mikulas Patocka discovered that malicious multiple-image (e.g. animated) GIF images can cause a segmentation fault in zgv. For the stable distribution (woody) these problems have been fixed in version 5.5-3woody1. For the unstable distribution (sid) these problems will be fixed soon. We recommend that you upgrade your zgv package immediately. Upgrade Instructions --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody -------------------------------- Source archives: Size/MD5 checksum: 601 f6114a026863db918a6bd9a6cc201a97 Size/MD5 checksum: 8541 f501ad407808235577b2bc746ddfe4e6 Size/MD5 checksum: 329235 629386a4df72f6ec007319bf12db1374 Intel IA-32 architecture: Size/MD5 checksum: 211772 36e675c74bafb546e5f6fb0da36385c3 These files will probably be moved into the stable distribution on its next update. ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. Package info: `apt-cache show ' and https://www.debian.org/distrib/packages . Debian Security Notice DSA 609-1 discusses vulnerabilities in the package zcat, providing comprehensive steps for remediation.. zgv security issue, Debian security advisory, graphics viewer fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 14, 2004 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here