Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
87

Debian: DSA 1389-2 Critical: Zoph SQL Injection Risk Mitigated

It was discovered that zoph, a web based photo management system, performs insufficient input sanitising, which allows SQL injection. This is an updated advisory to make the update for oldstable (sarge) available, which had been uploaded to the wrong suite.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1389-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Thijs Kinkhorst October 24th, 2007 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : zoph Vulnerability : missing input sanitising Problem-Type : remote Debian-specific: no CVE ID : CVE-2007-3905 Debian Bug : 435711 It was discovered that zoph, a web based photo management system, performs insufficient input sanitising, which allows SQL injection. This is an updated advisory to make the update for oldstable (sarge) available, which had been uploaded to the wrong suite. For the oldstable distribution (sarge) this problem has been fixed in version 0.3.3-12sarge3. For the stable distribution (etch) this problem has been fixed in version 0.6-2.1etch1. For the unstable distribution (sid) this problem has been fixed in version 0.7.0.2-1. We recommend that you upgrade your zoph package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 862a18d228cf9a669a12b9abaa5a5b259d3 Size/MD5 checksum: 54166 645da5f7fd9a8f43a85e516967f063b8 Size/MD5 checksum: 153902 5ff9d8e182e16d53e0511b6d51da8521 Architecture independent components: Size/MD5 checksum: 172336 134a3fd98459877251f5b4c6ab3a610b These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Zoph software has received critical updates to address vulnerabilities from SQL injection in Debian systems. It's essential to secure your environments. Perform the upgrade right away!. Debian Update, SQL Injection Fix, Zoph Security Advisory, Input Sanitizing. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 24, 2007 Critical Debian
87

Debian 3.1 DSA-989-1 Critical: Fix for Zoph SQL Injection Issue

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 989-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Moritz Muehlenhoff March 9th, 2006 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : zoph Vulnerability : SQL injection Problem-Type : remote Debian-specific: no CVE ID : CVE-2006-0402 Debian Bug : 350717 Neil McBride discovered that Zoph, a web based photo management system performs insufficient sanitising for input passed to photo searches, which may lead to the execution of SQL commands through a SQL injection attack. The old stable distribution (woody) does not contain zoph packages. For the stable distribution (sarge) this problem has been fixed in version 0.3.3-12sarge1. For the unstable distribution (sid) this problem has been fixed in version 0.5-1. We recommend that you upgrade your zoph package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 570 ce9957fa5af8115a5aec530aabe6847f Size/MD5 checksum: 53959 7c37d28798981a054c634cca92122199 Size/MD5 checksum: 153902 5ff9d8e182e16d53e0511b6d51da8521 Architecture independent components: Size/MD5 checksum: 172190 a185b3cba99ea4bc0f46c73b68bb5a46 These files will probably be moved into the stabledistribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 989-1 http://www.debian.org/security/ Moritz Muehlenhoff March 9th, 200. updated, package, --------------------------------------------------------------------------debian. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Mar 09, 2006 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here