Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 483
Alerts This Week
Warning Icon 1 483

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -6 articles for you...
203

Mageia 9 MGASA-2025-0162 critical: zsync pointer arithmetic flaw

Improper Pointer Arithmetic in pcl. (CVE-2025-4638) References: - https://bugs.mageia.org/show_bug.cgi?id=34301 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/OPTP7IW7Z54KXHWHH6JSVJ75RDCVQ4Z7/ . MGASA-2025-0162 - Updated zsync packages fix security vulnerabilities Publication date: 24 May 2025 URL: https://advisories.mageia.org/MGASA-2025-0162.html Type: security Affected Mageia releases: 9 CVE: CVE-2025-4638 Improper Pointer Arithmetic in pcl. (CVE-2025-4638) References: - https://bugs.mageia.org/show_bug.cgi?id=34301 - https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/OPTP7IW7Z54KXHWHH6JSVJ75RDCVQ4Z7/ - https://www.cve.org/CVERecord?id=CVE-2025-4638 SRPMS: - 9/core/zsync-0.6.2-11.1.mga9 . MGASA-2025-0162 addresses vulnerabilities related to improper pointer arithmetic in zsync, featuring essential bug fixes to enhance security, stability, and performance. Mageia Zsync Update, Pointer Arithmetic Fix, Security Patches, Software Vulnerability Management. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 May 24, 2025 Critical Mageia
87

Debian 3.1 DSA 798-3 Urgent: Zsync DOS Buffer Overflow Fix

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 797-2 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Stone September 28th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : zsync Vulnerability : DOS Problem-Type : buffer overflow Debian-specific: no CVE ID : CAN-2005-1849, CAN-2005-2096 zsync, a file transfer program, includes a modified local copy of the zlib library, and is vulnerable to certain bugs fixed previously in the zlib package. There was a build error for the sarge i386 proftpd packages released in DSA 797-1. A new build, zsync_0.3.3-1.sarge.1.2, has been prepared to correct this error. The packages for other architectures are unaffected. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Intel IA-32 architecture: Size/MD5 checksum: 94516 bb4ff605c6e3b94f23dd0986ca55e450 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 797-3 describes updated zsync packages addressing a critical DOS buffer overflowvulnerability. Please ensure timely action is taken.. Debian Security,DOS Attack,Zsync Update,Buffer Overflow Fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Sep 28, 2005 Important Debian
87

Debian Sarge: DSA 797-1 Critical: Zsync DoS Issue Fixed

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 797-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Michael Stone September 1st, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : zsync Vulnerability : DOS Problem-Type : buffer overflow Debian-specific: no CVE ID : CAN-2005-1849, CAN-2005-2096 zsync, a file transfer program, includes a modified local copy of the zlib library, and is vulnerable to certain bugs fixed previously in the zlib package. The old stable distribution (woody) does not contain the zsync package. For the stable distribution (sarge) this problem has been fixed in version 0.3.3-1.sarge.1. For the unstable distribution (sid) this problem has been fixed in version 0.4.0-2. We recommend that you upgrade your zsync package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 742 38abbfacbf93f57692641a0f257abe4e Size/MD5 checksum: 6213 224eae057a1eebdd3ffe16e6e3d584e6 Size/MD5 checksum: 241726 71efef80525276990cf8af97ee2b8f97 Alpha architecture: Size/MD5 checksum: 120612 0efd2b252f7a2eebac03d04aee7bff87 AMD64 architecture: Size/MD5 checksum: 99560 ede8508b5d555b6be89c5adbbea49c20 ARM architecture: Size/MD5 checksum: 100420 713b7d689f4ccdf4317c255dd0de7e6f Intel IA-32 architecture: Size/MD5 checksum: 98414 bb4ff605c6e3b94f23dd0986ca55e450 Intel IA-64 architecture: Size/MD5 checksum: 139370 91cef962076eb5d66ddda86e1ca1e8f8 HP Precision architecture: Size/MD5 checksum: 105062 ba01f3b644ea1be05e51d3d07b00d363 Motorola 680x0 architecture: Size/MD5 checksum: 85176 ec83816290778ca23005cbcf001962ed Big endian MIPS architecture: Size/MD5 checksum: 106840 bdd9b5d16ed84330292a97eb01deb381 Little endian MIPS architecture: Size/MD5 checksum: 107912 bf7c5dfcac00e250efefe59959f47deb PowerPC architecture: Size/MD5 checksum: 100460 7126e64533e31ccd1be3302772ca4158 IBM S/390 architecture: Size/MD5 checksum: 103472 b9712abdbaa529ab5ed20854b5b70406 Sun Sparc architecture: Size/MD5 checksum: 98614 534233dd79188ea592f23a0b00f5d524 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . To address the buffer overflow vulnerability in Debian's zsync package, update it by running specific terminal commands to enhance security and avoid DoS risks. zsync packages, Debian security update, DOS fix. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 01, 2005 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200