Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Uncontrolled Recursion has been discovered in pdfinfo and pdftops in version 0.89.0 of the Poppler PDF rendering library ( CVE-2020-23804 ). This severe stack overflow vulnerability, which has received a National Vulnerability Database base score of 7.5 out of 10, significantly threatens the availability of impacted systems. . This flaw allows remote attackers to cause a denial of service via crafted input, leading to loss of system access. Important updates for Poppler have been released to mitigate this severe flaw. Given this bug’s significant impact on affected systems, if left unpatched, we strongly recommend all impacted users apply the updates released by their distro(s) immediately to prevent inconvenient, costly downtime and protect access to their critical systems. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . This vulnerability enables distant intruders to trigger a denial of service through specially crafted data, resulting in the loss of essential access.. Denial Of Service, Poppler Update, Stack Overflow, Security Patch, System Access. . Brittany Day
A critical stack overflow vulnerability has been discovered in ash.c:6030 in BusyBox before 1.35 ( CVE-2022-48174 ). Due to the ease of exploitation and the severe threat it poses to the confidentiality, integrity, and availability of impacted systems, this bug has received a National Vulnerability Database base score of 9.8 out of 10. It was also discovered that BusyBox incorrectly handled certain malformed gzip archives ( CVE-2021-28831 ). . These issues could allow a remote attacker to execute arbitrary code or cause BusyBox to crash, resulting in a denial of service. Important updates for BusyBox have been released that mitigate these critical flaws. We urge all impacted users to apply the updates released by SUSE and Ubuntu immediately to protect against attacks leading to potential downtime or compromise. To stay on top of essential updates released by the open-source programs and applications you use, register as a LinuxSecurity user , subscribe to our Linux Advisory Watch newsletter, and customize your advisories for your distro(s). This will enable you to stay up-to-date on the latest, most significant issues impacting the security of your systems. Follow @LS_Advisories on Twitter for real-time updates on advisories for your distro(s) . . Critical buffer overflow issues in BusyBox have been resolved. Timely updates are essential to prevent potential breaches.. BusyBox Security, Stack Overflow Risk, Critical Vulnerability Update. . Brittany Day
Here we go again. Another obnoxious security bug, CVE-2022-0435: A Remote Stack Overflow in The Linux Kernel was found by Appgate senior exploit developer Samuel Page while he was poking around at a Linux heap overflow security bug, CVE-2021-43267 from November 2021. Page’s discovery is a remotely and locally reachable stack overflow in the Linux kernel’s Transparent Inter-Process Communication (TIPC) protocol networking module. . TIPC, as the name says, is used for intracluster communications. Cluster topology is managed using the concept of nodes and links between these nodes. Messages sent using TIPC can be sent over either UDP or Ethernet. So far, so good. . A fix for memory corruption issues related to local and remote buffer overflows has been implemented in the TIPC networking subsystem of the Linux kernel, enhancing system security.. Remote Stack Overflow, Linux Kernel Security, TIPC Protocol Update. . Brittany Day
An exploitable bug sitting in a popular Linux kernel module has been found after five years. A patch is finally available, experts say. . An exploitable bug sitting in a popular Linux kernel module, has been found after five years, researchers have claimed. Detailing the findings in a blog post , researcher Samuel Page from cybersecurity firm Appgate said the flaw was a stack buffer overflow, found in the kernel networking module for the Transparent Inter-Process Communication (TIPC) protocol. Page describes TIPC as an IPC mechanism designed for intra-cluster communication. “Cluster topology is managed around the concept of nodes and the links between these nodes,” he says. . A critical vulnerability within a widely-used Linux kernel component has been discovered after a prolonged five-year period, with accompanying instructions for remediation made available.. Linux Kernel Patch, Stack Overflow Exploit, Kernel Security Fix, TIPC Module Bug. . Brittany Day
A code audit of the popular protocol analyser, Ethereal, has revealed several stack overflows which can be remotely triggered, according to a posting to the Full-Disclosure vulnerability mailing list. . . .. A code audit of the popular protocol analyser, Ethereal, has revealed several stack overflows which can be remotely triggered, according to a posting to the Full-Disclosure vulnerability mailing list. Stefan Esser of e-matters Security, who discovered the vulnerabilities, described them as critical, and said the developers of the open source package were expected to release an updated version soon. Ethereal runs on all common platforms, including Unix, Linux and Windows. . Recent examination uncovers significant buffer overflow vulnerabilities within the Aether protocol analysis tool, jeopardizing its security protocols.. Ethereal Protocol Flaws, Stack Overflow Threats, Open Source Examination. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.