Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7386 7387 7388 7389 7390 7391 7392 7393 7394 7395 7396 ... 7438 ) Next »

The Tk Text Widget

  • Linux Journal (Posted by dave on Jan 20, 2003 8:00 AM EDT)
  • Story Type: News Story
The powerful text widget in the Tk toolkit offers many facilities to writers of Tcl, Perl and Python scripts.

Automating Perl Database Applications

  • Linux Journal (Posted by dave on Jan 20, 2003 8:00 AM EDT)
  • Story Type: News Story
Using Perl and CGIScripter to generate multi-platform Perl CGI code.

Linux in Academic Labs Revisited

  • Linux Journal (Posted by dave on Jan 20, 2003 8:00 AM EDT)
  • Story Type: News Story
Using an X-based client server model to maintain network consistency.

The Return of Mini Book Reviews

  • Linux Journal (Posted by dave on Jan 20, 2003 8:00 AM EDT)
  • Story Type: News Story
Perl for work and for fun, an introduction to CVS and developing for Linux are covered in this round of mini book reviews.

SuSE alert: dhcp

  • Mailing list (Posted by dave on Jan 20, 2003 7:46 AM EDT)
  • Story Type: Security; Groups: SUSE
The ISC (Internet Software Consortium) dhcp package is an imple- mentation of the "Dynamic Host Configuration Protocol" (DHCP). An internal source code audit done by ISC revealed several buffer overflows in the code which is responsible to handle dynamic DNS requests. These bugs allow an attacker to gain remote access to the dhcp server if the dynamic DNS feature is enabled. Dynamic DNS is not enabled by default on SuSE Linux.

Debian alert: New CUPS packages fix several vulnerabilities

  • Mailing list (Posted by dave on Jan 20, 2003 6:48 AM EDT)
  • Story Type: Security; Groups: Debian
Multiple vulnerabilities were discovered in the Common Unix Printing System (CUPS). Several of these issues represent the potential for a remote compromise or denial of service. The Common Vulnerabilities and Exposures project identifies the following problems:

SuSE alert: susehelp

  • Mailing list (Posted by dave on Jan 20, 2003 4:39 AM EDT)
  • Story Type: Security; Groups: SUSE
During a code review of the susehelp package the SuSE Security Team recognized that the security checks done by the susehelp CGI scripts are insufficient. Remote attackers can insert certain characters in CGI queries to the susehelp system tricking it into executing arbitrary code as the "wwwrun" user. Please note that this is only a vulnerability if you have a web server running and configured to allow access to the susehelp system by remote sites. We nevertheless recommend an update of this package. As a temporary workaround you may un-install the susehelp package by issuing the following command as root:

Slackware alert: New DHCP packages available

New DHCP packages are available for Slackware 8.1 and -current to fix buffer overflow security problems.

Mandrake alert: Updated KDE packages fix multiple vulnerabilities

Multiple instances of improperly quoted shell command execution exist in KDE 2.x up to and including KDE 3.0.5. KDE fails to properly quote parameters of instructions passed to the shell for execution. These parameters may contain data such as filenames, URLs, email address, and so forth; this data may be provided remotely to a victim via email, web pages, files on a network filesystem, or other untrusted sources.

Mandrake alert: Updated dhcp packages fix remote code execution vulnerability

Several potential vulnerabilities were detected by the ISC (Internet Software Consortium) in their dhcp server software. The vulnerabilities affect the minires library and may be exploitable as stack buffer overflows, which could lead to remote code execution. All Mandrake Linux users are encouraged to upgrade; only Mandrake Linux 8.0 came with dhcp 2.x and is not vulnerable.

Debian alert: New dhcp3 packages fix arbitrary code execution

  • Mailing list (Posted by dave on Jan 17, 2003 4:45 AM EDT)
  • Story Type: Security; Groups: Debian
The Internet Software Consortium discoverd several vulnerabilities during an audit of the ISC DHCP Daemon. The vulnerabilities exist in error handling routines within the minires library and may be exploitable as stack overflows. This could allow a remote attacker to execute arbitrary code under the user id the dhcpd runs under, usually root. Other DHCP servers than dhcp3 doesn't seem to be affected.

Debian alert: New bugzilla packages fix unauthorized data modification

  • Mailing list (Posted by dave on Jan 16, 2003 6:51 AM EDT)
  • Story Type: Security; Groups: Debian
Two vulnerabilities have been discovered in Bugzilla, a web-based bug tracking system, by its authors. The Common Vulnerabilities and Exposures Project identifies the following vulnerabilities:

Red Hat alert: Updated vim packages fix modeline vulnerability

  • Mailing list (Posted by dave on Jan 16, 2003 5:32 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated vim packages are now available for Red Hat Linux. These updates resolve a security issue when opening a specially crafted text file.

Red Hat alert: Updated dhcp packages fix security vulnerabilities

  • Mailing list (Posted by dave on Jan 15, 2003 11:41 PM EDT)
  • Story Type: Security; Groups: Red Hat
Several potential stack overflow vulnerabilities affect the ISC DHCPD server. This advisory provides fixed packages for Red Hat Linux 8.0.

Red Hat alert: Updated MySQL packages fix various security issues

  • Mailing list (Posted by dave on Jan 15, 2003 10:23 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated MySQL packages are available for Red Hat Linux 7, 7.1, 7.2, 7.3, and 8.0 which fix security vulnerabilities found in the MySQL server.

Debian alert: New IMP packages fix SQL injection and typo

  • Mailing list (Posted by dave on Jan 15, 2003 8:11 AM EDT)
  • Story Type: Security; Groups: Debian
The advisory DSA 229-1 contained a typo in one file which could cause certain installations to fail suddenly.

Debian alert: New IMP packages fix SQL injection

  • Mailing list (Posted by dave on Jan 15, 2003 6:15 AM EDT)
  • Story Type: Security; Groups: Debian
Jouko Pynnonen discovered a probem with IMP, a web based IMAP mail program. Using carefully crafted URLs a remote attacker is able to inject SQL code into SQL queries without proper user authentication. Even though results of SQL queries aren't directly readable from the screen, an attacker might. update his mail signature to contain wanted query results and then view it on the preferences page of IMP.

Mandrake alert: Updated OpenLDAP packages fix multiple vulnerabilities

A review was completed by the SuSE Security Team on the OpenLDAP server software, and this audit revealed several buffer overflows and other bugs that remote attackers could exploit to gain unauthorized access to the system running the vulnerable OpenLDAP servers. Additionally, various locally exploitable bugs in the OpenLDAP v2 libraries have been fixed as well.

Mandrake alert: Updated leafnode packages fix remote DoS vulnerability

A vulnerability was discovered by Jan Knutar in leafnode that Mark Brown pointed out could be used in a Denial of Service attack. This vulnerability causes leafnode to go into an infinite loop with 100% CPU use when an article that has been crossposed to several groups, one of which is the prefix of another, is requested by it's Message-ID.

Red Hat alert: Updated PostgreSQL packages fix security issues and bugs

  • Mailing list (Posted by dave on Jan 14, 2003 1:41 PM EDT)
  • Story Type: Security; Groups: Red Hat
Updated PostgreSQL packages are available for Red Hat Linux 7.3 and 8.0. These packages correct several security and other bugs. A separate advisory deals with updated PostgreSQL packages for Red Hat Linux 6.2, 7, 7.1, and 7.

« Previous ( 1 ... 7386 7387 7388 7389 7390 7391 7392 7393 7394 7395 7396 ... 7438 ) Next »