Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7395 7396 7397 7398 7399 7400 7401 7402 7403 7404 7405 ... 7438 ) Next »

Debian alert: New purity packages fix potential buffer overflows

  • Mailing list (Posted by dave on Sep 13, 2002 6:10 AM EDT)
  • Story Type: Security; Groups: Debian
Two buffer overflows have been discovered in purity, a game for nerds and hackers, which is installed setgid games on a Debian system. This problem could be exploited to gain unauthorized access to the group games. A malicious user could alter the highscore of several games.

Debian alert: New PostgreSQL packages fix several vulnerabilities

  • Mailing list (Posted by dave on Sep 12, 2002 6:58 AM EDT)
  • Story Type: Security; Groups: Debian
Mordred Labs and others found several vulnerabilities in PostgreSQL, an object-relational SQL database. They are inherited from several buffer overflows and integer overflows. Specially crafted long date and time input, currency, repeat data and long timezone names could cause the PostgreSQL server to crash as well as specially crafted input data for lpad() and rpad(). More buffer/integer overflows were found in circle_poly(), path_encode() and path_addr().

Mandrake alert: php update

A fifth parameter was added to PHP's mail() function in 4.0.5 that is not properly sanitized when the server is running in safe mode. This vulnerability would allow local users and, possibly, remote attackers to execute arbitrary commands using shell metacharacters. After upgrading to these packages, execute "service httpd restart" as root in order to close the hole immediately.

Debian alert: New cacti package fixes arbitrary code execution

  • Mailing list (Posted by dave on Sep 10, 2002 5:39 AM EDT)
  • Story Type: Security; Groups: Debian
A problem in cacti, a PHP based frontend to rrdtool for monitoring systems and services, has been discovered. This could lead into cacti executing arbitrary program code under the user id of the web server. This problem, however, is only persistant to users who already have administrator privileges in the cacti system.

Red Hat alert: Updated gaim client fixes URL vulnerability

  • Mailing list (Posted by dave on Sep 10, 2002 1:01 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated gaim packages are now available for Red Hat Powertools 7. These updates fix a vulnerability in the URL handler.

Red Hat alert: Updated gaim client fixes URL vulnerability

  • Mailing list (Posted by dave on Sep 10, 2002 1:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated gaim packages are now available for Red Hat Linux 7.1, 7.2, and 7.3. These updates fix a vulnerability in the URL handler.

Mandrake alert: kdelibs update

A vulnerability was discovered in KDE's SSL implementation in that it does not check the basic constraints on a certificate and as a result may accept certificates as valid that were signed by an issuer who is not authorized to do so. This can lead to Konqueror and other SSL- enabled KDE software falling victim to a man-in-the-middle attack without being aware of the invalid certificate. This will trick users into thinking they are on a secure connection with a valid site when in fact the site is different from that which they intended to connect to. This is fixed in KDE 3.0.3, and the KDE team provided a patch for KDE 2.2.2. This patch has been applied to the following packages. After upgrading kdelibs, you must restart KDE in order for the fix to work.

Mandrake alert: krb5 update

The network authentication system in Kerberos 5 contains an RPC library that includes an XDR decoder derived from Sun's RPC implementation. This implemenation is vulnerable to a heap overflow. With Kerberos, it is believed that an attacker would need to be able to successfully authenticate to kadmin to be able to exploit this vulnerability.

Debian alert: New mhonarc packages fix cross site scripting problems

  • Mailing list (Posted by dave on Sep 9, 2002 9:05 AM EDT)
  • Story Type: Security; Groups: Debian
Jason Molenda and Hiromitsu Takagi found ways to exploit cross site scripting bugs in mhonarc, a mail to HTML converter. When processing maliciously crafted mails of type text/html, mhonarc, does not deactivate all scripting parts properly. This is fixed in upstream version 2.5.3.

Debian alert: New Python packages fix problem introduced by security fix

  • Mailing list (Posted by dave on Sep 9, 2002 7:31 AM EDT)
  • Story Type: Security; Groups: Debian
[The mail just sent was formatted like an attachment due to a misconception on my side. This mail is only the clearsign version. ]

Red Hat alert: New wordtrans packages fix remote vulnerabilities

  • Mailing list (Posted by dave on Sep 9, 2002 5:36 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated wordtrans packages are now available for Red Hat Linux 7.3 which fix remote vulnerabilities in wordtrans-web.

Debian alert: New ethereal packages fix buffer overflow

  • Mailing list (Posted by dave on Sep 6, 2002 6:22 AM EDT)
  • Story Type: Security; Groups: Debian
Ethereal developers discovered a buffer overflow in the ISIS protocol dissector. It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.

Mandrake alert: gaim update

Versions of Gaim (an AOL instant message client) prior to 0.58 contain a buffer overflow in the Jabber plug-in module. As well, a vulnerability was discovered in the URL-handling code, where the "manual" browser command passes an untrusted string to the shell without reliable quoting or escaping. This allows an attacker to execute arbitrary commands on the user's machine with the user's permissions. Those using the built-in browser commands are not vulnerable. Update: The 8.1 package had an incorrect dependency on perl. This package has been replaced with a proper package. Please note the differing md5 sums.

Mandrake alert: linuxconf notice

A vulnerability was discovered in linuxconf by Dave Aitel and later by iDEFENSE that is locally exploitable to obtain elevated privilege.

Debian alert: New Mantis package fixes privilege escalation

  • Mailing list (Posted by dave on Sep 4, 2002 6:48 AM EDT)
  • Story Type: Security; Groups: Debian
A problem with user privileges has been discovered in the Mantis package, a PHP based bug tracking system. The Mantis system didn't check whether a user is permitted to view a bug, but displays it right away if the user entered a valid bug id.

Debian alert: New scrollkeeper packages fix insecure temporary file creation

  • Mailing list (Posted by dave on Sep 3, 2002 5:14 AM EDT)
  • Story Type: Security; Groups: Debian
Spybreak discovered a problem in scrollkeeper, a free electronic cataloging system for documentation. The scrollkeeper-get-cl program creates temporary files in an insecure manner in /tmp using guessable filenames. Since scrollkeeper is called automatically when a user logs into a Gnome session, an attacker with local access can easily create and overwrite files as another user.

Red Hat alert: Updated scrollkeeper packages fix tempfile vulnerability

  • Mailing list (Posted by dave on Sep 2, 2002 8:43 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated scrollkeeper packages are now available for Red Hat Linux 7.3 which fix a tempfile vulnerability.

SuSE alert: glibc

  • Mailing list (Posted by dave on Aug 30, 2002 9:04 AM EDT)
  • Story Type: Security; Groups: SUSE
An integer overflow has been discovered in the xdr_array() function, contained in the Sun Microsystems RPC/XDR library, which is part of the glibc library package on all SuSE products. This overflow allows a remote attacker to overflow a buffer, leading to remote execution of arbitrary code supplied by the attacker.

Red Hat alert: PXE server crashes from certain DHCP packets

  • Mailing list (Posted by dave on Aug 30, 2002 5:17 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated PXE packages are now available for Red Hat Linux which fix a vulnerability that can crash the PXE server using certain DHCP packets.

Mandrake alert: hylafax update

Numerous vulnerabilities in the HylaFAX product exist in versions prior to 4.1.3. It does not check the TSI string which is received from remote FAX systems before using it in logging and other places.

« Previous ( 1 ... 7395 7396 7397 7398 7399 7400 7401 7402 7403 7404 7405 ... 7438 ) Next »