Showing all newswire headlines
View by date, instead?« Previous ( 1 ... 7413 7414 7415 7416 7417 7418 7419 7420 7421 7422 7423 ... 7437 ) Next »
Red Hat alert: Insecure setserial initscript
The initscript distributed with the setserial package (which is not
installed or enabled by default) uses predictable temporary file names, and
should not be used. setserial-
Debian alert: New UUCP packages fix local exploit
zen-parse has found a problem with Taylor UUCP as distributed with
many GNU/Linux distributions. It was possible to make `uux' execute
`uucp' with malicious commandline arguments which gives an attacker
access to files owned by uid/gid uucp.
Debian alert: slrn command invocation
Byrial Jensen found a nasty problem in slrn (a threaded news reader).
The notice on slrn-announce describes it as follows:
Debian alert: squid FTP PUT problem
Vladimir Ivaschenko found a problem in squid (a popular proxy cache).
He discovered that there was a flaw in the code to handle FTP PUT
commands: when a mkdir-only request was done squid would detect
an internal error and exit. Since squid is configured to restart
itself on problems this is not a big problem.
Red Hat alert: Updated man package fixing GID security problems.
Updated man packages fixing a local GID man exploit and a
potential GID man to root exploit, as well as a problem with the
man paths of Red Hat Linux 5.x and 6.x.
Red Hat alert: Updated man package fixing GID security problems.
Updated man packages fixing a local GID man exploit and a
potential GID man to root exploit, as well as a problem with the
man paths of Red Hat Linux 5.x and 6.x.
SuSE alert: wmaker/WindowMaker
The window manager Window Maker was found vulnerable to a buffer overflow due to improper bounds checking when setting the window title. An attacker can remotely exploit this buffer overflow by using malicious web page titles or terminal escape sequences to set a excessively long window title. This attack can lead to remote command execution with the privileges of the user running Window Maker.
Debian alert: New most packages available
Pavel Machek has found a buffer overflow in the `most' pager program.
The problem is part of most's tab expansion where the program would
write beyond the bounds two array variables when viewing a malicious
file. This could lead into other data structures being overwritten
which in turn could enable most to execute arbitrary code being able
to compromise the users environment.
Red Hat alert: New bugzilla packages are available
The updated bugzilla package fixes numerous security issues which were
present in previous releases of bugzilla.
Red Hat alert: New bugzilla packages are available
The updated bugzilla package fixes numerous security issues which were
present in previous releases of bugzilla.
Red Hat alert: New bugzilla packages are available
The updated bugzilla package fixes numerous security issues which were
present in previous releases of bugzilla.
Red Hat alert: New bugzilla packages are available
The updated bugzilla package fixes numerous security issues which were
present in previous releases of bugzilla.
SuSE alert: apache-contrib
The Apache module mod_auth_mysql 1.4,which is shipped since SuSE Linux 7.1, was found vulnerable to possible bypass authentication by MySQL command injection. An adversary could insert MySQL commands along with a password and these commands will be interpreted by MySQL while mod_auth_mysql is doing the password lookup in the database. A positive authentication could be returned.
Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1
A security audit has been done by Solar Designer on xinetd, and the
results are now being made available as a preemptive measure.
Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1
A security audit has been done by Solar Designer on xinetd, and the
results are now being made available as a preemptive measure.
Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1
A security audit has been done by Solar Designer on xinetd, and the
results are now being made available as a preemptive measure.
Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1
A security audit has been done by Solar Designer on xinetd, and the
results are now being made available as a preemptive measure.
Red Hat alert: New sendmail packages available which fix a local root exploit
An input validation error in the debugging functionality of all currently
released versions of sendmail can enable a local user to gain root
access. New packages that fix this problem are available for Red Hat Linux
5.2, 6.2, 7.0, and 7.1.
Red Hat alert: New sendmail packages available which fix a local root exploit
An input validation error in the debugging functionality of all currently
released versions of sendmail can enable a local user to gain root
access. New packages that fix this problem are available for Red Hat Linux
5.2, 6.2, 7.0, and 7.1.
Red Hat alert: New sendmail packages available which fix a local root exploit
An input validation error in the debugging functionality of all currently
released versions of sendmail can enable a local user to gain root
access. New packages that fix this problem are available for Red Hat Linux
5.2, 6.2, 7.0, and 7.1.
« Previous ( 1 ... 7413 7414 7415 7416 7417 7418 7419 7420 7421 7422 7423 ... 7437 ) Next »