Showing all newswire headlines
View by date, instead?« Previous ( 1 ... 7454 7455 7456 7457 7458 7459 7460 7461 7462 7463 7464 ... 7467 ) Next »
Red Hat alert: Updated cyrus-sasl packages available for Red Hat Linux 7
Updated cyrus-sasl packages are now available for Red Hat Linux 7.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated usermode packages available
Updated usermode packages are now available for Red Hat Linux 6.x and 7.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated apache, php, mod_perl, and auth_ldap packages available.
Updated apache, php, mod_perl, and auth_ldap packages are now available for
Red Hat Linux 5.2, 6.0, 6.1, 6.2, and 7.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated gnorpm packages are available for Red Hat Linux 6.1, 6.2, and 7.0
(This is a re-release of the previous errata caused by a missing patch).
A locally-exploitable security hole was found where a normal user could
trick root running GnoRPM into writing to arbitrary files due to a bug in
the gnorpm tmp file handling.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated openssh packages available for Red Hat Linux 7
Updated openssh packages are now available for Red Hat Linux 7.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated joe packages are available for Red Hat Linux 5.2, 6.x and 7
Updated joe packages are available for Red Hat Linux 5.2, 6.x and 7.
Red Hat alert: Updated pine and imap packages are available for Red Hat Linux 5.2, 6.x and 7
Updated pine and imap packages are available for Red Hat Linux 5.2, 6.x and
7.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: new modutils release addresses more local root compromise possibilities
A new modutils-
Red Hat alert: ghostscript uses mktemp instead of mkstemp, and uses an improper LD_RUN_PATH
ghostscript makes use of mktemp instead of mkstemp to create temp files;
and also uses improper LD_RUN_PATH values, causing it to search for
libraries in the current directory.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: New ncurses packages fixing buffer overrun available
If you are any setuid applications that use ncurses and its cursor movement
functionality, local users may gain access to the program's privileges.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Red Hat alert: Updated bash (1.x) packages for Red Hat Linux 5.x, 6.x available
Updated bash (1.x) packages for Red Hat Linux 5.x and 6.x, fixing a security problem, are available.
Red Hat alert: New Netscape packages available
New Netscape packages are available that fix a buffer overflow
in parsing HTML.
It is recommended that all Netscape users update to the fixed
packages.
2000-11-27: Added packages for Red Hat Linux 7 for Alpha
Debian alert: New version of mc released
Maurycy Prodeus found a problem in cons.saver, a screensaver for
the console that is included in the mc package. cons.saver does not
check if it is started with a valid stdout, which combined with a
bug in its check to see if its argument is a tty (it forgot to
close the file-descriptor after opening the supposed tty) causes it
to write a NUL character to the file given as its parameter.
SuSE alert: openssh/ssh
openssh is an implementation of the secure shell protocol, available under the BSD license, primarily maintained by the OpenBSD Project.
Red Hat alert: New ncurses packages fixing buffer overrun available
If you are any setuid applications that use ncurses and its cursor movement
functionality, local users may gain access to the program's privileges.
Debian alert: New version of ghostscript released
ghostscript uses temporary files to do some of its work. Unfortunately
the method used to create those files wasn't secure: mktemp was used
to create a name for a temporary file, but the file was not opened
safely. A second problem is that during build the LD_RUN_PATH environment
variable was set to the empty string, which causes the dynamic linker
to look in the current directory for shared libraries.
Red Hat alert: new modutils release addresses more local root compromise possibilities
A new modutils-
Red Hat alert: ghostscript uses mktemp instead of mkstemp, and uses an improper LD_RUN_PATH
ghostscript makes use of mktemp instead of mkstemp to create temp files;
and also uses improper LD_RUN_PATH values, causing it to search for
libraries in the current directory.
Debian alert: New version of modutils released
Sebastian Krahmer raised an issue in modutils. In an ideal world
modprobe should trust the kernel to only pass valid parameters to
modprobe. However he has found at least one local root exploit
because high level kernel code passed unverified parameters direct
from the user to modprobe. So modprobe no longer trusts kernel input
and switches to a safemode.
Debian alert: No koules vulnerability
Guido Bakker has reported a local root vulnerability that can result
in local users gaining root permission on a host running
koules.sndsrv.linux using a buffer overflow.
« Previous ( 1 ... 7454 7455 7456 7457 7458 7459 7460 7461 7462 7463 7464 ... 7467 ) Next »