Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7215 7216 7217 7218 7219 7220 7221 7222 7223 7224 7225 ... 7264 ) Next »

Debian alert: New tetex-lib packages fix arbitrary command execution

  • Mailing list (Posted by dave on Dec 11, 2002 7:37 AM EDT)
  • Story Type: Security; Groups: Debian
The SuSE security team discovered a vulnerability in kpathsea library (libkpathsea) which is used by xdvi and dvips. Both programs call the system() function insecurely, which allows a remote attacker to execute arbitrary commands via cleverly crafted DVI files.

Debian alert: tcpdump BGP decoding error

  • Mailing list (Posted by dave on Dec 10, 2002 1:41 PM EDT)
  • Story Type: Security; Groups: Debian
The BGP decoding routines for tcpdump used incorrect bounds checking when copying data. This could be abused by introducing malicious traffic on a sniffed network for a denial of service attack against tcpdump, or possibly even remote code execution.

Debian alert: gtetrinet buffer overflows

  • Mailing list (Posted by dave on Dec 10, 2002 1:25 PM EDT)
  • Story Type: Security; Groups: Debian
Steve Kemp and James Antill found several buffer overflows in the gtetrinet (a multiplayer tetris-like game) package as shipped in Debian GNU/Linux 3.0, which could be abused by a malicious server.

Red Hat alert: Updated wget packages fix directory traversal bug

  • Mailing list (Posted by dave on Dec 10, 2002 6:23 AM EDT)
  • Story Type: Security; Groups: Red Hat
The wget packages shipped with Red Hat Linux 6.2 through 8.0 contain a security bug which, under certain circumstances, can cause local files to be written outside the download directory.

Red Hat alert: Updated Canna packages fix vulnerabilities

  • Mailing list (Posted by dave on Dec 10, 2002 6:22 AM EDT)
  • Story Type: Security; Groups: Red Hat
The Canna server, used for Japanese character input, has two security vulnerabilities including an exploitable buffer overrun allowing a local user to gain 'bin' user privileges. Updated packages for Red Hat Linux are available.

Mandrake alert: Updated python packages fix local arbitrary code execution vulnerability

A vulnerability was discovered in python by Zack Weinberg in the way that the execvpe() method from the os.py module uses a temporary file name. The file is created in an unsafe manner and execvpe() tries to execute it, which can be used by a local attacker to execute arbitrary code with the privilege of the user running the python code that is using this method. Update: The previously released packages for 9.0 had an incorrect dependency on libdb.so.2 instead of libdb.so.3. This update corrects that problem.

Debian alert: New IM packages correct hidden architecture dependency

  • Mailing list (Posted by dave on Dec 6, 2002 5:08 AM EDT)
  • Story Type: Security; Groups: Debian
Despite popular belief, the IM packages are not architecture independent, since the number of the fsync syscal is detected on build time and this number differs on Linux architectures and other operating systems. As a result of this the optional feature ``NoSync=no'' does only work on the architecture the package was built on. As usual, we are including the text of the original advisory DSA 202-1:

Debian alert: New html2ps packages correct fix against arbitrary code execution

  • Mailing list (Posted by dave on Dec 6, 2002 5:07 AM EDT)
  • Story Type: Security; Groups: Debian
The security update from DSA 192-1 contained a syntax error which is now fixed. For completeness we include the text of the old advisory:

SuSE alert: OpenLDAP2

  • Mailing list (Posted by dave on Dec 6, 2002 2:16 AM EDT)
  • Story Type: Security; Groups: SUSE
OpenLDAP is the Open Source implementation of the Lightweight Directory Access Protocol (LDAP) and is used in network environments for distributing certain information such as X.509 certificates or login information.

Debian alert: New kdlibs packages fix arbitrary program execution

  • Mailing list (Posted by dave on Dec 5, 2002 6:11 AM EDT)
  • Story Type: Security; Groups: Debian
The KDE team has discovered a vulnerability in the support for various network protocols via the KIO The implementation of the rlogin and protocol allows a carefully crafted URL in an HTML page, HTML email or other KIO-enabled application to execute arbitrary commands on the system using the victim's account on the vulnerable machine.

Debian alert: New smb2www packages fix arbitrary command execution

  • Mailing list (Posted by dave on Dec 4, 2002 6:12 AM EDT)
  • Story Type: Security; Groups: Debian
Robert Luberda found a security problem in smb2www, a Windows Network client that is accessible through a web browser. This could lead a remote attacker to execute arbitrary programs under the user id www-data on the host where smb2www is running.

Red Hat alert: Updated KDE packages fix security issues

  • Mailing list (Posted by dave on Dec 4, 2002 1:55 AM EDT)
  • Story Type: Security; Groups: Red Hat
A number of vulnerabilities have been found that affect various versions of KDE. This errata provides updates which resolve these issues.

Red Hat alert: Updated Webalizer packages fix vulnerability

  • Mailing list (Posted by dave on Dec 3, 2002 11:34 PM EDT)
  • Story Type: Security; Groups: Red Hat
Updated Webalizer packages which fix an obscure buffer overflow bug in the DNS resolver code are available for Red Hat Linux 7.

Debian alert: New IM packages fix insecure temporary file creation

  • Mailing list (Posted by dave on Dec 3, 2002 5:53 AM EDT)
  • Story Type: Security; Groups: Debian
Tatsuya Kinoshita discovered that IM, which contains interface commands and Perl libraries for E-mail and NetNews, creates temporary files insecurely.

Mandrake alert: Updated WindowMaker packages fix buffer overflow vulnerability

Al Viro discovered a vulnerability in the WindowMaker window manager. A function used to load images, for example when configuring a new background image or previewing themes, contains a buffer overflow. The function calculates the amount of memory necessary to load the image by doing some multiplication but does not check the results of this multiplication, which may not fit into the destination variable, resulting in a buffer overflow when the image is loaded.

Mandrake alert: Updated pine packages fix buffer overflow vulnerability

A vulnerability was discovered in pine while parsing and escaping characters of email addresses; not enough memory is allocated for storing the escaped mailbox part of the address. The resulting buffer overflow on the heap makes pine crash. This new version of pine, 4.50, has the vulnerability fixed. It also offers many other bug fixes and new features.

Red Hat alert: Updated xinetd packages fix denial of service vulnerability

  • Mailing list (Posted by dave on Dec 2, 2002 11:38 AM EDT)
  • Story Type: Security; Groups: Red Hat
Xinetd contains a denial-of-service (DoS) vulnerability. UPDATE 2002-12-02: Updated packages are available to fix issues encountered with the previous errata packages.

Debian alert: New Free/SWan packages fix denial of service

  • Mailing list (Posted by dave on Dec 2, 2002 6:22 AM EDT)
  • Story Type: Security; Groups: Debian
Bindview discovered a problem in several IPSEC implementations that do not properly handle certain very short packets. IPSEC is a set of security extensions to IP which provide authentication and encryption. Free/SWan in Debain is affected by this and is said to cause a kernel panic.

Mandrake alert: Updated sendmail packages fix smrsh insecurities

A vulnerability was discovered by zen-parse and Pedram Amini in the sendmail MTA. They found two ways to exploit smrsh, an application intended as a replacement for the sh shell for use with sendmail; the first by inserting specially formatted commands in the ~/.forward file and secondly by calling smrsh directly with special options. These can be exploited to give users with no shell account, or those not permitted to execute certain programs or commands, the ability to bypass these restrictions.

Mandrake alert: Updated python packages fix local arbitrary code execution vulnerability

A vulnerability was discovered in python by Zack Weinberg in the way that the execvpe() method from the os.py module uses a temporary file name. The file is created in an unsafe manner and execvpe() tries to execute it, which can be used by a local attacker to execute arbitrary code with the privilege of the user running the python code that is using this method.

« Previous ( 1 ... 7215 7216 7217 7218 7219 7220 7221 7222 7223 7224 7225 ... 7264 ) Next »