Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7237 7238 7239 7240 7241 7242 7243 7244 7245 7246 7247 ... 7250 ) Next »

Red Hat alert: race condition exists in diskcheck

  • Mailing list (Posted by dave on Dec 8, 2000 10:55 AM EDT)
  • Story Type: Security; Groups: Red Hat
A race vulnerability exists in the diskcheck package.

Red Hat alert: race condition exists in diskcheck

  • Mailing list (Posted by dave on Dec 4, 2000 10:26 AM EDT)
  • Story Type: Security; Groups: Red Hat
A race vulnerability exists in the diskcheck package.

Debian alert: Revised security fix for joe

  • Mailing list (Posted by dave on Dec 1, 2000 7:20 AM EDT)
  • Story Type: Security; Groups: Debian
The security fix for joe released on November 22, 2000 had a problem: it created the DEADJOE file securily but didn't write anything to it. This has been fixed in version 2.8.15.2 .

SuSE alert: netscape

  • Mailing list (Posted by dave on Nov 30, 2000 9:36 AM EDT)
  • Story Type: Security; Groups: SUSE
Michal Zalewski <lcamtuf@DIONE.IDS.PL> has found a buffer overflow in the html parser code of the Netscape Navigator in all versions before and including 4.75. html code of the form

Debian alert: fsh symlink attack

  • Mailing list (Posted by dave on Nov 29, 2000 2:46 PM EDT)
  • Story Type: Security; Groups: Debian
Colin Phipps found an interesting symlink attack problem in fsh (a tool to quickly run remote commands over rsh/ssh/lsh). When fshd starts it creates a directory in /tmp to hold its sockets. It tries to do that securely by checking of it can chown that directory if it already exists to check if it is owner by the user invoking it. However an attacker can circumvent this check by inserting a symlink to a file that is owner by the user who runs fhsd and replacing that with a directory just before fshd creates the socket.

Red Hat alert: Ethereal vulnerable to buffer overflows

  • Mailing list (Posted by dave on Nov 29, 2000 12:53 PM EDT)
  • Story Type: Security; Groups: Red Hat
Updated Ethereal packages are available.

Debian alert: ed symlink attack

  • Mailing list (Posted by dave on Nov 28, 2000 4:14 PM EDT)
  • Story Type: Security; Groups: Debian
Alan Cox discovered that GNU ed (a classed line editor tool) created temporary files unsafely. This has been fixed in version 0.2-18.1.

Red Hat alert: Updated bind packages fixing DoS attack available

  • Mailing list (Posted by dave on Nov 27, 2000 6:15 PM EDT)
  • Story Type: Security; Groups: Red Hat
A remote DoS (denial of service) attack is possible with bind versions prior to 8.

Red Hat alert: Updated nss_ldap packages are now available.

  • Mailing list (Posted by dave on Nov 27, 2000 10:52 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated nss_ldap packages are now available for Red Hat Linux 6.1, 6.2, and 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha.

Red Hat alert: Updated cyrus-sasl packages available for Red Hat Linux 7

  • Mailing list (Posted by dave on Nov 27, 2000 10:52 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated cyrus-sasl packages are now available for Red Hat Linux 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated usermode packages available

  • Mailing list (Posted by dave on Nov 27, 2000 10:51 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated usermode packages are now available for Red Hat Linux 6.x and 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated apache, php, mod_perl, and auth_ldap packages available.

  • Mailing list (Posted by dave on Nov 27, 2000 10:51 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated apache, php, mod_perl, and auth_ldap packages are now available for Red Hat Linux 5.2, 6.0, 6.1, 6.2, and 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated gnorpm packages are available for Red Hat Linux 6.1, 6.2, and 7.0

  • Mailing list (Posted by dave on Nov 27, 2000 10:51 AM EDT)
  • Story Type: Security; Groups: Red Hat
(This is a re-release of the previous errata caused by a missing patch). A locally-exploitable security hole was found where a normal user could trick root running GnoRPM into writing to arbitrary files due to a bug in the gnorpm tmp file handling. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated openssh packages available for Red Hat Linux 7

  • Mailing list (Posted by dave on Nov 27, 2000 10:50 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated openssh packages are now available for Red Hat Linux 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated joe packages are available for Red Hat Linux 5.2, 6.x and 7

  • Mailing list (Posted by dave on Nov 27, 2000 10:50 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated joe packages are available for Red Hat Linux 5.2, 6.x and 7.

Red Hat alert: Updated pine and imap packages are available for Red Hat Linux 5.2, 6.x and 7

  • Mailing list (Posted by dave on Nov 27, 2000 10:49 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated pine and imap packages are available for Red Hat Linux 5.2, 6.x and 7. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: new modutils release addresses more local root compromise possibilities

  • Mailing list (Posted by dave on Nov 27, 2000 10:49 AM EDT)
  • Story Type: Security; Groups: Red Hat
A new modutils-

Red Hat alert: ghostscript uses mktemp instead of mkstemp, and uses an improper LD_RUN_PATH

  • Mailing list (Posted by dave on Nov 27, 2000 10:47 AM EDT)
  • Story Type: Security; Groups: Red Hat
ghostscript makes use of mktemp instead of mkstemp to create temp files; and also uses improper LD_RUN_PATH values, causing it to search for libraries in the current directory. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: New ncurses packages fixing buffer overrun available

  • Mailing list (Posted by dave on Nov 27, 2000 10:46 AM EDT)
  • Story Type: Security; Groups: Red Hat
If you are any setuid applications that use ncurses and its cursor movement functionality, local users may gain access to the program's privileges. 2000-11-27: Added packages for Red Hat Linux 7 for Alpha

Red Hat alert: Updated bash (1.x) packages for Red Hat Linux 5.x, 6.x available

  • Mailing list (Posted by dave on Nov 27, 2000 10:11 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated bash (1.x) packages for Red Hat Linux 5.x and 6.x, fixing a security problem, are available.

« Previous ( 1 ... 7237 7238 7239 7240 7241 7242 7243 7244 7245 7246 7247 ... 7250 ) Next »