Showing all newswire headlines
View by date, instead?« Previous ( 1 ...
2046
2047
2048
2049
2050
2051
2052
2053
2054
2055
2056
... 2062
) Next »
The default package selection in SuSE distributions includes apache. The configuration file that comes with the package contains two security relevant errors:
screen, a tty multiplexer, is installed suid root by default on SuSE Linux distributions. By supplying a thoughtfully designed string as the visual bell message, local users can obtain root privilege. Exploit information has been published on security forums.
The glibc implementations in all SuSE distributions starting with SuSE-6.0 have multiple security problems where at least one of them allows any local user to gain root access to the system.
Three locale-related vulnerabilities with glibc 2.1.3 were recently
reported on BugTraq. These vulnerabilities could allow local users to
gain root access.
Recently two problems have been found in the glibc suite, which could be
used to trick setuid applications to run arbitrary code.
Recently two problems have been found in the glibc suite, which could be
used to trick setuid applications to run arbitrary code.
A format string bug was recently discovered in screen which can be used
to gain elevated privilages if screen is setuid. Debian 2.1 (slink) did
ship screen setuid and the exploit can be used to gain root privilages.
In Debian 2.2 (potato) screen is not setuid, and is not vulnerable to a
root exploit. screen is, however, setgid utmp in Debian 2.2 (potato) and
we recommend upgrading.
A root exploit was found in the /usr/bin/suidperl5.6.0 program that
shipped with the Slackware 7.1 perl.tgz package.
Recently two problems have been found in the glibc suite, which could be
used to trick setuid applications to run arbitrary code.
Existing Netscape Communicator/Navigator packages contain the following
vulnerabilities:
Several bugs were discovered in glibc which could allow local users to
gain root privileges.
The version of X-Chat that was distributed with Debian GNU/Linux 2.2
has a vulnerability in the URL handling code: when a user clicks on
a URL X-Chat will start netscape to view its target. However it
did not check the URL for shell metacharacters, and this could be
abused to trick xchat into executing arbitraty commands.
The version of X-Chat that was distributed with Debian GNU/Linux 2.2
has a vulnerability in the URL handling code: when a user clicks on
a URL X-Chat will start netscape to view its target. However it
did not check the URL for shell metacharacters, and this could be
abused to trick xchat into executing arbitraty commands.
The updated version of ntop (1.2a7-10) that was released on August 5
was found to still be insecure: it was still exploitable using buffer
overflows. Using this technique it was possible to run arbitrary code
as the user who ran ntop in web mode.
Updated usermode packages are now available for Red Hat Linux 6.0, 6.1, and
6.
Due to US-American export restrictions for cryptographical software,
we are unable to provide update packages on our US ftp server ftp.suse.com. Instead, the packages can be found on ftp.suse.de. For
The legal issues have been resolved: Here are the links to download
the SuSE Netscape update packages from our US-American ftp server:
A new XChat package is available that fixes a possible
security hole.
Two security problems exist in the netscape package as shipped with SuSE Linux distributions. a) Improper verification in Netscape's jpeg processing code can lead to a buffer overflow where data read from the network can overwrite memory. As a result, arbitrary code from a remote origin could be executed. The attack is particularly dangerous since it can penetrate firewall setups. Netscape version 4.74 fixes (fixed) this vulnerability. b) Due to an error in the java implementation in Netscape, it is possible for an attacker to view files and directories with the priviledges of the user running Netscape if the user visits a malisciously crafted webpage. This issue is known as "Brown Orifice" and requires the user to have Java enabled in her browser configuration. Again, this attack can penetrate firewall setups. See
http://www.brumleve.com/BrownOrifice for details.
On versions of Zope prior to 2.2.1 it was possible for a user with the
ability to edit DTML to gain unauthorized access to extra roles during a
request. A fix was previously announced in the Debian zope package
2.1.6-5.1, but that package did not fully address the issue and has been
superseded by this announcement. More information is available at
http://www.zope.org/Products/Zope/Hotfix_2000-08-17/security_alert
New Netscape packages are available to fix a serious security
problem with Java. It is recommended that all netscape users
update to the new packages. Users of Red Hat Linux 6.0 and 6.1
should use the packages for Red Hat Linux 6.
« Previous ( 1 ...
2046
2047
2048
2049
2050
2051
2052
2053
2054
2055
2056
... 2062
) Next »