Showing all newswire headlines
View by date, instead?« Previous ( 1 ...
2049
2050
2051
2052
2053
2054
2055
2056
2057
2058
2059
... 2062
) Next »
Security vulnerabilities have been found in the Kerberos 5 implementation
shipped with Red Hat Linux 6.
Security vulnerabilities have been found in the Kerberos 5 implementation
shipped with Red Hat Linux 6.
With emacs < 20.7, unprivileged local users can eavesdrop the communication between Emacs and its subprocesses.
The 2.2.16 release of the Linux kernel is available and includes a number of
security fixes. The following list of fixes comes from the kernel release
notes:
In kdelibs 1.1.2 there are security issues for some applications when they are run suid root.
This is an update to the previous splitvt advisory. The previous release
had incorrrect addresses for the updates for Debian GNU/Linux potato.
The version of splitvt distributed in Debian GNU/Linux 2.1 (a.k.a. slink),
as well as in the frozen (potato) and unstable (woody) distributions, is
vulnerable to a local buffer overflow. This could be exploited to give a
shell running as root.
The version of mailx distributed in Debian GNU/Linux 2.1 (a.k.a. slink), as
well as in the frozen (potato) and unstable (woody) distributions is
vulnerable to a local buffer overflow while sending messages. This could be
exploited to give a shell running with group "mail".
The majordomo package as shipped in the non-free section accompanying
Debian GNU/Linux 2.1/slink allows any local user to trick majordomo into
executing arbitrary code or to create or write files as the majordomo user
anywhere on the filesystem.
New majordomo packages are available to fix local security problems in majordomo.
The KDE CD player kscd is setgid disk to be able to access the device file of the CDROM. To perform some action kscd calls the unix command shell specified in the environment variable SHELL with the privileges of group disk.
The GNOME package includes a xdm replacement called gdm for handling graphical console and network logins. The gdm code, that process' logins over the network, could be tricked into writing data from the network right into the stack. This condition exists while gdm is running with root privileges and before the user is authenticated.
The fdmount program shipped with Slackware has been shown to be vulnerable to
a buffer overflow exploit. A user must be in the "floppy" group to execute
fdmount, but because fdmount is suid root this is a security problem.
New mailman packages are available which close security holes present
in earlier versions of mailman.
New mailman packages are available which close security holes present
in earlier versions of mailman.
New mailman packages are available which close security holes present
in earlier versions of mailman.
Netscape 4.73 packages are available. These new packages fix
bugs in SSL certificate validation; these bugs could allow
for the compromising of encrypted SSL sessions.
It is recommended that all users of Netscape update to the new packages.
Netscape 4.73 packages are available. These new packages fix
bugs in SSL certificate validation; these bugs could allow
for the compromising of encrypted SSL sessions.
It is recommended that all users of Netscape update to the new packages.
A new Lynx package is available in the Slackware-current tree. Users of
Slackware 7.0 and -current are urged to upgrade to this version. Versions
of Lynx prior to 2.8.3pre.5 contained numerous security holes which could
permit a malicious server to execute arbitrary code on the user's system.
This version was heavily audited by the Lynx team before release.
« Previous ( 1 ...
2049
2050
2051
2052
2053
2054
2055
2056
2057
2058
2059
... 2062
) Next »