Showing all newswire headlines
View by date, instead?« Previous ( 1 ...
2058
2059
2060
2061
2062
2063
2064
2065
2066
2067
2068
... 2137
) Next »
Several vulnerabilities were discovered in all versions of phpgroupware prior to 0.9.14.006. This latest version fixes an exploitable condition in all versions that can be exploited remotely without authentication and can lead to arbitrary code execution on the web server. This vulnerability is being actively exploited.
Updated Mozilla packages fixing various bugs and security issues are now
available.
[Updated 18 July 2003]
Our Mozilla packages were found to be incompatible with Galeon. Updated
versions of Galeon are now included for Red Hat Linux 7.2, 7.3, and 8.0.
In addition new builds of Mozilla for Red Hat Linux 8.0 are included as the
previous packages were built with the wrong compiler.
Updated kernel packages are now available fixing several security
vulnerabilities.
An off-by-one buffer overflow was found in the logging code in nfs-utils when adding a newline to the string being logged. This could allow an attacker to execute arbitrary code or cause a DoS (Denial of Service) on the server by sending certain RPC requests.
Several vulnerabilities were discovered in Apache 2.x versions prior to 2.0.47. From the Apache 2.0.47 release notes:
Multiple vulnerabilities were discovered and fixed in the Linux kernel.
Updated Xpdf packages are available that fix a vulnerability where a
malicious PDF document could run arbitrary code.
[Updated 16 July 2003]
Updated packages are now available, as the original errata packages did not
fix all possible ways of exploiting this vulnerability.
The transparent session ID feature in the php4 package does not
properly escape user-supplied input before inserting it into the
generated HTML page. An attacker could use this vulnerability to
execute embedded scripts within the context of the generated page.
Multiple vulnerabilities were discovered and fixed in the Linux kernel.
New nfs-utils packages are available for Slackware 8.1, 9.0, and -current
to replace the ones that were issued yesterday. A bug in has been fixed
in utils/mountd/auth.c that could cause mountd to crash.
The falconseye package is vulnerable to a buffer overflow exploited
via a long '-s' command line option. This vulnerability could be used
by an attacker to gain gid 'games' on a system where falconseye is
installed.
The nfs-utils package contains various programs to offer and manage certain RPC services such as the rpc.mountd. iSEC Security Research has reported an off-by-one bug in the xlog() function used by the rpc.mountd. It is possible for remote attackers to use this off-by-one overflow to execute arbitrary code as root. Some of the products listed above seem not vulnerable to this one byte overflow due to the stack alignment generated by the compiler during the build. Nevertheless, since there is no easy workaround except shutting down the RPC services, an update is strongly recommended for every product listed above.
Updated Mozilla packages fixing various bugs and security issues are now
available.
New nfs-utils packages are available for Slackware 8.1, 9.0, and -current
to fix an off-by-one buffer overflow in xlog.c. Thanks to Janusz
Niewiadomski for discovering and reporting this problem.
The logging code in nfs-utils contains an off-by-one buffer overrun
when adding a newline to the string being logged. This vulnerability
may allow an attacker to execute arbitrary code or cause a denial of
service condition by sending certain RPC requests.
Updated nfs-utils packages are available that fix a remotely exploitable
Denial of Service vulnerability.
traceroute-nanog, an enhanced version of the common traceroute
program, contains an integer overflow bug which could be exploited to
execute arbitrary code. traceroute-nanog is setuid root, but drops
root privileges immediately after obtaining raw ICMP and raw IP
sockets. Thus, exploitation of this bug provides only access to these
sockets, and not root privileges.
teapop, a POP-3 server, includes modules for authenticating users
against a PostgreSQL or MySQL database. These modules do not properly
escape user-supplied strings before using them in SQL queries. This
vulnerability could be exploited to execute arbitrary SQL under the
privileges of the database user as which teapop has authenticated.
Albert Puigsech Galicia <ripe@7a69ezine.org> reported that phpsysinfo,
a web-based program to display status information about the system,
contains two vulnerabilities which could allow local files to be read,
or arbitrary PHP code to be executed, under the privileges of the web
server process (usually www-data). These vulnerabilities require
access to a writable directory on the system in order to be exploited.
Another buffer overflow was discovered in xbl, distinct from the one
addressed in DSA-327 (CAN-2003-0451), involving the -display command
line option. This vulnerability could be exploited by a local
attacker to gain gid 'games'.
« Previous ( 1 ...
2058
2059
2060
2061
2062
2063
2064
2065
2066
2067
2068
... 2137
) Next »