Showing headlines posted by dave

« Previous ( 1 ... 517 518 519 520 521 522 523 524 525 526 527 ... 595 ) Next »

Mandrake alert: Updated CUPS packages fix denial of service vulnerability

A bug in versions of CUPS prior to 1.1.19 was reported by Paul Mitcheson in the Internet Printing Protocol (IPP) implementation would result in CUPS going into a busy loop, which could result in a Denial of Service (DoS) condition. To be able to exploit this problem, an attacker would need to be able to make a TCP connection to the IPP port (port 631 by default).

Slackware alert: apache security update (SSA:2003-308-01)

Upgraded Apache packages are available for Slackware 8.1, 9.0, 9.1, and -current. These fix local vulnerabilities that could allow users who can create or edit Apache config files to gain additional privileges. Sites running Apache should upgrade to the new packages.

Mandrake alert: Updated apache packages fix vulnerabilities

A buffer overflow in mod_alias and mod_rewrite was discovered in Apache versions 1.3.19 and earlier as well as Apache 2.0.47 and earlier. This happens when a regular expression with more than 9 captures is confined. An attacker would have to create a carefully crafted configuration file (.htaccess or httpd.conf) in order to exploit these problems.

Mandrake alert: Updated postgresql packages fix buffer overflow vulnerability

Two bugs were discovered that lead to a buffer overflow in PostgreSQL versions 7.2.x and 7.3.x prior to 7.3.4, in the abstract data type (ADT) to ASCII conversion functions. It is believed that, under the right circumstances, an attacker may use this vulnerability to execute arbitrary instructions on the PostgreSQL server.

Red Hat alert: Updated CUPS packages fix denial of service

  • Mailing list (Posted by dave on Nov 3, 2003 6:30 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated CUPS packages that fix a problem where CUPS can hang are now available.

Red Hat alert: Updated fileutils/coreutils package fix ls vulnerabilities

  • Mailing list (Posted by dave on Nov 3, 2003 6:28 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated fileutils and coreutils packages that close a potential denial of service vulnerability are now available.

Red Hat alert: Updated CUPS packages fix denial of service

  • Mailing list (Posted by dave on Nov 3, 2003 12:26 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated CUPS packages that fix a problem where CUPS can hang are now available.

SuSE alert: thttpd

  • Mailing list (Posted by dave on Oct 31, 2003 3:36 AM EDT)
  • Story Type: Security; Groups: SUSE
Two vulnerabilities were found in the "tiny" web-server thttpd. The first bug is a buffer overflow that can be exploited remotely to overwrite the EBP register of the stack. Due to memory-alignment of the stack done by gcc 3.x this bug can not be exploited. All thttpd versions mentioned in this advisory are compiled with gcc 3.x and are therefore not exploitable. The other bug occurs in the virtual-hosting code of thttpd. A remote attacker can bypass the virtual-hosting mechanism to read arbitrary files.

Debian alert: New thttpd packages fix information leak, DoS and arbitrary code execution

  • Mailing list (Posted by dave on Oct 28, 2003 11:00 PM EDT)
  • Story Type: Security; Groups: Debian
Several vulnerabilities have been discovered in thttpd, a tiny HTTP server.

Mozilla Links Newsletter - 5 - October 28, 2003

Past couple of weeks have been pretty interesting.

Slackware alert: fetchmail security update (SSA:2003-300-02)

Upgraded fetchmail packages are available for Slackware 8.1, 9.0, 9.1, and -current. These fix a vulnerability where a specially crafted email could crash fetchmail, preventing the user from downloading or forwarding their email.

Slackware alert: gdm security update (SSA:2003-300-01)

GDM is the GNOME Display Manager, and is commonly used to provide a graphical login for local users.

Mandrake alert: Updated apache2 packages fix CGI scripting deadlock

A problem was discovered in Apache2 where CGI scripts that output more than 4k of output to STDERR will hang the script's execution which can cause a Denial of Service on the httpd process because it is waiting for more input from the CGI that is not forthcoming due to the locked write() call in mod_cgi.

Mandrake alert: Updated fetchmail packages fix DoS vulnerability

A bug was discovered in fetchmail 6.2.4 where a specially crafted email message can cause fetchmail to crash.

Mandrake alert: Updated gdm packages fix local vulnerabilities

Two vulnerabilities were discovered in gdm by Jarno Gassenbauer that would allow a local attacker to cause gdm to crash or freeze.

Debian alert: New tomcat4 packages fix denial of service

  • Mailing list (Posted by dave on Oct 15, 2003 1:02 AM EDT)
  • Story Type: Security; Groups: Debian
Aldrin Martoq has discovered a denial of service (DoS) vulnerability in Apache Tomcat 4.0.x. Sending several non-HTTP requests to Tomcat's HTTP connector makes Tomcat reject further requests on this port until it is restarted.

Mozilla Links Newsletter - 4 - October 14, 2003

Mozilla Links is now being translated into Italian, German and Dutch, making Mozilla Links available in five different languages.

Debian alert: New openssl095 packages fix denial of service

  • Mailing list (Posted by dave on Oct 11, 2003 5:54 AM EDT)
  • Story Type: Security; Groups: Debian
Steve Henson of the OpenSSL core team identified and prepared fixes for a number of vulnerabilities in the OpenSSL ASN1 code that were discovered after running a test suite by British National Infrastructure Security Coordination Centre (NISCC).

Mandrake alert: Updated sane packages fix remote vulnerabilities

Several vulnerabilities were discovered in the saned daemon, a part of the sane package, which allows for a scanner to be used remotely. The IP address of the remote host is only checked after the first communication occurs, which causes the saned.conf restrictions to be ignored for the first connection. As well, a connection that is dropped early can cause Denial of Service issues due to a number of differing factors. Finally, a lack of error checking can cause various other unfavourable actions.

Red Hat alert: Updated MySQL packages fix vulnerability

  • Mailing list (Posted by dave on Oct 9, 2003 12:59 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated MySQL server packages fix a buffer overflow vulnerability.

« Previous ( 1 ... 517 518 519 520 521 522 523 524 525 526 527 ... 595 ) Next »