Showing headlines posted by dave

« Previous ( 1 ... 553 554 555 556 557 558 559 560 561 562 563 ... 595 ) Next »

Debian alert: New Python packages fix problem introduced by security fix

  • Mailing list (Posted by dave on Sep 9, 2002 7:31 AM EDT)
  • Story Type: Security; Groups: Debian
[The mail just sent was formatted like an attachment due to a misconception on my side. This mail is only the clearsign version. ]

Red Hat alert: New wordtrans packages fix remote vulnerabilities

  • Mailing list (Posted by dave on Sep 9, 2002 5:36 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated wordtrans packages are now available for Red Hat Linux 7.3 which fix remote vulnerabilities in wordtrans-web.

Debian alert: New ethereal packages fix buffer overflow

  • Mailing list (Posted by dave on Sep 6, 2002 6:22 AM EDT)
  • Story Type: Security; Groups: Debian
Ethereal developers discovered a buffer overflow in the ISIS protocol dissector. It may be possible to make Ethereal crash or hang by injecting a purposefully malformed packet onto the wire, or by convincing someone to read a malformed packet trace file. It may be possible to make Ethereal run arbitrary code by exploiting the buffer and pointer problems.

Mandrake alert: gaim update

Versions of Gaim (an AOL instant message client) prior to 0.58 contain a buffer overflow in the Jabber plug-in module. As well, a vulnerability was discovered in the URL-handling code, where the "manual" browser command passes an untrusted string to the shell without reliable quoting or escaping. This allows an attacker to execute arbitrary commands on the user's machine with the user's permissions. Those using the built-in browser commands are not vulnerable. Update: The 8.1 package had an incorrect dependency on perl. This package has been replaced with a proper package. Please note the differing md5 sums.

Mandrake alert: linuxconf notice

A vulnerability was discovered in linuxconf by Dave Aitel and later by iDEFENSE that is locally exploitable to obtain elevated privilege.

Debian alert: New Mantis package fixes privilege escalation

  • Mailing list (Posted by dave on Sep 4, 2002 6:48 AM EDT)
  • Story Type: Security; Groups: Debian
A problem with user privileges has been discovered in the Mantis package, a PHP based bug tracking system. The Mantis system didn't check whether a user is permitted to view a bug, but displays it right away if the user entered a valid bug id.

Debian alert: New scrollkeeper packages fix insecure temporary file creation

  • Mailing list (Posted by dave on Sep 3, 2002 5:14 AM EDT)
  • Story Type: Security; Groups: Debian
Spybreak discovered a problem in scrollkeeper, a free electronic cataloging system for documentation. The scrollkeeper-get-cl program creates temporary files in an insecure manner in /tmp using guessable filenames. Since scrollkeeper is called automatically when a user logs into a Gnome session, an attacker with local access can easily create and overwrite files as another user.

Red Hat alert: Updated scrollkeeper packages fix tempfile vulnerability

  • Mailing list (Posted by dave on Sep 2, 2002 8:43 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated scrollkeeper packages are now available for Red Hat Linux 7.3 which fix a tempfile vulnerability.

SuSE alert: glibc

  • Mailing list (Posted by dave on Aug 30, 2002 9:04 AM EDT)
  • Story Type: Security; Groups: SUSE
An integer overflow has been discovered in the xdr_array() function, contained in the Sun Microsystems RPC/XDR library, which is part of the glibc library package on all SuSE products. This overflow allows a remote attacker to overflow a buffer, leading to remote execution of arbitrary code supplied by the attacker.

Red Hat alert: PXE server crashes from certain DHCP packets

  • Mailing list (Posted by dave on Aug 30, 2002 5:17 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated PXE packages are now available for Red Hat Linux which fix a vulnerability that can crash the PXE server using certain DHCP packets.

Mandrake alert: hylafax update

Numerous vulnerabilities in the HylaFAX product exist in versions prior to 4.1.3. It does not check the TSI string which is received from remote FAX systems before using it in logging and other places.

Mandrake alert: gaim update

Versions of Gaim (an AOL instant message client) prior to 0.58 contain a buffer overflow in the Jabber plug-in module. As well, a vulnerability was discovered in the URL-handling code, where the "manual" browser command passes an untrusted string to the shell without reliable quoting or escaping. This allows an attacker to execute arbitrary commands on the user's machine with the user's permissions. Those using the built-in browser commands are not vulnerable.

Red Hat alert: Updated ethereal packages are available

  • Mailing list (Posted by dave on Aug 29, 2002 6:43 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated ethereal packages are available which fix various security issues.

Debian alert: New Python packages fix insecure temporary file use

  • Mailing list (Posted by dave on Aug 28, 2002 3:32 AM EDT)
  • Story Type: Security; Groups: Debian
Zack Weinberg discovered an insecure use of a temporary file in os._execvpe from os.py. It uses a predictable name which could lead execution of arbitrary code.

Red Hat alert: Updated mailman packages close cross-site scripting vulnerability

  • Mailing list (Posted by dave on Aug 27, 2002 5:59 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated mailman packages are now available for Red Hat Secure Web Server 3.2 (U.S.). These updates close a cross-site scripting vulnerability present in mailman versions prior to version

Debian alert: New gaim packages fix arbitrary program execution

  • Mailing list (Posted by dave on Aug 27, 2002 5:01 AM EDT)
  • Story Type: Security; Groups: Debian
The developers of Gaim, an instant messenger client that combines several different networks, found a vulnerability in the hyperlink handling code. The 'Manual' browser command passes an untrusted string to the shell without escaping or reliable quoting, permitting an attacker to execute arbitrary commands on the users machine. Unfortunately, Gaim doesn't display the hyperlink before the user clicks on it. Users who use other inbuilt browser commands aren't vulnerable.

Mandrake alert: xinetd update

A vulnerability was discovered by Solar Designer in xinetd. File descriptors for the signal pipe that were introduced in version 2.3.4 are leaked into services started by xinetd, which can then be used to talk to xinetd, resulting in a crash of xinetd.

Debian alert: New mailman packages fix cross-site scripting problem

  • Mailing list (Posted by dave on Aug 26, 2002 9:03 AM EDT)
  • Story Type: Security; Groups: Debian
Quoting DSA 147-1:

Red Hat alert: Updated mailman packages close cross-site scripting vulnerability

  • Mailing list (Posted by dave on Aug 23, 2002 9:08 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated mailman packages are now available for Red Hat Power Tools 7 and 7.1. These updates close a cross-site scripting vulnerability present in mailman versions prior to version

Red Hat alert: Updated mailman packages close cross-site scripting vulnerability

  • Mailing list (Posted by dave on Aug 23, 2002 9:07 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated mailman packages are now available for Red Hat Linux 7.2 and 7.3. These updates close a cross-site scripting vulnerability present in mailman versions prior to version

« Previous ( 1 ... 553 554 555 556 557 558 559 560 561 562 563 ... 595 ) Next »