Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7444 7445 7446 7447 7448 7449 7450 7451 7452 7453 7454 ... 7468 ) Next »

SuSE alert: wmaker/WindowMaker

  • Mailing list (Posted by dave on Sep 20, 2001 8:50 AM EDT)
  • Story Type: Security; Groups: SUSE
The window manager Window Maker was found vulnerable to a buffer overflow due to improper bounds checking when setting the window title. An attacker can remotely exploit this buffer overflow by using malicious web page titles or terminal escape sequences to set a excessively long window title. This attack can lead to remote command execution with the privileges of the user running Window Maker.

Debian alert: New most packages available

  • Mailing list (Posted by dave on Sep 18, 2001 6:36 AM EDT)
  • Story Type: Security; Groups: Debian
Pavel Machek has found a buffer overflow in the `most' pager program. The problem is part of most's tab expansion where the program would write beyond the bounds two array variables when viewing a malicious file. This could lead into other data structures being overwritten which in turn could enable most to execute arbitrary code being able to compromise the users environment.

Red Hat alert: New bugzilla packages are available

  • Mailing list (Posted by dave on Sep 10, 2001 11:42 AM EDT)
  • Story Type: Security; Groups: Red Hat
The updated bugzilla package fixes numerous security issues which were present in previous releases of bugzilla.

Red Hat alert: New bugzilla packages are available

  • Mailing list (Posted by dave on Sep 10, 2001 11:42 AM EDT)
  • Story Type: Security; Groups: Red Hat
The updated bugzilla package fixes numerous security issues which were present in previous releases of bugzilla.

Red Hat alert: New bugzilla packages are available

  • Mailing list (Posted by dave on Sep 10, 2001 11:42 AM EDT)
  • Story Type: Security; Groups: Red Hat
The updated bugzilla package fixes numerous security issues which were present in previous releases of bugzilla.

Red Hat alert: New bugzilla packages are available

  • Mailing list (Posted by dave on Sep 10, 2001 11:42 AM EDT)
  • Story Type: Security; Groups: Red Hat
The updated bugzilla package fixes numerous security issues which were present in previous releases of bugzilla.

SuSE alert: apache-contrib

  • Mailing list (Posted by dave on Sep 10, 2001 9:17 AM EDT)
  • Story Type: Security; Groups: SUSE
The Apache module mod_auth_mysql 1.4,which is shipped since SuSE Linux 7.1, was found vulnerable to possible bypass authentication by MySQL command injection. An adversary could insert MySQL commands along with a password and these commands will be interpreted by MySQL while mod_auth_mysql is doing the password lookup in the database. A positive authentication could be returned.

Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1

  • Mailing list (Posted by dave on Sep 10, 2001 8:09 AM EDT)
  • Story Type: Security; Groups: Red Hat
A security audit has been done by Solar Designer on xinetd, and the results are now being made available as a preemptive measure.

Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1

  • Mailing list (Posted by dave on Sep 10, 2001 8:09 AM EDT)
  • Story Type: Security; Groups: Red Hat
A security audit has been done by Solar Designer on xinetd, and the results are now being made available as a preemptive measure.

Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1

  • Mailing list (Posted by dave on Sep 10, 2001 8:09 AM EDT)
  • Story Type: Security; Groups: Red Hat
A security audit has been done by Solar Designer on xinetd, and the results are now being made available as a preemptive measure.

Red Hat alert: Updated xinetd package available for Red Hat Linux 7 and 7.1

  • Mailing list (Posted by dave on Sep 10, 2001 8:09 AM EDT)
  • Story Type: Security; Groups: Red Hat
A security audit has been done by Solar Designer on xinetd, and the results are now being made available as a preemptive measure.

Red Hat alert: New sendmail packages available which fix a local root exploit

  • Mailing list (Posted by dave on Sep 10, 2001 8:08 AM EDT)
  • Story Type: Security; Groups: Red Hat
An input validation error in the debugging functionality of all currently released versions of sendmail can enable a local user to gain root access. New packages that fix this problem are available for Red Hat Linux 5.2, 6.2, 7.0, and 7.1.

Red Hat alert: New sendmail packages available which fix a local root exploit

  • Mailing list (Posted by dave on Sep 10, 2001 8:08 AM EDT)
  • Story Type: Security; Groups: Red Hat
An input validation error in the debugging functionality of all currently released versions of sendmail can enable a local user to gain root access. New packages that fix this problem are available for Red Hat Linux 5.2, 6.2, 7.0, and 7.1.

Red Hat alert: New sendmail packages available which fix a local root exploit

  • Mailing list (Posted by dave on Sep 10, 2001 8:08 AM EDT)
  • Story Type: Security; Groups: Red Hat
An input validation error in the debugging functionality of all currently released versions of sendmail can enable a local user to gain root access. New packages that fix this problem are available for Red Hat Linux 5.2, 6.2, 7.0, and 7.1.

Red Hat alert: Updated fetchmail packages available

  • Mailing list (Posted by dave on Sep 10, 2001 8:07 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated fetchmail packages are now available for Red Hat Linux 5.2, 6.2, 7, and 7.1. These packages close a remotely-exploitable vulnerability in fetchmail.

Red Hat alert: Updated fetchmail packages available

  • Mailing list (Posted by dave on Sep 10, 2001 8:07 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated fetchmail packages are now available for Red Hat Linux 5.2, 6.2, 7, and 7.1. These packages close a remotely-exploitable vulnerability in fetchmail.

Red Hat alert: Updated fetchmail packages available

  • Mailing list (Posted by dave on Sep 10, 2001 8:07 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated fetchmail packages are now available for Red Hat Linux 5.2, 6.2, 7, and 7.1. These packages close a remotely-exploitable vulnerability in fetchmail.

SuSE alert: screen

  • Mailing list (Posted by dave on Sep 5, 2001 8:31 AM EDT)
  • Story Type: Security; Groups: SUSE
screen is a terminal multiplexer program that allows reattaching to a detached session as well as multi-attached (shared) sessions.

SuSE alert: nkitb/nkitserv/telnetd

  • Mailing list (Posted by dave on Sep 3, 2001 4:53 AM EDT)
  • Story Type: Security; Groups: SUSE
The telnet server which is shipped with SuSE distributions contains a remotely exploitable buffer-overflow within its telnet option negotiation code. This bug is wide-spread on UN*X systems and affects almost all implementations of telnet daemons available. SuSE 7.2 distribution ships the telnet-server package which contains the vulnerable telnet daemon. This package has been fixed.

SuSE alert: sendmail

  • Mailing list (Posted by dave on Aug 23, 2001 8:34 AM EDT)
  • Story Type: Security; Groups: SUSE
Cade Cairns of Securityfocus discovered a vulnerability in the sendmail program, the widely spread MTA used in Unix- and Unix-like systems. A local user can write arbitrary data to the process memory, resulting in user-controlled code to be executed as user root. Please note that this is a _local_ vulnerability: Local shell access is needed for the attacker to be able to take advantage of this error. The /usr/sbin/sendmail program is installed set-uid root in most installations. This special privilege is needed for the sendmail program to operate properly. The attack pattern involves running sendmail to make use of the setuid-bit. Please note that this is the first sendmail security problem since 1997.

« Previous ( 1 ... 7444 7445 7446 7447 7448 7449 7450 7451 7452 7453 7454 ... 7468 ) Next »