Linux Security
Debian: 2009-1: tdiary: insufficient input sanitisi
LinuxSecurity.com: It was discovered that tdiary, a communication-friendly weblog system, is prone to a cross-site scripting vulnerability due to insuficient input sanitising in the TrackBack transmission plugin. [More...]
Mandriva: 2010:058: php
LinuxSecurity.com: Multiple vulnerabilities has been found and corrected in php:
* Improved LCG entropy. (Rasmus, Samy Kamkar)
* Fixed safe_mode validation inside tempnam() when the directory
path does not end with a /). (Martin Jansen)
[More...]
Pardus: 2010-39: Firefox: Multiple Vulnerabilities
LinuxSecurity.com: Multiple vulnerabilities have been fixed in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks or compromise a user's system.
Pardus: 2010-38: Sudo: Privilege Escalation
LinuxSecurity.com: A security issue has been fixed in sudo, which can be exploited by malicious, local users to gain escalated privileges.
Debian: 2008-1: typo3-src Multiple Vulnerabilities
LinuxSecurity.com: Several remote vulnerabilities have been discovered in the TYPO3 web content management framework: Cross-site scripting vulnerabilities have been discovered in both the frontend and the backend. Also, user data could be leaked.
Slackware: 2010-067-01: httpd: Security Update
LinuxSecurity.com: New httpd packages are available for Slackware 12.0, 12.1, 12.2, 13.0, and -current to fix security issues. mod_ssl: A partial fix for the TLS renegotiation prefix injection attack by rejecting any client-initiated renegotiations. mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent [More Info...]
Ubuntu: 907-1: gnome-screensaver vulnerabilities
LinuxSecurity.com: It was discovered that gnome-screensaver did not correctly lock all screenswhen monitors get hotplugged. An attacker with physical access could usethis flaw to gain access to a locked session. (CVE-2010-0285) [More...]
SuSE: 2010-016: Linux kernel
LinuxSecurity.com: The openSUSE 11.0 kernel was updated to fix following security issues: CVE-2009-4020: Stack-based buffer overflow in the hfs subsystem in the Linux kernel 2.6.32 allows remote attackers to have an unspecified impact via a crafted Hierarchical File System (HFS) filesystem, related to the [More...]
Mandriva: 2010:057: apache
LinuxSecurity.com: A vulnerabilitiy has been found and corrected in apache:
The ap_read_request function in server/protocol.c in the Apache HTTP
Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does
not properly handle headers in subrequests in certain circumstances
[More...]
Mandriva: 2010:056: openoffice.org
LinuxSecurity.com: This update provides the OpenOffice.org 3.0 major version and holds
the security fixes for the following issues:
An integer underflow might allow remote attackers to execute arbitrary
code via crafted records in the document table of a Word document
[More...]
Mandriva: 2010:055: poppler
LinuxSecurity.com: An out-of-bounds reading flaw in the JBIG2 decoder allows remote attackers to cause a denial of service (crash) via a crafted PDF file (CVE-2009-0799). Multiple input validation flaws in the JBIG2 decoder allows [More...]
Mandriva: 2010:054: pam_krb5
LinuxSecurity.com: Pam_krb5 2.2.14 through 2.3.4 generates different password prompts depending on whether the user account exists, which allows remote attackers to enumerate valid usernames (CVE-2009-1384). This update provides the version 2.3.5 of pam_krb5, which is not [More...]
SuSE: 2010-015: Mozilla Firefox
LinuxSecurity.com: Mozilla Firefox was upgraded to version 3.5.8, fixing various bugs and security issues. On openSUSE 11.0 and 11.1 Mozilla Firefox was updated to version 3.0.18. On openSUSE 11.2 Mozilla Seamonkey was updated to version 2.0.2. Following security issues have been fixed: MFSA 2010-01 / CVE-2010-0159: Mozilla developers identified and fixed several stability bugs in the browser [More...]
Ubuntu: 906-1: CUPS vulnerabilities
LinuxSecurity.com: It was discovered that the CUPS scheduler did not properly handle certainnetwork operations. A remote attacker could exploit this flaw and cause theCUPS server to crash, resulting in a denial of service. This issue onlyaffected Ubuntu 8.04 LTS, 8.10, 9.04 and 9.10. (CVE-2009-3553,CVE-2010-0302) [More...]
Red Hat: 2010:0130-01: java-1.5.0-ibm: Moderate Advisory
LinuxSecurity.com: Updated java-1.5.0-ibm packages that fix a security issue are now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary. This update has been rated as having moderate security impact by the Red [More...]
Red Hat: 2010:0129-01: cups: Moderate Advisory
LinuxSecurity.com: Updated cups packages that fix one security issue are now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red [More...]
Gentoo: 201003-01: sudo: Privilege escalation
LinuxSecurity.com: Two vulnerabilities in sudo might allow local users to escalateprivileges and execute arbitrary code with root privileges.
SuSE: 2010-014: Linux kernel
LinuxSecurity.com: The SUSE Linux Enterprise 11 and openSUSE 11.1 Kernel were updated to 2.6.27.45 fixing various bugs and security issues. CVE-2010-0622: The wake_futex_pi function in kernel/futex.c in the Linux kernel before 2.6.33-rc7 does not properly handle certain unlock operations for a Priority Inheritance (PI) futex, which allows local [More...]
Debian: 2006-1: sudo: Multiple vulnerabilities
LinuxSecurity.com: Several vulnerabilities have been discovered in sudo, a program designed to allow a sysadmin to give limited root privileges to users database server. The Common Vulnerabilities and Exposures project identifies the [More...]
Mandriva: 2010:053: apache
LinuxSecurity.com: A vulnerabilitiy has been found and corrected in apache: mod_proxy_ajp: Respond with HTTP_BAD_REQUEST when the body is not sent after request headers indicate a request body is incoming; this is not a case of HTTP_INTERNAL_SERVER_ERROR (CVE-2010-0408). [More...]








