Linux Security

Distribuir contenido
The central voice for Linux and Open Source security news.
Actualizado: hace 3 horas 42 mins

Debian: New mplayer packages fix integer overflows

Dom, 2008-10-05 13:55
LinuxSecurity.com: Felipe Andres Manzano discovered that mplayer, a multimedia player, is vulnerable to several integer overflows in the Real video stream demuxing code. These flaws could allow an attacker to cause a denial of service (a crash) or potentially the execution of arbitrary code by supplying a maliciously crafted video file.

Debian: New feta packages fix denial of service

Dom, 2008-10-05 04:53
LinuxSecurity.com: Dmitry E. Oboukhov discovered that the "to-upgrade" plugin of Feta, a simpler interface to APT, dpkg, and other Debian package tools creates temporary files insecurely, which may lead to local denial of service through symlink attacks.

Mandriva: Subject: [Security Announce] [ MDVA-2008:132 ] mandriva-release

Vie, 2008-10-03 18:50
LinuxSecurity.com: mandriva-release for Mandriva 2008 Spring should contain a product_branch set to Official, and not devel, otherwise it could lead to an error with the new mdkonline. The updated package fixes it.

Mandriva: Subject: [Security Announce] [ MDVA-2008:131 ] rpmdrake

Vie, 2008-10-03 18:40
LinuxSecurity.com: This update fixes several minor issues in rpmdrake: - it fixes a crash due to bad timing with the X server (#41010) - it fix empty per importance lists of updates in rpmdrake (list of all updates was OK, MandrivaUpdate was OK) (#41331) (regression introduced in 3.95 on 2007-09-14)

Mandriva: Subject: [Security Announce] [ MDVA-2008:130 ] drakxtools

Vie, 2008-10-03 18:30
LinuxSecurity.com: This update fixes several minor issues in drakxtools: - it fixes management of XEN kernels in bootloader-config, when adding a new kernel, a xen entry should not replace an existing 'linux' (#40865) - it fixes a crash in rpmdrake when description begins by Gtk2::.. (#43802) It also really enable draksnapashot to use Gtk+-2's new FileChooserDialog in future.

Mandriva: Subject: [Security Announce] [ MDVSA-2008:210 ] mono

Vie, 2008-10-03 17:15
LinuxSecurity.com: CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the query string. The updated packages have been patched to fix the issue.

RedHat: Moderate: pam_krb5 security update

Jue, 2008-10-02 07:33
LinuxSecurity.com: An updated pam_krb5 package that fixes a security issue is now available for Red Hat Enterprise Linux 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

RedHat: Important: tomcat security update

Jue, 2008-10-02 07:33
LinuxSecurity.com: Updated tomcat packages that fix multiple security issues are now available for Red Hat Developer Suite 3. This update has been rated as having important security impact by the Red Hat Security Response Team.

RedHat: Important: tomcat security update

Jue, 2008-10-02 07:32
LinuxSecurity.com: Updated tomcat packages that fix several security issues are now available for Red Hat Application Server v2. This update has been rated as having important security impact by the Red Hat Security Response Team.

RedHat: Moderate: thunderbird security update

Mié, 2008-10-01 10:50
LinuxSecurity.com: Updated thunderbird packages that fix several security issues are now available for Red Hat Enterprise Linux 4 and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

RedHat: Important: xen security and bug fix update

Mié, 2008-10-01 10:50
LinuxSecurity.com: Updated xen packages that resolve a couple of security issues and fix a bug are now available for Red Hat Enterprise Linux 5. This update has been rated as having important security impact by the Red Hat Security Response Team.

RedHat: Moderate: wireshark security update

Mié, 2008-10-01 10:50
LinuxSecurity.com: Updated wireshark packages that fix several security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. This update has been rated as having moderate security impact by the Red Hat Security Response Team.

Mandriva: Subject: [Security Announce] [ MDVSA-2008:208 ] pam_mount

Lun, 2008-09-29 19:39
LinuxSecurity.com: pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. The updated packages have been patched to fix the issue.

Mandriva: Subject: [Security Announce] [ MDVSA-2008:207 ] openafs

Lun, 2008-09-29 13:24
LinuxSecurity.com: A race condition in OpenAFS 1.3.40 through 1.4.5 allowed remote attackers to cause a denial of service (daemon crash) by simultaneously acquiring and giving back file callbacks (CVE-2007-6559). The updated packages have been patched to prevent this issue.

Slackware: mozilla-thunderbird

Vie, 2008-09-26 23:13
LinuxSecurity.com: New mozilla-thunderbird packages are available for Slackware 10.2, 11.0, 12.0, 12.1, and -current to fix security issues. More details about the issues may be found on the Mozilla site: http://www.mozilla.org/security/known-vulnerabilities/thunderbird20.html

Mandriva: Subject: [Security Announce] [ MDVSA-2008:206 ] mozilla-thunderbird

Vie, 2008-09-26 14:28
LinuxSecurity.com: A number of security vulnerabilities have been discovered and corrected in the latest Mozilla Thunderbird program, version 2.0.0.17 (CVE-2008-0016, CVE-2008-3835, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4065, CVE-2008-4066, CVE-2008-4067, CVE-2008-4068, CVE-2008-4070). This update provides the latest Thunderbird to correct these issues.

Slackware: seamonkey

Vie, 2008-09-26 00:39
LinuxSecurity.com: New seamonkey packages are available for Slackware 11.0, 12.0, 12.1, and -current to fix security issues. More details about the issues may be found here: http://www.mozilla.org/security/known-vulnerabilities/seamonkey11.html

Slackware: mozilla-firefox

Vie, 2008-09-26 00:39
LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 10.2, 11.0, 12.0, 12.1, and -current to fix security issues. More details about the issues may be found on the Mozilla site: http://www.mozilla.org/security/known-vulnerabilities/firefox20.html

Ubuntu: Thunderbird vulnerabilities

Jue, 2008-09-25 19:00
LinuxSecurity.com: It was discovered that the same-origin check in Thunderbird could be bypassed. If a user had JavaScript enabled and were tricked into opening a malicious website, an attacker may be able to execute JavaScript in the context of a different website. (CVE-2008-3835) Several problems were discovered in the browser engine of Thunderbird. If a user had JavaScript enabled, this could allow an attacker to execute code with chrome privileges. (CVE-2008-4058, CVE-2008-4059, CVE-2008-4060)

Mandriva: Subject: [Security Announce] [ MDVSA-2008:205 ] mozilla-firefox

Jue, 2008-09-25 16:01
LinuxSecurity.com: Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.17 (CVE-2008-0016, CVE-2008-3835, CVE-2008-3836, CVE-2008-3837, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4065, CVE-2008-4066, CVE-2008-4067, CVE-2008-4068, CVE-2008-4069). This update provides the latest Firefox to correct these issues.