Linux Security

Distribuir contenido
The central voice for Linux and Open Source security news.
Actualizado: hace 3 horas 52 mins

Red Hat: 2010:0616-01: dbus-glib: Moderate Advisory

Mar, 2010-08-10 15:05
LinuxSecurity.com: Updated dbus-glib packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]

Red Hat: 2010:0615-01: libvirt: Low Advisory

Mar, 2010-08-10 13:09
LinuxSecurity.com: Updated libvirt packages that fix two security issues and three bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having low [More...]

Red Hat: 2010:0610-01: kernel: Important Advisory

Mar, 2010-08-10 13:05
LinuxSecurity.com: Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]

Mandriva: 2010:147: firefox

Mar, 2010-08-10 10:03
LinuxSecurity.com: Security issues were identified and fixed in firefox: layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory [More...]

Ubuntu: 967-1: w3m vulnerability

Lun, 2010-08-09 15:29
LinuxSecurity.com: Ludwig Nussel discovered w3m does not properly handle SSL/TLScertificates with NULL characters in the certificate name. Anattacker could exploit this to perform a man in the middleattack to view sensitive information or alter encryptedcommunications. (CVE-2010-2074) [More...]

Pardus: 2010-104: Php: Multiple Vulnerabilities

Dom, 2010-08-08 23:20
LinuxSecurity.com: Multiple vulnerabilities have been fixed in PHP

Pardus: 2010-103: Git: Arbitrary Code Execution

Dom, 2010-08-08 23:20
LinuxSecurity.com: A vulnerability has been fixed in Git which can be exploited by malicious people to execute arbitrary code

Debian: 2090-1: socat: incorrect user-input valida

Vie, 2010-08-06 14:10
LinuxSecurity.com: A stack overflow vulnerability was found in socat that allows an attacker to execute arbitrary code with the privileges of the socat process. [More...]

Mandriva: 2010:146: libtiff

Vie, 2010-08-06 12:15
LinuxSecurity.com: Multiple vulnerabilities has been discovered and corrected in libtiff: The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service [More...]

Mandriva: 2010:145: libtiff

Vie, 2010-08-06 08:57
LinuxSecurity.com: Multiple vulnerabilities has been discovered and corrected in libtiff: The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service [More...]

Debian: 2089-1: php5: Multiple vulnerabilities

Jue, 2010-08-05 22:43
LinuxSecurity.com: Several remote vulnerabilities have been discovered in PHP 5, an hypertext preprocessor. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]

Ubuntu: 969-1: PCSC-Lite vulnerability

Jue, 2010-08-05 14:42
LinuxSecurity.com: It was discovered that the PC/SC service did not correctly handlemalformed messages. A local attacker could exploit this to executearbitrary code with root privileges. [More...]

Red Hat: 2010:0607-02: freetype: Important Advisory

Jue, 2010-08-05 11:47
LinuxSecurity.com: Updated freetype packages that fix two security issues are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2010:0606-01: kernel: Important Advisory

Jue, 2010-08-05 11:47
LinuxSecurity.com: Updated kernel packages that fix multiple security issues and one bug are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having [More...]

Debian: 2088-1: wget: missing input sanitization

Mié, 2010-08-04 22:30
LinuxSecurity.com: It was discovered that wget, a command line tool for downloading files from the WWW, uses server-provided file names when creating local files. This may lead to code execution in some scenarios. [More...]

Red Hat: 2010:0603-01: gnupg2: Moderate Advisory

Mié, 2010-08-04 16:10
LinuxSecurity.com: An updated gnupg2 package that fixes one security issue is now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]

Ubuntu: 966-1: Linux kernel vulnerabilities

Mié, 2010-08-04 15:29
LinuxSecurity.com: Junjiro R. Okajima discovered that knfsd did not correctly handlestrict overcommit. A local attacker could exploit this to crash knfsd,leading to a denial of service. (Only Ubuntu 6.06 LTS and 8.04 LTS wereaffected.) (CVE-2008-7256, CVE-2010-1643) [More...]

Mandriva: 2010:144: wireshark

Mié, 2010-08-04 13:08
LinuxSecurity.com: This advisory updates wireshark to the latest version(s), fixing several security issues: Buffer overflow in the ASN.1 BER dissector in Wireshark 0.10.13 through 1.0.13 and 1.2.0 through 1.2.8 has unknown impact and remote attack [More...]

Debian: 2087-1: cabextract: programming error

Mar, 2010-08-03 21:01
LinuxSecurity.com: It was discovered that a programming error in the archive test mode of cabextract, a program to extract Microsoft Cabinet files, could lead to the execution of arbitrary code. [More...]

Debian: 2086-1: avahi: Multiple vulnerabilities

Mar, 2010-08-03 19:48
LinuxSecurity.com: Several vulnerabilities have been discovered in the Avahi mDNS/DNS-SD daemon. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]