Showing all newswire headlines

View by date, instead?

« Previous ( 1 ... 7238 7239 7240 7241 7242 7243 7244 7245 7246 7247 7248 ... 7264 ) Next »

SuSE alert: squid

  • Mailing list (Posted by dave on Oct 30, 2001 2:34 AM EDT)
  • Story Type: Security; Groups: SUSE
The squid proxy server can be crashed with a malformed request, resulting in a denial of service attack. After the crash, the squid proxy must be restarted. The weakness can only be triggered from an address that is allowed to send requests, as configured in the squid configuration file.

Red Hat alert: Printing exposes system files to reading.

  • Mailing list (Posted by dave on Oct 26, 2001 3:53 PM EDT)
  • Story Type: Security; Groups: Red Hat
When used in a spooling environment, it is inappropriate to allow programs to read arbitrary files as a result of print requests. Ghostscript, a postscript interpreter, can read arbitrary system files with the same permissions as the print spooler, potentially exposing the system to an information compromise.

SuSE alert: kernel

  • Mailing list (Posted by dave on Oct 26, 2001 8:17 AM EDT)
  • Story Type: Security; Groups: SUSE
Two security related problems have been found in both the 2.2 and 2.4 series kernels:

Red Hat alert: Updated mod_auth_pgsql packages available

  • Mailing list (Posted by dave on Oct 24, 2001 7:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated mod_auth_pgsql packages are now available for Red Hat Linux 7.

Red Hat alert: Updated mod_auth_pgsql packages available

  • Mailing list (Posted by dave on Oct 24, 2001 7:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated mod_auth_pgsql packages are now available for Red Hat Linux 7.

SuSE alert: htdig

  • Mailing list (Posted by dave on Oct 24, 2001 2:17 AM EDT)
  • Story Type: Security; Groups: SUSE
ht://Dig is a powerfull indexing and information gathering tool for the web. ht://Dig's search engine htsearch could be run by a http server as CGI program or standalone as commandline tool. Due to insufficient checking of the running environment it is possible to use commandline options via CGI. An remote attacker could use the -c option to specify /dev/zero as an alternate config file to causes a denial of service for some minutes. To read files with the privilege of the http server by abusing the -c option an attacker needs write access to the server running htsearch.

SuSE alert: shadow/login

  • Mailing list (Posted by dave on Oct 23, 2001 8:27 AM EDT)
  • Story Type: Security; Groups: SUSE
Multiple Linux vendors have issued security announcements about failures of the /bin/login program to properly initialize the privileges of an authenticated user if the PAM module pam_limits is enabled. The bug has been categorized as a sequence bug, and is located in the code of the login program itself: A call to getpwnam(3) returns a pointer to a struct passwd, and the data is being used. Then, a call to PAM routines cause getpwnam(3) to be called again, but beyond the programmer's control or knowledge. The pointer as returned by the first getpwnam(3) remains the same, but the data may be different. By consequence, the data is in an undefined state. The error appears with the pam_limits PAM module only because other PAM modules do not call getpwnam(3).

Red Hat alert: New kernel 2.4 packages are available

  • Mailing list (Posted by dave on Oct 22, 2001 9:53 AM EDT)
  • Story Type: Security; Groups: Red Hat
A vulnerability has been found in the ptrace code of the kernel (ptrace is the part that allows program debuggers to run) that could be abused by local users to gain root privileges. 2001-10-22: Kernel updates are now available for Red Hat Linux 7.

Announcing the availability of Red Hat Linux 7.2 (Enigma)

Red Hat, Inc. (NASDAQ:RHAT) today announced that Red Hat Linux 7.2 and Red Hat Linux Professional are now available in stores, through computer resellers and direct from Red Hat. The latest version of the market leading Linux distribution adds significant new capabilities, both for use as a workstation and use as a server. Red Hat Linux 7.2 and Red Hat Linux Professional will also be available through hardware partners in the coming weeks.

Red Hat alert: New squid packages available to fix FTP-based DoS

  • Mailing list (Posted by dave on Oct 22, 2001 5:01 AM EDT)
  • Story Type: Security; Groups: Red Hat
New squid packages are available that fix a potential DoS in Squid's FTP handling code. It is recommened that squid users update to the fixed packages. The packages for Red Hat Linux 6.2 also fix the problem described in RHSA-2001:097-04; it was later discovered that Red Hat Linux 6.2 is vulnerable to the same problem in accelerator-only mode. 2001-10-22: Packages are now available for Red Hat Linux 7.

Red Hat alert: New squid packages available to fix FTP-based DoS

  • Mailing list (Posted by dave on Oct 22, 2001 5:01 AM EDT)
  • Story Type: Security; Groups: Red Hat
New squid packages are available that fix a potential DoS in Squid's FTP handling code. It is recommened that squid users update to the fixed packages. The packages for Red Hat Linux 6.2 also fix the problem described in RHSA-2001:097-04; it was later discovered that Red Hat Linux 6.2 is vulnerable to the same problem in accelerator-only mode. 2001-10-22: Packages are now available for Red Hat Linux 7.

Red Hat alert: New util-linux packages available to fix /bin/login pam problem

  • Mailing list (Posted by dave on Oct 22, 2001 5:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
New util-linux packages are available that fix a problem with /bin/login's PAM implementation. This could, in some non-default setups, cause users to receive credentials of other users. It is recommended that all users update to the fixed packages. 2001-10-22: Packages are now available for Red Hat Linux 7.

Red Hat alert: Updated openssh packages available

  • Mailing list (Posted by dave on Oct 22, 2001 5:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated openssh packages are now available for Red Hat Linux 7 and 7.1. These packages fix a vulnerability which may allow unauthorized users to log in from hosts that have been denied access. 2001-10-22: Pacakges are now available for Red Hat Linux 7.

Red Hat alert: New util-linux packages available to fix /bin/login pam problem

  • Mailing list (Posted by dave on Oct 22, 2001 5:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
New util-linux packages are available that fix a problem with /bin/login's PAM implementation. This could, in some non-default setups, cause users to receive credentials of other users. It is recommended that all users update to the fixed packages. 2001-10-22: Packages are now available for Red Hat Linux 7.

Red Hat alert: Updated openssh packages available

  • Mailing list (Posted by dave on Oct 22, 2001 5:00 AM EDT)
  • Story Type: Security; Groups: Red Hat
Updated openssh packages are now available for Red Hat Linux 7 and 7.1. These packages fix a vulnerability which may allow unauthorized users to log in from hosts that have been denied access. 2001-10-22: Pacakges are now available for Red Hat Linux 7.

Debian alert: New nvi packages fix format string vulnerability

  • Mailing list (Posted by dave on Oct 21, 2001 5:56 AM EDT)
  • Story Type: Security; Groups: Debian
Takeshi Uno found a very stupid format string vulnerability in all versions of nvi (in both, the plain and the multilingualized version). When a filename is saved, it ought to get displayed on the screen. The routine handling this didn't escape format strings.

Red Hat alert: Updated diffutils packages available

  • Mailing list (Posted by dave on Oct 18, 2001 11:54 PM EDT)
  • Story Type: Security; Groups: Red Hat
Updated diffutils packages are now available, fixing a temporary file handling vulnerability in the sdiff program.

Red Hat alert: New kernel 2.2 packages are available

  • Mailing list (Posted by dave on Oct 18, 2001 2:43 PM EDT)
  • Story Type: Security; Groups: Red Hat
A vulnerability has been found in the ptrace code of the kernel (ptrace is the part that allows program debuggers to run) that could be abused by local users to gain root privileges.

Red Hat alert: New kernel 2.4 packages are available

  • Mailing list (Posted by dave on Oct 18, 2001 2:42 PM EDT)
  • Story Type: Security; Groups: Red Hat
A vulnerability has been found in the ptrace code of the kernel (ptrace is the part that allows program debuggers to run) that could be abused by local users to gain root privileges.

Red Hat alert: New kernel 2.4 packages are available

  • Mailing list (Posted by dave on Oct 18, 2001 2:42 PM EDT)
  • Story Type: Security; Groups: Red Hat
A vulnerability has been found in the ptrace code of the kernel (ptrace is the part that allows program debuggers to run) that could be abused by local users to gain root privileges.

« Previous ( 1 ... 7238 7239 7240 7241 7242 7243 7244 7245 7246 7247 7248 ... 7264 ) Next »