Linux Advisories

Divulgar conteúdo
The central voice for Linux and Open Source security news.
Atualizado: 39 minutos 19 segundos atrás

SuSE: 2010-038: kernel

sex, 09/03/2010 - 06:02
LinuxSecurity.com: This SUSE Linux Enterprise 10 SP3 kernel update contains several bug fixes and fixes for the following security issues: CVE-2010-2240: the stack of a process could grow into other mapped areas, therefore overwriting memory instead of terminating the [More...]

Debian: 2102-1: barnowl: unchecked return value

sex, 09/03/2010 - 03:14
LinuxSecurity.com: It has been discovered that in barnowl, a curses-based instant-messaging client, the return codes of calls to the ZPending and ZReceiveNotice functions in libzephyr were not checked, allowing attackers to cause a denial of service (crash of the application), and possibly execute [More...]

Pardus: 2010-120: Flashplugin: Multiple

qui, 09/02/2010 - 23:09
LinuxSecurity.com: Multiple vulnerabilities have been fixed in flashplugin.

Pardus: 2010-119: OpenSSL: Use-after-free

qui, 09/02/2010 - 23:09
LinuxSecurity.com: A vulnerability has been fixed in OpenSSL, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise an application using the library.

Mandriva: 2010:170: wget

qui, 09/02/2010 - 16:21
LinuxSecurity.com: A vulnerability has been found and corrected in wget: GNU Wget 1.12 and earlier uses a server-provided filename instead of the original URL to determine the destination filename of a download, which allows remote servers to create or overwrite arbitrary files [More...]

Gentoo: 201009-01: wxGTK: User-assisted execution of arbitrary code

qui, 09/02/2010 - 14:20
LinuxSecurity.com: An integer overflow vulnerability in wxGTK might enable remoteattackers to cause the execution of arbitrary code.

Red Hat: 2010:0670-01: kernel: Important Advisory

qui, 09/02/2010 - 11:54
LinuxSecurity.com: Updated kernel packages that fix two security issues and three bugs are now available for Red Hat Enterprise Linux 5.4 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]

Mandriva: 2010:169: mozilla-thunderbird

qui, 09/02/2010 - 07:57
LinuxSecurity.com: Multiple vulnerabilities has been found and corrected in mozilla-thunderbird: dom/base/nsJSEnvironment.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x [More...]

Ubuntu: 982-1: Wget vulnerability

qui, 09/02/2010 - 06:52
LinuxSecurity.com: It was discovered that Wget would use filenames provided by the server whenfollowing 3xx redirects. If a user or automated system were tricked intodownloading a file from a malicious site, a remote attacker could createthe file with an arbitrary name (e.g. .wgetrc), and possibly run arbitrarycode. [More...]

Mandriva: 2010:168: openssl

qua, 09/01/2010 - 10:30
LinuxSecurity.com: A vulnerability has been found and corrected in openssl: Double free vulnerability in the ssl3_get_key_exchange function in the OpenSSL client (ssl/s3_clnt.c) in OpenSSL 1.0.0a, 0.9.8, 0.9.7, and possibly other versions, when using ECDH, allows context-dependent [More...]

SuSE: 2010-036: kernel

qua, 09/01/2010 - 05:04
LinuxSecurity.com: This update fixes various security issues and some bugs in the SUSE Linux Enterprise 9 kernel. Following security issues were fixed: CVE-2010-2521: A crafted NFS write request might have caused a buffer overwrite, [More...]

Mandriva: 2010:167: perl-libwww-perl

ter, 08/31/2010 - 17:24
LinuxSecurity.com: A vulnerability has been found and corrected in perl-libwww-perl: lwp-download in libwww-perl before 5.835 does not reject downloads to filenames that begin with a . (dot) character, which allows remote servers to create or overwrite files via (1) a 3xx redirect to a [More...]

Debian: 2101-1: wireshark: Multiple vulnerabilities

ter, 08/31/2010 - 14:29
LinuxSecurity.com: Several implementation errors in the dissector of the Wireshark network traffic analyzer for the ASN.1 BER protocol and in the SigComp Universal Decompressor Virtual Machine may lead to the execution of arbitrary code. [More...]

Mandriva: 2010:166: libgdiplus

ter, 08/31/2010 - 11:00
LinuxSecurity.com: A vulnerability has been found and corrected in libgdiplus: Multiple integer overflows in libgdiplus 2.6.7, as used in Mono, allow attackers to execute arbitrary code via (1) a crafted TIFF file, related to the gdip_load_tiff_image function in tiffcodec.c; [More...]

Ubuntu: 981-1: libwww-perl vulnerability

ter, 08/31/2010 - 06:43
LinuxSecurity.com: It was discovered that libwww-perl incorrectly filtered filenames suggestedby Content-Disposition headers. If a user were tricked into downloading afile from a malicious site, a remote attacker could overwrite hidden filesin the user's directory. [More...]

Debian: 2100-1: openssl: double free

seg, 08/30/2010 - 11:45
LinuxSecurity.com: George Guninski discovered a double free in the ECDH code of the OpenSSL crypto library, which may lead to denial of service and potentially the execution of arbitrary code. [More...]

Mandriva: 2010:165: libHX

seg, 08/30/2010 - 11:00
LinuxSecurity.com: A vulnerability has been found and corrected in libHX: Heap-based buffer overflow in the HX_split function in string.c in libHX before 3.6 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a string that [More...]

Red Hat: 2010:0661-01: kernel: Important Advisory

seg, 08/30/2010 - 08:09
LinuxSecurity.com: Updated kernel packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2010:0660-01: kernel: Important Advisory

seg, 08/30/2010 - 07:43
LinuxSecurity.com: Updated kernel packages that fix two security issues and multiple bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]

Red Hat: 2010:0659-01: httpd: Moderate Advisory

seg, 08/30/2010 - 07:42
LinuxSecurity.com: Updated httpd packages that fix two security issues and multiple bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]