|
|
|
| Top White Papers
Current Newswire:
Mandrakelinux Advisory: sysklogdApr 29, 2004, 05:30 (0 Talkback[s])Mandrakelinux Security Update Advisory Package name: sysklogd Problem Description: Steve Grubb discovered a bug in sysklogd where it allocates an insufficient amount of memory which causes sysklogd to write to unallocated memory. This could allow for a malicious user to crash sysklogd. The updated packages provide a patched sysklogd using patches from Openwall to correct the problem and also corrects the use of an unitialized variable (a previous use of "count"). Updated Packages: Mandrakelinux 10.0: Corporate Server 2.1: Corporate Server 2.1/x86_64: Mandrakelinux 9.1: Mandrakelinux 9.1/PPC: Mandrakelinux 9.2: Mandrakelinux 9.2/AMD64: Multi Network Firewall 8.2: To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you. A list of FTP mirrors can be obtained from: http://www.mandrakesecure.net/en/ftp.php All packages are signed by Mandrakesoft for security. You can obtain the GPG public key of the Mandrakelinux Security Team by executing: gpg --recv-keys --keyserver www.mandrakesecure.net 0x22458A98 Please be aware that sometimes it takes the mirrors a few hours to update. You can view other update advisories for Mandrakelinux at: http://www.mandrakesecure.net/en/advisories/ Mandrakesoft has several security-related mailing list services that anyone can subscribe to. Information on these lists can be obtained by visiting: http://www.mandrakesecure.net/en/mlist.php If you want to report vulnerabilities, please contact security_linux-mandrake.com Type Bits/KeyID Date User ID 0 Talkback[s]
(click to add your comment)
|