Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Ultimate Firefox Productivity Tips: For the Geeks.

GoldenDict: A Dictionary Nugget

Would You Like Linux With Your Jello?

Why I Use Linux: Lofton’s Story

Go to Toys 'R Us for your Linux netbook needs

Sun xVM VirtualBox 3.0: Virtual Developer's Delight

Apple Wary of Ogg Theora: No Agreement Yet on HTML5 Video Standard

Freedom is not Free for Countries nor Computer Users

Eyecandy Themes For Ubuntu - Download directly from Synaptic - No More Hassles

Sifting Through Billions and Billions of Bytes




Security Engineer (PA)
Next Step Systems
US-PA-Philadelphia

Justtechjobs.com Post A Job | Post A Resume
:Fedora Core Advisories: squirrelmail, squid
Fedora Core Advisories: squirrelmail, squid
Jun 9, 2004, 21 :13 UTC (0 Talkback[s]) (2245 reads)


Fedora Update Notification
FEDORA-2004-159
2004-06-09

Product : Fedora Core 1
Name : squirrelmail
Version : 1.4.3
Release : 0.f1.1
Summary : SquirrelMail webmail client

Description :
SquirrelMail is a standards-based webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no Javascript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. SquirrelMail has all the functionality you would want from an email client, including strong MIME support, address books, and folder manipulation.


Update Information:

An SQL injection flaw was found in SquirrelMail version 1.4.2 and earlier. If SquirrelMail is configured to store user addressbooks in the database, a remote attacker could use this flaw to execute arbitrary SQL statements. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0521 to this issue.

A number of cross-site scripting (XSS) flaws in SquirrelMail version 1.4.2 and earlier could allow remote attackers to execute scripts as other web users. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the names CAN-2004-0519 and CAN-2004-0520 to these issues.

This update includes the SquirrelMail version 1.4.3a which is not vulnerable to these issues.


* Mon Jun 07 2004 Gary Benson <gbenson@redhat.com> 1.4.3-0.f1.1
  • upgrade to 1.4.3a.
  • retain stuff after version when adding release to it.
    • Wed Jun 02 2004 Gary Benson <gbenson@redhat.com>
  • upgrade to 1.4.3.
    • Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
  • rebuilt.
    • Wed Jan 21 2004 Gary Benson <gbenson@redhat.com> 1.4.2-2
  • fix calendar plugin breakage (#113902).
    • Thu Jan 08 2004 Gary Benson <gbenson@redhat.com> 1.4.2-1
  • upgrade to 1.4.2.
  • tighten up permissions on /etc/squirrelmail/config.php (#112774).

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

be17fbe0ab2c017c9f8aafc407c3fb68 SRPMS/squirrelmail-1.4.3-0.f1.1.src.rpm
4c8288b42458e69e656230afd2a4a38f i386/squirrelmail-1.4.3-0.f1.1.noarch.rpm
4c8288b42458e69e656230afd2a4a38f x86_64/squirrelmail-1.4.3-0.f1.1.noarch.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2004-160
2004-06-09

Product : Fedora Core 2
Name : squirrelmail
Version : 1.4.3
Release : 1
Summary : SquirrelMail webmail client

Description :
SquirrelMail is a standards-based webmail package written in PHP4. It includes built-in pure PHP support for the IMAP and SMTP protocols, and all pages render in pure HTML 4.0 (with no Javascript) for maximum compatibility across browsers. It has very few requirements and is very easy to configure and install. SquirrelMail has all the functionality you would want from an email client, including strong MIME support, address books, and folder manipulation.


Update Information:

An SQL injection flaw was found in SquirrelMail version 1.4.2 and earlier. If SquirrelMail is configured to store user addressbooks in the database, a remote attacker could use this flaw to execute arbitrary SQL statements. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0521 to this issue.

A number of cross-site scripting (XSS) flaws in SquirrelMail version 1.4.2 and earlier could allow remote attackers to execute scripts as other web users. The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the names CAN-2004-0519 and CAN-2004-0520 to these issues.

This update includes the SquirrelMail version 1.4.3a which is not vulnerable to these issues.


  • Mon Jun 07 2004 Gary Benson <gbenson@redhat.com> 1.4.3-1
    • upgrade to 1.4.3a.
    • retain stuff after version when adding release to it.
  • Wed Jun 02 2004 Gary Benson <gbenson@redhat.com>
    • upgrade to 1.4.3.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

1a985829cd9b532953d8235083aa9ff2 SRPMS/squirrelmail-1.4.3-1.src.rpm
b76007bdb6f2a926d46cc6099e66a45d i386/squirrelmail-1.4.3-1.noarch.rpm
b76007bdb6f2a926d46cc6099e66a45d x86_64/squirrelmail-1.4.3-1.noarch.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2004-163
2004-06-09

Product : Fedora Core 1
Name : squid
Version : 2.5.STABLE3
Release : 2.fc1
Summary : The Squid proxy caching server.

Description :
Squid is a high-performance proxy caching server for Web clients, supporting FTP, gopher, and HTTP data objects. Unlike traditional caching software, Squid handles all requests in a single, non-blocking, I/O-driven process. Squid keeps meta data and especially hot objects cached in RAM, caches DNS lookups, supports non-blocking DNS lookups, and implements negative caching of failed requests.

Squid consists of a main server program squid, a Domain Name System lookup program (dnsserver), a program for retrieving FTP data (ftpget), and some management and client tools.


  • Mon Jun 07 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE3-2.fc1
    • Backport patch for CAN-2004-0541: buffer overflow in ntlm auth helper.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/1/

ac5bbb825c3ab5223b1b26f162f24c19 SRPMS/squid-2.5.STABLE3-2.fc1.src.rpm
28f6216478b102cbddcf6de38ea8f126 i386/squid-2.5.STABLE3-2.fc1.i386.rpm
c8fb3a9ddc44e0e8d01a092993877ed7 i386/debug/squid-debuginfo-2.5.STABLE3-2.fc1.i386.rpm
e034b4a07c0e00a285f115be6ac63cfa x86_64/squid-2.5.STABLE3-2.fc1.x86_64.rpm
6a4992a5d0244b297ddc9ca44a312541 x86_64/debug/squid-debuginfo-2.5.STABLE3-2.fc1.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.



Fedora Update Notification
FEDORA-2004-164
2004-06-09

Product : Fedora Core 2
Name : squid
Version : 2.5.STABLE5
Release : 4.fc2
Summary : The Squid proxy caching server.

Description :
Squid is a high-performance proxy caching server for Web clients, supporting FTP, gopher, and HTTP data objects. Unlike traditional caching software, Squid handles all requests in a single, non-blocking, I/O-driven process. Squid keeps meta data and especially hot objects cached in RAM, caches DNS lookups, supports non-blocking DNS lookups, and implements negative caching of failed requests.

Squid consists of a main server program squid, a Domain Name System lookup program (dnsserver), a program for retrieving FTP data (ftpget), and some management and client tools.


  • Mon Jun 07 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE3-4.fc2
    • Backport security fix for ntlm auth helper (CAN-2004-0541).
  • Thu Apr 08 2004 Jay Fenlason <fenlason@redhat.com> 7:2.5.STABLE5-3
    • Fix the -pipe patch to have the correct name of the winbind pipe.

This update can be downloaded from:
http://download.fedora.redhat.com/pub/fedora/linux/core/updates/2/

b735863f8f52314d1ff9981c85ea56b2 SRPMS/squid-2.5.STABLE5-4.fc2.src.rpm
4d80ef2db40a68a7ba2ecffdec9d3372 i386/squid-2.5.STABLE5-4.fc2.i386.rpm
779417acbbfe0e022bc1525d9faae339 i386/debug/squid-debuginfo-2.5.STABLE5-4.fc2.i386.rpm
c8c1bc2cd95f892ce602e3e38e9e7823 x86_64/squid-2.5.STABLE5-4.fc2.x86_64.rpm
fcb5484591641424a956b23c97614963 x86_64/debug/squid-debuginfo-2.5.STABLE5-4.fc2.x86_64.rpm

This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command.




No talkbacks posted.
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP