|
|
|
| Top White Papers
Current Newswire:
Slackware Linux Advisories: zlib, getmailOct 05, 2004, 17:29 (0 Talkback[s])[slackware-security] zlib DoS (SSA:2004-278-02)New zlib packages are available for Slackware 10.0 and -current to fix a possible denial of service security issue. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-797 Here are the details from the Slackware 10.0 ChangeLog: Where to find the new packages:Updated package for Slackware 10.0: Updated package for Slackware -current: MD5 signatures:Slackware 10.0 package: Slackware -current package: Installation instructions:Upgrade the packages as root: +-----+ Slackware Linux Security Team [slackware-security] getmail (SSA:2004-278-01)New getmail packages are available for Slackware 9.1, 10.0 and -current to fix a security issue. If getmail is used as root to deliver to user owned files or directories, it can be made to overwrite system files. More details about this issue may be found in the Common Vulnerabilities and Exposures (CVE) database: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-880 Here are the details from the Slackware 10.0 ChangeLog: This vulnerability is not exploitable if the administrator does not deliver mail to the maildirs/mbox files of untrusted local users, or if getmail is configured to use an external unprivileged MDA. This vulnerability is not remotely exploitable. Most users would not use getmail in such as way as to be vulnerable to this flaw, but if your site does this package closes the hole. I'd also recommend not using getmail like this. Either run it as the user that owns the target mailbox, or deliver through an external MDA. (* Security fix *) +--------------------------+ Where to find the new packages:Updated package for Slackware 9.1: Updated package for Slackware 10.0: Updated package for Slackware -current: MD5 signatures:Slackware 9.1 package: Slackware 10.0 package: Slackware -current package: Installation instructions:Upgrade the package as root: +-----+ Slackware Linux Security Team 0 Talkback[s]
(click to add your comment)
|