|
|
|
| Top White Papers
Current Newswire:
Advisories, August 13, 2006Aug 14, 2006, 04:30 (0 Talkback[s])Debian GNU/LinuxDebian Security Advisory DSA 1150-1 security@debian.org Package : shadow A bug has been discovered in several packages that execute teh setuid() system call without checking for sucess when trying to drop privileges, which may fail with some PAM configurations. For the stable distribution (sarge) this problem has been fixed in version 4.0.3-31sarge8. For the unstable distribution (sid) this problem has been fixed in version 4.0.17-2. We recommend that you upgrade your passwd package. Upgrade Instructions wget url will fetch the file for you will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given at the end of this advisory: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge Source archives: http://security.debian.org/pool/updates/main/s/shadow/shadow_4.0.3-31sarge8.dsc Alpha architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_alpha.deb AMD64 architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_amd64.deb ARM architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_arm.deb Intel IA-32 architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_i386.deb Intel IA-64 architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_ia64.deb HP Precision architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_hppa.deb Motorola 680x0 architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_m68k.deb Big endian MIPS architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_mips.deb Little endian MIPS architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_mipsel.deb PowerPC architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_powerpc.deb IBM S/390 architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_s390.deb Sun Sparc architecture: http://security.debian.org/pool/updates/main/s/shadow/login_4.0.3-31sarge8_sparc.deb These files will probably be moved into the stable distribution on its next update. For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: debian-security-announce@lists.debian.org Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg> Gentoo LinuxGentoo Linux Security Advisory [UPDATE] GLSA 200511-12:03 Severity: High UpdateThe previous versions of Scorched3D contain several vulnerabilities and had been masked in the Portage Tree. The version 40 which solves these issues has just been introduced into Portage. The updated sections appear below. Affected packages
Package / Vulnerable / Unaffected
1 games-strategy/scorched3d <= 39.1 >= 40 ResolutionAll Scorched 3D users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=games-strategy/scorched3d-40"
AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200511-12.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Gentoo Linux Security Advisory GLSA 200608-19 Severity: Normal SynopsisA flaw in WordPress allows registered WordPress users to elevate privileges. BackgroundWordPress is a PHP and MySQL based multiuser blogging system. Affected packages
Package / Vulnerable / Unaffected
1 www-apps/wordpress < 2.0.4 >= 2.0.4 DescriptionThe WordPress developers have confirmed a vulnerability in capability checking for plugins. ImpactBy exploiting a flaw, a user can circumvent WordPress access restrictions when using plugins. The actual impact depends on the configuration of WordPress and may range from trivial to critical, possibly even the execution of arbitrary PHP code. WorkaroundThere is no known workaround at this time. ResolutionAll WordPress users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-apps/wordpress-2.0.4"
AvailabilityThis GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-200608-19.xml Concerns?Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at http://bugs.gentoo.org. LicenseCopyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 Trustix Secure LinuxTrustix Secure Linux Security Advisory #2006-0046 Package names: clamav, kernel Package description: clamav Clam AntiVirus is a GPL anti-virus toolkit for UNIX. The main purpose of this software is the integration with mail servers (attachment scanning). The package provides a flexible and scalable multi-threaded daemon, a command line scanner, and a tool for automatic updating via Internet. The programs are based on a shared library distributed with package, which you can use with your own software. Most importantly, the virus database is kept up to date . kernel Problem description:
The Common Vulnerabilities and Exposures project has assigned the name CVE-2006-4018 this issue. kernel < TSL 3.0 >
The Common Vulnerabilities and Exposures project (cve.mitre.org/) has assigned the name CVE-2006-3468 to this issue. Action: Location: About Trustix Secure Linux: Automatic updates: Questions? Verification: The advisory itself is available from the errata pages at MD5sums of the packages: 8ef80d50fdc0515d1faa429bbb921a2a 3.0/rpms/clamav-0.88.4-1tr.i586.rpm 163a3be6371898f5d6079ab20ca1c75b 3.0/rpms/clamav-devel-0.88.4-1tr.i586.rpm 3bdda169b31eb2d551cb3e072d01fa04 3.0/rpms/kernel-2.6.17.8-1tr.i586.rpm db24646f5d08d98c992173c9712af557 3.0/rpms/kernel-doc-2.6.17.8-1tr.i586.rpm e08c6244d967e8546548a19ff730ded7 3.0/rpms/kernel-headers-2.6.17.8-1tr.i586.rpm f7e60992fc4b3cad1f794a17c025bc66 3.0/rpms/kernel-smp-2.6.17.8-1tr.i586.rpm ce1b43791152a32388a28ca8e0bc0e17 3.0/rpms/kernel-smp-headers-2.6.17.8-1tr.i586.rpm 6cf8e6eb7017672dbf885d853fc642e3 3.0/rpms/kernel-source-2.6.17.8-1tr.i586.rpm 8c16f9d4e0cf85d6193b73f2ca64cd44 3.0/rpms/kernel-utils-2.6.17.8-1tr.i586.rpm a95fb6d4ba24539b9538f117b62d7143
2.2/rpms/clamav-0.88.4-1tr.i586.rpm Trustix Security Team 0 Talkback[s]
(click to add your comment)
|