|
|
Security Linux News for Mar 19, 2001
-
Conectiva Linux Security Announcement - Zope (Mar 19, 2001, 22:41)
"Two hotfixes have been released that address security problems
with Zope-2.1.x."
-
Conectiva Linux Security Announcement - slrn (Mar 19, 2001, 22:38)
"Previous versions have a buffer overflow vulnerability that
could be exploited remotely via a carefully crafted news
message."
-
Conectiva Linux Security Announcement - mutt (Mar 19, 2001, 22:34)
"Versions prior to 1.2.5 have some format string vulnerabilities
that have now been fixed."
-
Conectiva Linux Security Announcement - icecast (Mar 19, 2001, 20:56)
"Matt Messier and John Viega have identified several buffer
overflow and format strings problems in Icecast that could be
remotely exploited."
-
Conectiva Linux Security Announcement - cups (Mar 19, 2001, 20:52)
"All users of the "cups" printing system should upgrade the
package. Users who only used apt to do the previous update will
only have to run apt again, as usual. No further intervention will
be necessary."
-
LinuxSecurity.com: Linux Security Week - March 19th 2001 (Mar 19, 2001, 07:51)
"This week, advisories were released for imap, joe, gnuserv,
zope, mailx, icecast, cfengine, rwhod, interbase, slrn, Mesa, sudo,
sgml-tools, and mutt. The vendors include Caldera, Debian, Immunix,
FreeBSD, Mandrake, Red Hat, and Trustix."
-
Security Portal: Weekly Linux Security Digest 2001/03/12 to 2001/03/18 (Mar 19, 2001, 07:45)
"Of course the other big news this week is a nasty denial of
service bug in ProFTPD. The good news is, you can avoid it by using
DenyFilter."
-
Conectiva Linux Security Announcement - Zope (Mar 02, 2001, 20:50)
"A user with through-the-web scripting capabilities on a Zope
site can view and assign class attributes to ZClasses, possibly
allowing them to make inappropriate changes to ZClass
instances."
-
Conectiva Linux Security Announcement - icecast (Jan 25, 2001, 22:18)
"The "Packet Knights" group has found a format string
vulnerability on this program that could be used to remotely
execute arbitrary code on the server with the privileges of the
user running it, normally root. This can lead to remote root
compromise."
|