Linux Today: Linux News On Internet Time.
Search Linux Today
Linux News Sections:  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Contribute
Contribute
Link to Us
Linux Jobs

Partner Sites
JustLinux.com
Linux Planet
PHPBuilder
Technology Jobs


Top White Papers





More on LinuxToday

Security Linux News for Jul 18, 2001

  • Red Hat Security Advisory: Updated openssl packages available (Jul 18, 2001, 22:52)
    "Versions of OpenSSL prior to 0.9.6a suffer from potential security problems. These include potential leakage of information after SSL version 3 key exchanges, imperfect distribution of random numbers used when generating signatures, honoring of sensitive environment variables in library functions in setuid or setgid applications, and not taking precautions to counter effects of potential hardware glitches when generating digital signatures. A flaw has also been found in the pseudo-random number generator used in versions of OpenSSL prior to 0.9.6b. The OpenSSL Project Team has released a patch which corrects this problem."

  • Caldera Security Advisory: docview (Jul 18, 2001, 00:15)
    "Docview is a set of CGI scripts providing documentation over http. A argument validation problem in one of the CGI scripts made it possible for a local attacker to gain access to the 'httpd' account."

  • Caldera Security Advisory: imp uses /tmp unsafely (Jul 18, 2001, 00:15)
    "Horde and Imp use /tmp in an unsafe manner, allowing local users to gain access to the webserver (httpd) account. They also do not protect internal data files from being viewed by local or remote attackers. The updates packages fix the /tmp problems, add restrictions on what files can be viewed and also disables it by default."