|
|
Security Linux News for Dec 04, 2003
-
Trustix Secure Linux Advisory: rsync (Aug 17, 2004, 21:29)
"There is a security problem in all versions prior to 2.6.1 that
affects only people running a read/write daemon WITHOUT using
chroot..."
-
Debian GNU/Linux Advisory: rsync (Dec 04, 2003, 22:59)
"The rsync team has received evidence that a vulnerability in
all versions of rsync prior to 2.5.7, a fast remote file copy
program, was recently used in combination with a Linux kernel
vulnerability to compromise the security of a public rsync
server..."
-
EnGarde Secure Linux Advisory: rsync (Dec 04, 2003, 21:59)
"This vulnerability, exploitable when rsync is being run in
'server mode,' may allow the attacker to run arbitrary code on the
compromised server..."
-
Trustix Secure Linux Advisory: rsync (Dec 04, 2003, 21:57)
"All versions of rsync prior to 2.5.7 contains a heap overflow
that can be used to exceute arbitary code from remote..."
-
Slackware Linux Advisory: rsync (Dec 04, 2003, 20:58)
"A security problem which may lead to unauthorized machine
access or code execution has been fixed by upgrading to
rsync-2.5.7..."
-
SUSE Linux Advisory: SuSE Linux 7.3 End of Life (Dec 04, 2003, 20:00)
"Vulnerabilities found after December 15th 2003 will not be
fixed any more for SuSE Linux 7.3..."
-
SUSE Linux Advisories: rsync, kernel (Dec 04, 2003, 19:58)
Two security advisories from SUSE Linux.
-
internetnews.com: Linux Security Expert Defends Debian (Dec 04, 2003, 18:00)
"A Linux expert is defending the way Debian Project leaders
handled a recent security breach that took down the servers of the
10-year-old open source effort..."
-
GNU.org: FSF Server Compromised 11/2, Discovered 12/2 (Dec 04, 2003, 02:20)
"On December 1st, 2003, we discovered that the 'Savannah'
system... was compromised at circa November 2nd, 2003..."
-
Gentoo Linux Advisory: rsync.gentoo.org Rotation Server Compromised (Dec 04, 2003, 01:46)
"On December 2nd at approximately 03:45 UTC, one of the servers
that makes up the rsync.gentoo.org rotation was compromised via a
remote exploit..."
-
SUSE Linux Advisory: gpg (Dec 04, 2003, 01:45)
"Two independent errors have been found in gpg (GnuPG) packages
as shipped with SUSE products..."
|