Section: .. / 0610-advisories /
| /// File Name: |
SUSE-SA-2006-058.txt |
Description:
|
SUSE Security Announcement SUSE-SA:2006:058: OpenSSL DoS.
| | Homepage: | http://www.suse.com | | File Size: | 19411 | | Last Modified: | Oct 3 21:22:18 2006 |
| MD5 Checksum: | ffa418c4ed8bf0a10d9e17b1a5f33aa4 |
|
| /// File Name: |
OpenPKG-SA-2006.021.txt |
Description:
|
OpenPKG Security Advisory OpenPKG-SA-2006.021: According to a vendor security advisory [0], four security issues were discovered in the cryptography and SSL/TLS toolkit OpenSSL [1]:
| | Homepage: | http://www.openpkg.org/security/ | | File Size: | 3501 | | Last Modified: | Oct 3 21:20:54 2006 |
| MD5 Checksum: | 6c6e70e30a6daad516734ee877eb1023 |
|
| /// File Name: |
dsa-1185-2.txt |
Description:
|
Debian Security Advisory 1185-2: The fix used to correct CVE-2006-2940 introduced code that could lead to the use of uninitialized memory. Such use is likely to cause the application using the openssl library to crash, and has the potential to allow an attacker to cause the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 9184 | | Last Modified: | Oct 3 21:18:06 2006 |
| MD5 Checksum: | 5a95e10f43762da9ca309bc9519403a7 |
|
| /// File Name: |
dsa-1187-1.txt |
Description:
|
Debian Security Advisory 1187-1: Jason Hoover discovered that migrationtools, a collection of scripts to migrate user data to LDAP creates several temporary files insecurely, which might lead to denial of service through a symlink attack.
| | Homepage: | http://www.debian.org/security | | File Size: | 3133 | | Last Modified: | Oct 3 21:17:59 2006 |
| MD5 Checksum: | fa1391880f06fc4c5a1d270fdb18f6f5 |
|
| /// File Name: |
dsa-1186-1.txt |
Description:
|
Debian Security Advisory 1186-1: Will Drewry of the Google Security Team discovered several buffer overflows in cscope, a source browsing tool, which might lead to the execution of arbitrary code.
| | Homepage: | http://www.debian.org/security | | File Size: | 5080 | | Last Modified: | Oct 3 21:17:52 2006 |
| MD5 Checksum: | 5f7c91d5119f028c9e5007004afb28ca |
|
| /// File Name: |
dsa-1185-1.txt |
Description:
|
Debian Security Advisory 1185-1: Multiple vulnerabilities have been discovered in the OpenSSL cryptographic software package that could allow an attacker to launch a denial of service attack by exhausting system resources or crashing processes on a victim's computer.
| | Homepage: | http://www.debian.org/security | | File Size: | 10674 | | Last Modified: | Oct 3 21:17:46 2006 |
| MD5 Checksum: | f0978f2b0f4fab912e0be5326a2a92ce |
|
| /// File Name: |
USN-354-1.txt |
Description:
|
Ubuntu Security Notice 354-1: firefox vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 20533 | | Last Modified: | Oct 3 21:16:13 2006 |
| MD5 Checksum: | 2c18f7b7e5739739e1884a4359c1c573 |
|
| /// File Name: |
USN-356-1.txt |
Description:
|
Ubuntu Security Notice 356-1: Will Drewry, of the Google Security Team, discovered buffer overflows in GDB's DWARF processing. This would allow an attacker to execute arbitrary code with user privileges by tricking the user into using GDB to load an executable that contained malicious debugging information.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 4603 | | Last Modified: | Oct 3 21:16:09 2006 |
| MD5 Checksum: | 35da0dcce6e19a49ae387f6a4cbe005f |
|
| /// File Name: |
USN-355-1.txt |
Description:
|
Ubuntu Security Notice 355-1: Tavis Ormandy discovered that the SSH daemon did not properly handle authentication packets with duplicated blocks. By sending specially crafted packets, a remote attacker could exploit this to cause the ssh daemon to drain all available CPU resources until the login grace time expired. (CVE-2006-4924)
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 12809 | | Last Modified: | Oct 3 21:16:05 2006 |
| MD5 Checksum: | e2595de5befd559480be17097fc39139 |
|
| /// File Name: |
USN-353-1.txt |
Description:
|
Ubuntu Security Notice 353-1: openssl vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 12539 | | Last Modified: | Oct 3 21:16:01 2006 |
| MD5 Checksum: | c5c4046a58109d7a9dc10e79cb146454 |
|
| /// File Name: |
MDKSA-2006-170-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-170-1: Webmin before 1.296 and Usermin before 1.226 does not properly handle a URL with a null ("%00") character, which allows remote attackers to conduct cross-site scripting (XSS), read CGI program source code, list directories, and possibly execute programs.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 2681 | | Last Modified: | Oct 3 20:47:44 2006 |
| MD5 Checksum: | 248efcbe7f319d6c819d466dd3d694b8 |
|
| /// File Name: |
MDKSA-2006-178.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-178: Openssl recently had several vulnerabilities which were patched (CVE-2006-2937,2940,3738,4339, 4343). Some versions of ntp are built against a static copy of the SSL libraries. As a precaution an updated copy built against the new libraries in being made available.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3762 | | Last Modified: | Oct 3 20:47:36 2006 |
| MD5 Checksum: | 85150bb23fac28a31fb4684c3fc240ea |
|
| /// File Name: |
MDKSA-2006-177.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-177: Openssl recently had several vulnerabilities which were patched (CVE-2006-2937,2940,3738,4339, 4343). Some MySQL versions are built against a static copy of the SSL libraries. As a precaution an updated copy built against the new libraries in being made available.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5502 | | Last Modified: | Oct 3 20:47:28 2006 |
| MD5 Checksum: | 742ab8590b84f07fa11ec840001a0ccf |
|
| /// File Name: |
MDKSA-2006-172-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-172-1: Dr S N Henson of the OpenSSL core team and Open Network Security recently developed an ASN1 test suite for NISCC (www.niscc.gov.uk). When the test suite was run against OpenSSL two denial of service vulnerabilities were discovered.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 9118 | | Last Modified: | Oct 3 20:47:19 2006 |
| MD5 Checksum: | fb6eb884b31ae8e9c20c753e0ab10a98 |
|
| /// File Name: |
MDKSA-2006-176.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-176: Xine-lib uses an embedded copy of ffmpeg and as such has been updated to address the following issue: Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4)sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10)shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 8898 | | Last Modified: | Oct 3 20:47:08 2006 |
| MD5 Checksum: | f3225bb9d65122a89bb67b51c09f9ce0 |
|
| /// File Name: |
MDKSA-2006-175.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-175: Mplayer uses an embedded copy of ffmpeg and as such has been updated to address the following issue: Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4)sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10)shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 5266 | | Last Modified: | Oct 3 20:47:00 2006 |
| MD5 Checksum: | ab75d0ef9bd1f21cb02f3f77d23324ed |
|
| /// File Name: |
MDKSA-2006-174.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-174: Gstreamer-ffmpeg uses an embedded copy of ffmpeg and as such has been updated to address the following issue: Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4)sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10)shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3231 | | Last Modified: | Oct 3 20:46:51 2006 |
| MD5 Checksum: | 3838d0206ec2140adac4c1277c7ca750 |
|
| /// File Name: |
MDKSA-2006-173.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-173: Multiple buffer overflows in libavcodec in ffmpeg before 0.4.9_p20060530 allow remote attackers to cause a denial of service or possibly execute arbitrary code via multiple unspecified vectors in (1) dtsdec.c, (2) vorbis.c, (3) rm.c, (4)sierravmd.c, (5) smacker.c, (6) tta.c, (7) 4xm.c, (8) alac.c, (9) cook.c, (10)shorten.c, (11) smacker.c, (12) snow.c, and (13) tta.c. NOTE: it is likely that this is a different vulnerability than CVE-2005-4048 and CVE-2006-2802.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 4537 | | Last Modified: | Oct 3 20:46:44 2006 |
| MD5 Checksum: | e0297abe46507c5f7af2b4bb815e32e1 |
|
| /// File Name: |
MDKSA-2006-172.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-172: Dr S N Henson of the OpenSSL core team and Open Network Security recently developed an ASN1 test suite for NISCC (www.niscc.gov.uk). When the test suite was run against OpenSSL two denial of service vulnerabilities were discovered.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 8494 | | Last Modified: | Oct 3 20:46:38 2006 |
| MD5 Checksum: | 9989d95b9fe1028d5c59239a313e1b89 |
|
| /// File Name: |
MDKSA-2006-171.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-171: slapd in OpenLDAP before 2.3.25 allows remote authenticated users with selfwrite Access Control List (ACL) privileges to modify arbitrary Distinguished Names (DN).
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3753 | | Last Modified: | Oct 3 20:46:32 2006 |
| MD5 Checksum: | 10ffc1b61bea04405ed373821f7d978e |
|
| /// File Name: |
MDKSA-2006-157-1.txt |
Description:
|
Mandriva Linux Security Advisory MDKSA-2006-157-1: Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.
| | Homepage: | http://www.mandriva.com/security/advisories | | File Size: | 3175 | | Last Modified: | Oct 3 20:46:24 2006 |
| MD5 Checksum: | aba30520490ef3ebfa43ceda77c4511b |
|
| /// File Name: |
RISE-2006002.txt |
Description:
|
There exists a vulnerability within a architecture dependent function of the FreeBSD kernel (FreeBSD 5.2-RELEASE through FreeBSD 5.5-RELEASE), which when properly exploited can lead to local compromise of the vulnerable system. This vulnerability was fixed in FreeBSD 6.0-RELEASE, but production (legacy) releases 5.2 through 5.5 are still vulnerable.
| | Author: | RISE Security | | Homepage: | http://www.risesecurity.org/ | | File Size: | 5765 | | Last Modified: | Oct 3 20:45:32 2006 |
| MD5 Checksum: | c0e9b3fed5a808b71477f31faa9eb155 |
|
| /// File Name: |
rPSA-2006-0175-1.txt |
Description:
|
rPath Security Advisory: 2006-0175-1: openssl Remote Deterministic Unauthorized Access
| | Homepage: | http://www.rpath.com | | File Size: | 1550 | | Last Modified: | Oct 3 20:44:50 2006 |
| MD5 Checksum: | f4a921792724776d163ae2825bb36e26 |
|
| /// File Name: |
glsa-200609-20.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200609-20 - Input validation flaws have been discovered in the image handling of fetch.php if ImageMagick is used, which is not the default method. Versions less than 20060309e are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3557 | | Last Modified: | Oct 3 20:43:44 2006 |
| MD5 Checksum: | 380559f5965e8c5fa9096b3f80993b26 |
|
|
|
|
|