Section: .. / 0603-advisories /
| /// File Name: |
USN-263-1.txt |
Description:
|
Ubuntu Security Notice USN-263-1 - linux-source-2.6.8.1/-2.6.10/-2.6.12 vulnerabilities
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 97263 | | Last Modified: | Mar 13 22:13:11 2006 |
| MD5 Checksum: | a35e47f4bd15d03df463dc2fb74284b7 |
|
| /// File Name: |
sa19220.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and gain knowledge of potentially sensitive information.
| | Homepage: | http://secunia.com/advisories/19220/ | | File Size: | 88079 | | Last Modified: | Mar 13 21:05:36 2006 |
| MD5 Checksum: | fc66f8ce82c5b4158fa2142e1bfaeb67 |
|
| /// File Name: |
USN-260-1.txt |
Description:
|
Ubuntu Security Notice USN-260-1 - Chris Moore discovered a buffer overflow in a particular class of lexicographical scanners generated by flex. This could be exploited to execute arbitrary code by processing specially crafted user-defined input to an application that uses a flex scanner for parsing.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 62319 | | Last Modified: | Mar 8 05:57:15 2006 |
| MD5 Checksum: | 909c248cde3f1a763d9dd0aa98442a3a |
|
| /// File Name: |
sa19374.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for kernel-source-2.6.8. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose potentially sensitive information, cause a DoS (Denial of Service), gain escalated privileges, and bypass certain security restrictions, or by malicious people to cause a DoS, bypass certain security restrictions, and disclose certain sensitive information.
| | Homepage: | http://secunia.com/advisories/19374/ | | File Size: | 59289 | | Last Modified: | Mar 27 02:53:51 2006 |
| MD5 Checksum: | fdb036706c6310ae036629da1486a36a |
|
| /// File Name: |
sa19126.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for flex / gpc. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19126/ | | File Size: | 57667 | | Last Modified: | Mar 8 05:17:23 2006 |
| MD5 Checksum: | d21cec76f90d83df6f6e284cc38687a0 |
|
| /// File Name: |
dsa-1008-1.txt |
Description:
|
Debian Security Advisory DSA 1008-1 - Marcelo Ricardo Leitner noticed that the current patch in DSA 932 (CVE-2005-3627) for kpdf, the PDF viewer for KDE, does not fix all buffer overflows, still allowing an attacker to execute arbitrary code.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 46364 | | Last Modified: | Mar 21 22:45:26 2006 |
| MD5 Checksum: | 0981a3d6e4b059d40efc719732870855 |
|
| /// File Name: |
dsa-1004-1.txt |
Description:
|
Debian Security Advisory DSA 1004-1 - Simon Kilvington discovered that specially crafted PNG images can trigger a heap overflow in libavcodec, the multimedia library of ffmpeg, which may lead to the execution of arbitrary code. The vlc media player links statically against libavcodec.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 43913 | | Last Modified: | Mar 17 01:18:42 2006 |
| MD5 Checksum: | 0d3b0cc434959f68c8db09bf943d99f0 |
|
| /// File Name: |
sa19369.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for kernel-source-2.4.27. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information, cause a DoS (Denial of Service), and gain escalated privileges, or by malicious people to cause a DoS and bypass certain security restrictions.
| | Homepage: | http://secunia.com/advisories/19369/ | | File Size: | 42511 | | Last Modified: | Mar 27 02:53:51 2006 |
| MD5 Checksum: | 10509ac4a22ae1cee2fb9b0d65dbba1a |
|
| /// File Name: |
sa19264.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for kdegraphics. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19264/ | | File Size: | 42459 | | Last Modified: | Mar 20 22:27:23 2006 |
| MD5 Checksum: | 5d9f8f060ba4a46755d4a2877e613a64 |
|
| /// File Name: |
sa19272.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for vlc. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially to compromise a user's system.
| | Homepage: | http://secunia.com/advisories/19272/ | | File Size: | 39886 | | Last Modified: | Mar 18 22:11:21 2006 |
| MD5 Checksum: | a871ae156eaa1f0b8ef76054e88a22fb |
|
| /// File Name: |
USN-258-1.txt |
Description:
|
Ubuntu Security Notice USN-258-1 - Akio Ishida discovered that the SET SESSION AUTHORIZATION command did not properly verify the validity of its argument. An authenticated PostgreSQL user could exploit this to crash the server.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 23444 | | Related CVE(s): | CVE-2006-0678 | | Last Modified: | Mar 2 10:36:00 2006 |
| MD5 Checksum: | 290b89e80b530357f66ece8ddf771e99 |
|
| /// File Name: |
sa19364.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for koffice. This fixes some potential vulnerabilities with unknown impacts.
| | Homepage: | http://secunia.com/advisories/19364/ | | File Size: | 22561 | | Last Modified: | Mar 27 02:53:51 2006 |
| MD5 Checksum: | 74ba96d9aac1f2f7562f73628ba346ab |
|
| /// File Name: |
FLSA-2006-168264-1.txt |
Description:
|
Fedora Legacy Update Advisory - An integer overflow flaw was found in libXpm, which is used by some applications for loading of XPM images. An attacker could create a malicious XPM file that would execute arbitrary code if opened by a victim using an application linked to the vulnerable library.
| | Homepage: | http://www.fedoralegacy.org | | File Size: | 22324 | | Last Modified: | Mar 9 04:20:47 2006 |
| MD5 Checksum: | 5c40212a963b3ea170edee02ddf09944 |
|
| /// File Name: |
sa19035.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for PostgreSQL. This fixes a vulnerability, which can be exploited by malicious users to cause a DoS (Denial of Service).
| | Homepage: | http://secunia.com/advisories/19035/ | | File Size: | 22114 | | Last Modified: | Mar 1 04:50:51 2006 |
| MD5 Checksum: | abaf8928d6841126786957051b59c11d |
|
| /// File Name: |
USN-261-1.txt |
Description:
|
Ubuntu Security Notice USN-261-1 - Stefan Esser discovered that the 'session' module did not sufficiently verify the validity of the user-supplied session ID. A remote attacker could exploit this to insert arbitrary HTTP headers into the response sent by the PHP application, which could lead to HTTP response splitting and cross site scripting attacks. PHP applications were also vulnerable to several cross site scripting flaws if the options 'display_errors' and 'html_errors' were enabled. Please note that enabling 'html_errors' is not recommended for production systems.
| | Homepage: | http://security.ubuntu.com/ | | File Size: | 21790 | | Related CVE(s): | CVE-2006-0207, CVE-2006-0208 | | Last Modified: | Mar 11 03:42:03 2006 |
| MD5 Checksum: | 69e663453fec962a2c52f862b7c8d388 |
|
| /// File Name: |
sa19179.txt |
Description:
|
Secunia Security Advisory - Ubuntu has issued an update for php. This fixes some vulnerabilities, which can be exploited by malicious people to conduct HTTP response splitting attacks and potentially conduct cross-site scripting attacks.
| | Homepage: | http://secunia.com/advisories/19179/ | | File Size: | 20211 | | Last Modified: | Mar 11 03:24:56 2006 |
| MD5 Checksum: | 8c0131c4b53d2ad45045d0f2db0b4d9c |
|
| /// File Name: |
dsa-1021-1.txt |
Description:
|
Debian Security Advisory DSA 1021-1 - Max Vozeler from the Debian Audit Project discovered that pstopnm, a converter from Postscript to the PBM, PGM and PNM formats, launches Ghostscript in an insecure manner, which might lead to the execution of arbitrary shell commands, when converting specially crafted Postscript files.
| | Author: | Moritz Muehlenhoff | | Homepage: | http://www.debian.org/security/ | | File Size: | 19272 | | Related CVE(s): | CVE-2005-2471 | | Last Modified: | Apr 1 08:35:53 2006 |
| MD5 Checksum: | 1c459b8d6e7ffc433c0876f5220f365e |
|
| /// File Name: |
dsa-919-2.txt |
Description:
|
Debian Security Advisory DSA 919-2 - The upstream developer of curl, a multi-protocol file transfer library, informed us that the former correction to several off-by-one errors are not sufficient.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 18874 | | Related CVE(s): | CVE-2005-4077 | | Last Modified: | Mar 11 03:33:46 2006 |
| MD5 Checksum: | 8fcbffc66948f4672e97ed57bee2c327 |
|
| /// File Name: |
sendmail0058.txt |
Description:
|
Sendmail, Inc. has recently become aware of a security vulnerability in certain versions of sendmail Mail Transfer Agent (MTA) and UNIX and Linux products that contain it. Sendmail was notified by security researchers at ISS that, under some specific timing conditions, this vulnerability may permit a specifically crafted attack to take over the sendmail MTA process, allowing remote attackers to execute commands and run arbitrary programs on the system running the MTA, affecting email delivery, or tampering with other programs and data on this system. Versions 8.13.5 and below are affected.
| | Homepage: | http://www.sendmail.com | | File Size: | 17462 | | Related CVE(s): | CVE-2006-0058 | | Last Modified: | Mar 28 07:38:55 2006 |
| MD5 Checksum: | 16374816bcdc48726dfca23914a5b38b |
|
| /// File Name: |
sa19436.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for netpbm-free. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/19436/ | | File Size: | 17359 | | Last Modified: | Mar 31 09:50:26 2006 |
| MD5 Checksum: | 1375d3dbfe1ac09971baac4f63fe1bd8 |
|
| /// File Name: |
sa19367.txt |
Description:
|
Secunia Security Advisory - Debian has issued an update for sendmail. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system.
| | Homepage: | http://secunia.com/advisories/19367/ | | File Size: | 16429 | | Last Modified: | Mar 23 21:22:03 2006 |
| MD5 Checksum: | 7e50d29c1ab0ba7b0085e68dfd3b863d |
|
| /// File Name: |
MDKSA-2006-054.txt |
Description:
|
Mandriva Linux Security Advisory - Marcelo Ricardo Leitner discovered the official published kpdf patches for several previous xpdf vulnerabilities were lacking some hunks published by upstream xpdf. As a result, kpdf is still vulnerable to certain carefully crafted pdf files.
| | Homepage: | http://www.mandriva.com/security/ | | File Size: | 15262 | | Last Modified: | Mar 9 04:31:38 2006 |
| MD5 Checksum: | 7efd0562495f24e96fc836267df24ac3 |
|
| /// File Name: |
SUSE-SA-2006-015.txt |
Description:
|
SUSE Security Announcement - SUSE-SA:2006:015 - A critical security vulnerability has been identified in the Adobe Macromedia Flash Player that allows an attacker who successfully exploits these vulnerabilities to take control of the application running the flash player.
| | Homepage: | http://www.suse.com | | File Size: | 13587 | | Last Modified: | Mar 21 23:19:07 2006 |
| MD5 Checksum: | 60418e77d7a8b6eb204fee235c10b784 |
|
| /// File Name: |
dsa-1006-1.txt |
Description:
|
Debian Security Advisory DSA 1006-1 - "kcope" discovered that the wzdftpd FTP server lacks input sanitising for the SITE command, which may lead to the execution of arbitrary shell commands.
| | Author: | Martin Schulze | | Homepage: | http://www.debian.org/security/ | | File Size: | 12991 | | Last Modified: | Mar 21 22:44:11 2006 |
| MD5 Checksum: | 3bdfb10502cb28476e9df81a709123c7 |
|
| /// File Name: |
nCipher13.txt |
Description:
|
nCipher Security Advisory No. 13 - Application programmers using the nCore API to calculate and verify CBC MACs may have accidentally implemented a MAC protocol which fails to detect certain modifications to messages it is supposed to protect.
| | Homepage: | http://www.ncipher.com/ | | File Size: | 12727 | | Last Modified: | Mar 10 01:20:39 2006 |
| MD5 Checksum: | 0aa4ad3331d28e689d50b2109f68a692 |
|
|
|
|
|