January 16th Linux Advisory Watch![]() January Linux Advisory Watch
Linux Advisory Watch is a comprehensive newsletter that outlines the
This week, advisories were released for phpgroupware, kernel, jitterbug,
Implementing any large security project on the Linux operating system
The first several chapters of the book focus on the basics. It gives an
For the long time manager, this book may be slightly on the technical
Hard-copies of the book can also be purchased through Amazon or any other
When any company decides to take on a in-house software development
Managing Linux Security Effectively in 2004 This article examines the process of proper Linux security management in 2004. First, a system should be hardened and patched. Next, a security routine should be established to ensure that all new vulnerabilities are addressed. Linux security should be treated as an evolving process. -------------------------------------------------------------------- CONCERNED ABOUT THE NEXT THREAT? EnGarde is the undisputed winner! Hardened Linux Puts Hackers EnGarde! Winner of the Network Computing Editor's Choice Award, EnGarde "walked away with our Editor's Choice award thanks to the depth of its security strategy..." Find out what the other Linux vendors are not telling you. -------------------------------------------------------------------- FEATURE: OSVDB: An Independent and Open Source Vulnerability Database This article outlines the origins, purpose, and future of the Open Source Vulnerability Database project. Distribution: Debian phpgroupware Multiple vulnerabilities Improper remote execution and SQL code injection issues. kernel Priv. Escal. additional patches Since DSA 417-1 lacked fixed kernel image files for the alpha architecture these are added now. jitterbug Improper input sanatizing Allows an attacker to execute arbitary commands on server hosting bug database. mod-auth-shadow Account expiration not enforced Improper input sanatizing In this Apache module, expiration status of the user's account and password were not enforced. cvs Multiple vulnerabilities Anyone who could modify the CVSROOT/passwd could gain access to all local users on the CVS server, including root. kernel-image-2.4.17-ia64 Many backported vuln fixes Multiple vulnerabilities The IA-64 maintainers fixed several security related bugs in the Linux kernel 2.4.17 used for the IA-64 architecture, mostly by backporting fixes from 2.4.18. Distribution: Gentoo kernel Privilege escalation vulnerability A critical security vulnerability has been found in recent Linux kernels which allows for local privilege escalation. Distribution: Mandrake ethereal Multiple DoS vulernabilities Two vulnerabilities can be exploited to make Ethereal crash. kdepim Permission leak vulnerability This vulnerability allows for a carefully crafted .VCF file to enable a local attacker to execute arbitrary commands with the victim's privileges. Distribution: Red Hat cvs Chroot breakout vulnerability cvs can attempt to create files and directories in the root file system kdepim Buffer overflow vulnerability Updated kdepim packages are now available that fix a local buffer overflow vulnerability. tcpdump Denial of service vulnerability Crafted remote packets can result in a denial of service, or possibly execute arbitrary code as the 'pcap' user. Distribution: Slackware kernel Priv. Escal. patch for 8.1 There is a bounds-checking problem in the kernel's mremap() call which could be used by a local attacker to gain root privileges. INN Buffer overflow vulnerability Upgrade to inn-2.4.1 to fix a potentially exploitable buffer overflow. kdepim Permission leak vulnerability A carefully crafted .VCF file enables local attackers to execute arbitrary commands with the victim's privileges. Distribution: Suse tcpdump Denial of service vulnerability There is a remote DoS condition in tcpdumps ISAKMP handling. kernel Many vulnerabilities fixed for 64bit Fixes vulnerabilities that can be used to gain root privilages. Distribution: Trustix tcpdump Denial of Service vulnerability A problem in tcpdump was discovered, where it was possible to crash the program by sending carefully crafted packets on the network.
|
|
Best of the Web 1 | Best of the Web 2 | Best of the Web 3 | Best of the Web 4
Worlds Largest Network
Active © 2006; WorldsLargestNetwork.com ; Rights Reserved