Linux Advisory 404![]() Linux Advisory 404Linux Advisory Watch outlines the
This week, advisories were released for mailman, kde, MySQL, mc, Apache,
Incident Response
One of the most overlooked aspects of information security is incident
In preparation for a security incident, it is important to establish a
Administrators should also take appropriate steps to ensure event
Upon detection of an incident, it is important to have containment
After an incident has commenced, the next step is system restoration. It
---- Guardian Digital Security Solutions Win Out At Real World Linux Enterprise Email and Small Business Solutions Impres at Linux Exposition. Internet and network security was a consistent theme and Guardian Digital was on hand with innovative solutions to the most common security issues. Attending to the growing concern for cost-effective security, Guardian Digital's enterprise and small business applications were stand-out successes. Interview with Siem Korteweg: System Configuration Collector In this interview we learn how the System Configuration Collector (SCC) project began, how the software works, why Siem chose to make it open source, and information on future developments. Distribution: Conectiva mailman Multiple vulnerabilities Fixes cross site scripting and remote password retrieval vulnerabilities, plus a denial of service. - kde Insufficient input sanitation The telnet, rlogin, ssh and mailto URI handlers in KDE do not check for '-' at the beginning of the hostname passed. Distribution: FreeBSD core:sys Buffer cache invalidation vulnerability Insufficient input sanitation In some situations, a user with read access to a file may be able to prevent changes to that file from being committed to disk. Distribution: Gentoo MySQL Symlink vulnerability Two MySQL utilities create temporary files with hardcoded paths, allowing an attacker to use a symlink to trick MySQL into overwriting important data. mc Multiple vulnerabilities Multiple security issues have been discovered in Midnight Commander including several buffer overflows and string format vulnerabilities. Apache 1.3 Multiple vulnerabilities Several security vulnerabilites have been fixed in the latest release of Apache 1.3. Heimdal Buffer overflow vulnerability A possible buffer overflow in the Kerberos 4 component of Heimdal has been discovered. Distribution: Mandrake mailman Password leak vulnerability Mailman versions >= 2.1 have an issue where 3rd parties can retrieve member passwords from the server. kolab-server Plain text passwords Password leak vulnerability The affected versions store OpenLDAP passwords in plain text. Distribution: Red Hat utempter Symlink vulnerability An updated utempter package that fixes a potential symlink vulnerability is now available. LHA Multiple vulnerabilities Ulf Harnhammar discovered two stack buffer overflows and two directory traversal flaws in LHA. tcpdump,libpcap,arpwatch Denial of service vulnerability Multiple vulnerabilities Upon receiving specially crafted ISAKMP packets, TCPDUMP would crash. Distribution: SuSE kdelibs/kdelibs3 Insufficient input sanitation Multiple vulnerabilities The URI handler of the kdelibs3 and kdelibs class library contains a flaw which allows remote attackers to create arbitrary files as the user utilizing the kdelibs3/kdelibs package.
|
|
Best of the Web 1 | Best of the Web 2 | Best of the Web 3 | Best of the Web 4
Worlds Largest Network
Active © 2006; WorldsLargestNetwork.com ; Rights Reserved