Slackware Essential And Critical Security Patch Updates - Page 75
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Upgraded ProFTPD packages are available for Slackware 8.1, 9.0 and-current. These fix a security issue where an attacker could gaina root shell by downloading a specially crafted file.
Upgraded WU-FTPD packages are available for Slackware 9.0 and-current. These fix a problem where an attacker could use aspecially crafted filename in conjunction with WU-FTPD'sconversion feature to execute arbitrary commands on the server.
There are multiple vulnerabilities in the sendmail package.
These packages fix additional buffer managementerrors that were not corrected in the recent 3.7p1 release.
These fix a buffer management error found in versions ofOpenSSH earlier than 3.7. The possibility exists that this errorcould allow a remote exploit, so we recommend all sites runningOpenSSH upgrade to the new OpenSSH package immediately.
Upgraded pine packages are available for Slackware 8.1, 9.0 and- -current.
These updates fix a previously hard-coded limit of 256connections-per-minute, after which the given service is disabledfor ten minutes.
These fix a security issue where a specially crafted archive mayoverwrite files (including system files anywhere on the filesystem)upon extraction by a user with sufficient permissions.
This fixes a bug where a local user may read any system file by making a symlink to it from $HOME/.xsession-errors and using GDM's error browser to read the file.
Note that this update addresses a security problem in Konqueror which may cause authentication credentials to be leaked to an unintended website through the HTTP-referer header when they have been entered into Konqueror as a URL
There is an off-by-one overflow in xlog() in the nfs-utils package.
This fixes an off-by-one buffer overflow in xlog.c which could be used by an attacker to produce a denial of NFS service, or to execute arbitrary code.
These provide an improved version of theptrace fix that had been applied to 2.4.20 in Slackware 9.0, andfix a potential denial of service problem with netfilter.
Upgraded CUPS packages are available for Slackware 8.1, 9.0, and -current to fix a denial of service attack vulnerability.
An upgraded sysvinit package is available which fixes a problem with the use of quotacheck in /etc/rc.d/rc.M.
An upgraded sysvinit package is available which fixes a problem with the use of quotacheck in /etc/rc.d/rc.M.
This version provides RSA blinding by default which prevents an extended timing analysis from revealing details of the secret key to an attacker.
A key validation bug which results in all user IDs on a given key being treated with the validity of the most-valid user ID on that key has been fixed with the release of GnuPG 1.2.2.
An integer overflow in the xdrmem_getbytes() function found in the glibc library has been fixed.
New EPIC4 packages are available to fix security problems found by Timo Sirainen.