SuSE Essential and Critical Security Patch Updates - Page 795
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
The Adobe Flash Player was updated to fix an unspecified vulnerability The Adobe Flash Player was updated to fix an unspecified vulnerability that allowed attackers to take control of the victim's system by that allowed attackers to take control of the victim's system by having the victim load a specially crafted SWF file, for instance embedded in a web page (CVE-2008-5499). 2) Solution or Work-A [More...]
The Mozilla Firefox browser was updated to version 3.0.5, fixing The Mozilla Firefox browser was updated to version 3.0.5, fixing various security issues and stability problems. various security issues and stability problems. The Mozilla Seamonkey browser was updated to version 1.1.14, also fixing various security issues and stability problems. The other Mozilla browsers and suites are still bein [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
The openwsman project provides an implementation of the Web Service The openwsman project provides an implementation of the Web Service Management specification. Management specification. The SuSE Security-Team has found two critical issues in the code: - two remote buffer overflows while decoding the HTTP basic authenticationheader (CVE-2008-2234) - a possible SSL session replay attack affectin [More...]
Postfix is a well known MTA. Postfix is a well known MTA. During a source code audit the SuSE Security-Team discovered a local During a source code audit the SuSE Security-Team discovered a local privilege escalation bug (CVE-2008-2936) as well as a mailbox ownership problem (CVE-2008-2937) in postfix. The first bug allowed local users to execute arbitrary commands as root while the second one al [More...]
To avoid flooding mailing lists with SUSE Security Announcements for minor To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Secu [More...]
The net-snmp daemon implements the "simple network management protocol". The net-snmp daemon implements the "simple network management protocol". The version 3 of SNMP as implemented in net-snmp uses the length of the The version 3 of SNMP as implemented in net-snmp uses the length of the HMAC in a packet to verify against a local HMAC for authentication. An attacker can therefore send a SNMPv3 pa [More...]
The bind daemon is responsible for resolving hostnames in IP addresses and The bind daemon is responsible for resolving hostnames in IP addresses and vice versa. vice versa. The new version of bind uses a random transaction-ID (TRXID) and a random UDP source-port for DNS queries to address DNS cache poisoning attacks possible because of the "birthday paradox" and an attack discovered by Dan Kamins [More...]
This update of OpenOffice fixes various critical security vulnerabilities This update of OpenOffice fixes various critical security vulnerabilities - heap-overflow when parsing PPT files (CVE-2008-0320) - heap-overflow when parsing PPT files (CVE-2008-0320) - various buffer-overflows while parsing QPRO files (CVE-2007-5745,CVE-2007-5747) (NLD9 not affected) - integer overflow while parsing EM [More...]
The krb5 package is the implementation of the Kerberos protocol suite The krb5 package is the implementation of the Kerberos protocol suite from MIT. from MIT. This update fixes three vulnerabilities, two of them are only possible if krb4 support is enabled: - CVE-2008-0062:null/dangling pointer (krb4) - CVE-2008-0063:operations on uninitialized buffer content, possible information leak (krb4)
Evolution is a personal information manager (PIM) and workgroup information Evolution is a personal information manager (PIM) and workgroup information management software. management software. The function emf_multipart_encrypted() that is used to process encrypted messages is vulnerable to format-string bugs. This bug can be abused by a remote attacker to execute arbitrary code by sending a cra [More...]
CUPS is the default printer system on SUSE Linux. CUPS is the default printer system on SUSE Linux. The current security update of cups fixes a double-free bug in the function process_browse_data() that can lead to a remote denial-of-service by crash- ing cupsd or possibly to a remote code execution (CVE-2008-0882). The bug can only be exploited if cupsd listens to 631/udp by crafted UDP Browse p [More...]
The X windows system is vulnerable to several kind of vulner- The X windows system is vulnerable to several kind of vulner- abilities that are caused due to insufficient input validation. abilities that are caused due to insufficient input validation. The bugs range from crashing the X server to executing arbitrary code with the privilges of the X server process. For a successful attack the oppo [More...]
The Samba suite is an open-source implementatin of the SMB protocol. The Samba suite is an open-source implementatin of the SMB protocol. This update of samba fixes a buffer overflow in function send_mailslot() This update of samba fixes a buffer overflow in function send_mailslot() that allows remote attackers to overwrite the stack with 0 (via memset(3)) by sending specially crafted SAMLOGON pac [More...]
The samba-suite is an open-source implementation of the SMB protocol. The samba-suite is an open-source implementation of the SMB protocol. CVE-2007-5398: Secunia Research has reported a bug in function reply_netbios_packet() that allowed remote attackers to execute arbitrary code by sending specially crafted WINS "Name Registration" requests followed by a WINS "Name Query" request packet.
Secunia Research reported three security bugs in xpdf. Secunia Research reported three security bugs in xpdf. The first problem occurs while indexing an array in DCTStream:: The first problem occurs while indexing an array in DCTStream:: readProgressiveDataUnit() and is tracked by CVE-2007-4352. Another method in the same class named reset() is vulnerable to an integer overflow which leads to an o [More...]