Fedora: 2003-004 Critical Update: Apache Buffer Overflow Threat
This update includes the latest stable release of Apache httpd 2.0,including a fix for the security issue CVE CAN-2003-0542, a bufferoverflow in the parsing of configuration files.
Find the information you need for your favorite open source distribution .
This update includes the latest stable release of Apache httpd 2.0,including a fix for the security issue CVE CAN-2003-0542, a bufferoverflow in the parsing of configuration files.
Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux kernel versions 2.4.23 and previous which may allow a local attacker to gain root privileges.
Both vulnerabilities will make the Ethereal application crash. The Q.931 vulnerability also affects Tethereal. It is not known if either vulnerability can be used to make Ethereal or Tethereal run arbitrary code.
An attacker could create a carefully crafted directory on a websitesuch that, if a user connects to that directory using the lftp clientand subsequently issues a 'ls' or 'rels' command, the attacker couldexecute arbitrary code on the users machine.
Phong Nguyen identified a severe bug in the way GnuPG creates anduses ElGamal keys, when those keys are used both to sign and encryptdata. This vulnerability can be used to trivially recover theprivate key.