Debian: DLA-2345 Important: Kernel Memory Leak Vulnerability Notification
Updated screen packages are now available that fix a security vulnerability which may allow privilege escalation for local users.
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Find the information you need for your favorite open source distribution .
Updated screen packages are now available that fix a security vulnerability which may allow privilege escalation for local users.
A local user could exploit this vulnerability to gain "slocate" group privileges and then read the entire slocate database.
This update includes the latest stable release of Apache httpd 2.0,including a fix for the security issue CVE CAN-2003-0542, a bufferoverflow in the parsing of configuration files.
Paul Starzetz discovered a flaw in bounds checking in mremap() in the Linux kernel versions 2.4.23 and previous which may allow a local attacker to gain root privileges.
Both vulnerabilities will make the Ethereal application crash. The Q.931 vulnerability also affects Tethereal. It is not known if either vulnerability can be used to make Ethereal or Tethereal run arbitrary code.