SuSE Linux Distribution - Page 608.5

Find the information you need for your favorite open source distribution .

SuSE: 2005-025: OpenOffice heap overflow problem Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This security update fixes a buffer overflow in OpenOffice_org This security update fixes a buffer overflow in OpenOffice_org Microsoft Word document reader which could allow a remote attacker Microsoft Word document reader which could allow a remote attacker sending a handcrafted .doc file to execute code as the user opening the document in OpenOffice.This is tracked by the Mitre CVE ID CAN [More...]

SuSE: 2005-024: cvs Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The Concurrent Versions System (CVS) offers tools which allow developers The Concurrent Versions System (CVS) offers tools which allow developers to share and maintain large software projects. to share and maintain large software projects. The current maintainer of CVS reported various problems within CVS such as a buffer overflow and memory access problems which have been fixed within the a [More...]

SuSE: 2005-022: various KDE security problems Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Several vulnerabilities have been identified and fixed in the KDE Several vulnerabilities have been identified and fixed in the KDE desktop environment. desktop environment. - A buffer overflow via specially crafted PCX pictures was fixed. This could lead to a remote attacker being able to execute code as the user opening or viewing a PCX images. This PCX image could

SuSE: 2005-021: kernel local privilege escalation Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This Linux kernel security update fixes a problem within the Bluetooth This Linux kernel security update fixes a problem within the Bluetooth kernel stack which can be used by a local attacker to gain root access or kernel stack which can be used by a local attacker to gain root access or crash the machine.To exploit this problem, the Bluetooth modules do not need to be loaded since they are [More...]

SuSE: 2005-020: ipsec-tools remote denial of service Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Racoon is a ISAKMP key management daemon used in IPsec setups. Racoon is a ISAKMP key management daemon used in IPsec setups. Sebastian Krahmer of the SUSE Security Team audited the daemon and found that it handles certain ISAKMP messages in a slightly wrong way, so that remote attackers can crash it via malformed ISAKMP packages.This update fixes this problem.

SuSE: 2005-019: MySQL vulnerabilities Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

MySQL is an Open Source database server, commonly used together with MySQL is an Open Source database server, commonly used together with web services provided by PHP scripts or similar. web services provided by PHP scripts or similar. This security update fixes a broken mysqlhotcopy script as well as several security related bugs:- CAN-2005-0709: MySQL allowed remote authenticated users wi [More...]

SuSE: 2005-017: ImageMagick problems Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update fixes several security issues in the ImageMagick program suite: This update fixes several security issues in the ImageMagick program suite: - A format string vulnerability was found in the display program which could lead to a remote attacker being to able to execute code as the user running display by providing handcrafted filenames of images. This is tracked by the Mitre CVE ID C [More...]

SuSE: 2005-016: multiple Mozilla Firefox vulnerabilities Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This security update for Mozilla Firefox fixes following problems: This security update for Mozilla Firefox fixes following problems: - CAN-2005-0231: "Fire tabbing" The javascript security manager usually prevents that a javascript: URL from one host is opened in a window displaying content from another host. But when the link is dropped to a tab, the security manager does not kick in.

SuSE: 2005-015: openslp Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The SUSE Security Team reviewed critical parts of the OpenSLP package, The SUSE Security Team reviewed critical parts of the OpenSLP package, an open source implementation of the Service Location Protocol (SLP). an open source implementation of the Service Location Protocol (SLP). SLP is used by Desktops to locate certain services such as printers and by servers to announce their services. [More...]

SuSE: 2005-014: RealPlayer remote buffer overflow Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Two security problems were found in the media player RealPlayer: Two security problems were found in the media player RealPlayer: - CAN-2005-0455: A buffer overflow in the handling of .smil files. - CAN-2005-0611: A buffer overflow in the handling of .wav files. Both buffer overflows can be exploited remotely by providing URLs opened by RealPlayer.

SuSE: 2005-012: uw-imap authentication bypass Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The University of Washington imap daemon can be used to access mails The University of Washington imap daemon can be used to access mails remotely using the IMAP protocol. remotely using the IMAP protocol. This update fixes a logical error in the challenge response authentication mechanism CRAM-MD5 used by UW IMAP. Due to this mistake a remote attacker can gain access to the IMAP server as [More...]

SuSE: 2005-011: curl buffer overflow in NTLM authentication Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This email address is being protected from spambots. You need JavaScript enabled to view it. reported a vulnerability in libcurl, the This email address is being protected from spambots. You need JavaScript enabled to view it. reported a vulnerability in libcurl, the HTTP/FTP retrieval library. This library is used by lots of programs, HTTP/FTP retrieval library. This library is used by lots of programs, including YaST2 and PHP4.The NTLM authorization in curl had a buffer overflow in the base64 decoding which allows a remote a [More...]

SuSE: 2005-010: kernel / nvidia bugfix update Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

The previous kernel security update for the SUSE Linux 9.1 The previous kernel security update for the SUSE Linux 9.1 and the SUSE Linux Enterprise Server 9 based products caused and the SUSE Linux Enterprise Server 9 based products caused problems with the NVidia driver for users with NVidia graphics cards. Stricter checking in the memory management functions in the kernel caused the kerne [More...]

SuSE: 2005-009: cyrus-imapd buffer overflows Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

This update fixes one-byte buffer overruns in the cyrus-imapd IMAP This update fixes one-byte buffer overruns in the cyrus-imapd IMAP server package. server package. Several overruns were fixed in the IMAP annote extension as well as in cached header handling which can be run by an authenticated user.Additionally bounds checking in fetchnews was improved to avoid

SuSE: 2005-006: mailman remote file disclosure Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Mailman is a flexible mailing list management tool. It provides Mailman is a flexible mailing list management tool. It provides mail controlled subscription front ends and also includes CGI scripts mail controlled subscription front ends and also includes CGI scripts to handle subscription, moderation and archive retrieval and other options.Due to incomplete input validation the "private" CG [More...]

SuSE: 2005-006: squid Security Update

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Squid is a feature-rich web-proxy with support for various web-related Squid is a feature-rich web-proxy with support for various web-related protocols. protocols. The last two squid updates from February the 1st and 10th fix several vulnerabilities. The impact of them range from remote denial-of-service over cache poisoning to possible remote command execution. Due to the hugh amount of b [More...]