Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -7 articles for you...
172

Ubuntu: USN-717-3 Critical: Firefox Script Bypass and Cookie Access

Kojima Hajime discovered that Firefox did not properly handle an escaped nullcharacter. An attacker may be able to exploit this flaw to bypass scriptsanitization. (CVE-2008-5510). ==========================================================Ubuntu Security Notice USN-717-3 February 11, 2009 firefox vulnerabilities CVE-2008-5510, CVE-2009-0357 ========================================================== A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 6.06 LTS: firefox 1.5.dfsg+1.5.0.15~prepatch080614j-0ubuntu1 After a standard system upgrade you need to restart Firefox to effect the necessary changes. Details follow: Kojima Hajime discovered that Firefox did not properly handle an escaped null character. An attacker may be able to exploit this flaw to bypass script sanitization. (CVE-2008-5510) Wladimir Palant discovered that Firefox did not restrict access to cookies in HTTP response headers. If a user were tricked into opening a malicious web page, a remote attacker could view sensitive information. (CVE-2009-0357) Updated packages for Ubuntu 6.06 LTS: Source archives: Size/MD5: 184569 201540f2560ee07d0a7b30d367ce41bd Size/MD5: 1800 e8a6f2726dbc06dade12a0ebc19c7fae Size/MD5: 48454140 496d1a74f2a98e8983737a874a9db29f Architecture independent packages: Size/MD5: 53638 9a18c7067527411eababced232354e7c Size/MD5: 52746 fa9d687831d30b8f8ef39da07c7a1ff4 amd64 architecture (Athlon64, Opteron, EM64T Xeon): Size/MD5: 47675616 d3b427dc0d4db0eebb5f3147ce3d29bb Size/MD5: 3045278 1683527a70cdf674f7b711ad559db6b4 Size/MD5: 85802 d88ad731cdfc825cb1f88ad91d8fbe2d Size/MD5: 9522850 b6d18064354f4e733894ce40fe048be4 Size/MD5: 22811690343b0a500020dd643c049164ba9c93 Size/MD5: 165590 3c2be076fb6d9c61cb42d938a90b93d2 Size/MD5: 254734 4198117776b43f20ca6d70b554b81db7 Size/MD5: 826298 b88f70f60cb48caa96add58750e5b4bd Size/MD5: 218730 e76dcc4583433117dbd7b81a77a858f5 i386 architecture (x86 compatible Intel/AMD): Size/MD5: 44222898 8c37f41c90782d6f7a1bef130a33bebc Size/MD5: 3042728 4542d11b7a0d330ba036246b518b7348 Size/MD5: 78320 a09d5ac38d8656b09b02f61de4a3a848 Size/MD5: 8031042 89edcd5c182b752bd4a81d53bb4fcf9c Size/MD5: 226174 0837e3ee67b4f6cde742c775e037f458 Size/MD5: 150976 6405eb0e815c96e8627f2b4d136eff11 Size/MD5: 255144 0e40cab26f0632c3d8687def727799c5 Size/MD5: 716692 950b133f03721a6e850c39374211eed9 Size/MD5: 212318 32b6d850fe57e89ae8646adb606552df powerpc architecture (Apple Macintosh G3/G4/G5): Size/MD5: 49080148 8c660c35194a0d6ea0eaef04217fabee Size/MD5: 2858774 459ccaa976dadf0a084d79a749a1117e Size/MD5: 81422 ebce34e5fbdc9f9512eb52ff4722ae5b Size/MD5: 9112744 6b2cda45169a8a9bb7b13afd2698a304 Size/MD5: 222260 6aae274c9ced525cd99cc4995a893118 Size/MD5: 163044 390f958f20ee78f041342d934b67edcd Size/MD5: 247834 3a4363d4e6b72e79826f46013328d975 Size/MD5: 816088 69bf430f8f920576685682d684dd0159 Size/MD5: 215280 33d4ae48f71b7ac9c0b8a3ddaccbe9b9 sparc architecture (Sun SPARC/UltraSPARC): Size/MD5: 45627582 86289259deef3338488deff398981f8f Size/MD5: 2858786 b846d70d98da5c911c56175900f38561 Size/MD5: 79926 b001d774bd2f4eeba25abe99aaf806f1 Size/MD5: 8498570 191dac8aa9174eefd1a0bdfe212b453a Size/MD5: 222282 2dc8e2df944c5d49c4e7a409077eb3ff Size/MD5: 152948 68af6ea71c2386cff897d0862f2025ab Size/MD5: 247844 243fcbcde87e019f0e81748b9db25014 Size/MD5: 727550 dcb087f639cc1fe8be4fea51c4034d28 Size/MD5: 212730 d74dc227e12ba13b96cb586edefe1c90 . Ubuntu Security Notice USN-718-1 details significant vulnerabilities in Chromium and recommends comprehensive safeguards.. Firefox Vulnerabilities, Script Bypass, Cookie Access Issues, Ubuntu Update. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Feb 11, 2009 Critical Ubuntu
87

Debian GNU/Linux 2.1 Advisory: Mailman Cookie Access Severity Critical

We have become aware that the version mailman as supplied in Debian GNU/Linux 2.1 has a problem with verifying list administrators. The problem is that the cookie value generation used was predictable, so using forged authentication cookies it was possible to access the list administration webpages without knowing the proper password. . -----BEGIN PGP SIGNED MESSAGE----- We have become aware that the version mailman as supplied in Debian GNU/Linux 2.1 has a problem with verifying list administrators. The problem is that the cookie value generation used was predictable, so using forged authentication cookies it was possible to access the list administration webpages without knowing the proper password. More information about this vulnerability can be found at June/001128.html This has been fixed in version 1.0rc2-5. We recommend you upgrade your mailman package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink - -------------------------------- This version of Debian was released only for Intel, the Motorola 680x0, the alpha and the Sun sparc architecture. Source archives: source/mailman_1.0rc2-5.diff.gz MD5 checksum: 096d96ebf89341b148d2ae917037559a source/mailman_1.0rc2-5.dsc MD5 checksum: a407c72b6d80163b04ddc5fb895b8fbd es/binary-source/mailman_1.0rc2.orig.tar.gz MD5 checksum: 6916959db9144ecaf004fcd9be32a020 Alpha architecture: alpha/mailman_1.0rc2-5_alpha.deb MD5 checksum: 0f053b62d9dd51d4e2c0843258eee453 Intel ia32 architecture: i386/mailman_1.0rc2-5_i386.deb MD5 checksum: d9b0f93458a41055ba1b39891e0a5ca5 Motorola 680x0 architecture: m68k/mailman_1.0rc2-5_m68k.deb MD5 checksum: 94fc7996e4b296a4c944fe08ccb44503 Sun Sparc architecture: sparc/mailman_1.0rc2-5_sparc.deb MD5 checksum: e27d100b24d0c87c02cc86b7aadded0d These files will be copied into soon. Please note you canalso use apt to always get the latest security updates. To do so add the following line to /etc/apt/sources.list: deb Debian -- Security Information stable updates - -- Debian GNU/Linux . Security Managers . This email address is being protected from spambots. You need JavaScript enabled to view it. This email address is being protected from spambots. You need JavaScript enabled to view it. Christian Hudon . Wichert Akkerman . Martin Schulze . . -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQB1AwUBN3Av9KjZR/ntlUftAQFFjwL/VwNslEzha3yT4k3wwDSedm0XEiHIUCS1 +ngWFIrPnLzfJ/jK2atXAZc98wwFxjxOTDWnGuc4RBjRi4NqBduQsVwaIHelSbK2 u9uPiNvzUhPiCUdzDusjy8ysUmzJIHd8 =PgQB -----END PGP SIGNATURE----- . Mail server in Debian GNU/Linux 2.1 faces a cookie vulnerability permitting unauthorized entry. Security patch advised for protection.. Mailman Security, Debian Cookie Attack, List Administration Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Dec 13, 1999 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here