Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -2 articles for you...
87

Debian: DSA 777-1 Critical: Mozilla Frame Injection Attack Fix

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 777-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze August 17th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mozilla Vulnerability : frame injection spoofing Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0718 CAN-2005-1937 BugTraq ID : 14242 A vulnerability has been discovered in Mozilla and Mozilla Firefox that allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site. Thunderbird is not affected by this and Galeon will be automatically fixed as it uses Mozilla components. For the stable distribution (sarge) this problem has been fixed in version 1.7.8-1sarge1. For the unstable distribution (sid) this problem has been fixed in version 1.7.10-1. We recommend that you upgrade your Mozilla package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 1123 7ab0311756a0de3407f84b923b053533 Size/MD5 checksum: 307355 2012677529e86d28c0e5a24294903ad3 Size/MD5 checksum: 30589520 13c0f0331617748426679e8f2e9f537a Alpha architecture: Size/MD5 checksum: 168066 fe5db18b73d89c677c4b4a3635793b83 Size/MD5 checksum: 1405429a988dc0e6fc3901bf16cff43bd55d13 Size/MD5 checksum: 184952 3495f9cbbb3f6f7fd9198b98fc1c25f2 Size/MD5 checksum: 850120 58e878f30f82b120f332c22f974c9330 Size/MD5 checksum: 1032 b32e47e0f786e4ee3896b76a53499a42 Size/MD5 checksum: 11462324 c1b82022b4eaa7d133e6cbe86868e57f Size/MD5 checksum: 403296 421577f02c3b6b88615f4339bd18d0c3 Size/MD5 checksum: 158346 059e84b66aa680681923deed7ba66b7e Size/MD5 checksum: 3355028 dc43b577acdc4c40c089567b53e1cd0e Size/MD5 checksum: 122306 6d4aba83fd04bc34a36dd13a6dcd04fb Size/MD5 checksum: 204150 e2db0c815caeb3c9fef57cb1a4812591 Size/MD5 checksum: 1936702 f24ebcb7ecbdf953992ad297903bff51 Size/MD5 checksum: 212302 d78b38041bc90a6ca78c1f8e57e3e3b3 AMD64 architecture: Size/MD5 checksum: 168056 01fe31ac723a4a82c3c5d7c8f32df92c Size/MD5 checksum: 139664 a2a501b2435eea376234a9530125f56e Size/MD5 checksum: 184944 664061d174dde41a9a640cddf67ca506 Size/MD5 checksum: 708484 2d5e7ecc4753425b70863b9e046c6000 Size/MD5 checksum: 1030 ffceb9ef440f5ae3477db3f7084db101 Size/MD5 checksum: 10937902 cf64fa09458651e25086046db6673e62 Size/MD5 checksum: 403284 41319f34441400e2c520bcbdeda64cc2 Size/MD5 checksum: 158338 40ed63c199d675695f008ef754432935 Size/MD5 checksum: 3345598 99b00e6c50d91a2dae53a44d50faff60 Size/MD5 checksum: 121176 de6eb44c40cfc9bc183827d199381a96 Size/MD5 checksum: 204152 be4c266252b3377f94b2f198f880d457 Size/MD5 checksum: 1935806 5f32496d2cfadfbc1b9c2e6c02fd6c73 Size/MD5 checksum: 204116 98cdcfed83d173f8197c0d23d298be99 ARM architecture: Size/MD5 checksum: 168072 6f5a448752b8e6ba6325a8ff2a2df67c Size/MD5 checksum: 118050 9bb76ef7f7770fe15a8bfc3ea897deea Size/MD5 checksum: 184954 2e46576a7d6d998551325d8eb2f0c74d Size/MD5 checksum: 625708 12f00280e96540ff0abe74c105546cd4 Size/MD5 checksum: 1034 fa3c6e72a47795e1ef413bdd38826d33 Size/MD5 checksum: 9194340 61b44bd9352c9e2bc38ee840220df3e1 Size/MD5 checksum: 403308 da3d8b0e79299e44654d7a1a08e961bc Size/MD5 checksum: 158338 11d61ce4adfec687b96ec6fee88776d3 Size/MD5 checksum: 3338606 cb07fb3f9ace01d8da22ded6cd86ff2e Size/MD5 checksum: 112664 e0d808afb09214b47493e4a0cab432c1 Size/MD5 checksum: 204150 90d5b95d8ec5f3818e99f5fc7cfa16f6 Size/MD5 checksum: 1604236 4b9b9e5e9bedd501bfee53963681fb07 Size/MD5 checksum: 168716 1b0ff67888379dc8a87b8983af97b0d3 Intel IA-32 architecture: Size/MD5 checksum: 168074 da8497a0b770f1c41d4195fc6356b461 Size/MD5 checksum: 130372 98fd23761563d3942df4473c3243d978 Size/MD5 checksum: 184956 d0b65b504cf226c8cb1578ce6bea7422 Size/MD5 checksum: 654240 9d25a31d785f3785f1444bb6df5c97ae Size/MD5 checksum: 1030 c11512ac6c0aa2d70acf5c563a829554 Size/MD5 checksum: 10287026 ffdc113a91821c82b1d6ef7c6c920bef Size/MD5 checksum: 403286 4b059c14da633f42716aba12bd9a0cca Size/MD5 checksum: 158342 3aa7215f4cb1261589ab13304f44c117 Size/MD5 checksum: 3344356 e7a20515ccc6db34c74f3e7f51f8fffb Size/MD5 checksum: 116216 630b0ecb082b2d33a27019f87f4bfadf Size/MD5 checksum: 204162 41ba78c68277097f602c5195e04ec2a9 Size/MD5 checksum: 1811096 f061f50b17ea899da27c1fba26430a47 Size/MD5 checksum: 192308 908067740b8466440ed33e8910a99db2 Intel IA-64 architecture: Size/MD5 checksum: 168048 74baf8eb1a9cfa0584deeaa742435903 Size/MD5 checksum: 168052 27e30141c62b2e7f9aa2976d25883fde Size/MD5 checksum: 184918 f2d4b2a556c70df07761df3fc9e20495 Size/MD5 checksum: 960434 0172fe253a8741fdf77c4d5c6110f3fb Size/MD5 checksum: 1030e7df4da73c1fbb7bbb5ff453e3ed4250 Size/MD5 checksum: 12927484 7391b9e306b8f8fcb2d909274dc1e802 Size/MD5 checksum: 403272 e2b4f122371aef71fdae48f8da45b2fa Size/MD5 checksum: 158328 48fcceb9b1cb0767ad0fe789e4fa543f Size/MD5 checksum: 3374932 85908c1696361658be81ac9af571e0ae Size/MD5 checksum: 125578 26db6256c5e0328ff1341b5121d13fb7 Size/MD5 checksum: 204148 0b867cbb015c00b21f6ed49e3c00767c Size/MD5 checksum: 2302092 3ec77e8430276623f3f4235362f4e8f3 Size/MD5 checksum: 242272 9e76da79c6dc43fa6f6fb9d617dbe962 HP Precision architecture: Size/MD5 checksum: 168072 1cd103a31607398fa9810da5aea71aa3 Size/MD5 checksum: 150580 261e527cdf20991dcd5bc0fcf344e805 Size/MD5 checksum: 184968 d9c926b9eb0ce435c6ad3d16336e0e81 Size/MD5 checksum: 748456 d4e0e10f05b1717555708a47f7223d8a Size/MD5 checksum: 1038 5ffc79a546a5b9ad82a3fa97252af202 Size/MD5 checksum: 12137588 9d4f5ce191df1141247b586438c293a1 Size/MD5 checksum: 403300 19068a8ae5292c9d312e804e4d21aa97 Size/MD5 checksum: 158350 d1bd336593b2d9d5f261868161be54ed Size/MD5 checksum: 3355510 6b687cb5de1639f24cd0f458becbd973 Size/MD5 checksum: 123520 60af4d62e1d671183b272180c73cc8f4 Size/MD5 checksum: 204172 2be0db85e67fa831e58f7b5069e97580 Size/MD5 checksum: 2135028 8d104012d6012b8c7b464df7e37be436 Size/MD5 checksum: 216076 2237121338e9463c79487783b0742550 Motorola 680x0 architecture: Size/MD5 checksum: 168096 b6d7a71599cd138c4f8b652edc5b77f5 Size/MD5 checksum: 119734 5daa5117559e40125335769f9b77d781 Size/MD5 checksum: 184990 3178f1e171276b061f52de177220a17b Size/MD5 checksum: 593776 fab971e41776faf370b7f5502725889d Size/MD5 checksum: 1042 03ecf1aacdce8b191f5cc9ab61c167d3 Size/MD5 checksum: 968820205b50d66d93d38f19b4cf4c1fb9471b6 Size/MD5 checksum: 403384 983c115d6e86953c69b4491189a4dc71 Size/MD5 checksum: 158408 ca47244e7172265550d11057c6583180 Size/MD5 checksum: 3334376 ca591499853bc4a6aac38af2e06bdcf6 Size/MD5 checksum: 114506 eb17bf839c6cf15ca17e648fd0ae4aac Size/MD5 checksum: 204244 99abf2db86319a701c290465c03eada8 Size/MD5 checksum: 1683068 caf8165b4af9eda6f06eed0e1e5238ed Size/MD5 checksum: 174664 448d057f3ea9a4e9487194cf2629c458 Big endian MIPS architecture: Size/MD5 checksum: 168076 f7729a4215e50a8f50fe7cf93a6a66e1 Size/MD5 checksum: 134522 fe661f9bf78605047b45792fa9f1fee6 Size/MD5 checksum: 184966 37704d27018222a9942b68910142d96a Size/MD5 checksum: 719572 3acfad01b9072fd8d168f75f08c30c00 Size/MD5 checksum: 1038 87ece36f816acb1a2feb5fa444e85c72 Size/MD5 checksum: 10709602 5f47457619a6ddc192ecba7685cbb6b0 Size/MD5 checksum: 403310 2127f4aefb131de0ae8187926ad04cc0 Size/MD5 checksum: 158356 46f5806667782b338b289b3a0e647e50 Size/MD5 checksum: 3354910 f34a776a4bb1603dda691a95552373c0 Size/MD5 checksum: 117648 f86273f726c99701aeb74ded63e02d91 Size/MD5 checksum: 204190 497eb918f11ccbe9594860c24d049ef4 Size/MD5 checksum: 1795442 6f76a2a57d4b776ce476a926af212144 Size/MD5 checksum: 189698 c4c33fa5be39a071da8a22253d7d8a2b Little endian MIPS architecture: Size/MD5 checksum: 168072 62b5021be4a2e817fd42f46ac4e02d35 Size/MD5 checksum: 134470 48f5936b5ed61a62074f845c4e4a9cf3 Size/MD5 checksum: 184956 9f2781aa77e45c66d5434e26c835f323 Size/MD5 checksum: 708974 7f86eb1313701fc9c4a9a2979bd8bbbd Size/MD5 checksum: 1038 5808a4427ee7f6d3867423c56d97fe85 Size/MD5 checksum: 10588162 8e0c2ca16c7ddcd4aa01f990c70e8be0 Size/MD5 checksum: 403290abdbfea11bdf5081d8642227c9f8525b Size/MD5 checksum: 158338 20bc1bf6b3d8683389d908414c68e5fe Size/MD5 checksum: 3355498 42dfc73ec31618b3d5ec9aa6cf79e23b Size/MD5 checksum: 117200 f9da71080daffca5e262707ae0966408 Size/MD5 checksum: 204158 0a98168eeb8905144787ff501075c758 Size/MD5 checksum: 1777510 604445ed5644ca786132b47811ade183 Size/MD5 checksum: 187284 c87359e6613f4cf36b141d6d480e8dfb PowerPC architecture: Size/MD5 checksum: 168072 961c3fe8ab2994b5f6e0eb8972a83465 Size/MD5 checksum: 125072 80e453c80c1c9dcb0e391ae6526ffce7 Size/MD5 checksum: 184962 a12c81b696a0acbbe3bfeb87b47a9944 Size/MD5 checksum: 712714 30699c25f8e63ed3b9143694ce05e3e5 Size/MD5 checksum: 1038 7b706a704c8ea502c3225434d804dc6b Size/MD5 checksum: 9683088 5094032aa6f3d64db4f39decdafb56d9 Size/MD5 checksum: 403310 c23889a4ad8098b4322c6dec6265a307 Size/MD5 checksum: 158364 007c2ad171f74862d6fb453dd6ac2a59 Size/MD5 checksum: 3337100 382f06390acf9bfc9eeba496a9ad4ade Size/MD5 checksum: 114600 033ee754e3e175a202c607c35bf29bde Size/MD5 checksum: 204172 61675534cef26849cb54342dbf7d8970 Size/MD5 checksum: 1642932 0306ae5ce3709dbaba40d18c2e40f6e3 Size/MD5 checksum: 175502 90778a628ed97d4cbc7c5400787eae18 IBM S/390 architecture: Size/MD5 checksum: 168076 d2afc2a24593ff088c0b585e0201c03f Size/MD5 checksum: 150370 5dc6e70c792a5646ba227af074fb57a0 Size/MD5 checksum: 184942 368f48efcbce533415ee83db8e3d2b89 Size/MD5 checksum: 792708 84972f8e21b0e08f0452d393d7eda49a Size/MD5 checksum: 1034 7540473b684567cfe839051f8182218e Size/MD5 checksum: 11309168 bac4aeea83a9b9233d4ff41c569fc7d7 Size/MD5 checksum: 403286 3c4eb8807c45f90d682f7781624bff0d Size/MD5 checksum: 158354 d658aa731fc85d28a6bee04ad8ec68a9 Size/MD5 checksum: 3349814 85275a8e4c217bf147324b3b4821a065 Size/MD5 checksum: 121354 ad4613cfb421ef11910da1e567ed8673 Size/MD5 checksum: 204158 afc733c58d35fa71c6fd1d3127e7b3da Size/MD5 checksum: 1944642 d5bc11e62553f1b4adb3b9bb344f354e Size/MD5 checksum: 213340 98c7a540b74238471ad54e2c49508b54 Sun Sparc architecture: Size/MD5 checksum: 168076 6428ec559f02195ff50f699d712d7d18 Size/MD5 checksum: 122230 9d47e07ab455ae0f1cf910174a10befc Size/MD5 checksum: 184942 913e521909494e81255818d68f37a5a1 Size/MD5 checksum: 666542 bf2b1a10ee1289f2357a2e5ed381c2db Size/MD5 checksum: 1034 7d9cf470bceff30a2d5dd50dd5ebf27a Size/MD5 checksum: 9356026 c4b85a65fff0b19534860b270ee8b48c Size/MD5 checksum: 403296 cc6c7adb31b6b7e9e4535e1c637b6983 Size/MD5 checksum: 158356 8b067ab9cf3a5092d61f2c2677e855cc Size/MD5 checksum: 3338322 425efb21651816eec8e850e7823839fe Size/MD5 checksum: 112524 075ae0b2561d1f29a6c4136419037394 Size/MD5 checksum: 204182 ec4696e83df611458ac53a3e2ece0d37 Size/MD5 checksum: 1583722 8761e0ad9c6d41e694f019b52e0c939a Size/MD5 checksum: 167906 cf862aa0ba44bbd443977d3345ce41ed These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian Security Advisory DSA 888-2 addressing a severe memory corruption vulnerability resolution for Apache software.. Mozilla Package Update, Debian Security Fix, Frame Injection Solution, Remote Exploit Guidance. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 17, 2005 Critical Debian
87

Debian DSA-775-1 Critical: Mozilla Frame Injection Spoofing

Updated package.. - --------------------------------------------------------------------------Debian Security Advisory DSA 775-1 This email address is being protected from spambots. You need JavaScript enabled to view it. http://www.debian.org/security/ Martin Schulze August 15th, 2005 http://www.debian.org/security/faq - --------------------------------------------------------------------------Package : mozilla Vulnerability : frame injection spoofing Problem-Type : remote Debian-specific: no CVE ID : CAN-2004-0718 CAN-2005-1937 BugTraq ID : 14242 A vulnerability has been discovered in Mozilla and Mozilla Firefox that allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site. Thunderbird is not affected by this and Galeon will be automatically fixed as it uses Mozilla components. The old stable distribution (woody) does not contain Mozilla Firefox packages. For the stable distribution (sarge) this problem has been fixed in version 1.0.4-2sarge1. For the unstable distribution (sid) this problem has been fixed in version 1.0.6-1. We recommend that you upgrade your mozilla-firefox package. Upgrade Instructions - --------------------wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.1 alias sarge - -------------------------------- Source archives: Size/MD5 checksum: 1001 248d8f9e82f3cade699588f729b26aba Size/MD5 checksum: 227342 b5bff4a3262a6bd69dfb66b654dd1baf Size/MD5 checksum: 40212297 8e4ba81ad02c7986446d4e54e978409d Alpha architecture: Size/MD5 checksum:11156416 70c32a6e9517462f18bb828a454b3212 Size/MD5 checksum: 164986 e3b758071d4be7c98bfd8a0540791de6 Size/MD5 checksum: 56802 a45946418ff52e979d402455eb910a48 AMD64 architecture: Size/MD5 checksum: 9392060 636d020aff9b205714b45b739110425b Size/MD5 checksum: 159748 49544cb67eafedfa22248d7d8fdd8663 Size/MD5 checksum: 55276 8f948a91991238f70f75e3775c2d0801 ARM architecture: Size/MD5 checksum: 8209620 89ecd8c94f4fbbb90300c345dd6c3563 Size/MD5 checksum: 151096 f8fb6c08b9258a1ff01b98ec0a45c2c4 Size/MD5 checksum: 50648 7cf42eb18d94903784c6bccdc5b325e3 Intel IA-32 architecture: Size/MD5 checksum: 8880930 c52905c0b136e7539670c41018b9c9b3 Size/MD5 checksum: 154894 b2a599514fda8a36228ca74cc6e642eb Size/MD5 checksum: 52186 665e3b76f6303cf62cfaa8673a5c67a3 Intel IA-64 architecture: Size/MD5 checksum: 11608384 7a4b9639a9cdaf21243ed7a3be74e598 Size/MD5 checksum: 165308 11a3066857ca62dec1d60dbe8ac14851 Size/MD5 checksum: 59988 a7465c43cf91cf81fbaa342f027d10c0 HP Precision architecture: Size/MD5 checksum: 10258426 d5ffabecc48a1a6bfa7d3a8d26980732 Size/MD5 checksum: 162692 58a4a0a39bafd202a2919a5543a7ab55 Size/MD5 checksum: 55782 d475a913358c0621373cfaa6759f3858 Motorola 680x0 architecture: Size/MD5 checksum: 8159568 14665ff28f3988e53f27b2a69ac6969e Size/MD5 checksum: 153808 0fa57632ae398ffac16a51a7a38ef4aa Size/MD5 checksum: 51458 8b05ef20891031341e127772cf467009 Big endian MIPS architecture: Size/MD5 checksum: 9913666 0be44208606d670654eceaf1f0467395 Size/MD5 checksum: 152774 7cb360f46abc025799c9a8ae4b2f195d Size/MD5 checksum: 52480 921b88b8540a0bb7cfabb68490055d00 Little endian MIPS architecture: Size/MD5 checksum: 9794034 f6bc5806b30ba861b45abbd945338f32 Size/MD5 checksum: 152272 bf7d062c8aaa7177233069d67849b311 Size/MD5 checksum: 52272 d268d7c64ed36ac6c08d0786f0717abf PowerPC architecture: Size/MD5 checksum: 8553770 4867ba093d827168e933ffda4e6919fa Size/MD5 checksum: 153316 cdcc5efb2ab59de06336ad19c19d4f0f Size/MD5 checksum: 54574 96ce5e54ce3d3431430319ed18d185f6 IBM S/390 architecture: Size/MD5 checksum: 9631110 6e4bfb79847ae61b7e273cc2bb5498a0 Size/MD5 checksum: 160320 60b84a49f19bc3a4b22aa945ccf3e2bf Size/MD5 checksum: 54716 e7b8bc318ee6bb50e02c5d53246d7d05 Sun Sparc architecture: Size/MD5 checksum: 8643914 594b8fb1f240d890bdda7d0a3ad3fc71 Size/MD5 checksum: 153508 167227e2dccc4264cdc4ba8c20986df8 Size/MD5 checksum: 51014 6a3225585fb9f8a8632e09ba6403b8d9 These files will probably be moved into the stable distribution on its next update. - ---------------------------------------------------------------------------------For apt-get: deb https://www.debian.org/security/ stable/updates main For dpkg-ftp: dists/stable/updates/main Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . Debian DSA-775-2 addresses a security flaw in Mozilla’s handling of frame injections. All users should consider updating their installations.. Debian Security, Mozilla Update, Remote Threats, Frame Injection, Software Security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Aug 15, 2005 Critical Debian
89

Fedora: FEDORA-2004-293 Severe: Kdebase Multiple Issues

Several KDE vulnerabilities.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-293 2004-09-08 --------------------------------------------------------------------- Product : Fedora Core 2 Name : kdebase Version : 3.2.2 Release : 6.FC2 Summary : K Desktop Environment - core files Description : Core applications for the K Desktop Environment. Included are: kdm (replacement for xdm), kwin (window manager), konqueror (filemanager, web browser, ftp client, ...), konsole (xterm replacement), kpanel (application starter and desktop pager), kaudio (audio server), kdehelp (viewer for kde help files, info and man pages), kthememgr (system for managing alternate theme packages) plus other KDE components (kcheckpass, kikbd, kscreensaver, kcontrol, kfind, kfontmanager, kmenuedit). --------------------------------------------------------------------- Update Information: Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue. WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue. A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This issue could allow a malicious website to show arbitrary content in a named frame of adifferent browser window. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0746 to this issue. All users of KDE are advised to upgrade to these packages, which contain backported patches from the KDE team for these issues. --------------------------------------------------------------------- * Mon Sep 06 2004 Than Ngo 6:3.2.2-6.FC2 - fix a bug in keyboard layout with xorg.x11, bug #121950 - fix df problem on AFS * Wed Sep 01 2004 Than Ngo 6:3.2.2-5.FC2 - Konqueror Frame Injection Vulnerability, CAN-2004-0721 --------------------------------------------------------------------- This update can be downloaded from: 80f87d426b760776fc7fc03653ad30a6 SRPMS/kdebase-3.2.2-6.FC2.src.rpm 6bbf33f60b428bc3f2e0fac4fa09b64f x86_64/kdebase-3.2.2-6.FC2.x86_64.rpm 8eb7ca6d4dd1557114980885744ecdfd x86_64/kdebase-devel-3.2.2-6.FC2.x86_64.rpm 4e9b9094fc7abd21083de2c17b9f51f0 x86_64/debug/kdebase-debuginfo-3.2.2-6.FC2.x86_64.rpm a05b23c8202566417a5bc2d3a3a5cd88 i386/kdebase-3.2.2-6.FC2.i386.rpm bc6d4263395d4af1a4b89503ff4a8e28 i386/kdebase-devel-3.2.2-6.FC2.i386.rpm 1835604099fdd8c8ed532f5c15709c0d i386/debug/kdebase-debuginfo-3.2.2-6.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Secure your KDE on Fedora Core 2 by backing up, updating packages, applying patches, reconfiguring settings, and monitoring updates regularly for safety. KDESecurity,FedoraUpdates,KDEVulnerabilities,LocalAttacker,FrameInjection. . LinuxSecurity.com Team

Calendar 2 Sep 08, 2004 Fedora
89

Fedora: kdelibs Update Notification, Critical: Session Fixation Threat

Several KDE vulnerabilities.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-290 2004-09-08 --------------------------------------------------------------------- Product : Fedora Core 1 Name : kdelibs Version : 3.1.4 Release : 7 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------- Update Information: Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue. WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue. A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This issue could allow a malicious website to show arbitrary content in a named frame of a different browser window. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0746 to this issue. All users of KDE are advised to upgrade to these erratum packages, which containbackported patches from the KDE team for these issues. --------------------------------------------------------------------- * Wed Sep 01 2004 Than Ngo 6:3.1.4-7 - Konqueror Frame Injection Vulnerability CAN-2004-0721 - Konqueror Cross-Domain Cookie Injection CAN-2004-0746 * Wed Jul 28 2004 Than Ngo 6:3.1.4-6 - temporary directory vulnerability, CAN-2004-0689 --------------------------------------------------------------------- This update can be downloaded from: 008938cbdcd2153b84d2dda1cbcbf887 SRPMS/kdelibs-3.1.4-7.src.rpm eb7ea45f4d74c1445336bcef9761f02f x86_64/kdelibs-3.1.4-7.x86_64.rpm 09e622613f98b001d548815e0e8a8a1e x86_64/kdelibs-devel-3.1.4-7.x86_64.rpm 5b239bdfa7ccadb00fe6eca14b4c0593 x86_64/debug/kdelibs-debuginfo-3.1.4-7.x86_64.rpm 61cef6ddcc8a103f0aae6d7c8a31e224 i386/kdelibs-3.1.4-7.i386.rpm 987c650d14f71dc848cce75f8bf4dc3a i386/kdelibs-devel-3.1.4-7.i386.rpm b2831db469e778da7a7d4073d6cb5517 i386/debug/kdelibs-debuginfo-3.1.4-7.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Several security flaws detected in Fedora's kdelibs affecting KDE libraries' operations. Performing an upgrade is highly recommended to mitigate possible risks.. KDE Libraries,Fedora Security,Session Fixation,Cross-Site Scripting,Directory Traversal. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 08, 2004 Critical Fedora
89

Fedora Core 2: 2004-291 Moderate: kde Frame Injection and Cookie Issues

Several KDE vulnerabilities.. --------------------------------------------------------------------- Fedora Update Notification FEDORA-2004-291 2004-09-08 --------------------------------------------------------------------- Product : Fedora Core 2 Name : kdelibs Version : 3.2.2 Release : 8.FC2 Summary : K Desktop Environment - Libraries Description : Libraries for the K Desktop Environment: KDE Libraries included: kdecore (KDE core library), kdeui (user interface), kfm (file manager), khtmlw (HTML widget), kio (Input/Output, networking), kspell (spelling checker), jscript (javascript), kab (addressbook), kimgio (image manipulation). --------------------------------------------------------------------- Update Information: Andrew Tuitt reported that versions of KDE up to and including 3.2.3 create temporary directories with predictable names. A local attacker could prevent KDE applications from functioning correctly, or overwrite files owned by other users by creating malicious symlinks. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0689 to this issue. WESTPOINT internet reconnaissance services has discovered that the KDE web browser Konqueror allows websites to set cookies for certain country specific secondary top level domains. An attacker within one of the affected domains could construct a cookie which would be sent to all other websites within the domain leading to a session fixation attack. This issue does not affect popular domains such as .co.uk, .co.in, or .com. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0721 to this issue. A frame injection spoofing vulnerability has been discovered in the Konqueror web browser. This issue could allow a malicious website to show arbitrary content in a named frame of a different browser window. The Common Vulnerabilities and Exposures project has assigned the name CAN-2004-0746 to this issue. All users of KDE are advised to upgrade to these packages, which containbackported patches from the KDE team for these issues. --------------------------------------------------------------------- * Wed Sep 01 2004 Than Ngo 6:3.2.2-8.FC2 - Konqueror Frame Injection Vulnerability CAN-2004-0721 - Konqueror Cross-Domain Cookie Injection CAN-2004-0746 * Wed Jul 28 2004 Than Ngo 6:3.2.2-7 - DCOPServer Temporary Filename Vulnerability, CAN-2004-0690 - temporary directory vulnerability, CAN-2004-0689 --------------------------------------------------------------------- This update can be downloaded from: 1f58d8b1b9a5598e249f9cca9dfd989d SRPMS/kdelibs-3.2.2-8.FC2.src.rpm b5106d0e1e28796c79df11a798d1e1bb x86_64/kdelibs-3.2.2-8.FC2.x86_64.rpm 9460641c334c4e448cd94f20dfda49fd x86_64/kdelibs-devel-3.2.2-8.FC2.x86_64.rpm 82353b5f48c540655dbec591ff6afa28 x86_64/debug/kdelibs-debuginfo-3.2.2-8.FC2.x86_64.rpm bbe4cd8f2842be7209f7821d8548926a i386/kdelibs-3.2.2-8.FC2.i386.rpm 9d25c78e9ae1e911411c47f8f4aaae2f i386/kdelibs-devel-3.2.2-8.FC2.i386.rpm 3cb3189b5c72aa10fef2bfb99b2059d2 i386/debug/kdelibs-debuginfo-3.2.2-8.FC2.i386.rpm This update can also be installed with the Update Agent; you can launch the Update Agent with the 'up2date' command. --------------------------------------------------------------------- . Examine several vulnerabilities within the KDE desktop environment that were addressed with backported patches tailored for Fedora Core 2. Ensure to stay updated on mitigating measures.. KDE Vulnerabilities,Fedora Update,Security Patches,Local Attack Prevention. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Sep 08, 2004 Important Fedora
99

Slackware 10.0: 2004-247-01 Critical: KDE Frame Injection Issue

New kdelibs and kdebase packages are available for Slackware 9.1, 10.0, and -current to fix security issues. More details about this issues may be found in the Common Vulnerabilities and Exposures (CVE) database: . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] kde (SSA:2004-247-01) New kdelibs and kdebase packages are available for Slackware 9.1, 10.0, and -current to fix security issues. More details about this issues may be found in the Common Vulnerabilities and Exposures (CVE) database: https://www.cve.org/CVERecord?id=CAN-2004-0689 https://www.cve.org/CVERecord?id=CAN-2004-0690 https://www.cve.org/CVERecord?id=CAN-2004-0721 https://www.cve.org/CVERecord?id=CAN-2004-0746 Here are the details from the Slackware 10.0 ChangeLog: +--------------------------+ Fri Sep 3 13:13:09 PDT 2004 patches/packages/kdebase-3.2.3-i486-2.tgz: Patched frame injection vulnerability in Konqueror. For more details, see: https://www.cve.org/CVERecord?id=CAN-2004-0721 (* Security fix *) patches/packages/kdelibs-3.2.3-i486-2.tgz: Patched unsafe temporary directory usage, cross-domain cookie injection vulnerability for certain country specific domains, and frame injection vulnerability in Konqueror. For more details, see: https://www.cve.org/CVERecord?id=CAN-2004-0689 https://www.cve.org/CVERecord?id=CAN-2004-0690 https://www.cve.org/CVERecord?id=CAN-2004-0721 https://www.cve.org/CVERecord?id=CAN-2004-0746 (* Security fix *) +--------------------------+ Where to find the new packages: +-----------------------------+ Updated packages for Slackware 9.1: ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/kdebase-3.1.4-i486-2.tgz ftp://ftp.slackware.com/pub/slackware/slackware-9.1/patches/packages/kdelibs-3.1.4-i486-3.tgz Updated packages for Slackware 10.0: Updated packages for Slackware -current: MD5 signatures: +-------------+ Slackware 9.1 packages: 296fc0b2d31c5914b08ab54332312cf9 kdebase-3.1.4-i486-2.tgz c0de072389daeb6bd8a1cde2ed1dc8ef kdelibs-3.1.4-i486-3.tgz Slackware 10.0 packages: 528edca97f8d6c412742fa8f817abd76 kdebase-3.2.3-i486-2.tgz 8eabfa597ea805ceb457933d36e144be kdelibs-3.2.3-i486-2.tgz Slackware -current packages: 528edca97f8d6c412742fa8f817abd76 kdebase-3.2.3-i486-2.tgz 8eabfa597ea805ceb457933d36e144be kdelibs-3.2.3-i486-2.tgz Installation instructions: +------------------------+ Upgrade the packages as root: # upgradepkg kdebase-3.2.3-i486-2.tgz kdelibs-3.2.3-i486-2.tgz +-----+ . Enhance the security of kdelibs and kdebase on Slackware to mitigate severe vulnerabilities impacting various editions.. KDE Security Fix, Slackware Critical Update, kdelibs Patch, KDE Package Management. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Sep 04, 2004 Critical Slackware
91

Gentoo: GLSA-200408-13 Normal: kdebase And kdelibs Multiple Issues

KDE contains three security issues that can allow an attacker to compromise system accounts, cause a Denial of Service, or spoof websites via frame injection. [More...]. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200408-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: kdebase, kdelibs: Multiple security issues Date: August 12, 2004 Bugs: #60068 ID: 200408-13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= KDE contains three security issues that can allow an attacker to compromise system accounts, cause a Denial of Service, or spoof websites via frame injection. Background ========= KDE is a powerful Free Software graphical desktop environment for Linux and Unix-like Operating Systems. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 kde-base/kdebase < 3.2.3-r1 > = 3.2.3-r1 2 kde-base/kdelibs < 3.2.3-r1 > = 3.2.3-r1 ------------------------------------------------------------------- 2 affected packages on all of their supported architectures. ------------------------------------------------------------------- Description ========== KDE contains three security issues: * Insecure handling of temporary files when running KDE applications outside of the KDE environment * DCOPServer creates temporary files in an insecure manner * The Konqueror browser allows websites to load webpages into a target frame of any other open frame-basedwebpage Impact ===== An attacker could exploit these vulnerabilities to create or overwrite files with the permissions of another user, compromise the account of users running a KDE application and insert arbitrary frames into an otherwise trusted webpage. Workaround ========= There is no known workaround at this time. All users are encouraged to upgrade to the latest available version of kdebase. Resolution ========= All KDE users should upgrade to the latest versions of kdelibs and kdebase: # emerge sync # emerge -pv "> =kde-base/kdebase-3.2.3-r1" # emerge "> =kde-base/kdebase-3.2.3-r1" # emerge -pv "> =kde-base/kdelibs-3.2.3-r1" # emerge "> =kde-base/kdelibs-3.2.3-r1" References ========= [ 1 ] KDE Advisory: Temporary Directory Vulnerability https://kde.org/info/security/advisory-20040811-1.txt [ 2 ] KDE Advisory: DCOPServer Temporary Filename Vulnerability https://kde.org/info/security/advisory-20040811-2.txt [ 3 ] KDE Advisory: Konqueror Frame Injection Vulnerability https://kde.org/info/security/advisory-20040811-3.txt Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200408-13 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2004 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/1.0/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBG9xAzKC5hMHO6rkRAi1RAJ9H+j296zFbm+HDuas4yFtpT4nx9gCbB4yv 9+omEDE6ghXjxkJxLSGFGFM=bfdr -----END PGP SIGNATURE----- . Various vulnerabilities impact Gentoo's kdebaseand kdelibs, providing avenues for attacks on user accounts and potential Denial of Service scenarios.. Gentoo Security,KDE Vulnerabilities,KDE Security Issues,KDE Updates. . LinuxSecurity.com Team

Calendar 2 Aug 12, 2004 Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here