An update that solves one vulnerability and has two fixes is now available.. openSUSE Security Update: Security update for libheimdal ______________________________________________________________________________ Announcement ID: openSUSE-SU-2018:2376-1 Rating: important References: #1047218 #1071675 #1084909 Cross-References: CVE-2017-17439 Affected Products: openSUSE Leap 42.3 ______________________________________________________________________________ An update that solves one vulnerability and has two fixes is now available. Description: This update for libheimdal to version 7.5.0 fixes the following issues: The following security vulnerability was fixed: - CVE-2017-17439: Fixed a remote denial of service vulnerability through which remote unauthenticated attackers were able to crash the KDC by sending a crafted UDP packet containing empty data fields for client name or realm (boo#1071675) The following other bugs were fixed: - Override the build date (boo#1047218) - Use constant hostname (boo#1084909) - Handle long input lines when reloading database dumps - In pre-forked mode, correctly clear the process ids of exited children, allowing new child processes to replace the old. - Fixed incorrect KDC response when no-cross realm TGT exists, allowing client requests to fail quickly rather than time out after trying to get a correct answer from each KDC. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 42.3: zypper in -t patch openSUSE-2018-876=1 Package List: - openSUSE Leap 42.3 (i586 x86_64): libheimdal-7.5.0-9.1 libheimdal-debuginfo-7.5.0-9.1 libheimdal-debugsource-7.5.0-9.1 libheimdal-devel-7.5.0-9.1 References: https://www.suse.com/security/cve/CVE-2017-17439.html https://bugzilla.suse.com/1047218 https://bugzilla.suse.com/1071675 https://bugzilla.suse.com/1084909 -- . The latest libheimdal update addresses significant security vulnerabilities, resolving remote Denial-of-Service risks and improving overall software reliability.. libheimdal security update, openSUSE patch, remote dos threat. . Severity: Important. LinuxSecurity.com Team
There are multiple vulnerabilities in MySQL. . - --------------------------------------------------------------------GENTOO LINUX SECURITY ANNOUNCEMENT 200212-2 - --------------------------------------------------------------------PACKAGE : mysql SUMMARY : remote DOS and arbitrary code execution DATE : 2002-12-15 12:12 UTC EXPLOIT : remote - --------------------------------------------------------------------From e-matters advisory: "We have discovered two flaws within the MySQL server that can be used by any MySQL user to crash the server. Furthermore one of the flaws can be used to bypass the MySQL password check or to execute arbitrary code with the privileges of the user running mysqld. We have also discovered an arbitrary size heap overflow within the mysql client library and another vulnerability that allows to write '\0' to any memory address. Both flaws could allow DOS attacks against or arbitrary code execution within anything linked against libmysqlclient." SOLUTION It is recommended that all Gentoo Linux users who are running net-misc/freeswan-3.23.53 and earlier update their systems as follows: emerge rsync emerge mysql emerge clean - --------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.