Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 0 articles for you...
200

SciLinux: SLSA-2017-1615-1 Important Kernel Security And Bug Fix Update

A flaw was found in the way Linux kernel allocates heap memory to build the scattergather list from a fragment list(skb_shinfo(skb)-> frag_list) in the socket buffer(skb_buff). The heap overflow occurred if 'MAX_SKB_FRAGS + 1' parameter and 'NETIF_F_FRAGLIST' feature were used together. A remote user or process could use this flaw to potentially escalate their privilege on a system. (CVE-2017-7 [More...]. Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2017:1615-1 Issue Date: 2017-06-28 CVE Numbers: CVE-2017-6214 CVE-2017-2583 CVE-2017-7645 CVE-2017-7477 CVE-2017-7895 -- Security Fix(es): * A flaw was found in the way Linux kernel allocates heap memory to build the scattergather list from a fragment list(skb_shinfo(skb)-> frag_list) in the socket buffer(skb_buff). The heap overflow occurred if 'MAX_SKB_FRAGS + 1' parameter and 'NETIF_F_FRAGLIST' feature were used together. A remote user or process could use this flaw to potentially escalate their privilege on a system. (CVE-2017-7477, Important) * The NFS2/3 RPC client could send long arguments to the NFS server. These encoded arguments are stored in an array of memory pages, and accessed using pointer variables. Arbitrarily long arguments could make these pointers point outside the array and cause an out-of-bounds memory access. A remote user or program could use this flaw to crash the kernel (denial of service). (CVE-2017-7645, Important) * The NFSv2 and NFSv3 server implementations in the Linux kernel through 4.10.13 lacked certain checks for the end of a buffer. A remote attacker could trigger a pointer-arithmetic error or possibly cause other unspecified impacts using crafted requests related to fs/nfsd/nfs3xdr.c and fs/nfsd/nfsxdr.c. (CVE-2017-7895, Important) * The Linux kernel built with the Kernel-based Virtual Machine (CONFIG_KVM) support was vulnerable to an incorrect segment selector(SS) value error. The error couldoccur while loading values into the SS register in long mode. A user or process inside a guest could use this flaw to crash the guest, resulting in DoS or potentially escalate their privileges inside the guest. (CVE-2017-2583, Moderate) * A flaw was found in the Linux kernel's handling of packets with the URG flag. Applications using the splice() and tcp_splice_read() functionality could allow a remote attacker to force the kernel to enter a condition in which it could loop indefinitely. (CVE-2017-6214, Moderate) Bug Fix(es): * Previously, the reserved-pages counter (HugePages_Rsvd) was bigger than the total-pages counter (HugePages_Total) in the /proc/meminfo file, and HugePages_Rsvd underflowed. With this update, the HugeTLB feature of the Linux kernel has been fixed, and HugePages_Rsvd underflow no longer occurs. * If a directory on a NFS client was modified while being listed, the NFS client could restart the directory listing multiple times. Consequently, the performance of listing the directory was sub-optimal. With this update, the restarting of the directory listing happens less frequently. As a result, the performance of listing the directory while it is being modified has improved. * The Fibre Channel over Ethernet (FCoE) adapter in some cases failed to reboot. This update fixes the qla2xxx driver, and FCoE adapter now reboots as expected. * When a VM with Virtual Function I/O (VFIO) device was rebooted, the QEMU process occasionally terminated unexpectedly due to a failed VFIO Direct Memory Access (DMA) map request. This update fixes the vfio driver and QEMU no longer crashes in the described situation. * When the operating system was booted with the in-box lpfc driver, a kernel panic occurred on the little-endian variant of IBM Power Systems. This update fixes lpfc, and the kernel no longer panics in the described situation. * When creating or destroying a VM with Virtual Function I/O (VFIO) devices with "Hugepages" feature enabled, errors in Direct Memory Access (DMA) page table entry (PTE)mappings occurred, and QEMU memory usage behaved unpredictably. This update fixes range computation when making room for large pages in Input/Output Memory Management Unit (IOMMU). As a result, errors in DMA PTE mappings no longer occur, and QEMU has a predictable memory usage in the described situation. -- SL7 x86_64 kernel-3.10.0-514.26.1.el7.x86_64.rpm kernel-debug-3.10.0-514.26.1.el7.x86_64.rpm kernel-debug-debuginfo-3.10.0-514.26.1.el7.x86_64.rpm kernel-debug-devel-3.10.0-514.26.1.el7.x86_64.rpm kernel-debuginfo-3.10.0-514.26.1.el7.x86_64.rpm kernel-debuginfo-common-x86_64-3.10.0-514.26.1.el7.x86_64.rpm kernel-devel-3.10.0-514.26.1.el7.x86_64.rpm kernel-headers-3.10.0-514.26.1.el7.x86_64.rpm kernel-tools-3.10.0-514.26.1.el7.x86_64.rpm kernel-tools-debuginfo-3.10.0-514.26.1.el7.x86_64.rpm kernel-tools-libs-3.10.0-514.26.1.el7.x86_64.rpm perf-3.10.0-514.26.1.el7.x86_64.rpm perf-debuginfo-3.10.0-514.26.1.el7.x86_64.rpm python-perf-3.10.0-514.26.1.el7.x86_64.rpm python-perf-debuginfo-3.10.0-514.26.1.el7.x86_64.rpm kernel-tools-libs-devel-3.10.0-514.26.1.el7.x86_64.rpm noarch kernel-abi-whitelists-3.10.0-514.26.1.el7.noarch.rpm kernel-doc-3.10.0-514.26.1.el7.noarch.rpm - Scientific Linux Development Team . Crucial system update for Academic Linux resolves heap buffer overflow and NFS service disruption security issues.. linux kernel heap overflow update, Scientific Linux security fix, NFS denial service patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 28, 2017 Important Scientific Linux
200

Scientific Linux 6.x SLSA-2015:0864-1 Important Kernel Update CVE-2014-7825

Important: kernel security and bug fix update. Date: Tue, 21 Apr 2015 19:24:18 +0000 Reply-To: scientific-linux-users@ Sender: Security Errata for Scientific Linux From: Pat Riehecky Subject: Security ERRATA Important: kernel on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Important: kernel security and bug fix update Advisory ID: SLSA-2015:0864-1 Issue Date: 2015-04-21 CVE Numbers: CVE-2014-7825 CVE-2014-7826 CVE-2014-3690 CVE-2014-8884 CVE-2015-1421 CVE-2014-3215 CVE-2014-9529 CVE-2014-9584 CVE-2014-8171 -- * A flaw was found in the way seunshare, a utility for running executables under a different security context, used the capng_lock functionality of the libcap-ng library. The subsequent invocation of suid root binaries that relied on the fact that the setuid() system call, among others, also sets the saved set-user-ID when dropping the binaries' process privileges, could allow a local, unprivileged user to potentially escalate their privileges on the system. Note: the fix for this issue is the kernel part of the overall fix, and introduces the PR_SET_NO_NEW_PRIVS functionality and the related SELinux exec transitions support. (CVE-2014-3215, Important) * A use-after-free flaw was found in the way the Linux kernel's SCTP implementation handled authentication key reference counting during INIT collisions. A remote attacker could use this flaw to crash the system or, potentially, escalate their privileges on the system. (CVE-2015-1421, Important) * It was found that the Linux kernel's KVM implementation did not ensure that the host CR4 control register value remained unchanged across VM entries on the same virtual CPU. A local, unprivileged user could use this flaw to cause a denial of service on the system. (CVE-2014-3690, Moderate) * An out-of-bounds memory access flaw was found in the syscall tracing functionality of the Linux kernel's perf subsystem. A local, unprivileged user could use this flaw to crash the system. (CVE-2014-7825, Moderate) * An out-of-bounds memory access flaw wasfound in the syscall tracing functionality of the Linux kernel's ftrace subsystem. On a system with ftrace syscall tracing enabled, a local, unprivileged user could use this flaw to crash the system, or escalate their privileges. (CVE-2014-7826, Moderate) * It was found that the Linux kernel memory resource controller's (memcg) handling of OOM (out of memory) conditions could lead to deadlocks. An attacker able to continuously spawn new processes within a single memory- constrained cgroup during an OOM event could use this flaw to lock up the system. (CVE-2014-8171, Moderate) * A race condition flaw was found in the way the Linux kernel keys management subsystem performed key garbage collection. A local attacker could attempt accessing a key while it was being garbage collected, which would cause the system to crash. (CVE-2014-9529, Moderate) * A stack-based buffer overflow flaw was found in the TechnoTrend/Hauppauge DEC USB device driver. A local user with write access to the corresponding device could use this flaw to crash the kernel or, potentially, elevate their privileges on the system. (CVE-2014-8884, Low) * An information leak flaw was found in the way the Linux kernel's ISO9660 file system implementation accessed data on an ISO9660 image with RockRidge Extension Reference (ER) records. An attacker with physical access to the system could use this flaw to disclose up to 255 bytes of kernel memory. (CVE-2014-9584, Low) The system must be rebooted for this update to take effect. -- SL6 x86_64 kernel-2.6.32-504.16.2.el6.x86_64.rpm kernel-debug-2.6.32-504.16.2.el6.x86_64.rpm kernel-debug-debuginfo-2.6.32-504.16.2.el6.x86_64.rpm kernel-debug-devel-2.6.32-504.16.2.el6.x86_64.rpm kernel-debuginfo-2.6.32-504.16.2.el6.x86_64.rpm kernel-debuginfo-common-x86_64-2.6.32-504.16.2.el6.x86_64.rpm kernel-devel-2.6.32-504.16.2.el6.x86_64.rpm kernel-headers-2.6.32-504.16.2.el6.x86_64.rpm perf-2.6.32-504.16.2.el6.x86_64.rpm perf-debuginfo-2.6.32-504.16.2.el6.x86_64.rpm python-perf-debuginfo-2.6.32-504.16.2.el6.x86_64.rpm python-perf-2.6.32-504.16.2.el6.x86_64.rpm i386 kernel-2.6.32-504.16.2.el6.i686.rpm kernel-debug-2.6.32-504.16.2.el6.i686.rpm kernel-debug-debuginfo-2.6.32-504.16.2.el6.i686.rpm kernel-debug-devel-2.6.32-504.16.2.el6.i686.rpm kernel-debuginfo-2.6.32-504.16.2.el6.i686.rpm kernel-debuginfo-common-i686-2.6.32-504.16.2.el6.i686.rpm kernel-devel-2.6.32-504.16.2.el6.i686.rpm kernel-headers-2.6.32-504.16.2.el6.i686.rpm perf-2.6.32-504.16.2.el6.i686.rpm perf-debuginfo-2.6.32-504.16.2.el6.i686.rpm python-perf-debuginfo-2.6.32-504.16.2.el6.i686.rpm python-perf-2.6.32-504.16.2.el6.i686.rpm noarch kernel-abi-whitelists-2.6.32-504.16.2.el6.noarch.rpm kernel-doc-2.6.32-504.16.2.el6.noarch.rpm kernel-firmware-2.6.32-504.16.2.el6.noarch.rpm - Scientific Linux Development Team . An important enhancement to the operating system core addresses numerous security flaws in Scientific Linux, bolstering both protective features and reliability throughout the SL6.x series.. kernel update, Scientific Linux, local escalation, security patch. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Apr 21, 2015 Important Scientific Linux
100

SUSE Linux 9.0: SUSE-SA:2004:045 Critical: Samba Remote Elevation

The Samba developers informed us about several potential integer overflow The Samba developers informed us about several potential integer overflow issues in the Samba 2 and Samba 3 code. issues in the Samba 2 and Samba 3 code. This update adds constraints to the Samba server code which protects it from using values from untrusted sources as operands in arithmetic operations to determine he [More...]. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SUSE Security Announcement Package: samba Announcement-ID: SUSE-SA:2004:045 Date: Wednesday, Dec 22st 2004 14:30 MEST Affected products: 8.1, 8.2, 9.0, 9.1, 9.2 SUSE Linux Desktop 1.0 SUSE Linux Enterprise Server 8, 9 Novell Linux Desktop 9 Vulnerability Type: remote privilege escalation Severity (1-10): 9 SUSE default package: no Cross References: CAN-2004-1154 Content of this advisory: 1) security vulnerability resolved: - several integer overflows problem description 2) solution/workaround 3) special instructions and notes 4) package location and checksums 5) pending vulnerabilities, solutions, workarounds: - none 6) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion The Samba developers informed us about several potential integer overflow issues in the Samba 2 and Samba 3 code. This update adds constraints to the Samba server code which protects it from using values from untrusted sources as operands in arithmetic operations to determine heap memory space needed to copy data. Without these limitations a remote attacker maybe able to overflow the heap memory of the process and to overwrite vital information structures which can be abused to execute arbitrary code. 2) solution/workaround There is no workaround known. Please install the new packages provided on our FTP servers. 3) special instructions and notes Please make sure that all running instances of smbd which were started before the update were terminated. Run the following command as root: /usr/sbin/rcsmb try-restart 4) package location and checksums Download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered for installation from the maintenance web. x86 Platform: SUSE Linux 9.1: 31d6dce3c460010b98a105a234fdfc29 5970e5495401201fd17bf72d42806756 076bbc4a366e9294ea00e4ce6df5d92c 94519e295e8c2bb70b6d11381be7ce4b 9385c5f9ff0b727db2bd0ac8d5d71d0b patch rpm(s): d73986ed6e5d65c293e5ecba075bf380 5817596556919012df4a9c5b64f096d3 e712e8b43540e0471c118463637208ce dfaea082943a41c2e70628c661cb3f41 03d7db3fbc15a7a9662bf2f491ebd10d source rpm(s): cb7ae8682eb81165ac85fb240476aad8 SUSE Linux 9.0: ee2fb1cc077f3a042f4dbc283e595059 f4a3e0b3301d331f69d2f68aaf023923 cfa30b9837ddf28f9473e3a30c502977 80bf72a472af1f4e0740620d0a11efcd 6d3017a019779c6bab77d4420fd9d25a patch rpm(s): 95a6d02fe783c624c9c91863731fa725 4fc881c60bbd642fe45bc1bf45dcab66 51474087fae63e6990a405a47659dbca 49fb1785f3b2482c82188456288f00c9 0178214fa88081ff7a81cf45212474a3 source rpm(s): 4379b75dd8a56c30b7692f98d2e5ce1f SUSE Linux 8.2: 61357920f6867471d7620bbc89f7c5ac ae6be84a1cd10cc3e9a3b35ffc655202 f0a8b417898c72a9f01bc8a585edca50 6f9a7fcb1a312e69a1180d830b7c20f9 1655622d433a92cc681933b8789cb626 patch rpm(s): fc0f1995b339155671e1e815197d9207 548e87b48b1860ef0cca5d7b4f515ad2 a0bed64f240cb05661ee2940d3674495 f3d8ce4cfa47c2339ddd667542f86aaf d4f5f688b670c3622a4cfa946ff2b213 source rpm(s): 716200e217b2ace1d7408c05b19a6aa2 SUSE Linux 8.1: e18ca12ea203e0088678d6d8ce250a78 24b7a5fadadc6db6347f4748cef1b0fd e5e1f125cd181b4a19422bb6f3b55c3f patch rpm(s): 1945bf0bf7ff7d2c81568e5bc09a52fe 5383658a41c122daef14dfa2c5b55784 6fb046905637c3a6af3f12fec3f0b292 source rpm(s): c56bd7063220447f67e716aba72d0892 x86-64 Platform: SUSE Linux 9.1: 953d948cad88670011ae7a3ed2118762 85199d04b3d15e6c1dd58ab544a1e510 3509a79794efd0f0f63872bd3007b0fc b22487852b695b8b60490be0a455c289 942fbf53d0b646aca7ab260090dcbf8e patch rpm(s): 2864fcaad4c8d7068edd876af3ec2bae ec5764c99de3f9c56d8ac340d9d1643a d324917057e9a2a2bde0931bc73c7bc7 731cc0be9fd9b716dd7f35d21909ae4b d1e2effe2b1354b9024c7a89c6387442 source rpm(s): 40da40f8ff9f1db087eac4d7b620a35d SUSE Linux 9.0: 1c22bc894586a1c9c5e9d44deaa2ba4a 0d0217165b53d305d7c798d9b5e32ff3 ef3a6e86f61846f4205ebe022c9664e1 855242455eb372013af4d011d2bcf594 fd83b22302546721730c33b18771e527 patch rpm(s): f73247663792f7da9bfbd8509bd17d98 6540338d9ea046f15a8008a3dfb992c4 8fe413f93cba0007e1121110b42bf0ed d074f8dfde22f1b4f4e853e8cd09a808 ab366f5de0559174c665dfc4113dce35 source rpm(s): 371b70146d4b1bbb9795b29b2276e36a ______________________________________________________________________________ 5) pendingvulnerabilities in SUSE Distributions and Workarounds: Please have a look at: https://www.suse.com/de-de/ ______________________________________________________________________________ 6) standard appendix: authenticity verification, additional information - Package authenticity verification: SUSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SUSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it.), the checksums show proof of the authenticity of the package. We recommend against subscribing to security lists that cause the e-mail message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the file name of the rpm package that you have downloaded. Of course, package authenticity verification can only target an uninstalled rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SUSE in rpm packages for SUSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SUSE Linux distributions version 7.1 and thereafter install the key "This email address is being protected from spambots. You need JavaScript enabled to view it." upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de . - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Advisory foropenssl tackles buffer overflow, a severe remote compromise threat. Upgrade immediately!. Samba Security Update, Integer Overflow, SUSE Linux Critical Update, Remote Privilege Escalation. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Dec 22, 2004 Critical SuSE
100

SUSE 7.3-9.0: 2003-045 Moderate: nginx Network Vulnerability Assessment

Two vulnerabilities were found in the "tiny" web-server thttpd. Two vulnerabilities were found in the "tiny" web-server thttpd. The first bug is a buffer overflow that can be exploited remotely The first bug is a buffer overflow that can be exploited remotely to overwrite the EBP register of the stack. Due to memory-alignment of the stack done by gcc 3.x this bug can not be exploited. All th [More...]. -----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ SUSE Security Announcement Package: thttpd Announcement-ID: SuSE-SA:2003:044 Date: Friday, Oct 31st 2003 13:04 MEST Affected products: 7.3, 8.0, 8.1, 8.2, 9.0 Vulnerability Type: remote privilege escalation/ information leak Severity (1-10): 5 SUSE default package: no Cross References: CAN-2003-0899 CAN-2002-1562 Content of this advisory: 1) security vulnerability resolved: - buffer overflow - information leak (virtual hosting) problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - libnids - KDE - postgresql - frox - sane - ircd - fileutils - mc - apache1/2 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information Two vulnerabilities were found in the "tiny" web-server thttpd. The first bug is a buffer overflow that can be exploited remotely to overwrite the EBP register of the stack. Due to memory-alignment of the stack done by gcc 3.x this bug can not be exploited. All thttpd versionsmentioned in this advisory are compiled with gcc 3.x and are therefore not exploitable. The other bug occurs in the virtual-hosting code of thttpd. A remote attacker can bypass the virtual-hosting mechanism to read arbitrary files. Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web. Intel i386 Platform: SuSE-9.0: e33f3897cac1e1fe117eff8ca252ec0f patch rpm(s): cd5c2aeb6d31d6a6781f392af17a4989 source rpm(s): c6e2446bc94c8c00d35b7741b67df678 SuSE-8.2: a491b55f562fa0f3b1679ee819140c72 patch rpm(s): bbb3dd624b19d8683223049a070d4cf2 source rpm(s): 2710751ff1ee8fbab3c2934c5cb09f3d SuSE-8.1: 428db4fb2eccebb5ed16cb28161ba2a5 patch rpm(s): b32fb0a87d8d7de3ed1953e64da89bc8 source rpm(s): e64bc1488747a414f6bd60735f82385f SuSE-8.0: 952dcca179b647afdeea02b987e3daf8 patch rpm(s): e596221f34a73ba6fdd29abcecb6e211 source rpm(s): 8500be9c635d1c5c9618ecca2a09a5e7 SuSE-7.3: 16ffc5238c1f57b8a1e6e02989524e82 source rpm(s): b5c4b9c65182fcd2a326e3edad7b2dfb PPC Power PC Platform: SuSE-7.3: e7aaff82bd90c459849dd78b1cc47515 source rpm(s): 8ac31eb38063a891e37ed327a5ddbc0c ______________________________________________________________________________ 2) Pending vulnerabilities in SUSE Distributions and Workarounds: - libnids New libnids packages were released to stop remote command execution due to a memory corruption in the TCP reassembly code. (CAN-2003-0850) Please download them from our FTP servers. - KDE New KDE packages are currentlybeing tested. These packages fixes several vulnerabilities: + remote root compromise (CAN-2003-0690) + weak cookies (CAN-2003-0692) + SSL man-in-the-middle attack + information leak through HTML-referrer (CAN-2003-0459) The packages will be release as soon as testing is finished. - postgresql Several buffer overflow problems were fixed in the pg_to_asci() function of postgresql server. New packages are available on our FTP servers. - frox A denial-of-service attack in frox can be trigger remotely. The packages are currently tested and will be release as soon as possible. - sane The scanner service sane of SuSE Linux 7.3-8.1 is vulnerable to a remote denial-of-service attack. This attack can even be triggered if the attackers host is not listed in the saned.conf file. The packages are currently tested and will be release as soon as possible. - ircd The Internet Relay Chat daemon is vulnerable to a remote denial-of- service attack. The attack can be triggered by irc clients directly connected to the daemon. The packages are currently tested and will be release as soon as possible. - fileutils A local denial-of-service attack can be triggered by abusing the -w option of ls(1). This attack can be turned into a remote denial-of- service by using network services, like wuftpd, that rely on the ls(1) command installed on the system. The packages are currently tested and will be release as soon as possible. - mc By using a special combination of links in archive-files it is possible to execute arbitrary commands while mc tries to open it in its VFS. The packages are currently tested and will be release as soon as possible. - apache1/2 The widely used HTTP server apache has several security vulnerabilities: - locally exploitable buffer overflow in the regular expression code. The attacker must be able to modify .htaccess or httpd.conf. (affects: mod_alias and mod_rewrite) - under some circumstances mod_cgid will output its data to the wrong client (affects: apache2) ______________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SUSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SUSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it.), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of thepackage, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verification can only target an un-installed rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SUSE in rpm packages for SUSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SUSE Linux distributions version 7.1 and thereafter install the key "This email address is being protected from spambots. You need JavaScript enabled to view it." upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at . - SUSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SUSE security discussion. All SUSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SUSE's announce-only mailing list. Only SUSE's security announcements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SUSE's security contact is or . The public key is listed below. ==================================================================== . SUSE Security Advisory outlines vulnerabilities inthttpd, associated updates, and potential remote exploit threats. Crucial information for system administrators.. thttpd Security, Remote Exploit, SUSE Updates. . LinuxSecurity.com Team

Calendar%202 Oct 31, 2003 SuSE
100

SuSE: 2002:038 Moderate: PostgreSQL Buffer Overflow Risk

The PostgreSQL Object-Relational DBMS was found vulnerable to several security related buffer overflow problems.. ______________________________________________________________________________ SuSE Security Announcement Package: postgresql Announcement-ID: SuSE-SA:2002:038 Date: Monday, Oct 21th 2002 17:30 MEST Affected products: 7.0, 7.1, 7.2, 7.3, 8.0 SuSE eMail Server 3.1 SuSE eMail Server III Vulnerability Type: remote privilege escalation Severity (1-10): 3 SuSE default package: no Cross References: CAN-2002-0972 Content of this advisory: 1) security vulnerability resolved: several buffer overflows problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - mod_php4 - kon2 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information The PostgreSQL Object-Relational DBMS was found vulnerable to several security related buffer overflow problems. The buffer overflows are located in: * handling long datetime input * lpad() and rpad() function with multibyte * repeat() function * TZ and SET TIME ZONE environment variables These bugs could just be exploited by attackers who have access to the postgresql server to gain the privileges postgres user ID . The PostgreSQL package is not installed by default. A temporary fix is not known. Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Ourmaintenance customers are being notified individually. The packages are being offered to install from the maintenance web. i386 Intel Platform: SuSE-8.0 295a8b92176718fa0f31d8753b086e3d SuSE-8.0 ce9a41bcb3711a369168e6b412881e6d SuSE-8.0 c39f7b4bf8474b05a690168cb1580cc9 SuSE-8.0 f30d7656ac76b508d02a40fdbab90c4d SuSE-8.0 9b371b39106a4f79ca56d1b03b66eac5 SuSE-8.0 b153e3e6ea61e35fb14c4264beecd577 SuSE-8.0 1a1f7922e167f37378f52b59fbde7651 SuSE-8.0 ac259e05005d1cbaf1f34f27ef9b92c7 SuSE-8.0 b5145ffd46e3bf6471c87dcfe1c411b2 SuSE-8.0 866925a31b6e5529440bf08ac787ad7a SuSE-8.0 77bdf60627640b8a6baaccd73f2eef9a SuSE-8.0 e570f6b712bd5a4752a18b8cf1fab9ff SuSE-8.0 49362f0d17092e2da8adae5bf81f1906 SuSE-8.0 4ab42090bd625e5c1cf1741fc05a685a SuSE-8.0 11ada7e5e749e78eb98d82f7b1846aa6 SuSE-8.0 968526d469a4450550ab4ba5b6f83027 SuSE-8.0 e7b986baf11871378560d9c2fa61b717 SuSE-8.0 ad7359f18de98e9bbdb77e92ff0de37f SuSE-8.0 b7d92162a97d27e63e8bee03abff0716 SuSE-8.0 65aba6a9afd5d38efca03cdf708597f2 SuSE-8.0 547ce19ff0921855fdedbd2f644725cc SuSE-8.0 3097e791c00a11b4fd53914009677eb2 SuSE-8.0 6a41815ed8de498044b9e58851232135 SuSE-8.0 959c2270454ee03bd639b34d677ee1a7 SuSE-8.0 e8fd82140e1ffd6e29f53bda5d8598ed SuSE-8.0 7ea684c3a96ec347921dba32d70e905e source rpm: a41380367f2b198c697f7d3409769633 SuSE-7.3 666fafcf35e113ce1a4f36c79abac810 SuSE-7.3 f69d09bbcfcf41c36f929de48b48282a SuSE-7.3 fd4de823cfc05743a9919eaedf SuSE-7.3 1d5d8b74cae636cd10baa3a6c419bd14 SuSE-7.3 da9a94d3a582ce37f353a82af8934d5c SuSE-7.3 a86c849130f63036b8d66f9880c91d98 SuSE-7.3 ab55332c9a8742b456dbf44079b93c62 SuSE-7.3 8f40f336912f9c11222aa8e75a8f42d0 SuSE-7.3 8e87f0fb3b8b44824ae53cf364f7452d SuSE-7.3 738aabbc7c2f86443b6f2f37bdaf45e1 SuSE-7.3 d2741442b2d87d665a400dd20efdd379 SuSE-7.3 122befa7a0b5021e85f7348ec1e959f4 SuSE-7.3 9eab7b2c22e0c82f327fd1685a3d9eb1 source rpm: df2bbdb0e393e98175277351a3ded1ac Sparc Platform: Due to lack of resources new packages will be made available later without any further notice. AXP Alpha Platform: Due to lack of resources new packages will be made available later without any further notice. PPC Power PC Platform: SuSE-7.3 e67b7b469ffd9cc90d674159270cb5c9 SuSE-7.3 ee2f6f8d149fc651e88e7b183a33727e SuSE-7.3 58e9b9d3e8939fbe8d243ff183d2950d SuSE-7.3 018928248f9052ee0e92a143e35fed44 SuSE-7.3 1d906d52a9de9020bea1cb0f62dcfb1b SuSE-7.3 d7fd91833f8b6cf62334351c1114bc30 SuSE-7.3 ea2bba775ec4b4518e63f9130d5cf7d6 SuSE-7.3 265b8715c2961cf6e6c53745c14d9c5e SuSE-7.3 48b0aeb6aacdc4e6a756ff47914bbfa8 SuSE-7.3 5b1a62fe810df234d10a64b7fdba2481 SuSE-7.3 c6aa4f989319efb9217df0d1cae51103 SuSE-7.3 ec661b2e8e483bda2d3587556f17010f SuSE-7.3 06de87a238751fe6113fb0f8dbe11dd1 source rpm: c98a8567cb2c9f7d0c2b095fed7daeb1 SuSE-7.1 8e005c33619240fda1461fb35c08c9b5 SuSE-7.1 06d51dd04c9490064bc4a07c81ee9f24 SuSE-7.1 e1c07b01422f37c656481c1a6566698e SuSE-7.1 c897de110479618be9b122cdc897442e SuSE-7.1 26e09530d4aba750a93dac74d68aeded SuSE-7.1 1cc6f6f78dd5459ac3b7573bb40951fd SuSE-7.1 a38f645bc5ba6046ee2de0fae2be3ee5 SuSE-7.1 d0a90015bae1937411f2e424c8d0f2f3 SuSE-7.1 967d48e91bed1a41d0a236024d01c95f SuSE-7.1 2d7e5e348404c467a8bb3a54dbddd4eb SuSE-7.1 10500a645eabc14f806e08f43bf238e7 source rpm: 49ad314541f098a1f24884a22049275a ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - mod_php4 There was a mistake in Advisory SuSE-SA:2002:036 in section "Affected products". SuSE 7.0 and 7.1 are _not_ vulnerable. - kon2 There is a vulnerability in kon2, a Japanese input manager for the VGA console, that can be exploited by local users to obtain root privilege. We recommend to un-install kon2. __________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SuSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SuSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed inthe announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it. ), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verification can only target an un-installed rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SuSE in rpm packages for SuSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SuSE Linux distributions version 7.1 and thereafter install the key " This email address is being protected from spambots. You need JavaScript enabled to view it. " upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at . - SuSE runs two securitymailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security announcements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (FAQ) send mail to: or respectively. ==================================================================== SuSE's security contact is or . The public key is listed below. ====================================================================______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, it is desired that the clear-text signature shows proof of the authenticity of the text. SuSE Linux AG makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. Type Bits/KeyID Date User ID pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see The GNU Privacy Guard mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff 4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3 0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot 1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/ HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM 523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q 2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8 QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ 1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1 wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol 0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J /LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8 RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ 8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X 11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA 8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+ AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0 zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM /3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7 whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=LRKC -----END PGP PUBLIC KEY BLOCK----- . Canonical publishes critical update fixing major flaws in MySQL memory leaks affecting its Web Hosting Platform, customers recommended to upgrade.. PostgreSQL Security, SuSEeMail Server, Buffer Overflow, Remote Escalation, Security Fix. . LinuxSecurity.com Team

Calendar%202 Oct 21, 2002 SuSE
100

SuSE: 2002:036 Moderate: mod_php4 Remote Escalation And XSS Threat

Multiple vulnerabilities including improper behavior and XSS exploits have been fixed.. ______________________________________________________________________________ SuSE Security Announcement Package: mod_php4 Announcement-ID: SuSE-SA:2002:036 Date: Friday, Oct 4th 2002 10:30 MEST Affected products: 7.0, 7.1, 7.2, 7.3, 8.0 SuSE eMail Server 3.1 SuSE eMail Server III SuSE Linux Enterprise Server SuSE Linux Connectivity Server SuSE Linux Office Server Vulnerability Type: remote privilege escalation Severity (1-10): 5 SuSE default package: no Cross References: CAN-2002-0985 Content of this advisory: 1) security vulnerability resolved: - control char injection in mail() - handling 5th argument of mail() while in "safe mode" - CRLF injection 2) pending vulnerabilities, solutions, workarounds: - glibc - ghostview/kghostview - fetchmail - kdelibs - ethereal 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information PHP is a well known and widely used web programming language. If a PHP script runs in "safe mode" several restrictions are applied to it including limits on execution of external programs. An attacker can pass shell meta-characters or sendmail(8) command line options via the 5th argument (introduced in version 4.0.5) of the mail() function to execute shell commands or control the behavior of sendmail(8). The CRLF injection vulnerabilities in fopen(), file(), header(), ... allow an attacker to bypassACLs or trigger cross-side scripting. The mod_php4 package is not installed by default. A temporary fix is not known. Please note, that the following packages were rebuild too: - mod_php4-core - mod_php4-aolserver - mod_php4-devel - mod_php4-servlet - mod_php4-roxen Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web. i386 Intel Platform: SuSE-8.0 00ce030f55f4d0af32528402a5cbe269 SuSE-8.0 3399c5b577464a282c85a6fcb56be915 source rpm: 730c4b802dd14b9f9fc0ce2bb83fdc4e SuSE-7.3 c82972d8b1933a388adb6669e625835f source rpm: 8a8bf1262e11f4adbfa973b1ba9c9b54 SuSE-7.2 b93a3680eef353f3e16de8f7dd13dfb8 source rpm: 3304dae258e667a56b6d095eb552016f SuSE-7.1 8a829c7fd56622b736a7f538e2d8cc3c source rpm: 23e6b8d1f2128dd4885f85d939646078 SuSE-7.0 99e3e87bf1f18a839f2b1a2f80c3f336 source rpm: 68013bd4050dff75267cdde07894e5d8 Sparc Platform: SuSE-7.3 397044fb23b60f444fcb6b76986027bf source rpm: 431de04e4b31cf939e0cb9a1881c9e72 SuSE-7.1 a6146130f0c20821696406e62ab22863 source rpm: e1019229ec79ea7175f188ecc348e2b6 AXP Alpha Platform: SuSE-7.1 8010e1ef878dd366bb3dcce07b5c8a99 source rpm: 7906462b3a64d505dc78e298512312de SuSE-7.0 55e770e7a01a680e3a776bb085d91254 source rpm: 0e6654da0c43f3170ddcf0b132ae9ac3 PPC Power PC Platform: SuSE-7.3 52421717b8fdd0c9ee4d96d3f0bb1e89 source rpm: df7274f651888c62ad3693d3672ccc00 SuSE-7.1 b43d618d2eba73477dd8f9e2d2215118 source rpm: f9457dc7736cdfecaa2e4a7a01c0c53f SuSE-7.0 56d6fb88d0032f5dcc12397f295e42b2 source rpm: b684c0aa03ec7ec9c8d75f5558bbea1e ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - glibc Client applications which use res_search/res_nsreach and/or res_query()/ res_nquery() of libresolv could trigger a DNS decoding error, a SEGV or leak information by reading beyond the end of a too small 'answer' buffer. The update packages are being built and tested. We will publish a security announcement as soon as they are ready. - ghostview/kghostview Bufferoverflows have recently been discovered in these packages. They allow attackers to execute arbitrary code with the privileges of the user viewing special crafted documents created by the attacker. New packgaes will soon be available on our ftp servers. - fetchmail Fetchmail contains remotely exploitable overflows in the mail header parsing functions. In depth discussion of these problems can be found at . New packages will soon be available on our ftp servers. - kdelibs KDE's SSL implementation fails to check the trust chain in SSL certificates. This bug allows faking valid SSL certificates. New KDE packages will be available soon to fix this and other bugs. - ethereal Several potential security issues have been discovered in ethereal 0.9.4. After this package is tested succesfuly it will be relased. ______________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SuSE update packages areavailable on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SuSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it. ), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verification can only target an un-installed rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg programin the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SuSE in rpm packages for SuSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SuSE Linux distributions version 7.1 and thereafter install the key " This email address is being protected from spambots. You need JavaScript enabled to view it. " upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the top-level directory of the first CD (pubring.gpg) and at . - SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security announcements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SuSE's security contact is or . The public key is listed below. ====================================================================______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, it is desired that the clear-text signature shows proof of the authenticity of the text. SuSE Linux AG makes no warranties of any kind whatsoever with respect to the information contained in thissecurity advisory. Type Bits/KeyID Date User ID pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see The GNU Privacy Guard mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff 4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3 0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot 1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/ HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM 523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q 2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8 QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ 1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1 wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol 0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J /LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8 RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ 8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X 11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA 8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+ AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0 zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM /3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7 whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=LRKC -----END PGP PUBLIC KEY BLOCK----- . Multiple vulnerabilities in mod_php4 on SuSE resolved: apply updates to safeguard against exploitation risks.. SuSE Security Update, mod_php4 Exploits, PHP Security, RemoteEscalation. . LinuxSecurity.com Team

Calendar%202 Oct 07, 2002 SuSE
100

SuSE 8.0 Moderate Advisory on imlib Remote Escalation Vulnerability

An attacker could send a maliciously formated image file to trigger a Denial-of-Service attack or even execute arbitrary code on the victim's machine.. ______________________________________________________________________________ SuSE Security Announcement Package: imlib Announcement-ID: SuSE-SA:2002:015 Date: Tuesday, May 7th 2002 11:30 MEST Affected products: 6.4, 7.0, 7.1, 7.2, 7.3, 8.0 Vulnerability Type: remote privilege escalation Severity (1-10): 3 SuSE default package: yes Other affected systems: all systems/applications using imlib Content of this advisory: 1) security vulnerability resolved: imlib fallback and Denial-of-Service problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information The imlib library can be used by X11 applications to handle various kinds of image data. Imlib could, under certain circumstances, revert to using a netpbm library which is well known to have security problems and should not be used for handling untrusted data. Furthermore a heap corruption could occur in the imlib code. An attacker could send a maliciously formated image file to trigger a Denial-of-Service attack or even execute arbitrary code on the victim's machine. Thanks go to Al Viro and Alan Cox who discovered these bugs. The imlib RPM package is installed by default and affects all applications linked against imlib, like imager viewers, browsers, mail clients and so on. About 140 applications shipped with the SuSE Linux distribution depend on imlib. You need to update your system, as no temporaryworkaround is possbible. Please run ldconfig(8) as root after updating imlib and restart all applications using imlib. Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. Our maintenance customers are being notified individually. The packages are being offered to install from the maintenance web. i386 Intel Platform: SuSE-8.0 9137d95a9205a335871a71341c2c70b4 SuSE-8.0 4abd84a67aacb2c2fa21582e228e6a1d SuSE-8.0 43103d0ff1e60f008499a69519d722d3 SuSE-8.0 02df11424f082e4aed1c93527f7bab69 SuSE-8.0 7680c38f5fef811bc96ff2fc00baafad SuSE-8.0 bb449e5db3bf0827168b78d7636accac source rpm: d7cb0ddd0e18d645191f967b5b6e8109 SuSE-7.3 b114e4ea9babf4ac8bd241674b0be0fd SuSE-7.3 7b3cd1c19161ed500bc4a0306eb66d0c SuSE-7.3 41af6a469645a4ce4399935604cbf4c0 source rpm: 1839a719883e4aa5e543ee1bd22dc780 SuSE-7.2 9ec9fb90418a6ba76432334cb7e15bb8 SuSE-7.2 584e88a451341910524740cc54ca9c64 SuSE-7.2 c8c25f5396d565f75f68d48d7911813b source rpm: a5691ba54118a52454d394e346a6b8b4 SuSE-7.1 dc9d57492cd4faa497e23e14fcf5e57b SuSE-7.1 58f03af3039c42db5b5a9d1a6acd9c27 SuSE-7.1 b82aa8abda460e45094fb4a0d683971f source rpm: f16db540325f4626aa5fda6ab5aa196b SuSE-7.0 c089d699c31addadba09fd967677e535 SuSE-7.0 ee3c4bf8ab5e7068afcfb7160c38653f SuSE-7.0 253759ffd47eb19831e61c52673ebc6f source rpm: 2bb8b096627c72e25949d4e22fc26c3a SuSE-6.4 b3175095dade1c545822b42707a99820 SuSE-6.4 a54bfa0d5b6333c20497dfd6ae1c65f6 SuSE-6.4 6d5815e9cfc1e9020dd758fcf3e15f0b source rpm: ce83d062fb32cf34ed6921490c732a51 Sparc Platform: SuSE-7.3 58f0df8b16d05b7b28d919c53b20ddfd SuSE-7.3 92c1e1a5a67b0a73197f793101af5955 SuSE-7.3 744db88a54bcff79068a7b2392e34fc2 source rpm: fa4c576fea3185bc7624e50620dbaaf5 SuSE-7.1 dc3336004bc77ceca74035cb05b050f9 SuSE-7.1 a27820491016c5ff1fac5706b7042158 SuSE-7.1 b8b28901c088bc6763f462753ca58b7c source rpm: 7605166c8ee6fa6439ade68e0d67c5c6 SuSE-7.0 8b1e28d9aa91061aed4569015e058fac SuSE-7.0 01c5dae090bfe25d641d3389a11c16c2 SuSE-7.0 3be7654afc64fb5a10c145f67dce9ba3 source rpm: 6531693204e86106ceee748758038a07 AXP Alpha Platform: SuSE-7.1 a84242de9afeec0b77f9d85b54f51f5b SuSE-7.1 a2829f4eba557fbc3160b6b4ffec0ac5 SuSE-7.1 691b3d75dab0a3487b9f57c9b3501b17 source rpm: 58697086bf51f5231a1708765db8312c SuSE-7.0 fbbf3f167844f0b046aafc14fed3b50e SuSE-7.0 e5a8c05ca99ce4b38de47b35258423d7 SuSE-7.0 26cc11948b4d61d6e4c0aa35472d2d7d source rpm: 90df4b7a6860281ad6130b09e7e634e3 SuSE-6.4 2b231d47fed0f5ac88299abbb6abb1cd SuSE-6.4 99b4a22d820a3d846fc1bf0ca94843e4 SuSE-6.4 a7e9b77c92c28fe6bd07d4d8634a5253 source rpm: 11a996b48ee33c34b34acffad3a2a56c PPC Power PC Platform: SuSE-7.3 f9c093c06636b62507846c6679e1e86d SuSE-7.3 973e484ba78847b5c47d5d6ef3972f56 SuSE-7.3 e06812ab04e4cbdc781d8e8d29dc3372 source rpm: 8f85b9a40d36d328deb20b3255ddc05c SuSE-7.1 4a22c12194b6f1b80123a3466fe944c3 SuSE-7.1 85139eb233c567783c053f110baadb66 SuSE-7.1 ae31194e59d40267b36e38344b1ad139 source rpm: 6558c6ca5bee620485fd52a9a7ec316d SuSE-7.0 e34ddef90edd1effb95771b5d7f6f935 SuSE-7.0 13eb42a163f919c9a4c097d8dc55a4a3 SuSE-7.0 9e73db46c744ee38118c9cd4b97bda7a source rpm: d321ee18493970c45b232362653dc447 SuSE-6.4 3d255a622cd006656a662b0e7a5efb87 SuSE-6.4 311ac75ac7622c6b453c5d6ed5ef9c28 SuSE-6.4 c5a86e6598a9fc801f56533e060dcc61 source rpm: 294626d55b89e1a5b940b4441172b578 ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - screen A security report about a locally exploitable bug in screen's braile code was published on Bugtraq. SuSE ships screen without this code enabled. On SuSE version 8.0 screen isn't even running with higher privileges anymore. ______________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SuSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SuSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the This email address is being protected from spambots. You need JavaScript enabled to view it.), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verification can only target an uninstalled rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SuSE in rpm packages for SuSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SuSE Linux distributions version 7.1 and thereafter install the key "This email address is being protected from spambots. You need JavaScript enabled to view it." upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the toplevel directory of the first CD (pubring.gpg) and at ftp://ftp.suse.com/pub/suse/pubring.gpg-build.suse.de . - SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SuSE's security contact is or . The public key is listed below. ====================================================================______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. In particular, it is desired that the cleartext signature shows proof of the authenticity of the text. SuSE Linux AG makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. Type Bits/KeyID Date User ID pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info seehttp://www.gnupg.org mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff 4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3 0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot 1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/ HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM 523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q 2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8 QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ 1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1 wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol 0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J /LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8 RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ 8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X 11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA 8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+ AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0 zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM /3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7 whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=LRKC -----END PGP PUBLIC KEY BLOCK----- . ______________________________________________________________________________ SuSE Security Announc. attacker, maliciously, formated, image,trigger, denial-of-service, attack. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 07, 2002 Important SuSE
100

SuSE: 2002:005 Moderate Vulnerability in CUPS Remote Escalation Risks

The buffer overflow could be exploited by a remote attacker as long as their IP address is allowed to connect to the CUPS server. This advisory has been retracted due to errors in the binary packages. . Date: Tue, 26 Feb 2002 14:52:32 +0100 (MET) From: Roman Drahtmueller To: This email address is being protected from spambots. You need JavaScript enabled to view it. Subject: [suse-security-announce] Re: SuSE Security Announcement: cups (SuSE-SA:2002:005) Follow-up to SuSE Security announcement: cups (SuSE-SA:2002:005) ---- We have retracted the security update packages for cups as announced by SuSE Security announcement SuSE-SA:2002:005 due to errors in the binary packages. Please note that the update packages indeed fix the security problem, but may disrupt printing service due to a malfunction in the package if installed and activated. The corrected packages are currently being built and will be published on the ftp server as soon as they are ready. Users of Yast Online Update (YOU) will get the fresh cups packages offered for installation as soon as the packages become available, regardless if the defective packages have been installed or not. We will re-release SuSE Security announcement SuSE-SA:2002:005 as soon as all packages have been built and are available. Regards, Roman Drahtmüller, SuSE Security -- - - | Roman Drahtmüller // "You don't need eyes to see, | SuSE GmbH - Security Phone: // you need vision!" | Nürnberg, Germany +49-911-740530 // Maxi Jazz, Faithless | - - ______________________________________________________________________________ SuSE Security Announcement Package: cups Announcement-ID: SuSE-SA:2002:005 Date: Saturday, Feb 23st 2002 09:10 MET Affected SuSE versions: 7.1, 7.2, 7.3 Vulnerability Type: remote privilege escalation Severity (1-10): 5 SuSE default package: no Other affected systems: all systems running CUPS Content of this advisory: 1) security vulnerability resolved: CUPS bufferoverflow in IPP problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information The well known Common Unix Printing System (CUPS) was found vulnerable to a buffer overflow in the Internet Printing Protocol (IPP) handling code. The buffer overflow could be exploited by a remote attacker as long as their IP address is allowed to connect to the CUPS server. Please download the update package for your distribution and verify its integrity by the methods listed in section 3) of this announcement. Then, install the package using the command "rpm -Fhv file.rpm" to apply the update. After updateing the packages run "rclpd restart" as root to start the new daemon. i386 Intel Platform: SuSE-7.3 bfb52a55305ac12880b5e59410205a6e source rpm: e3d276cb505eaa1bf35946b5c1029562 SuSE-7.3 527eeb095abeb0ee0cad95f028a8222b SuSE-7.3 9a125db90716f71b4fa31cf2ba4180a8 SuSE-7.3 d8457f2c62e7a85e927b615570efa82b SuSE-7.2 9a6c6b3fcd1dea6504121b76de1615b5 source rpm: 92c0fc63d6b9c6c299583868f69ac649 SuSE-7.2 a0ed0a207040b6aa6b8080d7e146ce04 SuSE-7.1 488317348075ae50f0d5f5bd9e82b247 source rpm: 54f3b1bcb3cc727dfcf05514d84c402d SuSE-7.1 6019620534415dd4d09681583ee627a1 Sparc Platform: SuSE-7.3 7777fb032e1c2b45956db2d3ccf9b3c3 source rpm: 91684561da7f476055c71239b61c549b SuSE-7.3 8badff242e1903d7f812bafb0e6a1831 SuSE-7.3 355221f9ca9c435a24251915b3384ea2 SuSE-7.3 60daf45ca8a75237421c8abd27c9f433 SuSE-7.1 063b7953d50ad4b4958541bfaccd270c source rpm: d5d5e4bf719ab2eca49cadc9708e0ff3 SuSE-7.1 2cbd702f7d978a098ce9c84e3b1cc7ff AXP Alpha Platform: SuSE-7.1 7188e40aac0c097095c2df088a93265d source rpm: ac122fe5b1305bab6a8c5904699d4bd5 SuSE-7.1 ae6685e65e7db1b9afe276d51d6da51a PPC PowerPC Platform: SuSE-7.3 99aa8fcf0f21d5799931953c90435d72 source rpm: 6e0b6c9e04eb7167b3585aebbc0deb29 SuSE-7.3 61f807924b16930166d711c1da8a4cc0 SuSE-7.3 090132d0ae790027382c88a9b331fa9e SuSE-7.3 f211da7b5dc400c8e087a6ef8178afd5 SuSE-7.1 52c247f3cbf4836dacec7a767a4fe3c7 source rpm: 1937730cf78b1c658b430e9525084a93 SuSE-7.1 c906d4106d30f1e84133e8d45a857b2d ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: - squid A heap overflow in squid's URL constructing functions is fixed and new packages are currently being built. - ucd-snmpd The UCD snmpd contains various security releated bugs. We are currently reviewing the code and available fixes to ensure they all get fixed. Patches will be available as soon as possible. It is strongly recommended to filter SNMP (TCP and UDP packets with destination of port 161) traffic. - hanterm/wmtv The recently reported vulnerabilities in hanterm and wmtv do not affect SuSE installations because they are not installed setuid or setgid. - cipe We are about to prepare kernel update packages that fix a DoS problem in the kernel modules for the cipe encrypted tunneling software. ______________________________________________________________________________ 3) standard appendix: authenticity verification, additional information - Package authenticity verification: SuSE update packages are available on many mirror ftp servers all over the world. While this service is being considered valuable and important to the free and open source software community, many users wish to be sure about the origin of the package and its content before installing the package. There are two verification methods that can be used independently from each other to prove the authenticity of a downloaded file or rpm package: 1) md5sums as provided in the (cryptographically signed) announcement. 2) using the internal gpg signatures of the rpm package. 1) execute the command md5sum after you downloaded the file from a SuSE ftp server or its mirrors. Then, compare the resulting md5sum with the one that is listed in the announcement. Since the announcement containing the checksums is cryptographically signed (usually using the key This email address is being protected from spambots. You need JavaScript enabled to view it. ), the checksums show proof of the authenticity of the package. We disrecommend to subscribe to security lists which cause the email message containing the announcement to be modified so that the signature does not match after transport through the mailing list software. Downsides: You must be able to verify the authenticity of the announcement in the first place. If RPM packages are being rebuilt and a new version of a package is published on the ftp server, all md5 sums for the files are useless. 2) rpm package signatures provide an easy way to verify the authenticity of an rpm package. Use the command rpm -v --checksig to verify the signature of the package, where is the filename of the rpm package that you have downloaded. Of course, package authenticity verificationcan only target an uninstalled rpm package file. Prerequisites: a) gpg is installed b) The package is signed using a certain key. The public part of this key must be installed by the gpg program in the directory ~/.gnupg/ under the user's home directory who performs the signature verification (usually root). You can import the key that is used by SuSE in rpm packages for SuSE Linux by saving this announcement to a file ("announcement.txt") and running the command (do "su -" to be root): gpg --batch; gpg < announcement.txt | gpg --import SuSE Linux distributions version 7.1 and thereafter install the key " This email address is being protected from spambots. You need JavaScript enabled to view it. " upon installation or upgrade, provided that the package gpg is installed. The file containing the public key is placed at the toplevel directory of the first CD (pubring.gpg) and at . - SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ==================================================================== SuSE's security contact is or . The public key is listed below. ====================================================================______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified inany way. In particular, it is desired that the cleartext signature shows proof of the authenticity of the text. SuSE GmbH makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. Type Bits/KeyID Date User ID pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v1.0.6 (GNU/Linux) Comment: For info see The GNU Privacy Guard mQGiBDnu9IERBACT8Y35+2vv4MGVKiLEMOl9GdST6MCkYS3yEKeueNWc+z/0Kvff 4JctBsgs47tjmiI9sl0eHjm3gTR8rItXMN6sJEUHWzDP+Y0PFPboMvKx0FXl/A0d M+HFrruCgBlWt6FA+okRySQiliuI5phwqkXefl9AhkwR8xocQSVCFxcwvwCglVcO QliHu8jwRQHxlRE0tkwQQI0D+wfQwKdvhDplxHJ5nf7U8c/yE/vdvpN6lF0tmFrK XBUX+K7u4ifrZlQvj/81M4INjtXreqDiJtr99Rs6xa0ScZqITuZC4CWxJa9GynBE D3+D2t1V/f8l0smsuYoFOF7Ib49IkTdbtwAThlZp8bEhELBeGaPdNCcmfZ66rKUd G5sRA/9ovnc1krSQF2+sqB9/o7w5/q2qiyzwOSTnkjtBUVKn4zLUOf6aeBAoV6NM CC3Kj9aZHfA+ND0ehPaVGJgjaVNFhPi4x0e7BULdvgOoAqajLfvkURHAeSsxXIoE myW/xC1sBbDkDUIBSx5oej73XCZgnj/inphRqGpsb+1nKFvF+rQoU3VTRSBQYWNr YWdlIFNpZ25pbmcgS2V5IDxidWlsZEBzdXNlLmRlPohcBBMRAgAcBQI57vSBBQkD wmcABAsKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyl8sAJ98BgD40zw0GHJHIf6d NfnwI2PAsgCgjH1+PnYEl7TFjtZsqhezX7vZvYCIRgQQEQIABgUCOnBeUgAKCRCe QOMQAAqrpNzOAKCL512FZvv4VZx94TpbA9lxyoAejACeOO1HIbActAevk5MUBhNe LZa/qM2JARUDBRA6cGBvd7LmAD0l09kBATWnB/9An5vfiUUE1VQnt+T/EYklES3t XXaJJp9pHMa4fzFa8jPVtv5UBHGee3XoUNDVwM2OgSEISZxbzdXGnqIlcT08TzBU D9i579uifklLsnr35SJDZ6ram51/CWOnnaVhUzneOA9gTPSr+/fT3WeVnwJiQCQ3 0kNLWVXWATMnsnT486eAOlT6UNBPYQLpUprF5Yryk23pQUPAgJENDEqeU6iIO9Ot 1ZPtB0lniw+/xCi13D360o1tZDYOp0hHHJN3D3EN8C1yPqZd5CvvznYvB6bWBIpW cRgdn2DUVMmpU661jwqGlRz1F84JG/xe4jGuzgpJt9IXSzyohEJB6XG5+D0BiF0E ExECAB0FAjxqqTQFCQoAgrMFCwcKAwQDFQMCAxYCAQIXgAAKCRCoTtronIAKyp1f AJ9dR7saz2KPNwD3U+fy/0BDKXrYGACfbJ8fQcJqCBQxeHvt9yMPDVq0B0W5Ag0E Oe70khAIAISR0E3ozF/la+oNaRwxHLrCet30NgnxRROYhPaJB/Tu1FQokn2/Qld/ HZnh3TwhBIw1FqrhWBJ7491iAjLR9uPbdWJrn+A7t8kSkPaF3Z/6kyc5a8fas44h t5h+6HMBzoFCMAq2aBHQRFRNp9Mz1ZvoXXcI1lk1l8OqcUM/ovXbDfPcXsUVeTPT tGzcAi2jVl9hl3iwJKkyv/RLmcusdsi8YunbvWGFAF5GaagYQo7YlF6UaBQnYJTM 523AMgpPQtsKm9o/w9WdgXkgWhgkhZEeqUS3m5xNey1nLu9iMvq9M/iXnGz4sg6Q 2Y+GqZ+yAvNWjRRou3zSE7Bzg28MI4sAAwYH/2D71Xc5HPDgu87WnBFgmp8MpSr8 QnSs0wwPg3xEullGEocolSb2c0ctuSyeVnCttJMzkukL9TqyF4s/6XRstWirSWaw JxRLKH6Zjo/FaKsshYKf8gBkAaddvpl3pO0gmUYbqmpQ3xDEYlhCeieXS5MkockQ 1sj2xYdB1xO0ExzfiCiscUKjUFy+mdzUsUutafuZ+gbHog1CN/ccZCkxcBa5IFCH ORrNjq9pYWlrxsEn6ApsG7JJbM2besW1PkdEoxak74z1senh36m5jQvVjA3U4xq1 wwylxadmmJaJHzeiLfb7G1ZRjZTsB7fyYxqDzMVul6o9BSwO/1XsIAnV1uuITAQY EQIADAUCOe70kgUJA8JnAAAKCRCoTtronIAKyksiAJsFB3/77SkH3JlYOGrEe1Ol 0JdGwACeKTttgeVPFB+iGJdiwQlxasOfuXyITAQYEQIADAUCPGqpWQUJCgCCxwAK CRCoTtronIAKyofBAKCSZM2UFyta/fe9WgITK9I5hbxxtQCfX+0ar2CZmSknn3co SPihn1+OBNyZAQ0DNuEtBAAAAQgAoCRcd7SVZEFcumffyEwfLTcXQjhKzOahzxpo omuF+HIyU4AGq+SU8sTZ/1SsjhdzzrSAfv1lETACA+3SmLr5KV40Us1w0UC64cwt A46xowVq1vMlH2Lib+V/qr3b1hE67nMHjysECVx9Ob4gFuKNoR2eqnAaJvjnAT8J /LoUC20EdCHUqn6v+M9t/WZgC+WNR8cq69uDy3YQhDP/nIan6fm2uf2kSV9A7ZxE GrwsWl/WX5Q/sQqMWaU6r4az98X3z90/cN+eJJ3vwtA+rm+nxEvyev+jaLuOQBDf ebh/XA4FZ35xmi+spdiVeJH4F/ubaGlmj7+wDOF3suYAPSXT2QAFEbQlU3VTRSBT ZWN1cml0eSBUZWFtIDxzZWN1cml0eUBzdXNlLmRlPokBFQMFEDbhLUfkWLKHsco8 RQEBVw4H/1vIdiOLX/7hdzYaG9crQVIk3QwaB5eBbjvLEMvuCZHiY2COUg5QdmPQ 8SlWNZ6k4nu1BLcv2g/pymPUWP9fG4tuSnlUJDrWGm3nhyhAC9iudP2u1YQY37Gb B6NPVaZiYMnEb4QYFcqv5c/r2ghSXUTYk7etd6SW6WCOpEqizhx1cqDKNZnsI/1X 11pFcO2N7rc6byDBJ1T+cK+F1Ehan9XBt/shryJmv04nli5CXQMEbiqYYMOu8iaA 8AWRgXPCWqhyGhcVD3LRhUJXjUOdH4ZiHCXaoF3zVPxpeGKEQY8iBrDeDyB3wHmj qY9WCX6cmogGQRgYG6yJqDalLqrDOdmJARUDBRA24S0Ed7LmAD0l09kBAW04B/4p WH3f1vQn3i6/+SmDjGzUu2GWGq6Fsdwo2hVM2ym6CILeow/K9JfhdwGvY8LRxWRL hn09j2IJ9P7H1Yz3qDf10AX6V7YILHtchKT1dcngCkTLmDgC4rs1iAAl3f089sRG BafGPGKv2DQjHfR1LfRtbf0P7c09Tkej1MP8HtQMW9hPkBYeXcwbCjdrVGFOzqx+ AvvJDdT6a+oyRMTFlvmZ83UV5pgoyimgjhWnM1V4bFBYjPrtWMkdXJSUXbR6Q7Pi RZWCzGRzwbaxqpl3rK/YTCphOLwEMB27B4/fcqtBzgoMOiaZA0M5fFoo54KgRIh0 zinsSx2OrWgvSiLEXXYKiEYEEBECAAYFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM /3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7 whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI RgQQEQIABgUCOhpCpAAKCRDHUqoysN/3gCt7AJ9adNQMbmA1iSYcbhtgvx9ByLPI DgCfZ5Wj+f7cnYpFZI6GkAyyczG09sE=LRKC -----END PGP PUBLIC KEY BLOCK----- . SYSTEM reveals an underlying security risk linked to inadequate data processing; the alert rescinded due to script irregularities.. Cups Privilege Escalation, RemoteAccess, Security Advisory. . LinuxSecurity.com Team

Calendar%202 Feb 25, 2002 SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200