It was discovered that unattended-upgrades, a script for automatic installation of security upgrades, did not properly authenticate downloaded packages when the force-confold or force-confnew dpkg options were enabled via the DPkg::Options::* apt configuration. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-3297-1
An attacker could send an email to the victim who ago use of HORDE MTAin order to push it to visit a website. The website in issue log all theaccesses and describe in the particular the origin of every victim.. - - --------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT 200309-02.1 - - --------------------------------------------------------------------- � � � � � PACKAGE : horde � � � � � SUMMARY : session hijacking � � � � � � �DATE : 2003-09-01 14:38 UTC � � � � � EXPLOIT : remote VERSIONS AFFECTED : =horde-2.2.4_rc2 � � � � � � � CVE : - - --------------------------------------------------------------------- This advisory contains the correct values for VERSIONS AFFECTED and FIXED VERSION SOLUTION It is recommended that all Gentoo Linux users who are running net-www/horde upgrade to horde-2.2.4_rc2 as follows: emerge sync emerge horde emerge clean - - ---------------------------------------------------------------------
Get the latest Linux and open source security news straight to your inbox.