Thank you for reading the Linux Advisory Watch Security Newsletter.
The purpose of this document is to provide our readers with a quick
summary of each week's vendor security bulletins and pointers on
methods to improve the security posture of your open source system.
Vulnerabilities affect nearly every vendor virtually every week, so
be sure to read through to find the updates your distributor have
made available.
This report may also include some advisories that were published prior to the beginning of the week.
|
|
|
Guardian Digital is happy to announce the release of EnGarde Secure Community 3.0.22 (Version 3.0, Release 22). This release includes many updated packages and bug fixes and some feature enhancements to the EnGarde Secure Linux Installer and the SELinux policy.
|
|
|
|
(Jun 10) |
|
It was discovered that PCSCD, a daemon to access smart cards, was vulnerable to a buffer overflow allowing a local attacker to elevate his privileges to root. [More...]
|
|
(Jun 10) |
|
Several vulnerabilities have been discovered in the GNU C Library (aka glibc) and its derivatives. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]
|
|
(Jun 7) |
|
It was discovered that OpenOffice.org, a full-featured office productivity suite that provides a near drop-in replacement for Microsoft(R) Office, is not properly handling python macros embedded in an office document. This allows an attacker to perform user-assisted execution of arbitrary code in [More...]
|
|
(Jun 7) |
|
Several vulnerabilities have been discovered in the MySQL database server. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]
|
|
(Jun 5) |
|
It was discovered that in squidguard, a URL redirector/filter/ACL plugin for squid, several problems in src/sgLog.c and src/sgDiv.c allow remote users to either: [More...]
|
|
(Jun 5) |
|
It was discovered that mediawiki, a website engine for collaborative work, is vulnerable to a Cross-Site Request Forgery login attack, which could be used to conduct phishing or similar attacks to users via affected mediawiki installations. [More...]
|
|
(Jun 5) |
|
Florent Daigniere discovered multiple format string vulnerabilities in Linux SCSI target framework (which is known as iscsitarget under Debian) allow remote attackers to cause a denial of service in the ietd daemon. The flaw could be trigger by sending a carefully-crafted Internet Storage Name Service (iSNS) [More...]
|
|
(Jun 5) |
|
tixxDZ (DZCORE labs) discovered a vulnerability in vlc, the multimedia player and streamer. Missing data validation in vlc's real data transport (RDT) implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable [More...]
|
|
(Jun 5) |
|
Bob Clary, Dan Kaminsky and David Keeler discovered that in libtheora, a video library part of the Ogg project, several flaws allow allow context-dependent attackers via a large and specially crafted media file, to cause a denial of service (crash of the player using this [More...]
|
|
(Jun 5) |
|
tixxDZ (DZCORE labs) discovered a vulnerability in the mplayer movie player. Missing data validation in mplayer's real data transport (RDT) implementation enable an integer underflow and consequently an unbounded buffer operation. A maliciously crafted stream could thus enable an [More...]
|
|
(Jun 5) |
|
Several remote vulnerabilities have been discovered in phpgroupware, a Web based groupware system written in PHP. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]
|
|
(Jun 5) |
|
A vulnerability was discovered in aria2, a download client. The "name" attribute of the "file" element of metalink files is not properly sanitised before using it to download files. If a user is tricked into downloading from a specially crafted metalink file, this can be [More...]
|
|
(Jun 5) |
|
The packages for Pidgin released as DSA 2038-1 had a regression, as they unintentionally disabled the Zephyr instant messaging protocol. This update restores Zephyr functionality. For reference the original advisory text below. [More...]
|
|
(Jun 5) |
|
It has been discovered that barnowl, a curses-based tty Jabber, IRC, AIM and Zephyr client, is prone to a buffer overflow via its "CC:" handling, which could lead to the execution of arbitrary code. [More...]
|
|
(Jun 5) |
|
Dan Rosenberg discovered that in dvipng, a utility that converts DVI files to PNG graphics, several array index errors allow context-dependent attackers, via a specially crafted DVI file, to cause a denial of service (crash of the application), and possibly arbitrary code [More...]
|
|
(Jun 5) |
|
Several local vulnerabilities have been discovered in PostgreSQL, an object-relational SQL database. The Common Vulnerabilities and Exposures project identifies the following problems: [More...]
|
|
(Jun 5) |
|
Several local vulnerabilities have been discovered in KPDF, a PDF viewer for KDE, which allow the execution of arbitrary code or denial of service if a user is tricked into opening a crafted PDF document. [More...]
|
|
(Jun 5) |
|
Shawn Emery discovered that in MIT Kerberos 5 (krb5), a system for authenticating users and services on a network, a null pointer dereference flaw in the Generic Security Service Application Program Interface (GSS-API) library could allow an authenticated remote attacker [More...]
|
|
(Jun 5) |
|
Shawn Emery discovered that in MIT Kerberos 5 (krb5), a system for authenticating users and services on a network, a null pointer dereference flaw in the Generic Security Service Application Program Interface (GSS-API) library could allow an authenticated remote attacker [More...]
|
|
(Jun 5) |
|
CVE-2009-4537 Fabian Yamaguchi reported a missing check for Ethernet frames larger than the MTU in the r8169 driver. This may allow users on the local [More...]
|
|
(Jun 5) |
|
Several cache-poisoning vulnerabilities have been discovered in BIND. These vulnerabilities are apply only if DNSSEC validation is enabled and trust anchors have been installed, which is not the default. [More...]
|
|
|
|
(Jun 5) |
|
Multiple vulnerabilities in FreeType might result in the remoteexecution of arbitrary code.
|
|
(Jun 5) |
|
Multiple integer overflows in CamlImages might result in the remoteexecution of arbitrary code.
|
|
(Jun 5) |
|
An integer overflow in ImageMagick might allow remote attackers tocause the remote execution of arbitrary code.
|
|
(Jun 5) |
|
Multiple vulnerabilities in xine-lib might result in the remoteexecution of arbitrary code.
|
|
(Jun 5) |
|
Multiple vulnerabilities were found in Wireshark.
|
|
(Jun 5) |
|
Stack-based buffer overflows in Transmission may allow for remoteexecution of arbitrary code.
|
|
(Jun 5) |
|
Multiple vulnerabilities were discovered in SILC Toolkit and SILCClient, the worst of which allowing for execution of arbitrary code.
|
|
(Jun 5) |
|
Race conditions when editing files could lead to symlink attacks orchanges of ownerships of important files.
|
|
(Jun 5) |
|
A flaw in sudo's -e option may allow local attackers to executearbitrary commands.
|
|
(Jun 5) |
|
multipath-tools does not set correct permissions on the socket file,making it possible to send arbitrary commands to the multipath daemonfor local users.
|
|
(Jun 5) |
|
=======Several cache poisoning vulnerabilities have been found in BIND.
|
|
(Jun 5) |
|
Several cache poisoning vulnerabilities have been found in BIND.
|
|
(Jun 5) |
|
Multiple vulnerabilities have been reported in Fetchmail, allowingremote attackers to execute arbitrary code or to conductMan-in-the-Middle attacks.
|
|
(Jun 5) |
|
Multiple vulnerabilities in the Smarty template engine might allowremote attackers to execute arbitrary PHP code.
|
|
(Jun 5) |
|
A heap-based buffer overflow in the Newt library might allow remote,user-assisted attackers to execute arbitrary code.
|
|
(Jun 5) |
|
Multiple integer overflow errors in XEmacs might allow remote,user-assisted attackers to execute arbitrary code.
|
|
(Jun 5) |
|
The GD library is prone to a buffer overflow vulnerability.
|
|
(Jun 5) |
|
A processing error in lighttpd might result in a Denial of Servicecondition.
|
|
(Jun 5) |
|
The Oracle JDK and JRE are vulnerable to multiple unspecifiedvulnerabilities.
|
|
(Jun 5) |
|
Bugzilla is prone to multiple medium severity vulnerabilities.
|
|
(Jun 5) |
|
Multiple vulnerabilities in Asterisk might allow remote attackers tocause a Denial of Service condition, or conduct other attacks.
|
|
|
|
Mandriva: 2010:114: dhcp (Jun 11) |
|
A vulnerability has been found and corrected in dhcp: ISC DHCP 4.1 before 4.1.1-P1 and 4.0 before 4.0.2-P1 allows remote attackers to cause a denial of service (server exit) via a zero-length client ID (CVE-2010-2156). [More...]
|
|
Mandriva: 2010:113: wireshark (Jun 10) |
|
This advisory updates wireshark to the latest version(s), fixing several security issues: * The SMB dissector could dereference a NULL pointer. (Bug 4734) * J. Oquendo discovered that the ASN.1 BER dissector could overrun [More...]
|
|
Mandriva: 2010:112: glibc (Jun 8) |
|
Multiple vulnerabilities was discovered and fixed in glibc: Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory [More...]
|
|
Mandriva: 2010:111: glibc (Jun 8) |
|
Multiple vulnerabilities was discovered and fixed in glibc: Multiple integer overflows in the strfmon implementation in the GNU C Library (aka glibc or libc6) 2.10.1 and earlier allow context-dependent attackers to cause a denial of service (memory [More...]
|
|
Mandriva: 2010:084: java-1.6.0-openjdk (Jun 5) |
|
Multiple Java OpenJDK security vulnerabilities has been identified and fixed: - TLS: MITM attacks via session renegotiation (CVE-2009-3555). - Loader-constraint table allows arrays instead of only the b [More...]
|
|
Mandriva: 2010:090-1: samba (Jun 5) |
|
Multiple vulnerabilies has been found and corrected in samba: client/mount.cifs.c in mount.cifs in smbfs in Samba does not verify that the (1) device name and (2) mountpoint strings are composed of valid characters, which allows local users to cause a denial of service [More...]
|
|
Mandriva: 2010:094: tetex (Jun 5) |
|
Multiple vulnerabilities has been discovered and fixed in tetex: Buffer overflow in BibTeX 0.99 allows context-dependent attackers to cause a denial of service (memory corruption and crash) via a long .bib bibliography file (CVE-2009-1284). [More...]
|
|
Mandriva: 2010:095: libxext (Jun 5) |
|
A vulnerability has been discovered and fixed in libxext: There's a race condition in libXext that causes apps that use the X shared memory extensions to occasionally crash. [More...]
|
|
Mandriva: 2010:096: tetex (Jun 5) |
|
Multiple vulnerabilities has been discovered and fixed in tetex: Multiple buffer overflows in the JBIG2 decoder in Xpdf 3.02pl2 and earlier allow remote attackers to cause a denial of service (crash) via a crafted PDF file, related to (1) setBitmap and (2) [More...]
|
|
Mandriva: 2010:097: pidgin (Jun 5) |
|
A security vulnerability has been identified and fixed in pidgin: The msn_emoticon_msg function in slp.c in the MSN protocol plugin in libpurple in Pidgin before 2.7.0 allows remote attackers to cause a denial of service (application crash) via a custom emoticon in a [More...]
|
|
Mandriva: 2010:099: wireshark (Jun 5) |
|
This advisory updates wireshark to the latest version(s), fixing several bugs and one security issue: The DOCSIS dissector in Wireshark 0.9.6 through 1.0.12 and 1.2.0 through 1.2.7 allows user-assisted remote attackers to cause a denial [More...]
|
|
Mandriva: 2010:098: kdenetwork4 (Jun 5) |
|
A vulnerability has been discovered and fixed in kget (kdenetwork4): The name attribute of the file element of metalink files is not properly sanitized before being used to download files. If a user is tricked into downloading from a specially crafted metalink file, [More...]
|
|
Mandriva: 2010:100: krb5 (Jun 5) |
|
A vulnerability has been found and corrected in krb5: Certain invalid GSS-API tokens can cause a GSS-API acceptor (server) to crash due to a null pointer dereference in the GSS-API library (CVE-2010-1321). [More...]
|
|
Mandriva: 2010:101: mysql (Jun 5) |
|
A vulnerability has been found and corrected in mysql: It was possible for DROP TABLE of one MyISAM table to remove the data and index files of a different MyISAM table (CVE-2010-1626). [More...]
|
|
Mandriva: 2010:102: ghostscript (Jun 5) |
|
A vulnerability has been found and corrected in ghostscript: Stack-based buffer overflow in the parser function in GhostScript 8.70 and 8.64 allows context-dependent attackers to execute arbitrary code via a crafted PostScript file (CVE-2010-1869). [More...]
|
|
Mandriva: 2010:082-1: clamav (Jun 5) |
|
Multiple vulnerabilities has been found and corrected in clamav: ClamAV before 0.96 does not properly handle the (1) CAB and (2) 7z file formats, which allows remote attackers to bypass virus detection via a crafted archive that is compatible with standard archive utilities [More...]
|
|
Mandriva: 2010:103: postgresql (Jun 5) |
|
Multiple vulnerabilities was discovered and corrected in postgresql: The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified [More...]
|
|
Mandriva: 2010:104: dovecot (Jun 5) |
|
A vulnerability was discovered and corrected in dovecot: Unspecified vulnerability in Dovecot 1.2.x before 1.2.11 allows remote attackers to cause a denial of service (CPU consumption) via long headers in an e-mail message (CVE-2010-0745). [More...]
|
|
Mandriva: 2010:105: openoffice.org (Jun 5) |
|
This updates provides a new OpenOffice.org version 3.1.1. It holds security and bug fixes described as follow: An integer underflow might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, [More...]
|
|
Mandriva: 2010:106: aria2 (Jun 5) |
|
A vulnerability was discovered in aria2 which allows remote attackers to create arbitrary files via directory traversal sequences in the name attribute of a file element in a metalink file (CVE-2010-1512). This update fixes this issue. [More...]
|
|
Mandriva: 2010:107: mysql (Jun 5) |
|
Multiple vulnerabilities has been found and corrected in mysql: The server failed to check the table name argument of a COM_FIELD_LIST command packet for validity and compliance to acceptable table name standards. This could be exploited to bypass almost all forms of [More...]
|
|
Mandriva: 2010:108: kolab-horde-framework (Jun 5) |
|
A vulnerability was discovered and fixed in kolab-horde-framework: Unspecified vulnerability in Kolab Webclient before 1.2.0 in Kolab Server before 2.2.3 allows attackers to have an unspecified impact via vectors related to an image upload form. (CVE-2009-4824). [More...]
|
|
Mandriva: 2010:109: gtk+2.0 (Jun 5) |
|
A vulnerability was discovered and fixed in gtk+2.0: gdk/gdkwindow.c in GTK+ before 2.18.5, as used in gnome-screensaver before 2.28.1, performs implicit paints on windows of type GDK_WINDOW_FOREIGN, which triggers an X error in certain circumstances [More...]
|
|
Mandriva: 2010:110: clamav (Jun 5) |
|
Multiple vulnerabilities was discovered and fixed in clamav: The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length [More...]
|
|
|
|
Red Hat: 2010:0457-01: perl: Moderate Advisory (Jun 7) |
|
Updated perl packages that fix two security issues are now available for Red Hat Enterprise Linux 3 and 4. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0458-02: perl: Moderate Advisory (Jun 7) |
|
Updated perl packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0459-01: openoffice.org: Moderate Advisory (Jun 7) |
|
Updated openoffice.org packages that fix one security issue are now available for Red Hat Enterprise Linux 4 and 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0380-01: kernel: Important Advisory (Jun 5) |
|
Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 5.4 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0382-01: xorg-x11-server: Important Advisory (Jun 5) |
|
Updated xorg-x11-server packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0383-01: java-1.6.0-ibm: Critical Advisory (Jun 5) |
|
Updated java-1.6.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary. The Red Hat Security Response Team has rated this update as having critical [More...]
|
|
Red Hat: 2010:0394-01: kernel: Important Advisory (Jun 5) |
|
Updated kernel packages that fix multiple security issues, several bugs, and add three enhancements are now available for Red Hat Enterprise Linux 4. [More...]
|
|
Red Hat: 2010:0398-01: kernel: Important Advisory (Jun 5) |
|
Updated kernel packages that fix multiple security issues and several bugs are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0399-01: tetex: Moderate Advisory (Jun 5) |
|
Updated tetex packages that fix multiple security issues are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0400-01: tetex: Moderate Advisory (Jun 5) |
|
Updated tetex packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0401-01: tetex: Moderate Advisory (Jun 5) |
|
Updated tetex packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0423-01: krb5: Important Advisory (Jun 5) |
|
Updated krb5 packages that fix one security issue are now available for Red Hat Enterprise Linux 3, 4, and 5. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0424-01: kernel: Important Advisory (Jun 5) |
|
Updated kernel packages that fix one security issue and add one enhancement are now available for Red Hat Enterprise Linux 4.7 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0427-01: postgresql: Moderate Advisory (Jun 5) |
|
Updated postgresql packages that fix multiple security issues are now available for Red Hat Enterprise Linux 3. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0429-01: postgresql: Moderate Advisory (Jun 5) |
|
Updated postgresql packages that fix multiple security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0428-01: postgresql: Moderate Advisory (Jun 5) |
|
Updated postgresql packages that fix multiple security issues are now available for Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0430-01: postgresql84: Moderate Advisory (Jun 5) |
|
Updated postgresql84 packages that fix two security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0439-01: kernel: Important Advisory (Jun 5) |
|
Updated kernel packages that fix one security issue and two bugs are now available for Red Hat Enterprise Linux 5.3 Extended Update Support. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0442-01: mysql: Important Advisory (Jun 5) |
|
Updated mysql packages that fix three security issues are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]
|
|
Red Hat: 2010:0449-01: rhn-client-tools: Moderate Advisory (Jun 5) |
|
Updated rhn-client-tools packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having moderate [More...]
|
|
Red Hat: 2010:0383-01: java-1.6.0-ibm: Critical Advisory (Jun 5) |
|
Updated java-1.6.0-ibm packages that fix several security issues are now available for Red Hat Enterprise Linux 4 Extras and 5 Supplementary. The Red Hat Security Response Team has rated this update as having critical [More...]
|
|
Red Hat: 2010:0382-01: xorg-x11-server: Important Advisory (Jun 5) |
|
Updated xorg-x11-server packages that fix one security issue are now available for Red Hat Enterprise Linux 5. The Red Hat Security Response Team has rated this update as having [More...]
|
|
|
|
(Jun 5) |
|
New kdebase-workspace packages are available for Slackware 13.0 and -current to fix a security issue with KDM. [More Info...]
|
|
(Jun 5) |
|
New sudo packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, and -current to fix security issues. [More Info...]
|
|
(Jun 5) |
|
New irssi packages are available for Slackware 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, and -current to fix security issues. [More Info...]
|
|
(Jun 5) |
|
New fetchmail packages are available for Slackware 8.1, 9.0, 9.1, 10.0, 10.1, 10.2, 11.0, 12.0, 12.1, 12.2, 13.0, and -current to fix a security issue. [More Info...]
|
|
(Jun 5) |
|
New pidgin packages are available for Slackware 12.0, 12.1, 12.2, 13.0, and -current to fix a security issue. [More Info...]
|
|
|
|
SuSE: 2010-024: flash player (Jun 11) |
|
Adobe Flash Player was updated to fix multiple critical security vulnerabilities which allow an attacker to remotely execute arbitrary code or to cause a denial of service. The Flash Plugin was upgraded to version 10.1.53.64. The following CVE numbers have been assigned: [More...]
|
|
SuSE: 2010-023: Linux kernel (Jun 5) |
|
This update fixes several security issues and various bugs in the SUSE Linux Enterprise 10 SP 2 kernel. The bugs fixed include a serious data corruption regression in NFSv4 introduced by the previous update. Following security issues were fixed: CVE-2009-4537: drivers/net/r8169.c in the r8169 driver in the Linux [More...]
|
|
SuSE: Weekly Summary 2010:011 (Jun 5) |
|
To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. List of vulnerabilities in this summary include: dovecot12, cacti, java-1_6_0-openjdk, irssi, tar, fuse, apache2, libmysqlclient-devel, cpio, moodle, libmikmod, libicecore, evolution-data-server, libpng/libpng-devel, libesmtp.
|
|
SuSE: Weekly Summary 2010:012 (Jun 5) |
|
To avoid flooding mailing lists with SUSE Security Announcements for minor issues, SUSE Security releases weekly summary reports for the low profile vulnerability fixes. The SUSE Security Summary Reports do not list or download URLs like the SUSE Security Announcements that are released for more severe vulnerabilities. List of vulnerabilities in this summary include: evolution-data-server, python/libpython2_6-1_0, mozilla-nss, memcached, texlive/te_ams, mono/bytefx-data-mysql, libpng-devel, apache2-mod_php5, ncpfs, pango, libcmpiutil.
|
|
|
|
Ubuntu: 949-1: OpenOffice.org vulnerability (Jun 8) |
|
Marc Schoenefeld discovered that OpenOffice.org would run document macrosfrom the macro browser, even when macros were disabled. If a user weretricked into opening a specially crafted document and examining a macro,a remote attacker could execute arbitrary code with user privileges. [More...]
|
|
Ubuntu: 933-1: PostgreSQL vulnerability (Jun 5) |
|
It was discovered that PostgreSQL did not properly sanitize its input whenusing substring() with a SELECT statement. A remote authenticated attackercould exploit this to cause a denial of service via application crash. [More...]
|
|
Ubuntu: 934-1: Netpbm vulnerability (Jun 5) |
|
Marc Schoenefeld discovered a buffer overflow in Netpbm when loadingcertain images. If a user or automated system were tricked into opening aspecially crafted XPM image, a remote attacker could crash Netpbm. Thedefault compiler options for affected releases should reduce thevulnerability to a denial of service. [More...]
|
|
Ubuntu: 936-1: dvipng vulnerability (Jun 5) |
|
Dan Rosenberg discovered that dvipng incorrectly handled certain malformeddvi files. If a user or automated system were tricked into processing aspecially crafted dvi file, an attacker could cause a denial of service viaapplication crash, or possibly execute arbitrary code with the privilegesof the user invoking the program. [More...]
|
|
Ubuntu: 938-1: KDENetwork vulnerability (Jun 5) |
|
It was discovered that KGet did not properly perform input validation whenprocessing metalink files. If a user were tricked into opening a craftedmetalink file, a remote attacker could overwrite files via directorytraversal, which could eventually lead to arbitrary code execution. [More...]
|
|
Ubuntu: 939-1: X.org vulnerabilities (Jun 5) |
|
Lo
|