Monthly Archives: December, 2007
Mandriva: Updated ez-ipupdate packages correct crash on
Posted in Server & Linux Security
LinuxSecurity.com: A 64-bit type error in ez-ipupdate would cause it to creash on x86_64 systems. This update corrects the problem.
Gentoo: AMD64 x86 emulation GTK+ library User-assisted execution of arbitrary code
Posted in Server & Linux Security
LinuxSecurity.com: Multiple integer overflow vulnerabilities in the AMD64 x86 emulation GTK+ libraries may result in the execution of arbitrary code in applications using Cairo.
Gentoo: Mozilla Firefox, SeaMonkey Multiple vulnerabilities
Posted in Server & Linux Security
LinuxSecurity.com: Multiple vulnerabilities have been discovered in Mozilla Firefox and Mozilla Seamonkey.
Gentoo: ClamAV Multiple vulnerabilities
Posted in Server & Linux Security
LinuxSecurity.com: Multiple vulnerabilities have been discovered in ClamAV allowing remote execution of arbitrary code and Denial of Service attacks.
Gentoo: Syslog-ng Denial of Service
Posted in Server & Linux Security
LinuxSecurity.com: A Denial of Service vulnerability has been discovered in Syslog-ng.
December 2007 Web Server Survey
Posted in Server News
Fedora 8 Update: imlib-1.9.15-6.fc8
Posted in Server & Linux Security
LinuxSecurity.com: This update includes a fix for a denial-of-service issue (CVE-2007-3568) whereby an attacker who could get an imlib-using user to view a specially-crafted BMP image could cause the user's CPU to go into an infinite loop.
Debian: New peercast packages fix arbitrary code execution
Posted in Server & Linux Security
LinuxSecurity.com: Luigi Auriemma discovered that PeerCast, a P2P audio and video streaming server, is vulnerable to a heap overflow in the HTTP server code, which allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long SOURCE request.
Debian: New inotify-tools packages fix arbitrary code
Posted in Server & Linux Security
LinuxSecurity.com: It was discovered that a buffer overflow in the filename processing of the inotify-tools, a command-line interface to inotify, may lead to the execution of arbitrary code. This only affects the internal library and none of the frontend tools shipped in Debian.
Debian: New typo3-src packages fix SQL injection
Posted in Server & Linux Security
LinuxSecurity.com: Henning Pingel discovered that TYPO3, a web content management framework, performs insufficient input sanitising, making it vulnerable to SQL injection by logged-in backend users.



