Monthly Archives: July, 2008
Debian: New httrack packages fix arbitrary code execution
Posted in Server & Linux Security
LinuxSecurity.com: Joan Calvet discovered that httrack, a utility to create local copies of websites, is vulnerable to a buffer overflow potentially allowing to execute arbitrary code when passed excessively long URLs.
Gentoo: Python Multiple vulnerabilities
Posted in Server & Linux Security
LinuxSecurity.com: Multiple vulnerabilities in Python may allow for the execution of arbitrary code.
Debian: New libxslt packages fix arbitrary code execution
Posted in Server & Linux Security
LinuxSecurity.com: Chris Evans discovered that a buffer overflow in the RC4 functions of libexslt may lead to the execution of arbitrary code.
Gentoo: Pan User-assisted execution of arbitrary code
Posted in Server & Linux Security
LinuxSecurity.com: A buffer overflow vulnerability in Pan may allow remote attacker to execute arbitrary code.
Gentoo: VLC Multiple vulnerabilities
Posted in Server & Linux Security
LinuxSecurity.com: Multiple vulnerabilities in VLC may allow for the execution of arbitrary code.
Debian: New dnsmasq packages fix cache poisoning
Posted in Server & Linux Security
LinuxSecurity.com: This update changes Debian's dnsmasq packages to implement the recommended countermeasure: UDP query source port randomization. This change increases the size of the space from which an attacker has to guess values in a backwards-compatible fashion and makes successful attacks significantly more difficult.
Netcraft Toolbar for Firefox 3 ? Win an iPod
Posted in Server News
A new version of the Netcraft Toolbar is now available for the Firefox 3 web browser.
Related Netcraft Service: Netcraft Anti-Phishing Toolbar
Related Netcraft Service: Netcraft Anti-Phishing Toolbar
Slackware: libxslt
Posted in Server & Linux Security
LinuxSecurity.com: New libxslt packages are available for Slackware 12.0, 12.1, and -current to fix a security issue. A buffer overflow when processing XSL stylesheets could result in the execution of arbitrary code.
Slackware: mtr
Posted in Server & Linux Security
LinuxSecurity.com: New mtr packages are available for Slackware 12.0, 12.1, and -current to fix a security issue. Upgraded to mtr-0.73. This fixes a minor security bug where a very long hostname in the trace path could lead to an overflow (and most likely just a crash).
Slackware: links
Posted in Server & Linux Security
LinuxSecurity.com: New links packages are available for Slackware 11.0, 12.0, 12.1, and -current to fix a security issue when using proxies.Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."



