Category Archives: Server & Linux Security

The latest developments on the Server and Linux Security fronts

Debian: New libxml2 packages fix denial of service

LinuxSecurity.com: The previous security update of the libxml2 package introduced some problems with other packages, most notably with librsvg. This update corrects these problems whilst still fixing the reported scurity problem.

Debian: New tiff packages fix arbitrary code execution

LinuxSecurity.com: Drew Yao discovered that libTIFF, a library for handling the Tagged Image File Format, is vulnerable to a programming error allowing malformed tiff files to lead to a crash or execution of arbitrary code.

Ubuntu: Linux kernel vulnerabilities

LinuxSecurity.com: It was discovered that there were multiple NULL-pointer function dereferences in the Linux kernel terminal handling code. A local attacker could exploit this to execute arbitrary code as root, or crash the system, leading to a denial of service. (CVE-2008-2812)

Debian: New libxml2 packages fix denial of service

LinuxSecurity.com: Andreas Solberg discovered that libxml2, the GNOME XML library, could be forced to recursively evaluate entities, until available CPU & memory resources were exhausted.

RedHat: Critical: openssh security update

LinuxSecurity.com: These packages also fix a low severity flaw in the way ssh handles X11 cookies when creating X11 forwarding connections. When ssh was unable to create untrusted cookie, ssh used a trusted cookie instead, possibly allowing the administrative user of a untrusted remote server, or untrusted application run on the remote server, to gain unintended access to a users local X server

Mandriva: Subject: [Security Announce] [ MDVSA-2008:180 ] libxml2

LinuxSecurity.com: Andreas Solberg found a denial of service flaw in how libxml2 processed certain content. If an application linked against libxml2 processed such malformed XML content, it could cause the application to stop responding (CVE-2008-3281). The updated packages have been patched to prevent this issue.

All trademarks and copyrights owned by their respective owners and are used for illustration only
Kokopelli Creative Web Design
Webhosting Admin | Bargain Host | Host Wiki | Mean Servers | domainRIFFIC | Domain Sell | Domain a Lot | Domain Say | Site Gazette | Domain Names Pimp | Domain Dojo