
|
Find the information you need for your favorite open source distribution
To browse through our weekly Linux Advisory Watch newsletters, click here.
|
|
|
Posted by Benjamin D. Thomas
|
|
Andy Polyakov discovered that the DTLS implementation in OpenSSL
was vulnerable. A remote attacker could send a specially crafted
connection request to services using DTLS and execute arbitrary code
with the service's privileges. There are no known Ubuntu applications
that are currently using DTLS.
|
|
|
Posted by Benjamin D. Thomas
|
|
Nobuhiro Ban discovered that check_http in nagios-plugins did
not properly sanitize its input when following redirection
requests. A malicious remote web server could cause a denial
of service or possibly execute arbitrary code as the user.
|
|
|
Posted by Benjamin D. Thomas
|
|
Nahuel Riva and Gerardo Richarte discovered that the DHCP server did not
correctly handle certain client options. A remote attacker could send
malicious DHCP replies to the server and execute arbitrary code.
|
|
|
Posted by Benjamin D. Thomas
|
|
It was discovered that the hpssd tool of hplip did not correctly handle
shell meta-characters. A local attacker could exploit this to execute
arbitrary commands as the hplip user.
|
|
|
Posted by Benjamin D. Thomas
|
|
It was discovered that Tk could be made to overrun a buffer when loading
certain images. If a user were tricked into opening a specially crafted
GIF image, remote attackers could cause a denial of service or execute
arbitrary code with user privileges.
|
|
|
Posted by Benjamin D. Thomas
|
|
Neil Kettle discovered that MySQL could be made to dereference a NULL
pointer and divide by zero. An authenticated user could exploit this
with a crafted IF clause, leading to a denial of service. (CVE-2007-2583)
Victoria Reznichenko discovered that MySQL did not always require the
DROP privilege. An authenticated user could exploit this via RENAME
TABLE statements to rename arbitrary tables, possibly gaining additional
database access. |
|
|
Posted by Benjamin D. Thomas
|
|
Joris van Rantwijk discovered that the Xen host did not correctly validate
the contents of a Xen guests's grug.conf file. Xen guest root users could
exploit this to run arbitrary commands on the host when the guest system
was rebooted.
|
|
|
<< Start < Prev 163 164 165 Next > End >>
|
| Results 1135 - 1141 of 1354 |