
|
Find the information you need for your favorite open source distribution
To browse through our weekly Linux Advisory Watch newsletters, click here.
|
|
|
Posted by Benjamin D. Thomas
|
|
Luigi Auriemma discovered multiple flaws in pulseaudio's network
processing code. If an unauthenticated attacker sent specially crafted
requests to the pulseaudio daemon, it would crash, resulting in a denial
of service.
|
|
|
Posted by Benjamin D. Thomas
|
|
Philipp Richter discovered that the AppleTalk protocol handler did
not sufficiently verify the length of packets. By sending a crafted
AppleTalk packet, a remote attacker could exploit this to crash the
kernel.
|
|
|
Posted by Benjamin D. Thomas
|
|
Tomas Golembiovsky discovered that some vim commands were accidentally
allowed in modelines. By tricking a user into opening a specially
crafted file in vim, an attacker could execute arbitrary code with user
privileges.
|
|
|
Posted by Benjamin D. Thomas
|
|
A flaw was discovered in the FTP command handler in PHP. Commands were
not correctly filtered for control characters. An attacker could issue
arbitrary FTP commands using specially crafted arguments. |
|
|
Posted by Benjamin D. Thomas
|
|
USN-460-1 fixed several vulnerabilities in Samba. The upstream changes
for CVE-2007-2444 had an unexpected side-effect in Feisty. Paul Griffith and Andrew Hogue discovered that Samba did not fully drop root privileges while translating SIDs. A remote authenticated user could issue SMB operations during a small window of opportunity and gain root privileges. (CVE-2007-2444)
|
|
|
Posted by Benjamin D. Thomas
|
|
USN-459-1 fixed vulnerabilities in pptpd. However, a portion of the fix
caused a regression in session establishment under Dapper for certain
PPTP clients. This update fixes the problem.
We apologize for the inconvenience.
|
|
|
Posted by Benjamin D. Thomas
|
|
It was discovered that Quagga did not correctly verify length information sent from configured peers. Remote malicious peers could send a specially crafted UPDATE message which would cause bgpd to abort, leading to a denial of service.
|
|
|
<< Start < Prev 172 173 174 Next > End >>
|
| Results 1212 - 1218 of 1359 |