LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
How strictly do your users obey your security policies?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
Emily Ratliff: OS Security
DanWalsh LiveJournal
Security Bloggers Network
Latest Newsletters
Linux Advisory Watch: November 21st, 2008
Linux Security Week: November 17th, 2008
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Mandriva
Find the information you need for your favorite open source distribution

To browse through our weekly Linux Advisory Watch newsletters, click here.



Mandriva: Subject: [Security Announce] [ MDVSA-2008:218 ] lynx  28 October 2008 
A vulnerability was found in the Lynxcgi: URI handler that could allow an attacker to create a web page redirecting to a malicious URL that would execute arbitrary code as the user running Lynx, if they were using the non-default Advanced user mode (CVE-2008-4690). This update corrects these issues and, in addition, makes Lynx always prompt the user before loading a lynxcgi: URI. As well, the default lynx.cfg configuration file marks all lynxcgi: URIs as untrusted.
 
Mandriva: Subject: [Security Announce] [ MDVSA-2008:217 ] lynx  28 October 2008 
A flaw was found in the way Lynx handled .mailcap and .mime.types configuration files. If these files were present in the current working directory, they would be loaded prior to similar files in the user's home directory. This could allow a local attacker to possibly execute arbitrary code as the user running Lynx, if they could convince the user to run Lynx in a directory under their control (CVE-2006-7234)
 
Mandriva: Subject: [Security Announce] [ MDVSA-2008:216 ] emacs  27 October 2008 
A vulnerability was found in how Emacs would import python scripts from the current working directory during the editing of a python file. This could allow a local user to execute arbitrary code via a trojan python file (CVE-2008-3949).
 
Mandriva: Subject: [Security Announce] [ MDVSA-2008:215 ] wireshark  27 October 2008 
A number of vulnerabilities were discovered in Wireshark that could cause it to crash or abort while processing malicious packets
 
Mandriva: Subject: [Security Announce] [ MDVA-2008:155 ] kdebase4-runtime  22 October 2008 
When an attachment file is opened in a KDE4 application, it is copied to a temporary directory and opened by a 'kioexec' process. When you close the application, the 'kioexec' process should automatically close after some minutes of inactivity in the temporary file. The kdebase4-runtime package released in Mandriva Linux 2009 has a bug which prevents the 'kioexec' process from closing. This update fixes the problem.
 
Mandriva: Subject: [Security Announce] [ MDVA-2008:154 ] util-linux-ng  21 October 2008 
Several bugs were found in util-linux-ng package: - Using an offset on loopback device was broken - Creating an encrypted loopback with losetup -e was broken - Using fdisk to modify the partition table of an image file did not write the changes The updated package fixes these issues.
 
Mandriva: Subject: [Security Announce] [ MDVSA-2008:208-1 ] pam_mount  18 October 2008 
pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. The updated packages have been patched to fix the issue. Update: The fix for CVE-2008-3970 uncovered crashes in the code handling the 'allow', 'deny', and 'require' options in pam_mount-0.33, released for Mandriva Linux 2008 Spring. Also, the verification of the allowed mount options ('allow' configuration directive) was inverted in pam_mount-0.33. This update fixes these issues.
 
<< Start < Prev 4 5 6 Next > End >>

Results 22 - 28 of 1613
    
Partner:

 

Latest Features
A Secure Nagios Server
Never Installed a Firewall on Ubuntu? Try Firestarter
Review: Hacking Exposed Linux, Third Edition
Security Features of Firefox 3.0
Review: The Book of Wireless
April 2008 Open Source Tool of the Month: sudo
Open Source Tool of March: ZoneMinder
Yesterday's Edition
Hardening The Linux Kernel With Grsecurity (Debian)
Upcoming Conference Talks on SELinux Applications: sVirt and Kiosk Mode

QuickLinks: Comunity , HOWTOs , Blogs , Features , Book Reviews , Networking ,
  Security Projects ,   Latest News ,  Newsletters ,  SELinux ,  Privacy ,  Home,
 Hardening ,   About Us,   Advertise,   Legal Notice,   RSS,   Guardian Digital

(c)Copyright 2008 Guardian Digital, Inc. All rights reserved.