Go Back   Science Forums > Physical Sciences Forums > Computer Science and Technology
Reply
 
LinkBack Thread Tools
Old 01-13-2005   #1 (permalink)
alexander's Avatar
Dedicated Smart-ass

Senior Moderator
Gallery Curator
Dev Team Member

Location:
Just before 0xAA55
 
alexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond reputealexander has a reputation beyond repute
Send a message via AIM to alexander
 



Not Ranked  0 score     
Update Your Linux Box!

"Linux vendors Red Hat, Novell/SUSE, Mandrakesoft, Debian and Gentoo have issued advisories and patches this week for a number of different vulnerabilities that have hit them.

Red Hat issued updates for its libtiff package, which includes a function library for manipulating TIFF image files. Security research firm iDefense had reported an integer overflow bug that affected the package that could have allowed an attacker to exploit it when open, causing an image to crash or execute arbitrary code.

The Xpdf Red Hat packages were also updated to prevent the exploitation of a buffer overflow that was found in the PDF viewer. Red Hat noted in its advisory, however, that the Exec-Shield technology (enabled by default since Update 3) will block attempts to exploit this vulnerability on x86 architectures.

Red Hat Enterprise Linux Update 3, which was released in September and also included NX (no execute) support, was a source of discussion on the main Linux Kernel developers' list in June.

Red Hat also updated its Mozilla packages to fix a buffer overflow issue (CAN-2004-1316) in the way the browser handles NNTP (define) URLs.

Novell's SUSE Linux issued updates for multiple vulnerabilities, which, if exploited, could lead to systems being compromised, as well as cross-site scripting and DoS attacks. In an e-mail to the SUSE security announcement list, Marcus Meissner noted that the update solved nine security vulnerabilities, including problems with acroread document parsing, iproute2 denial of service, namazu cross-site scripting and an mpg123 play list option buffer overflow.

Both Debian and Gentoo issued updates for their respective exim packages, which could have possibly been exploited to allow for a local privilege escalation attack. Exim is a configurable message transfer agent (MTA).

Additionally, Gentoo issued an update to cover the "multiple overflows [that] have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code."

Not to be left out of the patch bonanza, Mandrakesoft issued a patch for its imlib image handler packages. There was a heap overflow as well as integer overflow vulnerability in the packages that could have allowed an attacker to crash a system or execute arbitrary code when an image file was opened. The same vulnerability also exists in Gentoo's imlib2 packages and has also had a patch issued for it. "

http://www.internetnews.com/security/article.php/3458861

Such things happen rarely, but happen (actually many times more in microsoft operating systems). This is more of an advisory for all linux users to update their boxes, even though it is best to do this every day or at least once a week, lots of linux users neglect updating, shame on those that do... This is just a heads up for everyone to strengthen their security so their box doesnt get owned by any scriptie.

(Edit: P.S. in the smiley above, scriptie is the fly...)


----------------
Microsoft, the leader in using innovative tactics to promote irksome experience, coupled with antiquated technology that's held together by a pyramid of makeshift afterthoughts.

Apple, the leader in using irksome tactics to promote innovative experience, coupled with an antiquated core that's enhanced by state-of-the-art afterthoughts.

Linux, the leader in not using any tactics to promote user-defined experience, coupled with state-of-the-art core enhanced by innovative afterthoughts.

Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Linux & Windows pgrmdave Computer Science and Technology 22 01-19-2005 06:26 PM
Linux has fewer bugs than rivals. alexander Computer Science and Technology 16 12-16-2004 05:27 AM
What is your favorite Linux window manager? alexander Computer Science and Technology 4 11-17-2004 06:33 AM
Line up the LINUX geeks, please... IrishEyes Computer Science and Technology 10 09-14-2004 01:30 PM

» Advertisement
» Current Poll
Who's the sexiest man alive? Johnny Depp or Robert Pattinson?
Johnny Depp - 33.33%
3 Votes
Robert Pattinson - 0%
0 Votes
Someone else (please specify) - 44.44%
4 Votes
I'm too macho to think a guy is sexy - 22.22%
2 Votes
Total Votes: 9
You may not vote on this poll.


All times are GMT -8. The time now is 04:29 PM.

Hypography?

Hypography [n.]: A combination of "hyperlink" and "bibliography" - ie, a list of links to electronic documents. Comparable to discography and bibliography, but not cartography.

We have been online since May 2000, and aim to be the best place to find and share science-related content of all kinds.

Share the love!

Please add more science to your life. Use our RSS feeds on your blog, your portal, or your favorite feedreader!


Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
Copyright © 2000-2009 Hypography
Part of the Hypography - Science for Everyone Network