LinuxLinks.com
Newbies What Next ? News Forums Calendar

Search





News Sections
Home
General News (3972/0)
Reviews (626/0)
Press Releases (464/0)
Distributions (187/0)
Software (807/0)
Hardware (522/0)
Security (192/0)
Tutorials (337/0)
Off Topic (180/0)


User Functions
Username:

Password:

Don't have an account yet? Sign up as a New User


Events
There are no upcoming events



Six Debian Security Advisories   
Monday, December 04 2006 @ 04:03 PM EST
Contributed by: sde

1. DSA-1223-1 - New tar packages fix arbitrary file overwrite
2. DSA 1224-1 - New Mozilla packages fix several vulnerabilities
3. DSA 1225-2 - New Mozilla Firefox packages fix several vulnerabilities
4. DSA 1226-1 - New links packages fix arbitrary shell command execution
5. DSA 1227-1 - New Mozilla Thunderbird packages fix several vulnerabilities
6. DSA 1205-2 - New thttpd packages fix insecure temporary file creation

1. Teemu Salmela discovered a vulnerability in GNU tar that could allow a malicious user to overwrite arbitrary files by inducing the victim to attempt to extract a specially crafted tar file containing a GNUTYPE_NAMES record with a symbolic link.

2. Several security related problems have been discovered in Mozilla and derived products.

3. Several security related problems have been discovered in Mozilla and derived products such as Mozilla Firefox.

4. Teemu Salmela discovered that the links character mode web browser performs insufficient sanitising of smb:// URIs, which might lead to the execution of arbitrary shell commands.

5. Several security related problems have been discovered in Mozilla and derived products such as Mozilla Thunderbird.

6. Marco d'Itri discovered that thttpd, a small, fast and secure webserver, makes use of insecure temporary files when its logfiles are rotated, which might lead to a denial of service through a symlink attack.

Read more

  [ Views: 1590 ]  


Six Debian Security Advisories | 0 comments | Create New Account
The following comments are owned by whoever posted them. This site is not responsible for what they say.
No user comments.


What's Related
  • Read more
  • More by sde
  • More from Security


  • Story Options
  • Mail Story to a Friend
  • Printable Story Format


  • We have written a range of guides highlighting excellent free books for popular programming languages. Check out the following guides: C, C++, C#, Java, JavaScript, CoffeeScript, HTML, Python, Ruby, Perl, Haskell, PHP, Lisp, R, Prolog, Scala, Scheme, and SQL.

    Built with GeekLog and phpBB
    Comments to the webmaster are welcome
    Copyright 2009 LinuxLinks.com - All rights reserved