Re: Glibc Local Root Exploit

2001-01-12 Thread Matt Zimmerman
On Thu, Jan 11, 2001 at 01:42:52AM +0200, Ari Saastamoinen wrote: On Wed, 10 Jan 2001, Pedro Margate wrote: install the ssh binary as suid root by default. This can be disabled during configuration or after the fact with chmod. I believe that would That exploit can use any suid root

Re: summary of recent glibc bugs (Re: SuSE Security Announcement: shlibs/glibc (SuSE-SA:2001:01))

2001-01-30 Thread Matt Zimmerman
On Sat, Jan 27, 2001 at 05:55:25AM +0300, Solar Designer wrote: The glibc 2.2 RESOLV_HOST_CONF bug which prompted this search for bugs was reported to Debian by Dale Thatcher but apparently wasn't kept private. The remaining bugs were discovered and dealt with within two days following the

Re: SuSe / Debian man package format string vulnerability

2001-02-05 Thread Matt Zimmerman
On Mon, Feb 05, 2001 at 06:34:47AM -0500, John wrote: On my Debian 2.2 system 'man' was installed suid root. I don't know about Debian 2.3 but, Debian 2.2 does install 'man' suid root. Are you certain? In Debian stable (2.2, potato), man is installed setgid man. In Debian unstable and

Cisco Secure Content Accelerator vulnerable to SSL worm

2002-10-04 Thread Matt Zimmerman
Product : Cisco SCA 11000 Series Secure Content Accelerator Product URL : http://www.cisco.com/warp/customer/cc/pd/cxsr/ps2083/ CVE : CAN-2002-0656 Software release: All current releases Vendor status : PSIRT and TAC notified 2002/09/17, last update 2002/09/24 Patch

[SECURITY] [DSA-307-1] New gps packages fix multiple vulnerabilities

2003-05-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 307-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman May 27th, 2003

[SECURITY] [DSA-319-1] New webmin packages fix remote session ID spoofing

2003-06-13 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 319-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 12th, 2003

[SECURITY] [DSA-318-1] New lyskom-server packages fix denial of service

2003-06-13 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 318-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 12th, 2003

[SECURITY] [DSA-321-1] New radiusd-cistron packages fix buffer overflow

2003-06-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 321-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 13th, 2003

[SECURITY] [DSA-323-1] New noweb packages fix insecure temporary file creation

2003-06-17 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 323-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 16th, 2003

[SECURITY] [DSA-322-1] New typespeed packages fix buffer overflow

2003-06-17 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 322-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 16th, 2003

[SECURITY] [DSA-324-1] New ethereal packages fix multiple vulnerabilities

2003-06-18 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 324-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 18th, 2003

[SECURITY] [DSA-316-3] New jnethack packages fix buffer overflow, incorrect permissions

2003-06-18 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 316-3 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 17th, 2003

[SECURITY] [DSA-325-1] New eldav packages fix insecure temporary file creation

2003-06-20 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 325-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 19th, 2003

[SECURITY] [DSA-330-1] New tcptraceroute packages fix failure to drop root privileges

2003-06-24 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 330-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 23rd, 2003

[SECURITY] [DSA-336-2] Factual correction for DSA-336-1

2003-07-01 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 336-2 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 29th, 2003

[SECURITY] [DSA-337-1] New semi, wemi packages fix insecure temporary file creation

2003-07-07 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 337-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 6th, 2003

[SECURITY] [DSA-339-1] New semi, wemi packages fix insecure temporary file creation

2003-07-07 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 339-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 6th, 2003

[SECURITY] [DSA-338-1] New x-face-el packages fix insecure temporary file creation

2003-07-07 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 338-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 6th, 2003

[SECURITY] [DSA-341-1] New liece packages fix insecure temporary file creation

2003-07-08 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 341-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 7th, 2003

[SECURITY] [DSA-342-1] New mozart packages fix unsafe mailcap configuration

2003-07-08 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 342-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 7th, 2003

[SECURITY] [DSA-347-1] New teapop packages fix SQL injection

2003-07-09 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 347-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 8th, 2003

[SECURITY] [DSA-344-1] New unzip packages fix directory traversal

2003-07-09 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 344-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 8th, 2003

[SECURITY] [DSA-343-1] New skk, ddskk packages fix insecure temporary file creation

2003-07-09 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 343-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 8th, 2003

[SECURITY] [DSA-346-1] New phpsysinfo packages fix directory traversal

2003-07-09 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 346-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 8th, 2003

[SECURITY] [DSA-331-1] New imagemagick packages fix insecure temporary file creation

2003-06-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 331-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 27th, 2003

[SECURITY] [DSA-332-1] New Linux 2.4.17 source code and MIPS kernel images fix several vulnerabilities

2003-06-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 332-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 27th, 2003

[SECURITY] [DSA-333-1] New acm packages fix integer overflow

2003-06-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 333-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 27th, 2003

[SECURITY] [DSA-334-1] New xgalaga packages fix buffer overflow

2003-06-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 334-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman June 28th, 2003

[SECURITY] [DSA-348-1] New traceroute-nanog packages fix integer overflow

2003-07-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 348-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 11th, 2003

[SECURITY] [DSA-350-1] New falconseye packages fix buffer overflow

2003-07-15 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 350-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 15th, 2003

[SECURITY] [DSA-351-1] New php4 packages fix cross-site scripting vulnerability

2003-07-17 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 351-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 16th, 2003

[SECURITY] [DSA-352-1] New fdclone packages fix insecure temporary directory usage

2003-07-23 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 352-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 22nd, 2003

[SECURITY] [DSA-353-1] New sup packages fix insecure temporary file creation

2003-07-29 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 353-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 29th, 2003

[SECURITY] [DSA-354-1] New xconq packages fix buffer overflows

2003-07-30 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 354-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 29th, 2003

[SECURITY] [DSA-355-1] New gallery packages fix cross-site scripting

2003-07-31 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 355-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 30th, 2003

[SECURITY] [DSA-356-1] New xtokkaetama packages fix buffer overflows

2003-07-31 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 356-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 30th, 2003

[SECURITY] [DSA-359-1] New atari800 packages fix buffer overflows

2003-08-01 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 359-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 31st, 2003

[SECURITY] [DSA-358-1] New kernel source and i386, alpha kernel images fix multiple vulnerabilities

2003-08-01 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 358-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman July 31st, 2003

[SECURITY] [DSA-363-1] New postfix packages fix remote denial of service, bounce scanning

2003-08-04 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 363-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 3rd, 2003

[SECURITY] [DSA-361-1] New kdelibs packages fix several vulnerabilities

2003-08-04 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 361-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 1st, 2003

[SECURITY] [DSA-370-1] New pam-pgsql packages fix format string vulnerability

2003-08-09 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 370-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 8th, 2003

[SECURITY] [DSA-367-1] New xtokkaetama packages fix buffer overflow

2003-08-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 367-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 8th, 2003

[SECURITY] [DSA-365-1] New phpgroupware package fix several vulnerabilities

2003-08-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 365-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 5th, 2003

[SECURITY] [DSA-371-1] New perl packages fix cross-site scripting

2003-08-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 371-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 11th, 2003

[SECURITY] [DSA-361-2] New kdelibs-crypto packages fix multiple vulnerabilities

2003-08-14 Thread Matt Zimmerman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 361-2 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman August 9th, 2003