Welcome to the LinuxSecurity.com advisories section. Our goal is to provide a centralized security advisory resource to members of the Linux / BSD / Open Source communites. We are currently monitoring and maintaining up to date listings of advisories for many of the major Linux and BSD distributions. If you are using a distribution that is not listed you will most likely be able to find any relevant advisories under the Other section.
If you are aware of any recent advisories that we have not posted you can let us know about it by clicking on the Contribute! image or by clicking here.
Recent Advisories
Below are the fifteen most recent advisories. For more please click on the vendor link on the left of the page.
| 8/14/2000 20:55 - FreeBSD: zope vulerability |
| zope is an object-based dynamic web application platform. |
|   |
| 8/14/2000 20:54 - FreeBSD: cvsweb vulnerability |
| cvsweb is a CGI script which provides a read-only interface to a CVS
repository for browsing via a web interface. |
|   |
| 8/14/2000 20:52 - FreeBSD: ntop vulnerability |
| ntop is a utility for monitoring and summarizing network usage, from
the command-line or remotely via HTTP. |
|   |
| 8/14/2000 20:51 - FreeBSD: proftpd vulnerability |
| The proftpd port, versions prior to 1.2.0rc2, contains a vulnerability
which allows FTP users, both anonymous FTP users and those with a
valid account, to execute arbitrary code as root on the local machine, |
|   |
| 8/14/2000 20:49 - FreeBSD: dhclient vulnerability |
| dhclient is vulnerable to malicious dhcp server. |
|   |
| 8/14/2000 18:51 - Trustix: perl and mailx vulnerability |
| Truxtix reports the same problem as others with perl and mailx. |
|   |
| 8/13/2000 15:02 - SuSE: perl vulnerability |
| suidperl is the perl interpreter for suid perl scripts, a part of the
perl package. A maliciously implemented feature causes the interpreter
to spawn the /bin/mail program to inform the superuser of its usage,
thereby passing on untrusted environment that causes /bin/mail to
execute arbitrary commands as user root. |
|   |
| 8/12/2000 20:49 - Mandrake: MandrakeUpdate vulnerability |
| There is a possible race condition in MandrakeUpdate that has the potential for users to tamper with RPMs downloaded by MandrakeUpdate prior to them being installed. |
|   |
| 8/12/2000 3:05 - FlagShip: insecure permission vulnerability |
| Several binary files are world
writeable. Anyone could
replace them with a trojan
and trick someone to
execute the trojaned binary
files. |
|   |
| 8/12/2000 3:03 - Gopherd: authentication vulnerability |
| If properly exploited,
this vulnerability allows a remote user to gain unauthorized root access to
affected systems. |
|   |
| 8/12/2000 3:01 - Conectiva: perl vulnerability |
| sperl uses /bin/mail in an insecure manner, possibly resulting in a root compromise. |
|   |
| 8/12/2000 2:58 - RedHat: usermode vulnerability |
| Console users can obtain root privileges |
|   |
| 8/12/2000 2:57 - Conectiva: usermode vulnerability |
| Console users can obtain root privileges |
|   |
| 8/12/2000 2:55 - RedHat: Zope Vulnerability |
| Vulnerabilities exist with all Zope-2.0 releases. |
|   |
| 8/12/2000 2:54 - Conectiva: Netscape Vulnerability |
| Netscape version 4.73 and below have a flaw in the processing of JPEG
images that could result in commands being executed in the client
machine. |
|   |