Advertisement
Home arrow Search
Saturday, 22 November 2008
 
 
Last week attacks
O.S.  Defs.  %
Linux  8778  71.58%
Win 2003  1950  15.90%
Win 2000  722  5.89%
Solaris 9/10  402  3.28%
FreeBSD  226  1.84%
Other  185  1.51%

Total attacks: 12263 of which 4619 single ip and 7644 mass defacements

Main Menu
Home
Digital Warfare
Geopolitics
ITsec News
ITsec Advisories
Test Drive
360°
Digital Attacks Archive
Zone-H events
Publications
Zone-H Friends/Partners
Contact Us
Search
Download Area
Zone-H forum
About this website
Login Form





Lost Password?
No account yet? Register
Visitors' Map
[DSA 622-1] New htmlheadline package fixes insecure temporary files PDF Print E-mail
User Rating: / 0
PoorBest 
Wednesday, 05 January 2005
lists.debian.org/debian-security-announce/debian-security-announce-2005/msg00000.html
Debian Security Advisory DSA 622-1 This e-mail address is being protected from spam bots, you need JavaScript enabled to view it http://www.debian.org/security/ Martin Schulze January 3rd, 2005 http://www.debian.org/security/faq - -------------------------------------------------------------------------- Package : htmlheadline Vulnerability : insecure temporary files Problem-Type : local Debian-specific: no CVE ID : CAN-2004-1181 Javier Fernández-Sanguino Peña has discovered multiple insecure uses of temporary files that could lead to overwriting arbitrary files via a symlink attack. For the stable distribution (woody) these problems have been fixed in version 21.8-3. The unstable distribution (sid) does not contain this package. We recommend that you upgrade your htmlheadline package. Upgrade Instructions - -------------------- wget url will fetch the file for you dpkg -i file.deb will install the referenced file. If you are using the apt-get package manager, use the line for sources.list as given below: apt-get update will update the internal database apt-get upgrade will install corrected packages You may use an automated update by adding the resources from the footer to the proper configuration. Debian GNU/Linux 3.0 alias woody - -------------------------------- Source archives: http://security.debian.org/pool/updates/main/h/htmlheadline/htmlheadline_21.8-3.dsc Size/MD5 checksum: 579 36da72a4ff991d7646a77eb7d8789f8a http://security.debian.org/pool/updates/main/h/htmlheadline/htmlheadline_21.8-3.diff.gz Size/MD5 checksum: 5383 8c098ae1c43cf8f5f702191864e29b84 http://security.debian.org/pool/updates/main/h/htmlheadline/htmlheadline_21.8.orig.tar.gz Size/MD5 checksum: 42360 319b218bd8c787a1455540a85428adc6 Architecture independent components: http://security.debian.org/pool/updates/main/h/htmlheadline/htmlheadline_21.8-3_all.deb Size/MD5 checksum: 44570 c55c6906ba256b1731d8d6c5a151eaf1 These files will probably be moved into the stable distribution on its next update. - --------------------------------------------------------------------------------- For apt-get: deb http://security.debian.org/ stable/updates main For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main Mailing list: This e-mail address is being protected from spam bots, you need JavaScript enabled to view it Package info: `apt-cache show ' and http://packages.debian.org/ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.5 (GNU/Linux) iD8DBQFB2RjGW5ql+IAeqTIRAvN8AKCJDQBYVNW1DNsjagMRCeZ56eVbWQCfRJdt 5n+zy6EUGbdCr5z/eDt2x2A= =8I0+ -----END PGP SIGNATURE-----


Comments Index (Total Messages: 0)


Post Reply
Name:Guest
Title:
Comment:



Enter this security word

Powered by a Zone-H(ified) version of AkoComment 3.0!


DISCLAIMER: Forum postings are the opinion of the posting author alone, and should not be taken as the opinion of Zone-h. The   author is entirely and solely responsible for all content that he/she uploads, posts, or otherwise transmits via the website. Zone-h is not responsible for such content. However, Zone-h shall have the right, but not the obligation, to delete, move, or edit any content that violates this agreement or is otherwise objectionable as determined by Zone-h in its sole discretion and without notice.
 
< Prev   Next >
Advertisement
 
Top! Top!