LinuxSecurity.com - Security AdvisoriesThe central voice for Linux and Open Source security news.Mandriva: Updated Firefox packages fix vulnerabilities- July 17, 2008 LinuxSecurity.com: Security vulnerabilities have been discovered and corrected in the latest Mozilla Firefox program, version 2.0.0.16 (CVE-2008-2785, CVE-2008-2933).http://www.linuxsecurity.com/content/view/140006?rdf Ubuntu: Firefox vulnerabilities- July 17, 2008 LinuxSecurity.com: A flaw was discovered in the browser engine. A variable could be made to overflow causing the browser to crash. If a user were tricked into opening a malicious web page, an attacker could cause a denial of service or possibly execute arbitrary code with the privileges of the user invoking the program. (CVE-2008-2785)http://www.linuxsecurity.com/content/view/140005?rdf Slackware: mozilla-firefox- July 17, 2008 LinuxSecurity.com: New mozilla-firefox packages are available for Slackware 10.2, 11.0, 12.0, and 12.1 to fix security issues. More details about the issues may be found on the Mozilla site: http:www.mozilla.orgsecurityknown-vulnerabilitiesfirefox20.htmlhttp://www.linuxsecurity.com/content/view/139938?rdf Slackware: seamonkey- July 17, 2008 LinuxSecurity.com: New seamonkey packages are available for Slackware 11.0, 12.0, 12.1, and -current to fix security issues. More details about the issues may be found here: http:www.mozilla.orgsecurityknown-vulnerabilitiesseamonkey11.htmlhttp://www.linuxsecurity.com/content/view/139939?rdf Debian: New afuse packages fix privilege escalation- July 16, 2008 LinuxSecurity.com: Anders Kaseorg discovered that afuse, an automounting file system in user-space, did not properly escape meta characters in paths. This allowed a local attacker with read access to the filesystem to execute commands as the owner of the filesystem.http://www.linuxsecurity.com/content/view/139936?rdf Debian: New pdns-recursor packages fix predictable randomness- July 16, 2008 LinuxSecurity.com: Thomas Biege discovered that the upstream fix for the weak random number generator released in DSA-1544-1 was incomplete: Source port randomization did still not use difficult-to-predict random numbers. This is corrected in this security update.http://www.linuxsecurity.com/content/view/139935?rdf |