MESSAGE
DATE | 2002-08-13 |
FROM | Ruben I Safir
|
SUBJECT | Subject: [hangout] Fwd: Your Linux Today Security Letter for August 13, 2002 [listsupport@internet.com]
|
On 2002.08.13 16:32 Linux Today wrote: Linux Today SECURITY LETTER FOR AUGUST 13, 2002
Latest Security News for the Linux and Open Source Community.
___________________________ Sponsors ________________________________ This newsletter sponsored by: Enterprise Linux Forum Conference & Expo, Dec. 3 & 4 Boston _____________________________________________________________________
------------------------------------------------------------------ ------------------------------------------------------------------
TODAY'S LINUX SECURITY NEWS:
------------------------------------------------------------------ THE REGISTER: SSL DEFEATED IN IE AND KONQUEROR
"A colossal stuff-up in Microsoft's and KDE's implementation of SSL (Secure Sockets Layer) certificate handling makes it possible for anyone with a valid VeriSign SSL site certificate to forge any other VeriSign SSL site certificate, and abuse hapless Konqueror and Internet Explorer users with impunity..."
COMPLETE STORY: http://www.theregister.co.uk/content/4/26620.html
------------------------------------------------------------------ RED HAT LINUX ADVISORY: TCL/TK
"Updated Tcl/Tk packages for Red Hat Linux 7 and 7.1 fix two local vulnerabilities..."
COMPLETE STORY: http://linuxtoday.com/story.php3?sn=42166
------------------------------------------------------------------ SUSE LINUX ADVISORY: I4L
"The ipppd program which is part of the package contained various buffer overflows and format string bugs. Since ipppd is installed setuid to root and executable by users of group 'dialout' this may allow attackers with appropriate group membership to execute arbitrary commands as root..."
COMPLETE STORY: http://linuxtoday.com/story.php3?sn=42167
------------------------------------------------------------------ LINUX AND MAIN: KONQUEROR SSL VULNERABILITY [FIX]
"As has been widely reported, particularly in The Register, there is a vulnerability in KDE's Konqueror web browser which makes it easy to forge SSL certificates..."
COMPLETE STORY: http://www.linuxandmain.com/modules.php?name=News&file=article&sid=175
------------------------------------------------------------------ DEBIAN GNU/LINUX ADVISORY: GLIBC
"An integer overflow bug has been discovered in the RPC library used by GNU libc, which is derived from the SunRPC library..."
COMPLETE STORY: http://linuxtoday.com/story.php3?sn=42175
------------------------------------------------------------------ THE REGISTER: PGP, GPG DEFEATED
"OpenPGP and GnuPG are susceptible to a chosen-cyphertext attack which would allow an adversary capable of intercepting an encrypted message to use the intended recipient as an unwitting 'decryption oracle', researchers Kahil Jallad, Jonathan Katz and Bruce Schneier report in a recent paper..."
COMPLETE STORY: http://www.theregister.co.uk/content/4/26643.html
------------------------------------------------------------------ DEBIAN GNU/LINUX ADVISORIES: INTERCHANGE, XINTED, L2TPD
Three advisories from the Debian Project.
COMPLETE STORY: http://linuxtoday.com/story.php3?sn=42180
------------------------------------------------------------------
/-------------------------------------------------------------------\ 2002 is the breakout year for enterprise Linux. Enterprise Linux Forum Conference & Expo, Dec 3 & 4 in Boston, is the only industry event that is dedicated to providing IT & business professionals with an understanding of all the issues related to the application of Linux and Linux-based datacenter solutions in the large enterprise to cut costs, reduce risk, increase architectural flexibility and deliver real business value. http://www.intmediaevents.com/elf/fall02/index.html
\--------------------------------------------------------------adv.-/
------------------------------------------------------------------ Visit the other sites in the Linux Channel: Linux Planet , LinuxStart , Linux Central , and JustLinux . Also, check out the ISP-Linux Moderated Digest . ------------------------------------------------------------------ To advertise on our newsletters and 125+ more at internet.com, please contact Frank Fazio: mailto:ffazio-at-internet.com Director, Inside Sales (203)-662-2997 ------------------------------------------------------------------ Copyright 2002 internet.com Corp. . ------------------------------------------------------------------ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
DEDICATED EMAIL LIST SERVERS! Get the speed, control, and responsiveness you need for your out-sourced Email Newsletters at an AFFORDABLE price! 100% UPTIME GUARANTEED! Sign-up by July 15th and the set-up is FREE for your DEDICATED solution just for mentioning this ad. Free Quote: mailto:sales-at-sparklist.com or surf the website: http://SparkLIST.com/ or direct: 920.490.5901, x1
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Advertising: If you are interested in advertising in our newsletters, call Claudia at 1-203-662-2863 or send email to mailto:nsladsales-at-internet.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For contact information on sales offices worldwide visit http://www.internet.com/mediakit/salescontacts.html ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For details on becoming a Commerce Partner, contact David Arganbright on 1-203-662-2858 or mailto:commerce-licensing-at-internet.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ To learn about other free newsletters offered by internet.com or to change your subscription visit http://e-newsletters.internet.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ internet.com's network of more than 160 Web sites is organized into 16 channels: Internet Technology http://internet.com/it E-Commerce/Marketing http://internet.com/marketing Web Developer http://internet.com/webdev Windows Internet Technology http://internet.com/win Linux/Open Source http://internet.com/linux Internet Resources http://internet.com/resources ISP Resources http://internet.com/isp Internet Lists http://internet.com/lists Download http://internet.com/downloads International http://internet.com/international Internet News http://internet.com/news Internet Investing http://internet.com/stocks ASP Resources http://internet.com/asp Wireless Internet http://internet.com/wireless Career Resources http://internet.com/careers EarthWeb http://www.earthweb.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ To find an answer - http://search.internet.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Looking for a job? Filling an opening? - http://jobs.internet.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ This newsletter is published by INT Media Group, Incorporated http://internet.com - The Internet & IT Network Copyright (c) 2002 INT Media Group, Incorporated. All rights reserved. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ For information on reprinting or linking to internet.com content: http://internet.com/corporate/permissions.html ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ --- You are currently subscribed to linuxtodaysecurity-text as: ruben-at-mrbrklyn.com To unsubscribe send a blank email to leave-linuxtodaysecurity-text-5736005G-at-list4.internet.com -- __________________________
Brooklyn Linux Solutions __________________________ http://www.mrbrklyn.com - Consulting http://www.nylxs.com/radio - Free Software Radio Show and Archives http://www.brooklynonline.com - For the love of Brooklyn http://www.nylxs.com - Leadership Development in Free Software http://www.nyfairuse.org - The foundation of Democracy http://www2.mrbrklyn.com/resources - Unpublished Archive or stories and articles from around the net http://www2.mrbrklyn.com/mp3/dr.mp3 - Imagine my surprise when I saw you... http://www2.mrbrklyn.com/downtown.html - See the New Downtown Brooklyn....
1-718-382-5752
____________________________ New Yorker Free Software Users Scene Fair Use - because it's either fair use or useless....
|
|