VULNERABILITIES
| 27/10/2005 |
Mantis: PHP code execution with t_core_path
A network attacker can use t_core_path parameter to inject PHP code in Mantis.
BUGTRAQ-15210, BUGTRAQ-15212, CVE-2005-3338, CVE-2005-3339, VIGILANCE-VUL-5312 |
PAM, SELinux: brute force attack with unix_chkpwd
A local attacker can use unix_chkpwd to conduct a brute force attack on user passwords.
BUGTRAQ-15217, CVE-2005-2977, FEDORA-2005-1030, RHSA-2005:805-01, VIGILANCE-VUL-5311 |
Antivirus: bypassing using "magic bytes"
An attacker can construct a file starting with special magic bytes in order to bypass antivirus.
BUGTRAQ-15189, BUGTRAQ-15191, VIGILANCE-VUL-5305 |
Thunderbird: clear network password retrieval
Even if CRAM-MD5 or TLS is used, an attacker can act as a "Man in the middle" to obtain password.
BUGTRAQ-15106, VIGILANCE-VUL-5279 |
uim: privilege increase
A local attacker can use a program linked to uim in order to obtain root privileges.
CVE-2005-3149, MDKSA-2005:198, VIGILANCE-VUL-5310 |
Ethereal: infinite loop in IRC
An attacker can send a malicious IRC packet in order to conduct a denial of service of Ethereal.
BUGTRAQ-15219, MDKSA-2005:193-1, VIGILANCE-VUL-5309 |
| 26/10/2005 |
RSA ACE Web Agent: Cross Site Scripting
An attacker can conduct a Cross Site Scripting using RSA ACE Web Agent.
BUGTRAQ-15206, SEC-CONSULT Security Advisory 20051025-1, VIGILANCE-VUL-5308 |
GNOME Data Access: format string attacks
An attacker can conduct two format string attacks in GNOME Data Access logging code.
BUGTRAQ-15200, CVE-2005-2958, DSA 871-1, DSA 871-2, VIGILANCE-VUL-5307 |
| 25/10/2005 |
Snort: buffer overflow of Back Orifice preprocessor
An attacker can send a malicious packet in order to lead to an overflow in Back Orifice preprocessor.
BUGTRAQ-15131, CVE-2005-3252, TA05-291A, VIGILANCE-VUL-5286, VU#175500 |
sudo: privilege increase with SHELLOPTS and PS4
An attacker, allowed to run sudo, can increase his privileges by setting SHELLOPTS and PS4 variables
CVE-2005-2959, DSA 870-1, MDKSA-2005:201, VIGILANCE-VUL-5306 |
Windows: buffer overflow of Plug and Play
An authenticated attacker can overflow a buffer in Plug and Play in order to increase his privileges.
BUGTRAQ-15065, CVE-2005-2120, MS05-047, VIGILANCE-VUL-5262, VU#214572 |
| 24/10/2005 |
SUSE: file reading with chkstat
A local attacker can read a protected file content after chkstat usage.
BUGTRAQ-15182, CVE-2005-3321, SUSE-SA:2005:062, VIGILANCE-VUL-5304 |
fetchmail: password disclosure in fetchmailconf
A local attacker can obtain a copy of configuration file during fetchmailconf usage.
BUGTRAQ-15179, CVE-2005-3088, RHSA-2005:823-01, VIGILANCE-VUL-5303, fetchmail-SA-2005-02 |
PHP: denial of service with session.save_path
A local attacker can redefine session.save_path value in order to stop Apache.
BUGTRAQ-15177, CVE-2005-3319, VIGILANCE-VUL-5302 |
| 21/10/2005 |
Linux kernel: denial of service of IPv6
A local attacker can generate an infinite loop using IPv6 packets.
BUGTRAQ-15156, CVE-2005-2973, FEDORA-2005-1007, FEDORA-2005-1013, VIGILANCE-VUL-5299 |
Eric: code execution with a project
An attacker can create a malicious project leading to code execution when Eric opens it.
CVE-2005-3068, DSA 869-1, VIGILANCE-VUL-5301 |
Symantec Norton AntiVirus: privilege escalation
Under Macintosh, a local attacker can obtain root privileges with Symantec Norton AntiVirus.
BUGTRAQ-15142, BUGTRAQ-15143, CVE-2005-2759, CVE-2005-3270, SYM05-020, SYM05-021, VIGILANCE-VUL-5296 |
Ethereal: several vulnerabilities
Several vulnerabilities of Ethereal permit a remote attacker to conduct a denial of service or to run code.
BUGTRAQ-15148, BUGTRAQ-15158, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, FEDORA-2005-1011, MDKSA-2005:193, MDKSA-2005:193-1, RHSA-2005:809-01, VIGILANCE-VUL-5295, enpa-sa-00021 |
| 20/10/2005 |
Linux kernel: information disclosure with DRM
A local attacker can activate DRM debugging in order to obtain sensitive information.
BUGTRAQ-15154, CVE-2005-3179, FEDORA-2005-1007, VIGILANCE-VUL-5298 |
Debian: file corruption with module-assistant
A local attacker can alter a file during module-assistant usage.
BUGTRAQ-15151, CVE-2005-3121, DSA 867-1, VIGILANCE-VUL-5297 |
XMail: buffer overflow of AddressFromAtPtr
A local attacker can increase his privileges by using an overflow of XMail.
BUGTRAQ-15103, CVE-2005-2943, VIGILANCE-VUL-5275 |
Cisco CSS: denial of service with a certificate
An attacker can send a malicious client certificate in order to stop Cisco 11500 Content Services Switch.
BUGTRAQ-15144, CSCee64771, VIGILANCE-VUL-5294 |
Windows: memory corruption of DirectShow
An attacker can create a malicious AVI file leading to code execution.
BUGTRAQ-15063, CVE-2005-2128, MS05-050, VIGILANCE-VUL-5263, VU#995220 |
Oracle Database: several vulnerabilities of October 2005
Several vulnerabilities are corrected by CPU of October 2005.
BUGTRAQ-15134, HPSBMA01235, SSRT051055, VIGILANCE-VUL-5288, VU#210524, VU#449444 |
| 19/10/2005 |
Squid: denial of service of FTP
An attacker can setup a malicious FTP server, stopping Squid proxies connecting to it.
BUGTRAQ-15157, CVE-2005-3258, FEDORA-2005-1010, MDKSA-2005:195, VIGILANCE-VUL-5293 |
RSA SecurID Web Agent: buffer overflow of IISWebAgentIF.dll
An attacker can conduct an overflow in IISWebAgentIF.dll in order to run code on server.
VIGILANCE-VUL-5292 |
HP-UX: buffer overflow of lpd
An attacker can send a malicious request in order to run code on lpd.
BUGTRAQ-15136, CVE-2005-3277, HPSBUX0208-213, SSRT2331, VIGILANCE-VUL-5291 |
HP-UX: directory listing with ftpd
A non authenticated attacker can list a ftpd directory.
BUGTRAQ-15138, CVE-2005-3296, VIGILANCE-VUL-5290 |
Oracle Application Server: several vulnerabilities of October 2005
Several vulnerabilities are corrected by CPU of October 2005.
BUGTRAQ-15134, BUGTRAQ-15146, BUGTRAQ-15163, VIGILANCE-VUL-5289, VU#171364, VU#210524, VU#376756, VU#512716 |
PHP: bypassing open_basedir with GD or curl
An attacker can create a PHP program using GD or curl to bypass open_basedir restriction.
BUGTRAQ-15119, VIGILANCE-VUL-5283 |
| 18/10/2005 |
netpbm: memory corruption during PNM to PNG conversion
When pnmtopng is called on a malicious PNM file, code can be run with user's rights.
BUGTRAQ-15128, CVE-2005-2978, DSA 878-1, MDKSA-2005:199, RHSA-2005:793-01, SUSE-SR:2005:024, VIGILANCE-VUL-5287 |
OpenWBEM: several buffer and integer overflows
An attacker can use several overflows of OpenWBEM in order to run code.
BUGTRAQ-15121, CVE-2005-3297, CVE-2005-3298, SUSE-SA:2005:060, VIGILANCE-VUL-5284 |
| 17/10/2005 |
Gallery: file reading
A network attacker can use Gallery to read files located on server.
BUGTRAQ-15108, CVE-2005-3251, VIGILANCE-VUL-5282 |
lynx: buffer overflow of NNTP
A malicious NNTP server can return data leading to an overflow in lynx.
20051003-01-U, BUGTRAQ-15117, CVE-2005-3120, DSA 874-1, FEDORA-2005-993, FEDORA-2005-994, MDKSA-2005:186, RHSA-2005:803-01, VIGILANCE-VUL-5281 |
AbiWord: several buffer overflow
Several buffer overflow of AbiWord permit an attacker to run code during RTF import.
BUGTRAQ-15096, CVE-2005-2972, FEDORA-2005-989, VIGILANCE-VUL-5280 |
| 14/10/2005 |
AIX: file corruption with lscfg
A local attacker can change a file during lscfg usage.
BUGTRAQ-15105, CVE-2005-3289, IY77624, VIGILANCE-VUL-5278 |
Solaris: denial of service of setsockopt on SCTP
A local attacker can use setsockopt() on a SCTP socket to panic kernel.
101881, 6248555, 6250374, CVE-2005-3238, VIGILANCE-VUL-5277 |
wget, cURL: buffer overflow during NTLM authentication
An attacker can run code on wget or cURL clients connecting to a malicious website.
BUGTRAQ-15102, CVE-2005-3185, FEDORA-2005-1000, FEDORA-2005-995, FEDORA-2005-996, MDKSA-2005:182, MDKSA-2005:183, SUSE-SA:2005:063, VIGILANCE-VUL-5276 |
Windows: file creation a during a FTP transfer
An attacker can store a malicious file on a FTP server. When user downloads this file, it is saved at location specified by attacker.
CVE-2005-2126, MS05-044, VIGILANCE-VUL-5259, VU#415828 |
| 13/10/2005 |
Solaris: information disclosure and denial of service
A local attacker can obtain some users' file names, or panic system.
101895, 101949, 101987, 6271688, 6271759, 6294867, BUGTRAQ-15090, BUGTRAQ-15115, CVE-2005-3250, VIGILANCE-VUL-5274 |
NetWare: denial of service during an analyze
An attacker can stop NetWare using a scan with a vulnerability scanner.
TID2972443, VIGILANCE-VUL-5273 |
Linux kernel: information disclosure with orinoco
Driver orinoco returns memory fragments in ARP replies.
BUGTRAQ-15085, CVE-2005-3180, FEDORA-2005-1007, RHSA-2005:514, VIGILANCE-VUL-5272 |
HP-UX: denial of service of exec and setrlimit
On an Itanium platform, a local attacker can conduct a denial of service when using exec() and setrlimit().
BUGTRAQ-15100, CVE-2005-3295, HPSBUX01233, SSRT5975, VIGILANCE-VUL-5270 |
Windows, Exchange: code execution with CDO
An attacker can send a malicious email in order to run code on system.
BUGTRAQ-15067, CVE-2005-1987, VIGILANCE-VUL-5265, VU#883460 |
| 12/10/2005 |
Sun Application Server: disclosure of JSP source code
An attacker can obtain source code of JSP pages.
101910, 6217658, BUGTRAQ-15084, VIGILANCE-VUL-5269 |
Linux kernel: local denials of service
A local attacker can overflow system by using several memory leaks.
BUGTRAQ-15076, CVE-2005-3119, CVE-2005-3181, FEDORA-2005-1007, RHSA-2005:514, VIGILANCE-VUL-5268 |
SquirrelMail: Cross Site Scripting of Address Add plugin
An attacker can send an email to obtain cookie of SquirrelMail user.
CVE-2005-3128, MDKSA-2005:178, VIGILANCE-VUL-5267 |
Windows: code execution with a shortcut or with Web View
An attacker can run code on computer of users accepting a shortcut or previewing a file.
BUGTRAQ-15064, BUGTRAQ-15069, BUGTRAQ-15070, CVE-2005-2117, CVE-2005-2118, CVE-2005-2122, MS05-049, VIGILANCE-VUL-5266, VU#922708, VU#950516 |
IE : memory corruption with msdds.dll
When opening an HTML document containing msdss.dll object, malicious code can execute on computer.
906267, BUGTRAQ-15061, CVE-2005-2127, MS05-052, VIGILANCE-VUL-5132, VU#740372 |
Windows: vulnerabilities of MSDTC, COM+ and TIP
Several vulnerabilities permit a remote or local attacker to execute code or to conduct a denial of service.
BUGTRAQ-15056, BUGTRAQ-15057, BUGTRAQ-15058, BUGTRAQ-15059, CVE-2005-1978, CVE-2005-1979, CVE-2005-1980, CVE-2005-2119, MS05-051, VIGILANCE-VUL-5264, VU#180868 |
Windows: buffer overflow of Client Service for NetWare
When Client Service for NetWare is active, an attacker can send packets to overflow a buffer and lead to code execution.
BUGTRAQ-15066, CVE-2005-1985, MS05-046, VIGILANCE-VUL-5261 |
Windows: denial of service of Network Connection Manager
An authenticated user can stop Network Connection Manager.
BUGTRAQ-14260, CVE-2005-2307, MS05-045, VIGILANCE-VUL-5260 |
| 11/10/2005 |
OpenSSL: use of SSL 2.0
An attacker, acting as a Man in the Middle can force OpenSSL to use SSL 2.0.
101974, 20051003-01-U, 6332476, BUGTRAQ-15071, CVE-2005-2969, DSA 875-1, FEDORA-2005-985, FEDORA-2005-986, FreeBSD-SA-05:21.openssl, MDKSA-2005:179, RHSA-2005:800-01, SSA:2005-286-01, SUSE-SA:2005:061, VIGILANCE-VUL-5257 |
KOffice: buffer overflow during RTF import
An attacker can create a malicious RTF file to run code of computers of KWord users.
BUGTRAQ-15060, CESA-2005-005, CVE-2005-2971, DSA 872-1, FEDORA-2005-984, MDKSA-2005:185, VIGILANCE-VUL-5256 |
Kaspersky, F-Secure: memory corruption with CHM
An attacker can create a malicious CHM file to conduct a denial of service or to run code.
BUGTRAQ-15054, CVE-2005-2937, VIGILANCE-VUL-5255 |
Bea WebLogic: several vulnérabilités
BEA Systems wrote 24 announces related to Bea WebLogic.
BEA05-100.00, BEA05-101.00, BEA05-102.00, BEA05-103.00, BEA05-104.00, BEA05-105.00, BEA05-106.00, BEA05-107.00, BEA05-80.02, BEA05-85.00, BEA05-86.00, BEA05-87.00, BEA05-88.00, BEA05-89.00, BEA05-90.00, BEA05-91.00, BEA05-92.00, BEA05-93.00, BEA05-94.00, BEA05-95.00, BEA05-96.00, BEA05-97.00, BEA05-98.00, BEA05-99.00, BUGTRAQ-15052, VIGILANCE-VUL-5254 |
IRIX: privileged commands execution with runpriv
A local attacker, allowed to execute runpriv, can bypass restrictions decided by administrator.
20051001-01-P, BUGTRAQ-15055, CVE-2005-2925, SGI BUG 942479, VIGILANCE-VUL-5253, iDEFENSE Security Advisory 10.10.05 |
| 10/10/2005 |
Graphviz: file corruption
A local attacker can alter a file during Graphviz usage.
BUGTRAQ-15050, CVE-2005-2965, DSA 857-1, MDKSA-2005:188, VIGILANCE-VUL-5252 |
Weex: format string attack with a filename
An attacker can create malicious filenames leading to code execution when Weex synchronizes them.
CVE-2005-3150, DSA 855-1, VIGILANCE-VUL-5251 |
up-imapproxy: format string attack
A format string attack of up-imapproxy permits an attacker owning an IMAP server to run code.
BUGTRAQ-15048, CVE-2005-2661, DSA 852-1, VIGILANCE-VUL-5250 |
Dia: code execution with a SVG document
Python code can execute in Dia when a SVG file is opened.
BUGTRAQ-15000, CVE-2005-2966, DSA 847-1, MDKSA-2005:18, SUSE-SR:2005:022, VIGILANCE-VUL-5249 |
Zope: vulnerability of reStructuredText
A vulnerability of Zope affects sites exposing reStructuredText functionality.
BUGTRAQ-15082, CVE-2005-3323, Hotfix 2005-10-09, VIGILANCE-VUL-5248 |
xine: format string attack of CDDB
An attacker can create malicious data on a CDDB server, in order to generate a format string attack in xine.
BUGTRAQ-15044, CVE-2005-2967, DSA 863-1, MDKSA-2005:180, SSA:2005-283-01, SUSE-SR:2005:024, VIGILANCE-VUL-5247 |
Libwww: buffer overflow of multipart/byteranges
A web server can return malicious multipart/byteranges data in order to run code on clients using Libwww.
BUGTRAQ-15035, CVE-2005-3183, FEDORA-2005-952, FEDORA-2005-953, VIGILANCE-VUL-5245 |
Antivirus: virus not found in RAR, CAB or ARJ archives
An attacker can create a RAR, CAB or ARJ archive containing a virus not detected by some antivirus.
BUGTRAQ-15046, CVE-2005-3210, CVE-2005-3211, CVE-2005-3212, CVE-2005-3213, CVE-2005-3214, CVE-2005-3215, CVE-2005-3216, CVE-2005-3217, CVE-2005-3218, CVE-2005-3219, CVE-2005-3220, CVE-2005-3221, CVE-2005-3222, CVE-2005-3223, CVE-2005-3224, CVE-2005-3225, CVE-2005-3226, CVE-2005-3227, CVE-2005-3228, CVE-2005-3229, CVE-2005-3230, CVE-2005-3231, CVE-2005-3232, CVE-2005-3233, CVE-2005-3234, CVE-2005-3235, VIGILANCE-VUL-5244 |
HylaFax: file corruption and information disclosure
Two vulnerabilities in HylaFax permit a local attacker to change a file or to retrieve information.
BUGTRAQ-14907, BUGTRAQ-15043, CVE-2005-3069, CVE-2005-3070, DSA 865-1, MDKSA-2005:177, VIGILANCE-VUL-5243 |
| 07/10/2005 |
Windows 2000 SP4 : minor vulnerabilities corrected by Update Rollup 1
This sheet lists minor vulnerabilities corrected by Update Rollup 1.
CVE-2005-3169, CVE-2005-3170, CVE-2005-3171, CVE-2005-3172, CVE-2005-3173, CVE-2005-3174, CVE-2005-3175, CVE-2005-3176, CVE-2005-3177, VIGILANCE-VUL-5242 |
xloadimage: buffer overflow of NIFF title
An attacker can create a malicious NIFF image leading to code execution when opened with xloadimage.
20051003-01-U, BUGTRAQ-15051, CVE-2005-3178, CVE-2005-3195, DSA 858-1, DSA 859-1, FEDORA-2005-981, MDKSA-2005:192, RHSA-2005:802-01, SUSE-SR:2005:024, VIGILANCE-VUL-5241 |
Texinfo: file corruption with texindex
A local attacker can alter a file during texindex usage.
328365, BUGTRAQ-14854, CVE-2005-3011, FEDORA-2005-990, FEDORA-2005-991, MDKSA-2005:175, SUSE-SR:2005:023, VIGILANCE-VUL-5240 |
Sun Directory Server: code execution
A network attacker can run code on Sun Java System Directory Server.
BUGTRAQ-15013, CVE-2005-3269, VIGILANCE-VUL-5239 |
Mozilla: file corruption with run-mozilla.sh
When run-mozilla.sh script is used to debug, a local attacker can alter a file with user's rights.
BUGTRAQ-15015, CVE-2005-2353, MDKSA-2005:173, MDKSA-2005:174, VIGILANCE-VUL-5238 |
| 06/10/2005 |
Windows: disclosure of WEP and WPA keys
A local attacker can obtain WEP and WPA 802.11 keys
BUGTRAQ-15008, VIGILANCE-VUL-5237 |
Ruby: code execution without safe level
When a Ruby program is received on stdin, safe level is ignored.
20051003-01-U, CVE-2005-2337, DSA 860-1, DSA 862-1, DSA 864-1, MDKSA-2005:191, RHSA-2005:799-01, VIGILANCE-VUL-5236, VU#160012 |
Firefox: denial of service with IFRAME
An attacker can create a page containing a malicious IFRAME tag in order to stop browser.
VIGILANCE-VUL-5235 |
Debian: firewall not activated with mason
Under Debian, firewall startup script is not installed by mason.
222384, BUGTRAQ-15019, CVE-2005-3118, DSA 845-1, VIGILANCE-VUL-5233 |
| 05/10/2005 |
UW-IMAP: overflow of mailbox name
An authenticated attacker can use a malicious mailbox name in order to run code on UW-IMAP.
BUGTRAQ-15009, CVE-2005-2933, DSA 861-1, MDKSA-2005:189, MDKSA-2005:194, SUSE-SR:2005:023, VIGILANCE-VUL-5232, VU#933601 |
mod_auth_shadow: bypassing defined authentication
In some particular configurations, authentication can use mod_auth_shadow instead of the one defined by administrator.
323789, BUGTRAQ-15224, CVE-2005-2963, DSA 844-1, MDKSA-2005:200, VIGILANCE-VUL-5231 |
arc: reading and changing file
During arc usage, a local attacker can read temporary file or use a symlink to alter a file.
CVE-2005-2945, CVE-2005-2992, DSA 843-1, VIGILANCE-VUL-5230 |
Kaspersky: buffer overflow with a CAB file
An attacker can create a malicious CAB file leading to code execution on antivirus.
BUGTRAQ-14998, VIGILANCE-VUL-5222 |
| 04/10/2005 |
ApacheTop: file corruption
A local attacker can change a file during ApacheTop usage.
CVE-2005-2660, DSA 839-1, VIGILANCE-VUL-5229 |
Microsoft Jet: buffer overflow
An attacker can use a buffer overflow of Microsoft Jet Database Engine to run code on computer.
BUGTRAQ-12960, CVE-2005-0944, VIGILANCE-VUL-4863, VU#176380 |
Linux kernel: denial of service with USB
A local attacker can prematurely end a process using an USB device in order to stop system.
CVE-2005-3055, VIGILANCE-VUL-5228 |
Linux kernel: denial of service with sys_set_mempolicy()
A local attacker can use sys_set_mempolicy() to stop system
CVE-2005-3053, RHSA-2005:514, VIGILANCE-VUL-5227 |
Linux kernel: denials of service on 64 bit computers
A local attacker can use fput or sockfd_put to stop 64 bit computers.
CVE-2005-3044, VIGILANCE-VUL-5226 |
Linux kernel: denials of service of ipt_recent
An attacker can conduct two denials of service in ipt_recent.
CVE-2005-2872, CVE-2005-2873, MDKSA-2005:171, RHSA-2005:514-01, VIGILANCE-VUL-5225 |
Linux kernel: ACL not applied on ext2 and ext3
An error prevents default ACL from being applied to ext2 and ext3 filesystems.
CVE-2005-2801, MDKSA-2005:171, RHSA-2005:514-01, SUSE-SA:2005:018, VIGILANCE-VUL-5224 |
| 03/10/2005 |
ProZilla: overflow with a link
A malicious HTML document can lead to an overflow in ProZilla.
BUGTRAQ-14993, CVE-2005-2961, VIGILANCE-VUL-5223 |
CFEngine: file corruption
A local attacker can change a file during CFEngine usage.
BUGTRAQ-14994, CVE-2005-2960, CVE-2005-3137, DSA 835-1, DSA 836-1, MDKSA-2005:184, SUSE-SR:2005:023, VIGILANCE-VUL-5221 |
AbiWord: code execution during RTF import
An attacker can create a malicious RTF file, leading to code execution on computers of users opening it with AbiWord.
BUGTRAQ-14971, CVE-2005-2964, FEDORA-2005-955, SUSE-SR:2005:023, VIGILANCE-VUL-5220 |
ZoneAlarm: firewall bypassing
A local attacker can use DDE-IPC is order to communicate with an external server.
BUGTRAQ-14966, VIGILANCE-VUL-5217 |
RealPlayer, Helix Player: format string attack
A remote attacker can create a malicious multimedia file in order to run code in RealPlayer or Helix Player.
BUGTRAQ-14945, CVE-2005-2710, DSA 826-1, FEDORA-2005-940, FEDORA-2005-941, RHSA-2005:762-02, RHSA-2005:788-01, SUSE-SA:2005:059, VIGILANCE-VUL-5214, VU#361181 |
| 30/09/2005 |
Debian: disclosure of NTLM APS password
A local attacker can read file containing password used by NTLM APS.
BUGTRAQ-14979, CVE-2005-2962, DSA 830-1, VIGILANCE-VUL-5219 |
| 29/09/2005 |
gtkdiskfree: file corruption
A local attacker can change a file during gtkdiskfree usage.
BUGTRAQ-14849, CVE-2005-2918, DSA 822-1, VIGILANCE-VUL-5218 |
IIS: viewing script source code on FAT/FAT32
A remote attacker can obtain source code of scripts located on a FAT or FAT32 filesystem.
BUGTRAQ-14764, VIGILANCE-VUL-5179 |
| 28/09/2005 |
OpenSSH: denial of service with LoginGraceTime
An attacker can wait LoginGraceTime timeout to conduct a denial of service.
20051002-01-U, BUGTRAQ-14963, CVE-2004-2069, RHSA-2005:550-01, VIGILANCE-VUL-5216 |
AIX: buffer overflow of getconf
A local attacker can obtain root privileges with an overflow in getconf.
BUGTRAQ-14959, CVE-2005-3060, IY73814, IY73850, VIGILANCE-VUL-5215, VU#602300 |
| 27/09/2005 |
PHP: open_basedir restriction not honored
In some cases, open_basedir directive is not honored.
323585, BUGTRAQ-14957, CVE-2005-3054, VIGILANCE-VUL-5213 |
Solaris: obtaining high privileges with Xsun or Xprt
A local attacker can use Xsun or Xprt to obtain root privileges.
101800, 6265045, BUGTRAQ-14949, CVE-2005-3099, VIGILANCE-VUL-5212 |
Qpopper: file creation with poppassd
A local attacker can create a file with root privileges by using poppassd.
BUGTRAQ-14944, CVE-2005-3098, VIGILANCE-VUL-5210 |
Mailutils: format string attack in imap4d
An attacker can send a malicious command to imap4d service in order to run code.
BUGTRAQ-14794, CVE-2005-2878, DSA 841-1, VIGILANCE-VUL-5187 |
|
SOLUTIONS
| 28/10/2005 |
Red Hat Enterprise Linux: new kernel packages
> Red Hat
BUGTRAQ-15076, BUGTRAQ-15085, CVE-2005-3053, CVE-2005-3108, CVE-2005-3110, CVE-2005-3119, CVE-2005-3180, CVE-2005-3181, RHSA-2005:514, VIGILANCE-SOL-9113 |
Linux kernel: version 2.6.14
> Linux
BUGTRAQ-14785, BUGTRAQ-14787, BUGTRAQ-15076, BUGTRAQ-15085, BUGTRAQ-15154, BUGTRAQ-15156, CVE-2005-2490, CVE-2005-2492, CVE-2005-2973, CVE-2005-3044, CVE-2005-3055, CVE-2005-3119, CVE-2005-3179, CVE-2005-3180, CVE-2005-3181, ERR-2004-2492, VIGILANCE-SOL-9013 |
Mandriva: new sudo packages
> Mandriva, Mandriva, Mandriva
CVE-2005-2959, MDKSA-2005:201, VIGILANCE-SOL-9112 |
Mandriva: new apache-mod_auth_shadow packages
> Mandriva
323789, BUGTRAQ-15224, CVE-2005-2963, MDKSA-2005:200, VIGILANCE-SOL-9111 |
Fedora Core: new pam packages
> Fedora
BUGTRAQ-15217, CVE-2005-2977, FEDORA-2005-1030, VIGILANCE-SOL-9107 |
Fedora: new gdb packages
> Fedora
BUGTRAQ-13697, CVE-2005-1704, CVE-2005-1705, FEDORA-2005-1032, FEDORA-2005-1033, VIGILANCE-SOL-9110 |
| 27/10/2005 |
SGI ProPack 4: patch for XFree86
> ProPack
20051004-01-U, BUGTRAQ-14807, CVE-2005-2495, VIGILANCE-SOL-9109, VU#102441 |
Mantis: new version 0.19.3
> Unix
BUGTRAQ-15210, BUGTRAQ-15212, CVE-2005-3338, CVE-2005-3339, VIGILANCE-SOL-9108 |
Red Hat Enterprise Linux: new pam packages
> Red Hat
BUGTRAQ-15217, CVE-2005-2977, RHSA-2005:805-01, VIGILANCE-SOL-9106 |
Debian: new lynx-ssl packages
> Debian
BUGTRAQ-15117, CVE-2005-3120, VIGILANCE-SOL-9105 |
Solaris: patch for SMC
> Solaris
102016, 5090761, BUGTRAQ-11604, BUGTRAQ-15222, BUGTRAQ-9506, BUGTRAQ-9561, CVE-2004-2320, Sun Alert ID 50603, Sun Alert ID 57670, Sun BugID 4808654, Sun BugID 5063481, VIGILANCE-SOL-9104, VU#867593 |
uim: new versions 0.4.9.1 et 0.5.0.1
> Unix
CVE-2005-3149, VIGILANCE-SOL-9103 |
Mandriva: new netpbm packages
> Mandriva
BUGTRAQ-15128, CVE-2005-2978, MDKSA-2005:199, VIGILANCE-SOL-9102 |
Mandriva: new uim packages
> Mandriva
CVE-2005-3149, MDKSA-2005:198, VIGILANCE-SOL-9101 |
Mandriva: new unzip packages
> Mandriva, Mandriva, Mandriva
BUGTRAQ-12996, BUGTRAQ-14447, BUGTRAQ-14450, CVE-2005-0602, CVE-2005-0953, CVE-2005-0988, CVE-2005-1228, CVE-2005-2475, MDKSA-2005:197, VIGILANCE-SOL-9100 |
Mandriva: new perl-Compress-Zlib packages
> Mandriva, Mandriva
BUGTRAQ-14162, BUGTRAQ-14340, CVE-2005-1849, CVE-2005-2096, DSA 763, MDKSA-2005:196, VIGILANCE-SOL-9099, VU#680620 |
Mandriva: new squid packages
> Mandriva, Mandriva, Mandriva
BUGTRAQ-15157, CVE-2005-3258, MDKSA-2005:195, VIGILANCE-SOL-9098 |
Mandriva: new php-imap packages
> Mandriva, Mandriva
BUGTRAQ-15009, CVE-2005-2933, MDKSA-2005:194, VIGILANCE-SOL-9097, VU#933601 |
Debian 3.0: new openssl094 packages
> Debian
BUGTRAQ-15071, CVE-2005-2969, DSA 875-1, VIGILANCE-SOL-9096 |
Ethereal: patch for IRC
> Unix
BUGTRAQ-15219, VIGILANCE-SOL-9095 |
Mandriva: new ethereal packages
> Mandriva
BUGTRAQ-15148, BUGTRAQ-15158, BUGTRAQ-15219, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, MDKSA-2005:193-1, VIGILANCE-SOL-9094, enpa-sa-00021 |
Mandriva: new lynx packages
> Mandriva, Mandriva, Mandriva
BUGTRAQ-15117, CVE-2005-3120, MDKSA-2005:186, VIGILANCE-SOL-9047 |
Red Hat Enterprise Linux: new fetchmail packages
> Red Hat
BUGTRAQ-15179, CVE-2005-3088, RHSA-2005:823-01, VIGILANCE-SOL-9093, fetchmail-SA-2005-02 |
Debian: new lynx packages
> Debian
BUGTRAQ-15117, CVE-2005-3120, DSA 874-1, VIGILANCE-SOL-9092 |
Debian: new net-snmp packages
> Debian
BUGTRAQ-14168, CVE-2005-2177, DSA 873-1, VIGILANCE-SOL-9091 |
| 26/10/2005 |
Solaris: patch pour Xsun et Xorg
> Solaris
101926, 6316436, 6316438, BUGTRAQ-14807, CVE-2005-2495, VIGILANCE-SOL-8814, VU#102441 |
Debian: new koffice packages
> Debian
BUGTRAQ-15060, CESA-2005-005, CVE-2005-2971, DSA 872-1, VIGILANCE-SOL-9090 |
Debian: new libgda2 packages
> Debian
BUGTRAQ-15200, CVE-2005-2958, DSA 871-1, DSA 871-2, VIGILANCE-SOL-9089 |
Debian: new imlib packages
> Debian
BUGTRAQ-11084, CVE-2004-0802, CVE-2004-0817, DSA 548, DSA 548-2, VIGILANCE-SOL-7242 |
SGI ProPack 3: new openldap, nss_ldap, lynx, xloadimage, util-linux, mount, ruby, openssl packages
> ProPack
20051003-01-U, BUGTRAQ-14125, BUGTRAQ-14126, BUGTRAQ-14816, BUGTRAQ-15051, BUGTRAQ-15071, BUGTRAQ-15117, CVE-2005-2069, CVE-2005-2337, CVE-2005-2876, CVE-2005-2969, CVE-2005-3120, CVE-2005-3178, CVE-2005-3195, VIGILANCE-SOL-9088, VU#160012 |
Mandriva: new ethereal packages
> Mandriva
BUGTRAQ-15148, BUGTRAQ-15158, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, MDKSA-2005:193, VIGILANCE-SOL-9087, enpa-sa-00021 |
Red Hat Enterprise Linux: new ethereal packages
> Red Hat
BUGTRAQ-15148, BUGTRAQ-15158, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, RHSA-2005:809-01, VIGILANCE-SOL-9086, enpa-sa-00021 |
| 25/10/2005 |
Debian: new sudo packages
> Debian
CVE-2005-2959, DSA 870-1, VIGILANCE-SOL-9085 |
| 24/10/2005 |
SUSE: new curl, wget packages
> Novell OES, SLES, SuSE
BUGTRAQ-15102, CVE-2005-3185, SUSE-SA:2005:063, VIGILANCE-SOL-9084 |
SUSE: new permissions, filesystem, xmcd packages
> SLES, SuSE
BUGTRAQ-15182, CVE-2005-3321, SUSE-SA:2005:062, VIGILANCE-SOL-9083 |
fetchmail: new versions fetchmail 6.2.9-rc6 and fetchmailconf 1.43.2
> Unix
BUGTRAQ-15179, CVE-2005-3088, VIGILANCE-SOL-9082, fetchmail-SA-2005-02 |
PHP : future versions 4.4.1, 5.0.6, 5.1.0
> Unix
BUGTRAQ-15177, CVE-2005-3319, VIGILANCE-SOL-9081 |
Windows: patch for Network Connection Manager
> Windows 2000, Windows 2003, Windows XP
BUGTRAQ-14260, CVE-2005-2307, MS05-045, VIGILANCE-SOL-8996 |
HP Oracle for OpenView: patch
> OpenView
BUGTRAQ-15134, HPSBMA01235, SSRT051055, VIGILANCE-SOL-9080, VU#210524, VU#449444 |
OpenView Operations, OpenView VantagePoint: patch for JRE
> OpenView
101749, BUGTRAQ-13958, CVE-2005-1974, HPSBMA01234, SSRT051052, VIGILANCE-SOL-9054 |
| 21/10/2005 |
SUSE: new net-snmp, xloadimage, netpbm, xine-lib, webmin packages
> SuSE
BUGTRAQ-14168, BUGTRAQ-14889, BUGTRAQ-15044, BUGTRAQ-15051, BUGTRAQ-15128, CVE-2005-2177, CVE-2005-2967, CVE-2005-2978, CVE-2005-3042, CVE-2005-3178, CVE-2005-3195, SUSE-SR:2005:024, VIGILANCE-SOL-9079 |
Debian: new eric packages
> Debian
CVE-2005-3068, DSA 869-1, VIGILANCE-SOL-9078 |
Eric: new version 3.7.2
> Unix
CVE-2005-3068, VIGILANCE-SOL-9077 |
Mandriva: new dia packages
> Mandriva
BUGTRAQ-15000, CVE-2005-2966, MDKSA-2005:18, VIGILANCE-SOL-9076 |
Mandriva: new xli packages
> Mandriva, Mandriva
BUGTRAQ-15051, CVE-2005-3178, CVE-2005-3195, MDKSA-2005:192, VIGILANCE-SOL-9075 |
Mandriva: new ruby packages
> Mandriva, Mandriva
CVE-2005-2337, MDKSA-2005:191, VIGILANCE-SOL-9074, VU#160012 |
Mandriva: new nss_ldap/pam_ldap packages
> Mandriva
BUGTRAQ-14649, CVE-2005-2641, MDKSA-2005:190, VIGILANCE-SOL-9073, VU#778916 |
Mandriva: new imap packages
> Mandriva, Mandriva
BUGTRAQ-15009, CVE-2005-2933, MDKSA-2005:189, VIGILANCE-SOL-9072, VU#933601 |
Mandriva: new graphviz packages
> Mandriva
BUGTRAQ-15050, CVE-2005-2965, MDKSA-2005:188, VIGILANCE-SOL-9071 |
Fedora Core 4: new kernel packages
> Fedora
BUGTRAQ-15156, CVE-2005-2973, FEDORA-2005-1013, VIGILANCE-SOL-9070 |
| 20/10/2005 |
Debian: new mozilla-thunderbird packages
> Debian
BUGTRAQ-14888, BUGTRAQ-14916, BUGTRAQ-14917, BUGTRAQ-14918, BUGTRAQ-14919, BUGTRAQ-14920, BUGTRAQ-14921, BUGTRAQ-14923, BUGTRAQ-14924, CVE-2005-2701, CVE-2005-2702, CVE-2005-2703, CVE-2005-2704, CVE-2005-2705, CVE-2005-2706, CVE-2005-2707, CVE-2005-2871, CVE-2005-2968, CVE-2005-3089, DSA 868-1, VIGILANCE-SOL-9069, VU#914681 |
Fedora Core: new squid packages
> Fedora
BUGTRAQ-15157, CVE-2005-3258, FEDORA-2005-1010, VIGILANCE-SOL-9068 |
Fedora Core: new ethereal packages
> Fedora
BUGTRAQ-15148, BUGTRAQ-15158, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, FEDORA-2005-1011, VIGILANCE-SOL-9067, enpa-sa-00021 |
Fedora Core 3: new kernel packages
> Fedora
BUGTRAQ-15076, BUGTRAQ-15085, BUGTRAQ-15154, BUGTRAQ-15156, CVE-2005-2973, CVE-2005-3119, CVE-2005-3179, CVE-2005-3180, CVE-2005-3181, FEDORA-2005-1007, VIGILANCE-SOL-9066 |
Debian: new module-assistant packages
> Debian
BUGTRAQ-15151, CVE-2005-3121, DSA 867-1, VIGILANCE-SOL-9065 |
Symantec Norton AntiVirus: update
> Norton Antivirus
BUGTRAQ-15142, BUGTRAQ-15143, CVE-2005-2759, CVE-2005-3270, SYM05-020, SYM05-021, VIGILANCE-SOL-9064 |
Ethereal: new version 0.10.13
> Unix
BUGTRAQ-15148, BUGTRAQ-15158, CVE-2005-3184, CVE-2005-3241, CVE-2005-3242, CVE-2005-3243, CVE-2005-3244, CVE-2005-3245, CVE-2005-3246, CVE-2005-3247, CVE-2005-3248, CVE-2005-3249, VIGILANCE-SOL-9063, enpa-sa-00021 |
Cisco CSS: new version
> Cisco CSS
BUGTRAQ-15144, CSCee64771, VIGILANCE-SOL-9062 |
Debian: new mozilla packages
> Debian
BUGTRAQ-14888, BUGTRAQ-14916, BUGTRAQ-14917, BUGTRAQ-14918, BUGTRAQ-14919, BUGTRAQ-14920, BUGTRAQ-14921, BUGTRAQ-14923, BUGTRAQ-14924, CVE-2005-2701, CVE-2005-2702, CVE-2005-2703, CVE-2005-2704, CVE-2005-2705, CVE-2005-2706, CVE-2005-2707, CVE-2005-2871, CVE-2005-2968, CVE-2005-3089, DSA 866-1, VIGILANCE-SOL-9061, VU#914681 |
Netscape Browser: new version 8.0.4
> Netscape Communicator
BUGTRAQ-14784, BUGTRAQ-14888, BUGTRAQ-14916, BUGTRAQ-14917, BUGTRAQ-14918, BUGTRAQ-14919, BUGTRAQ-14920, BUGTRAQ-14921, BUGTRAQ-14923, BUGTRAQ-14924, CVE-2005-2701, CVE-2005-2702, CVE-2005-2703, CVE-2005-2704, CVE-2005-2705, CVE-2005-2706, CVE-2005-2707, CVE-2005-2871, CVE-2005-2968, CVE-2005-3089, VIGILANCE-SOL-9060, VU#573857, VU#914681 |
AIX: solution for invscout
> AIX
BUGTRAQ-13909, BUGTRAQ-13911, BUGTRAQ-13912, BUGTRAQ-13914, BUGTRAQ-13915, BUGTRAQ-13916, BUGTRAQ-13917, BUGTRAQ-13918, BUGTRAQ-13919, BUGTRAQ-13920, BUGTRAQ-13921, CVE-2005-2232, CVE-2005-2233, CVE-2005-2234, CVE-2005-2235, CVE-2005-2236, CVE-2005-2237, VIGILANCE-SOL-8364 |
| 19/10/2005 |
SUSE: new openssl packages
> Novell Desktop, Novell OES, SLES, SuSE
BUGTRAQ-15071, CVE-2005-2969, SUSE-SA:2005:061, VIGILANCE-SOL-9059 |
Squid: patch for FTP
> Squid
BUGTRAQ-15157, CVE-2005-3258, VIGILANCE-SOL-9058 |
HP-UX: patch for ftpd
> HP-UX
BUGTRAQ-15138, CVE-2005-3296, VIGILANCE-SOL-9057 |
Oracle Application Server: CPU of October 2005
> Oracle AS
BUGTRAQ-15134, BUGTRAQ-15146, BUGTRAQ-15163, VIGILANCE-SOL-9056, VU#171364, VU#210524, VU#376756, VU#512716 |
Oracle Database: CPU of October 2005
> Oracle DB
BUGTRAQ-15134, VIGILANCE-SOL-9055, VU#210524, VU#449444 |
Apache HTTP: new version 1.3.34
> Apache httpd
BUGTRAQ-11604, BUGTRAQ-14106, BUGTRAQ-15222, BUGTRAQ-9506, BUGTRAQ-9561, CVE-2004-2320, CVE-2005-2088, Sun Alert ID 50603, Sun Alert ID 57670, Sun BugID 4808654, Sun BugID 5063481, VIGILANCE-SOL-9053, VU#867593 |
Zope: hotfix and new version
> Zope
BUGTRAQ-15082, CVE-2005-3323, Hotfix 2005-10-09, VIGILANCE-SOL-8939 |
Fedora: new curl packages
> Fedora
BUGTRAQ-15102, CVE-2005-3185, FEDORA-2005-1000, VIGILANCE-SOL-9052 |
| 18/10/2005 |
Red Hat Enterprise Linux: new xloadimage packages
> Red Hat
BUGTRAQ-15051, CVE-2005-3178, CVE-2005-3195, RHSA-2005:802-01, VIGILANCE-SOL-9051 |
Red Hat Enterprise Linux 4: new netpbm packages
> Red Hat
BUGTRAQ-15128, CVE-2005-2978, RHSA-2005:793-01, VIGILANCE-SOL-9050 |
Red Hat Enterprise Linux 2.1: new gdb packages
> Red Hat
BUGTRAQ-13697, CVE-2005-1704, CVE-2005-1705, RHSA-2005:801-01, VIGILANCE-SOL-9049 |
Snort: new version 2.4.3
> Snort
BUGTRAQ-15131, CVE-2005-3252, TA05-291A, VIGILANCE-SOL-9048, VU#175500 |
SUSE SLES, Novell OES: new OpenWBEM packages
> Novell OES, SLES
BUGTRAQ-15121, CVE-2005-3297, CVE-2005-3298, SUSE-SA:2005:060, VIGILANCE-SOL-9046 |
HP-UX: patch for smrsh
> HP-UX
BUGTRAQ-5845, CIAC N-030, CVE-2002-1165, HP234, HPSBUX0212-234, SSRT2432, VIGILANCE-SOL-5410 |
Fedora: new wget packages
> Fedora
BUGTRAQ-15102, CVE-2005-3185, FEDORA-2005-995, FEDORA-2005-996, VIGILANCE-SOL-9045 |
Fedora: new lynx packages
> Fedora
BUGTRAQ-15117, CVE-2005-3120, FEDORA-2005-993, FEDORA-2005-994, VIGILANCE-SOL-9044 |
| 17/10/2005 |
Solaris, Sun Java Enterprise: patch for Netscape Network Security Services (NSS)
> Solaris
BUGTRAQ-14162, CVE-2005-2096, VIGILANCE-SOL-9043, VU#680620 |
Solaris: patch for Mozilla
> Solaris
101952, 6281360, 6282170, 6282190, 6284465, BUGTRAQ-14242, BUGTRAQ-14888, BUGTRAQ-14916, BUGTRAQ-14917, BUGTRAQ-14918, BUGTRAQ-14919, BUGTRAQ-14920, BUGTRAQ-14921, BUGTRAQ-14923, BUGTRAQ-14924, CVE-2005-2260, CVE-2005-2261, CVE-2005-2262, CVE-2005-2263, CVE-2005-2264, CVE-2005-2265, CVE-2005-2266, CVE-2005-2267, CVE-2005-2268, CVE-2005-2269, CVE-2005-2270, CVE-2005-2701, CVE-2005-2702, CVE-2005-2703, CVE-2005-2704, CVE-2005-2705, CVE-2005-2706, CVE-2005-2707, CVE-2005-2871, CVE-2005-2968, CVE-2005-3089, VIGILANCE-SOL-9042, VU#652366, VU#914681, VU#996798 |
Gallery: new version 2.0.1
> Unix
BUGTRAQ-15108, CVE-2005-3251, VIGILANCE-SOL-9041 |
Red Hat Enterprise Linux: new lynx packages
> Red Hat
BUGTRAQ-15117, CVE-2005-3120, RHSA-2005:803-01, VIGILANCE-SOL-9040 |
lynx: patch
> Unix
BUGTRAQ-15117, CVE-2005-3120, VIGILANCE-SOL-9039 |
Fedora: new packages abiword
> Fedora
BUGTRAQ-15096, CVE-2005-2972, FEDORA-2005-989, VIGILANCE-SOL-9038 |
AbiWord: new version 2.2.11
> Unix
BUGTRAQ-15096, CVE-2005-2972, VIGILANCE-SOL-9037 |
Fedora: new texinfo packages
> Fedora
328365, BUGTRAQ-14854, CVE-2005-3011, FEDORA-2005-990, FEDORA-2005-991, VIGILANCE-SOL-9036 |
Fedora: new openssl packages
> Fedora
BUGTRAQ-15071, CVE-2005-2969, FEDORA-2005-985, FEDORA-2005-986, VIGILANCE-SOL-9035 |
Red Hat Enterprise Linux 4: new openldap and nss_ldap packages
> Red Hat
BUGTRAQ-14125, BUGTRAQ-14126, BUGTRAQ-14649, CVE-2005-2069, CVE-2005-2641, RHSA-2005:767-01, VIGILANCE-SOL-9034, VU#778916 |
Red Hat Enterprise Linux 2.1 and 3: new openldap and nss_ldap packages
> Red Hat
BUGTRAQ-14125, BUGTRAQ-14126, CVE-2005-2069, RHSA-2005:751-01, VIGILANCE-SOL-9033 |
Windows: patch for MSDTC, COM+ and TIP
> Windows 2000, Windows 2003, Windows XP
BUGTRAQ-15056, BUGTRAQ-15057, BUGTRAQ-15058, BUGTRAQ-15059, CVE-2005-1978, CVE-2005-1979, CVE-2005-1980, CVE-2005-2119, MS05-051, VIGILANCE-SOL-9000, VU#180868 |
Mandriva: new koffice packages
> Mandriva
BUGTRAQ-15060, CESA-2005-005, CVE-2005-2971, MDKSA-2005:185, VIGILANCE-SOL-9032 |
Fedora: new koffice packages
> Fedora
BUGTRAQ-15060, CESA-2005-005, CVE-2005-2971, FEDORA-2005-984, VIGILANCE-SOL-9031 |
| 14/10/2005 |
SUSE: new imap-lib, texinfo, cfengine, abiword, vnc packages
> SuSE
328365, BUGTRAQ-14807, BUGTRAQ-14854, BUGTRAQ-14971, BUGTRAQ-14994, BUGTRAQ-15009, CVE-2005-2495, CVE-2005-2933, CVE-2005-2960, CVE-2005-2964, CVE-2005-3011, CVE-2005-3137, SUSE-SR:2005:023, VIGILANCE-SOL-9030, VU#102441, VU#933601 |
AIX: patch for lscfg
> AIX
BUGTRAQ-15105, CVE-2005-3289, IY77624, VIGILANCE-SOL-9029 |
Solaris: patch for SCTP
> Solaris
101881, 6248555, 6250374, CVE-2005-3238, VIGILANCE-SOL-9028 |
Mandriva: new packages wget
> Mandriva
BUGTRAQ-15102, CVE-2005-3185, MDKSA-2005:183, VIGILANCE-SOL-9027 |
Mandriva: new curl packages
> Mandriva, Mandriva, Mandriva
BUGTRAQ-15102, CVE-2005-3185, MDKSA-2005:182, VIGILANCE-SOL-9026 |
wget: new version 1.10.2
> Unix
BUGTRAQ-15102, CVE-2005-3185, VIGILANCE-SOL-9025 |
cURL : new version 7.15.0 and patch
> Unix
BUGTRAQ-15102, CVE-2005-3185, VIGILANCE-SOL-9024 |
XMail: new version 1.22
> Unix
BUGTRAQ-15103, CVE-2005-2943, VIGILANCE-SOL-9023 |
Apache: new version 2.0.55
> Apache httpd
29962, BUGRAQ-14721, BUGTRAQ-14106, BUGTRAQ-14366, BUGTRAQ-14620, BUGTRAQ-14660, CVE-2005-1268, CVE-2005-2088, CVE-2005-2491, CVE-2005-2700, CVE-2005-2728, VIGILANCE-SOL-9022, VU#744929 |
|
NEWS
|