SUSE released updated packages to address multiple security vulnerabilities, which could be exploited by attackers to compromise a vulnerable system or conduct Cross Site Scripting attacks. Fixed vulnerabilities are :
- xpdf integer overflows (affect all SUSE Linux distributions)
- Awstats remote code injection (affects SUSE Linux 9.1 and 9.2)
- Java Plugin security issue (affects all SUSE Linux distributions on the Intel x86 and AMD64 / Intel Extended Memory Architecture (EM64T) platforms.)
- mpg123 buffer overflow (affects all SUSE Linux distributions)
- squirrelmail Cross Site Scripting
(affects all SUSE Linux distributions)
- MozillaThunderbird NNTP handling overflow (affects SUSE Linux 9.1 and 9.2)
- mailman cross site scripting and security bypass (affect all SUSE Linux distributions)
- xine-lib buffer overflows (affect all SUSE Linux distributions)
ChangeLog
2005-01-27 : Initial release
Vulnerability Management
Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.
Feedback
If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.