SUSE 5510 Published by Philipp Esselbach 0

Just a reminder that Novell is giving away a free DVD evaluation copy of SUSE LINUX Professional 9.1 as part of their Linux Technical Resource Kit

The Linux Technical Resource Kit comes on 3 DVDs and includes the following products:

DVD #1
SUSE Linux Enterprise Server 8.0 (ISO)
Ximian Red Carpet 2.02 (ISO)
Notes for ConsoleOne version 1.3.6
GroupWise 6.5 for Linux (ISO)
Novell Nterprise Linux Services (NNLS) 1.0 (ISO)
Linux Resource Materials (White Papers)

SUSE 5510 Published by Philipp Esselbach 0

Updated dhcp packages are available for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: dhcp/dhcp-server Announcement-ID: SuSE-SA:2004:019 Date: Tuesday, Jun 22st 2004 21:00 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 7, 8 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: yes Cross References: VU#317350 VU#654390 Content of this advisory: 1) security vulnerability resolved: buffer overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information)

SUSE 5510 Published by Philipp Esselbach 0

A Subversion update is available for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: subversion Announcement-ID: SuSE-SA:2004:018 Date: Thursday, Jun 17th 2004 09:30 MEST Affected products: 8.1, 8.2, 9.0, 9.1 Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: no Cross References: CAN-2004-0413 Content of this advisory: 1) security vulnerability resolved: heap overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information)

SUSE 5510 Published by Philipp Esselbach 0

A kernel update has been released for SUSE Linux: ______________________________________________________________________________ SUSE Security Announcement Package: kernel Announcement-ID: SuSE-SA:2004:017 Date: Wednesday, Jun 16th 2004 15:20 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SuSE Linux Database Server, SuSE eMail Server III, 3.1 SuSE Linux Enterprise Server 7, 8 SuSE Linux Firewall on CD/Admin host SuSE Linux Connectivity Server SuSE Linux Office Server Vulnerability Type: local denial-of-service attack Severity (1-10): 4 SUSE default package: no Cross References: CAN-2004-0554 Content of this advisory: 1) security vulnerability resolved: - floating point exception causes system crash problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information) ______________________________________________________________________________

SUSE 5510 Published by Philipp Esselbach 0

A squid update has been released for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: squid Announcement-ID: SuSE-SA:2004:016 Date: Wednesday, Jun 9th 2004 16:30 MEST Affected products: 8.2, 9.0, 9.1 Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: no Cross References: CAN-2004-0541 Content of this advisory: 1) security vulnerability resolved: - buffer overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - tla - OpenOffice_org - tripwire - postgresql - lha 3) standard appendix (further information)

SUSE 5510 Published by Philipp Esselbach 0

SUSE has released a cvs update

______________________________________________________________________________

SUSE Security Announcement

Package: cvs
Announcement-ID: SuSE-SA:2004:015
Date: Wed Jun 9 15:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0416
CAN-2004-0417
CAN-2004-0418

Content of this advisory:
1) security vulnerability resolved: various security issues in cvs problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- icecast
- sitecopy
- cadaver
- tla
- OpenOffice_org
- tripwire
- postgresql
- lha
- apache/mod_ssl
3) standard appendix (further information)

SUSE 5510 Published by Philipp Esselbach 0

SUSE has released a kdelibs update

______________________________________________________________________________

SUSE Security Announcement

Package: kdelibs/kdelibs3
Announcement-ID: SuSE-SA:2003:014
Date: Wed May 26 12:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Linux Database Server,
SuSE Linux Enterprise Server 7, 8
SuSE Linux Firewall on CD 2
SuSE Linux Connectivity Server
SuSE Linux Office Server
SuSE Linux Desktop 1.0
Vulnerability Type: remote file creation
Severity (1-10): 6
SUSE default package: yes
Cross References: CAN-2004-0411


Content of this advisory:
1) security vulnerability resolved: URI file creation vulnerability
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- rsync
- film
- apache/mod_ssl
3) standard appendix (further information)

______________________________________________________________________________

SUSE 5510 Published by Philipp Esselbach 0

A cvs update has been released for SUSE Linux

______________________________________________________________________________

SUSE Security Announcement

Package: cvs
Announcement-ID: SuSE-SA:2004:013
Date: Wed May 19 13:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0396

Content of this advisory:
1) security vulnerability resolved: buffer overflow in cvs
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- neon
- subversion
- kdelibs/kdelibs3
3) standard appendix (further information)

______________________________________________________________________________

SUSE 5510 Published by Philipp Esselbach 0

An updated SUSE Live CD 9.1 is available

______________________________________________________________________________

SuSE Security Announcement

Package: Live CD 9.1
Announcement-ID: SuSE-SA:2004:011
Date: Thursday, May 6th 2004 22:30 MEST
Affected products: SUSE LINUX 9.1 Personal Edition Live CD
Vulnerability Type: remote root access
Severity (1-10): 8
SuSE default package: yes
Other affected systems: none

Content of this advisory:
1) security vulnerability resolved: Live CD 9.1
problem description, discussion, solution and upgrade informatio
n
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)

______________________________________________________________________________

1) problem description, brief discussion, solution, upgrade information

The freshly released SUSE LINUX 9.1 comes in two variants:

* SUSE LINUX 9.1 Professional (5 CD-ROMs, 2 double sided DVDs, printed manuals, for Intel i386 32Bit platform and 1 DVD for the AMD 64Bit platform)
* SUSE LINUX 9.1 Personal (2 CD-ROMs: 1 installable CD-ROM, 1 Live CD-ROM for running SUSE LINUX on your PC without actually installing the system.)

SUSE 5510 Published by Philipp Esselbach 0

A kernel update has been released for SUSE Linux

______________________________________________________________________________

SUSE Security Announcement

Package: Linux Kernel
Announcement-ID: SuSE-SA:2004:010
Date: Tuesday, May 5th 2004 02:30 MEST
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Linux Database Server,
SuSE eMail Server III, 3.1
SuSE Linux Enterprise Server 7, 8
SuSE Linux Firewall on CD/Admin host
SuSE Linux Connectivity Server
SuSE Linux Office Server
UnitedLinux 1.0
SuSE Linux Desktop 1.0
Vulnerability Type: privilege escalation, local DoS
Severity (1-10): 7
SUSE default package: yes
Cross References: CAN-2004-0427
CAN-2004-0424
CAN-2004-0229
CAN-2004-0228
CAN-2004-0394

Content of this advisory:
1) security vulnerability resolved:
- do_fork() memory leak (CAN-2004-0427)
- setsockopt() buffer overflow (CAN-2004-0424)
- misuse of fb_copy_cmap() (CAN-2004-0229)
- cpufreq_procctl() integer overflow (CAN-2004-0228)
- buffer overflow in panic() (CAN-2004-0394)
- wrong permissions on /proc/scsi/qla2300/HbaApiNode
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- canna
- xchat
- tcpdump
- lha
3) standard appendix (further information)

______________________________________________________________________________

SUSE 5510 Published by Philipp Esselbach 0

A cvs update is available for SUSE Linux

______________________________________________________________________________

SUSE Security Announcement

Package: cvs
Announcement-ID: SuSE-SA:2004:008
Date: Wed Apr 14 16:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SLES 8 for IBM iSeries and IBM pSeries
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote code execution
Severity (1-10): 5
SUSE default package: No
Cross References:

Content of this advisory:
1) security vulnerability resolved: arbitrary file creation in cvs
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- neon
- tcpdump
- openssh
- kdeprint/kdelibs3
- MPlayer
- mailman
- systat
- apache2
- emil
3) standard appendix (further information)

______________________________________________________________________________

SUSE 5510 Published by Philipp Esselbach 0

SUSE has released a kernel update

______________________________________________________________________________

SUSE Security Announcement

Package: Linux Kernel
Announcement-ID: SuSE-SA:2004:009
Date: Wednesday, Apr. 14th 2004 16:00 MEST
Affected products: 8.0, 8.1, 8.2, 9.0
SuSE Linux Database Server,
SuSE eMail Server III, 3.1
SuSE Linux Enterprise Server 7, 8
SuSE Linux Firewall on CD/Admin host
SuSE Linux Connectivity Server
SuSE Linux Office Server
Vulnerability Type: - local privilege escalation
- information leakage
Severity (1-10): 6
SUSE default package: yes
Cross References: CAN-2004-0109
CAN-2004-0181

Content of this advisory:
1) security vulnerability resolved:
- buffer overflow in ISO9660 code
- information leakage in JFS
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- mailman
- sysstat
- neon
- openssh
- kdeprint/kdelibs3
- MPlayer
- sysstat
- apache2
- emil
- metamail
- tcpdump
3) standard appendix (further information)

______________________________________________________________________________