An updated kernel has been released for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: kernel Announcement-ID: SUSE-SA:2004:024 Date: Monday, Aug 9th 2004 08:50 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 7, 8, 9 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server Vulnerability Type: local privilege escalation Severity (1-10): 6 SUSE default package: yes Cross References: CAN-2004-0415 Content of this advisory: 1) security vulnerability resolved: - race condition in file offset pointer handling problem description 2) solution/workaround 3) special instructions and notes 4) package location and checksums 5) pending vulnerabilities, solutions, workarounds: - gaim - mozilla/firebird 6) standard appendix (further information)
An updated libpng package has been released for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: libpng Announcement-ID: SUSE-SA:2004:023 Date: Wednesday, Aug 4th 2004 16:00 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 7, 8, 9 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server Vulnerability Type: remote system compromise Severity (1-10): 9 SUSE default package: yes Cross References: VU#388984 VU#236656 VU#160448 VU#477512 VU#817368 VU#286464 CAN-2004-0597 CAN-2004-0598 CAN-2004-0599 Content of this advisory: 1) security vulnerability resolved: - stack based buffer overflows - NULL pointer dereference - integer overflows problem description 2) solution/workaround 3) special instructions and notes 4) package location and checksums 5) pending vulnerabilities, solutions, workarounds: - mod_ssl - lha - gfxboot - liby2util - pure-ftpd - neon - pavuk - sox - gaim - kernel 6) standard appendix (further information) ______________________________________________________________________________
It looks like that Novell will release an updated Linux Technical Resource Kit shortly.
Some users have received the following email from Novell:
Some users have received the following email from Novell:
Updated SAMBA packages has been released for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: samba Announcement-ID: SUSE-SA:2004:022 Date: Friday, Jul 23th 2004 12:30 MEST Affected products: 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 7, 8 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server Vulnerability Type: remote root compromise Severity (1-10): 7 SUSE default package: no Cross References: CAN-2004-0600 CAN-2004-0686 Content of this advisory: 1) security vulnerability resolved: - buffer overflow in base64 code - buffer overflow in "mangling method hash" code problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - cadaver - kopete - wv - gnats - OpenOffice_org - mod_ssl - lha 3) standard appendix (further information)
Updated PHP4 packages are available for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: php4/mod_php4 Announcement-ID: SUSE-SA:2004:021 Date: Friday, Jul 16th 2004 13:00:00 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1, SuSE Linux Enterprise Server 8, SuSE Linux Office Server, UnitedLinux 1.0 Vulnerability Type: remote code execution Severity (1-10): 7 SUSE default package: No. Cross References: CAN-2004-0594 CAN-2004-0595 http://security.e-matters.de/advisories/112004.html Content of this advisory: 1) security vulnerability resolved: memory_limit problem, strip_tags() bypassing problem problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - sitecopy - cadaver - freeswan - ipsec-tools - apache2 - dhcp/dhcp-server 3) standard appendix (further information) ______________________________________________________________________________
Just a reminder that Novell is giving away a free DVD evaluation copy of SUSE LINUX Professional 9.1 as part of their Linux Technical Resource Kit
The Linux Technical Resource Kit comes on 3 DVDs and includes the following products:
DVD #1
SUSE Linux Enterprise Server 8.0 (ISO)
Ximian Red Carpet 2.02 (ISO)
Notes for ConsoleOne version 1.3.6
GroupWise 6.5 for Linux (ISO)
Novell Nterprise Linux Services (NNLS) 1.0 (ISO)
Linux Resource Materials (White Papers)
The Linux Technical Resource Kit comes on 3 DVDs and includes the following products:
DVD #1
SUSE Linux Enterprise Server 8.0 (ISO)
Ximian Red Carpet 2.02 (ISO)
Notes for ConsoleOne version 1.3.6
GroupWise 6.5 for Linux (ISO)
Novell Nterprise Linux Services (NNLS) 1.0 (ISO)
Linux Resource Materials (White Papers)
Updated dhcp packages are available for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: dhcp/dhcp-server Announcement-ID: SuSE-SA:2004:019 Date: Tuesday, Jun 22st 2004 21:00 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SUSE Linux Database Server, SUSE eMail Server III, 3.1 SUSE Linux Enterprise Server 7, 8 SUSE Linux Firewall on CD/Admin host SUSE Linux Connectivity Server SUSE Linux Office Server Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: yes Cross References: VU#317350 VU#654390 Content of this advisory: 1) security vulnerability resolved: buffer overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information)
DistroWatch reports that SUSE 9.1 Personal is now available for free download
A Subversion update is available for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: subversion Announcement-ID: SuSE-SA:2004:018 Date: Thursday, Jun 17th 2004 09:30 MEST Affected products: 8.1, 8.2, 9.0, 9.1 Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: no Cross References: CAN-2004-0413 Content of this advisory: 1) security vulnerability resolved: heap overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information)
SUSE Linux 8.0 will be discontinued after June 30th 2004
A kernel update has been released for SUSE Linux: ______________________________________________________________________________ SUSE Security Announcement Package: kernel Announcement-ID: SuSE-SA:2004:017 Date: Wednesday, Jun 16th 2004 15:20 MEST Affected products: 8.0, 8.1, 8.2, 9.0, 9.1 SuSE Linux Database Server, SuSE eMail Server III, 3.1 SuSE Linux Enterprise Server 7, 8 SuSE Linux Firewall on CD/Admin host SuSE Linux Connectivity Server SuSE Linux Office Server Vulnerability Type: local denial-of-service attack Severity (1-10): 4 SUSE default package: no Cross References: CAN-2004-0554 Content of this advisory: 1) security vulnerability resolved: - floating point exception causes system crash problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - OpenOffice_org - tripwire - postgresql - lha - XDM - mod_proxy 3) standard appendix (further information) ______________________________________________________________________________
McDonald's Germany deploys SUSE LINUX Enterprise Server for DNS, FTP, and proxy services on the Internet. Thanks Spunz.
KDE 3.2.3 packages are available for SuSE distributions
A squid update has been released for SUSE Linux ______________________________________________________________________________ SUSE Security Announcement Package: squid Announcement-ID: SuSE-SA:2004:016 Date: Wednesday, Jun 9th 2004 16:30 MEST Affected products: 8.2, 9.0, 9.1 Vulnerability Type: remote system compromise Severity (1-10): 5 SUSE default package: no Cross References: CAN-2004-0541 Content of this advisory: 1) security vulnerability resolved: - buffer overflow problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds: - icecast - sitecopy - cadaver - tla - OpenOffice_org - tripwire - postgresql - lha 3) standard appendix (further information)
SUSE has released a cvs update
______________________________________________________________________________
SUSE Security Announcement
Package: cvs
Announcement-ID: SuSE-SA:2004:015
Date: Wed Jun 9 15:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0416
CAN-2004-0417
CAN-2004-0418
Content of this advisory:
1) security vulnerability resolved: various security issues in cvs problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- icecast
- sitecopy
- cadaver
- tla
- OpenOffice_org
- tripwire
- postgresql
- lha
- apache/mod_ssl
3) standard appendix (further information)
______________________________________________________________________________
SUSE Security Announcement
Package: cvs
Announcement-ID: SuSE-SA:2004:015
Date: Wed Jun 9 15:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0416
CAN-2004-0417
CAN-2004-0418
Content of this advisory:
1) security vulnerability resolved: various security issues in cvs problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- icecast
- sitecopy
- cadaver
- tla
- OpenOffice_org
- tripwire
- postgresql
- lha
- apache/mod_ssl
3) standard appendix (further information)
SUSE has released a kdelibs update
______________________________________________________________________________
SUSE Security Announcement
Package: kdelibs/kdelibs3
Announcement-ID: SuSE-SA:2003:014
Date: Wed May 26 12:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Linux Database Server,
SuSE Linux Enterprise Server 7, 8
SuSE Linux Firewall on CD 2
SuSE Linux Connectivity Server
SuSE Linux Office Server
SuSE Linux Desktop 1.0
Vulnerability Type: remote file creation
Severity (1-10): 6
SUSE default package: yes
Cross References: CAN-2004-0411
Content of this advisory:
1) security vulnerability resolved: URI file creation vulnerability
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- rsync
- film
- apache/mod_ssl
3) standard appendix (further information)
______________________________________________________________________________
______________________________________________________________________________
SUSE Security Announcement
Package: kdelibs/kdelibs3
Announcement-ID: SuSE-SA:2003:014
Date: Wed May 26 12:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Linux Database Server,
SuSE Linux Enterprise Server 7, 8
SuSE Linux Firewall on CD 2
SuSE Linux Connectivity Server
SuSE Linux Office Server
SuSE Linux Desktop 1.0
Vulnerability Type: remote file creation
Severity (1-10): 6
SUSE default package: yes
Cross References: CAN-2004-0411
Content of this advisory:
1) security vulnerability resolved: URI file creation vulnerability
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- rsync
- film
- apache/mod_ssl
3) standard appendix (further information)
______________________________________________________________________________
A cvs update has been released for SUSE Linux
______________________________________________________________________________
SUSE Security Announcement
Package: cvs
Announcement-ID: SuSE-SA:2004:013
Date: Wed May 19 13:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0396
Content of this advisory:
1) security vulnerability resolved: buffer overflow in cvs
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- neon
- subversion
- kdelibs/kdelibs3
3) standard appendix (further information)
______________________________________________________________________________
______________________________________________________________________________
SUSE Security Announcement
Package: cvs
Announcement-ID: SuSE-SA:2004:013
Date: Wed May 19 13:00:00 MEST 2004
Affected products: 8.0, 8.1, 8.2, 9.0, 9.1
SuSE Firewall on CD 2 - VPN
SuSE Firewall on CD 2
SuSE Linux Enterprise Server 7, 8
SuSE Linux Office Server
UnitedLinux 1.0
Vulnerability Type: remote command execution
Severity (1-10): 6
SUSE default package: No.
Cross References: CAN-2004-0396
Content of this advisory:
1) security vulnerability resolved: buffer overflow in cvs
problem description, discussion, solution and upgrade information
2) pending vulnerabilities, solutions, workarounds:
- neon
- subversion
- kdelibs/kdelibs3
3) standard appendix (further information)
______________________________________________________________________________
An updated SUSE Live CD 9.1 is available
______________________________________________________________________________
SuSE Security Announcement
Package: Live CD 9.1
Announcement-ID: SuSE-SA:2004:011
Date: Thursday, May 6th 2004 22:30 MEST
Affected products: SUSE LINUX 9.1 Personal Edition Live CD
Vulnerability Type: remote root access
Severity (1-10): 8
SuSE default package: yes
Other affected systems: none
Content of this advisory:
1) security vulnerability resolved: Live CD 9.1
problem description, discussion, solution and upgrade informatio
n
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The freshly released SUSE LINUX 9.1 comes in two variants:
* SUSE LINUX 9.1 Professional (5 CD-ROMs, 2 double sided DVDs, printed manuals, for Intel i386 32Bit platform and 1 DVD for the AMD 64Bit platform)
* SUSE LINUX 9.1 Personal (2 CD-ROMs: 1 installable CD-ROM, 1 Live CD-ROM for running SUSE LINUX on your PC without actually installing the system.)
______________________________________________________________________________
SuSE Security Announcement
Package: Live CD 9.1
Announcement-ID: SuSE-SA:2004:011
Date: Thursday, May 6th 2004 22:30 MEST
Affected products: SUSE LINUX 9.1 Personal Edition Live CD
Vulnerability Type: remote root access
Severity (1-10): 8
SuSE default package: yes
Other affected systems: none
Content of this advisory:
1) security vulnerability resolved: Live CD 9.1
problem description, discussion, solution and upgrade informatio
n
2) pending vulnerabilities, solutions, workarounds
3) standard appendix (further information)
______________________________________________________________________________
1) problem description, brief discussion, solution, upgrade information
The freshly released SUSE LINUX 9.1 comes in two variants:
* SUSE LINUX 9.1 Professional (5 CD-ROMs, 2 double sided DVDs, printed manuals, for Intel i386 32Bit platform and 1 DVD for the AMD 64Bit platform)
* SUSE LINUX 9.1 Personal (2 CD-ROMs: 1 installable CD-ROM, 1 Live CD-ROM for running SUSE LINUX on your PC without actually installing the system.)