GLSA 200403-10 - GLSA 200403-14

Címkék

Ma kiadtak 5 új GLSA-t. A következő programokban találtak biztonsági hibákat: Fetchmail, Squid, OpenLDAP, MPlayer, Monit.GLSA 200403-10 Fetchmail 6.2.5 fixes a remote DoS

Fetchmail versions 6.2.4 and earlier can be crashed by sending a

specially-crafted email to a fetchmail user.

GLSA 200403-11 Squid ACL [url_regex] bypass vulnerability

Squid versions 2.0 through to 2.5.STABLE4 could allow a remote attacker

to bypass Access Control Lists by sending a specially-crafted URL

request containing '%00': in such circumstances; the url_regex ACL may

not properly detect the malicious URL, allowing the attacker to

effectively bypass the ACL.

GLSA 200403-12 OpenLDAP DoS Vulnerability

A failed password operation can cause the OpenLDAP slapd server, if it

is using the back-ldbm backend, to free memory that was never

allocated.

GLSA 200403-13 Remote buffer overflow in MPlayer

MPlayer contains a remotely exploitable buffer overflow in the HTTP

parser that may allow attackers to run arbitrary code on a user's

computer.

GLSA 200403-14 Multiple Security Vulnerabilities in Monit

A denial of service and a buffer overflow vulnerability have been found

in Monit.