[SECURITY-L] Vulnerabilidades de Seguranca

CSIRT - UNICAMP security em unicamp.br
Qua Mar 22 12:35:32 -03 2006


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Srs. Assinantes,

Atualizamos o site do CSIRT (Computer Security Incident Response Team) da Unicamp
com os seguintes boletins de vulnerabilidades:


Anúncio de Segurança do Conectiva Linux:
========================================
20/03/2006 - CLA-2006:1067 
Assunto: sudo 
http://www.security.unicamp.br/docs/bugs/2006/03/v093.txt

Debian Security Advisory:
=========================
21/03/2006 - DSA 1012-1 
Assunto: unzip 
http://www.security.unicamp.br/docs/bugs/2006/03/v096.txt

21/03/2006 - DSA 1011-1 
Assunto: kernel-patch-vserver, util-vserver 
http://www.security.unicamp.br/docs/bugs/2006/03/v095.txt

20/03/2006 - DSA 1010-1 
Assunto: ilohamail 
http://www.security.unicamp.br/docs/bugs/2006/03/v090.txt

21/03/2006 - DSA 1009-1 
Assunto: crossfire 
http://www.security.unicamp.br/docs/bugs/2006/03/v087.txt

20/03/2006 - DSA 960-3 
Assunto: libmail-audit-perl 
http://www.security.unicamp.br/docs/bugs/2006/03/v086.txt

17/03/2006 - DSA 1008-1 
Assunto: kdegraphics
http://www.security.unicamp.br/docs/bugs/2006/03/v079.txt

17/03/2006 - DSA 1007-1
Assunto: drupal 
http://www.security.unicamp.br/docs/bugs/2006/03/v078.txt

16/03/2006 - DSA 1005-1 
Assunto: xine-lib 
http://www.security.unicamp.br/docs/bugs/2006/03/v080.txt

16/03/2006 - DSA 1006-1 
Assunto: wzdftpd 
http://www.security.unicamp.br/docs/bugs/2006/03/v077.txt

Fedora Legacy Update Advisory:
==============================
16/03/2006 - FLSA:157459-2 
Assunto: Updated kernel packages fix security issues
http://www.security.unicamp.br/docs/bugs/2006/03/v083.txt

16/03/2006 - FLSA:174479 
Assunto: Updated libungif packages fix security issues 
http://www.security.unicamp.br/docs/bugs/2006/03/v082.txt

16/03/2006 - FLSA:173274 
Assunto: Updated gdk-pixbuf packages fix security issues 
http://www.security.unicamp.br/docs/bugs/2006/03/v081.txt
16/03/2006 - FLSA:175404
Assunto: Updated xpdf package fixes security issues 
http://www.security.unicamp.br/docs/bugs/2006/03/v071.txt

Fedora Update Notification:
===========================
21/03/2006 - FEDORA-2006-189 
Assunto: Fedora Core 5: curl 
http://www.security.unicamp.br/docs/bugs/2006/03/v099.txt

21/03/2006 - FEDORA-2006-188 
Assunto: Fedora Core 5: beagle 
http://www.security.unicamp.br/docs/bugs/2006/03/v098.txt

20/03/2006 - FEDORA-2006-172 
Assunto: Fedora Core 5: xorg-x11-server 
http://www.security.unicamp.br/docs/bugs/2006/03/v088.txt

Gentoo Linux Security Advisory:
===============================
21/03/2006 - GLSA 200603-20 
Assunto: Macromedia Flash Player: Arbitrary code execution 
http://www.security.unicamp.br/docs/bugs/2006/03/v101.txt

21/03/2006 - GLSA 200603-19 
Assunto: cURL/libcurl: Buffer overflow in the handling of TFTP URLs 
http://www.security.unicamp.br/docs/bugs/2006/03/v100.txt

21/03/2006 - GLSA 200603-18 
Assunto: Pngcrush: Buffer overflow 
http://www.security.unicamp.br/docs/bugs/2006/03/v094.txt

21/03/2006 - GLSA 200603-17 
Assunto: PeerCast: Buffer overflow 
http://www.security.unicamp.br/docs/bugs/2006/03/v097.txt

17/03/2006 - GLSA 200603-16
Assunto: Metamail: Buffer overflow 
http://www.security.unicamp.br/docs/bugs/2006/03/v075.txt

17/03/2006 - GLSA 200603-15 
Assunto: Crypt::CBC: Insecure initialization vector 
http://www.security.unicamp.br/docs/bugs/2006/03/v074.txt

17/03/2006 - GLSA 200603-14 
Assunto: Heimdal: rshd privilege escalation 
http://www.security.unicamp.br/docs/bugs/2006/03/v072.txt

17/03/2006 - GLSA 200603-13 
Assunto: PEAR-Auth: Potential authentication bypass 
http://www.security.unicamp.br/docs/bugs/2006/03/v073.txt

HP Security Bulletin:
=====================
20/03/2006 - HPSBUX02074 SSRT051251 rev.2 
Assunto: Apache-based Web Server on HP-UX mod_ssl, proxy_http, Remote Execution of Arbitrary Code, Denial of Service (DoS), and Unauthorized Access 
http://www.security.unicamp.br/docs/bugs/2006/03/v089.txt

20/03/2006 - HPSBUX02101 SSRT051128 rev.1 
Assunto: HP-UX VirtualVault running Apache 1.3.X Remote Unauthorized Access 
http://www.security.unicamp.br/docs/bugs/2006/03/v085.txt

20/03/2006 - HPSBUX02102 SSRT051078 rev.1 
Assunto: HP-UX usermod(1M) Local UnaUthorized Access. 
http://www.security.unicamp.br/docs/bugs/2006/03/v084.txt

Mandriva Linux Security Update Advisory:
========================================
20/03/2006 - MDKSA-2006:057 
Assunto: cairo 
http://www.security.unicamp.br/docs/bugs/2006/03/v091.txt

20/03/2006 - MDKSA-2006:056
Assunto: xorg-x11
http://www.security.unicamp.br/docs/bugs/2006/03/v092.txt

- --
Computer Security Incident Response Team - CSIRT
Universidade Estadual de Campinas - UNICAMP
mailto:security at unicamp.br
http://www.security.unicamp.br
GnuPG Public Key: http://www.security.unicamp.br/security.asc


-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (FreeBSD)

iD8DBQFEIW40/UMb1l3gm8IRAhuaAJ9IINeRxr9hu6WYwEwI6WK/2z6sygCglFlC
JKn8YU/oOqwdar5OKohp3lA=
=ZMXv
-----END PGP SIGNATURE-----



Mais detalhes sobre a lista de discussão SECURITY-L