![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| USN-813-1: apr vulnerability | iBot | Security Advisories (RSS) | 0 | 08-07-2009 09:15 PM |
| S-358: DNS Vulnerability | iBot | Security Advisories (RSS) | 0 | 08-18-2008 02:50 PM |
| S-067: Tk Vulnerability | iBot | Security Advisories (RSS) | 0 | 02-22-2008 05:20 PM |
| USN-579-1: Qt vulnerability | iBot | Security Advisories (RSS) | 0 | 02-21-2008 10:30 AM |
| S-164: Tk Vulnerability | iBot | Security Advisories (RSS) | 0 | 02-11-2008 05:10 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
USN-843-1: BackupPC vulnerability
Referenced CVEs:
CVE-2009-3369 Description: =========================================================== Ubuntu Security Notice USN-843-1 October 06, 2009 backuppc vulnerability CVE-2009-3369 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.04 LTS Ubuntu 8.10 Ubuntu 9.04 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.04 LTS: backuppc 3.0.0-4ubuntu1.1 Ubuntu 8.10: backuppc 3.1.0-3ubuntu2.1 Ubuntu 9.04: backuppc 3.1.0-4ubuntu1.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: It was discovered that BackupPC did not restrict normal users from setting the ClientNameAlias parameter. An authenticated user could exploit this to gain access to unauthorized hosts. This update fixed the issue by preventing normal users from modifying the ClientNameAlias configuration parameter. More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|