![]() |
Hello and Welcome from United States to the UNIX and Linux Forums! Thank You for Visiting and Joining Our Global Community.
|
|
google unix.com
|
|||||||
| Forums | Register | Forum Rules | Links | Albums | FAQ | Members List | Calendar | Search | Today's Posts | Mark Forums Read |
| Security Advisories (RSS) UNIX and Linux Security Advisories Via RSS News |
More UNIX and Linux Forum Topics You Might Find Helpful
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| USN-810-1: NSS vulnerabilities | iBot | Security Advisories (RSS) | 0 | 08-04-2009 06:00 PM |
| USN-776-1: KVM vulnerabilities | iBot | Security Advisories (RSS) | 0 | 05-12-2009 07:15 PM |
| USN-761-2: PHP vulnerabilities | iBot | Security Advisories (RSS) | 0 | 04-27-2009 05:45 PM |
| USN-720-1: PHP vulnerabilities | iBot | Security Advisories (RSS) | 0 | 02-12-2009 03:50 PM |
| USN-653-1: D-Bus vulnerabilities | iBot | Security Advisories (RSS) | 0 | 10-14-2008 01:40 PM |
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
|
|||||
|
USN-844-1: mimeTeX vulnerabilities
Referenced CVEs:
CVE-2009-1382, CVE-2009-2459 Description: ===========================================================Ubuntu Security Notice USN-844-1 October 08, 2009mimetex vulnerabilitiesCVE-2009-1382, CVE-2009-2459===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: mimetex 1.50-1ubuntu0.8.04.1Ubuntu 8.10: mimetex 1.50-1ubuntu0.8.10.1Ubuntu 9.04: mimetex 1.50-1ubuntu0.9.04.1In general, a standard system upgrade is sufficient to effect thenecessary changes.Details follow:Chris Evans discovered that mimeTeX incorrectly handled certain long tags.An attacker could exploit this with a crafted mimeTeX expression and causea denial of service or possibly execute arbitrary code. (CVE-2009-1382)Chris Evans discovered that mimeTeX contained certain directives that maybe unsuitable for handling untrusted user input. This update fixed theissue by disabling the \input and \counter tags. (CVE-2009-2459) More... |
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|