---------------------------------------------------------------------- Did you know that a change in our assessment rating, exploit code availability, or if an updated patch is released by the vendor, is not part of this mailing-list? Click here to learn more: http://secunia.com/advisories/business_solutions/ ---------------------------------------------------------------------- TITLE: SUSE Update for Multiple Packages SECUNIA ADVISORY ID: SA33087 VERIFY ADVISORY: http://secunia.com/advisories/33087/ CRITICAL: Moderately critical IMPACT: Security Bypass, Manipulation of data, DoS WHERE: >From remote OPERATING SYSTEM: openSUSE 10.2 http://secunia.com/advisories/product/13375/ openSUSE 10.3 http://secunia.com/advisories/product/16124/ openSUSE 11.0 http://secunia.com/advisories/product/19180/ SUSE Linux Enterprise Server 10 http://secunia.com/advisories/product/12192/ DESCRIPTION: SUSE has issued an update for multiple packages. This fixes some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) and bypass certain security restrictions, and malicious people to conduct SQL injection attacks. For more information: SA31875 SA32119 SA32127 Additionally, a boundary error in php_imap.c has also been fixed in openSUSE 10.2, 10.3, and 11.0. SOLUTION: Apply updated packages via YaST Online Update or the SUSE FTP server. ORIGINAL ADVISORY: SUSE-SR:2008:027: http://lists.opensuse.org/opensuse-security-announce/2008-12/msg00002.html OTHER REFERENCES: SA31875: http://secunia.com/advisories/31875/ SA32119: http://secunia.com/advisories/32119/ SA32127: http://secunia.com/advisories/32127/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------