[KLUG Members] Bruce's security newsletter (not a regular thing). :-)

Bruce Smith members@kalamazoolinux.org
05 Mar 2003 09:59:23 -0500


If you haven't heard, a MAJOR security hole was recently found that
effects MANY Unix systems and Linux distributions running sendmail.

If you run sendmail on any OS, PLEASE CHECK FOR UPGRADES!  This also
effects Unix, as I had to patch all of my HP-UX boxes.  And it does NOT
matter if your sendmail servers are behind a firewall!  If your sendmail
server accepts email from anywhere, then you could be compromised by a
regular email message relayed through your firewall.

=======================================================================

Also, I know that a number of people on this list use IPCOP, and these
fixes sound major, so I forward this announcement, this one time only.

If you use IPCOP, pleases subscribe to their announce list.  That way we
don't need to clutter up our list with this kind of stuff.  I will NOT
forward any future IPCOP announcements here.

The IPCOP _announce_ list is only for announcements, not disccusion, and
is VERY LOW traffic.  Well worth subscribing!


--------------------------------------------
Bruce Smith                bruce@armintl.com
System Administrator / Network Administrator
Armstrong International, Inc.
Three Rivers, Michigan  49093  USA
http://www.armstrong-intl.com/
--------------------------------------------


-----Forwarded Message-----

From: ipcop-announce-admin@lists.sourceforge.net
To: ipcop-announce@lists.sourceforge.net, ipcop-user@lists.sourceforge.net, ipcop-devel@lists.sourceforge.net
Subject: [IPCop-Announce] IPCop v1.2.0 fixes1 release
Date: 05 Mar 2003 15:21:33 +0100

Hello,

You will find the fixes1 update for IPCop v1.2.0 on the website.

Size:    860350 (840KB)
MD5:     23bfe7c00ad12d1cae36f32f7541f74b
Fixes:	- Snort security vulnerability fixed
	- OpenSSL security vulnerability fixed
	- Vi local security vulnerability fixed
	- PNG security vulnerability fixed
	- Proxylog.dat debug code removed
	- Typo in ipsecpassthru fixed
	- PPPoE Dial-On-Demand for DNS fixed

No other functionality is included in this patch.

Kind regards,


Mark Wormgoor
-- 
***************************************************************
* |\    /|      |  /|  /       Mark Wormgoor                  *
* | \  / |      | / | /        mailto:mark@wormgoor.com       *
* |  \/  |ark   |/  |/ormgoor  http://www.wormgoor.com/mark/  *
***************************************************************



-------------------------------------------------------
This sf.net email is sponsored by:ThinkGeek
Welcome to geek heaven.
http://thinkgeek.com/sf
_______________________________________________
IPCop-Announce mailing list
IPCop-Announce@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/ipcop-announce