eWeek Security Watch
Advertisement
Advertisement

Open Source Archive

April 5, 2007

Thursday, April 05, 2007 12:50 PM/EST

Mozilla to Disable ANI Exploits' Path of Entry

The Mozilla Foundation is looking at disabling support for the Windows animated cursor format as a workaround for the ANI vulnerability that has left Windows systems open to exploit and complete takeover for the past week. Firefox users who use...

Read more... | Comment | del.icio.us | digg.com | View all of Browsers

March 27, 2007

Tuesday, March 27, 2007 2:11 PM/EST

Reloaded Metasploit Point-and-Click Pen Tool Ready to Get Down to Hacking

The new version of HD Moore's point-and-click Metasploit Framework that was rewritten from scratch in the Ruby scripting language is ready to penetrate, pick at patches, regress test and otherwise hack away. Moore has said that the primary goals of...

Read more... | Comment | del.icio.us | digg.com | View all of Exploits and Attacks

March 16, 2007

Friday, March 16, 2007 6:36 PM/EST

Red Hat Release Coincides with Host of Related Application, Kernel Fixes

It turns out that, after years of engineering work and collaboration efforts with strategic partners such as IBM, Red Hat's March 14 release of Red Hat Enterprise Linux 5 had the misfortune of coinciding with the company's release of a...

Read more... | Comment | del.icio.us | digg.com | View all of Open Source

March 15, 2007

Thursday, March 15, 2007 2:31 PM/EST

Hole Found in OpenBSD

The open-source operating system OpenBSD has a critical remote kernel buffer overflow vulnerability in its IPv6 protocol stack that can allow for a remote attacker to take over the system with malformed e-mail, Core Security Technologies disclosed on March 13....

Read more... | Comment | del.icio.us | digg.com | View all of Exploits and Attacks

March 7, 2007

Wednesday, March 07, 2007 6:32 PM/EST

Don't Trust GnuPG Encrypted and Signed E-Mail

Core Security Technologies has discovered a flaw in GNU Privacy Guard—the open-source cryptographic software system that's part of the GNU software project and at the heart of third-party e-mail that's signed, encrypted and trusted—that allows attackers to reach into e-mail...

Read more... | Comment | del.icio.us | digg.com | View all of Flaws
Wednesday, March 07, 2007 12:14 PM/EST

JavaScript Hole Found in Firefox, SeaMonkey

The Mozilla Foundation reported on Monday that a critical JavaScript bug in the Firefox browser and in the SeaMonkey Internet application suite could allow a malicious Web site to inject arbitrary code into a vulnerable PC. The bug was inadvertently...

Read more... | Comment | del.icio.us | digg.com | View all of Browsers
Wednesday, March 07, 2007 10:11 AM/EST

Thunderbird Open to Exploit

Ubuntu has a security alert out on its Thunderbird e-mail client, with a flaw that could allow an attacker to take over a vulnerable PC. Versions 5.10, 6.06 LTS and 6.10 are affected and can be fixed by upgrading to...

Read more... | Comment | del.icio.us | digg.com | View all of Flaws

March 3, 2007

Saturday, March 03, 2007 7:41 PM/EST

WordPress Code Subverted on Its Own Server

Users who have downloaded the 2.1.1 version of the open-source blogging platform WordPress should upgrade all files to 2.1.2 immediately, since they could include a security bug injected by a cracker who gained user-level access to one of the servers...

Read more... | Comment | del.icio.us | digg.com | View all of Exploits and Attacks

February 26, 2007

Monday, February 26, 2007 9:04 AM/EST

Critical Firefox Flaw Accidentally Fixed

After a flurry of "yes it's fixed" and "oh no it's not" between bug researchers over the weekend, the verdict is that Firefox 2.0.0.2 did indeed fix the memory corruption flaw found by Polish hacker Michal Zalewski on Feb. 23....

Read more... | Comment | del.icio.us | digg.com | View all of Flaws

February 23, 2007

Friday, February 23, 2007 4:48 PM/EST

Most Critical Firefox Flaw Remains Unzapped

The most critical flaw in Firefox hasn't been addressed in the update released today. Mozilla's out with Firefox updates and is urging that customers upgrade immediately to fix critical security holes and stability issues. Issued today were Firefox 1.5.0.10, Firefox...

Read more... | Comment | del.icio.us | digg.com | View all of Open Source
Previous Viewing articles: 10 - 20 Next
RSS Syndication
Advertisement

CAG

SEO

Advertisement
Security Watch     Contact Us | Advertise | Site Map
eWEEK Quick LInks

Ziff Davis Enterprise