Novell Inc. released to its SuSE Linux line on Friday numerous fixes to bugs that could enable a number of types of attacks, including DoS. The new set of patches fixes a variety of problems that can be exploited to cause denial-of-service, spoofing and cross-site scripting attacks, as well as to disclose sensitive information or compromise unpatched systems. The programs affected by the fixes include older versions of SuSE Linux, Desktop and SuSE Server Linux and the newest server operating system, SuSE Enterprise Linux 9.
Most of the flaws are not problems with SuSE's operating system per se, but with bundled programs, like CUPS (Common Unix Printing System), the Sun Java Plug-in and the KDE windows manager.
With this release, Novell's SuSE Linux division has started a new approach to releasing bug fixes. According to Marcus Meissner, a member of the SuSE Security Team, "To avoid spamming lists with advisories for every small incident, we will release weekly summary advisories for issues where we have released updates without a full advisory."
The fixes are currently available from SuSE's FTP servers and via the YaST Online Update program.
Read more... Source : YahooNews