----------------------------------------------------------------------

Secunia is pleased to announce the release of the annual Secunia
report for 2008.

Highlights from the 2008 report:
 * Vulnerability Research
 * Software Inspection Results
 * Secunia Research Highlights
 * Secunia Advisory Statistics

Request the full 2008 Report here:
http://secunia.com/advisories/try_vi/request_2008_report/

Stay Secure,

Secunia


----------------------------------------------------------------------

TITLE:
SUSE Update for Multiple Packages

SECUNIA ADVISORY ID:
SA34642

VERIFY ADVISORY:
http://secunia.com/advisories/34642/

DESCRIPTION:
SUSE has issued an update for multiple packages. This fixes some
security issues and vulnerabilities, which can be exploited by
malicious, local users to bypass certain security restrictions or
cause a DoS (Denial of Service), and by malicious people to conduct
spoofing attacks, disclose sensitive information, conduct cross-site
script and HTTP response splitting attacks, and compromise a
vulnerable system.

For more information:
SA25073
SA30111
SA32964
SA33047
SA33293
SA33980
SA33406
SA34081
SA34430
SA34468
SA34567

A security issue is caused due to the "/var/run/multipathd.sock"
being world-writable, which can be exploited to e.g. send arbitrary
commands to the multipath daemon.

SOLUTION:
Apply updated packages using YaST Online Update or the SUSE FTP
server.

ORIGINAL ADVISORY:
SUSE-SR:2009:008:
http://www.novell.com/linux/security/advisories/2009_8_sr.html

OTHER REFERENCES:
SA25073:
http://secunia.com/advisories/25073/

SA30111:
http://secunia.com/advisories/30111/

SA32964:
http://secunia.com/advisories/32964/

SA33047:
http://secunia.com/advisories/33047/

SA33293:
http://secunia.com/advisories/33293/

SA33980:
http://secunia.com/advisories/33980/

SA33406:
http://secunia.com/advisories/33406/

SA34081:
http://secunia.com/advisories/34081/

SA34430:
http://secunia.com/advisories/34430/

SA34468:
http://secunia.com/advisories/34468/

SA34567:
http://secunia.com/advisories/34567/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/advisories/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/advisories/about_secunia_advisories/


Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories
http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

----------------------------------------------------------------------