Security Advisories
KDE root compromise


The K Desktop Environment (KDE) provides an integrated graphical desktop environment for UNIX workstations. As a part of this environment, it supplies its own PPP implementation (kppp) and its own screen locking environment (klock), both of which are installed setuid root. Both of these programs have numerous security vulnerabilities which can expose the computer to a root compromise by a local user.
ICMP Address Mask Replies


Several host platforms improperly reply to ICMP address mask requests (ICMP_MASKREQ, type 17) in violation of RFC1122. The information leaked by these hosts can be used to gather topological information about unknown networks.
Livingston Telnet DOS


Livingston Enterprises routers and terminal servers running ComOS versions prior to 3.7 are vulnerable to a remote denial of service attack if an intruder has access to the telnet port.

