Debian has updated mono (arbitrary code execution via integer overflow), perdition (arbitrary code execution via crafted IMAP tag).
Fedora Core 6 has updated flac (arbitrary code execution via crafted FLAC file), tar (buffer overflow resulting in "crashing stack"), firefox (multiple vulnerabilities), thunderbird (multiple vulnerabilities), libpng (denial of service), xen (arbitrary file truncation via tmpfile symlink), ruby (insufficient SSL certificate verification), cups (arbitrary code execution via IPP), cpio (buffer overflow resulting in "crashing stack").
Fedora 7 has updated cpio (buffer overflow resulting in "crashing stack"), proftpd (authentication bypass).
Mandriva has updated opal (denial of service), pwlib (denial of service).
Red Hat has updated jboss (multiple vulnerabilities), perl (for Red Hat Application Stack and Red Hat Enterprise Linux) (arbitrary code execution), pcre (for RHEL 5 and RHEL 4) (two arbitrary code execution vulnerabilities).
Read full story...