★ wanayoo — archive 1999 http://search.linuxsecurity.com/advisories/mandrake.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Caldera
Corel
Debian
FreeBSD
LinuxPPC
Mandrake
NetBSD
OpenBSD
Other
Red Hat
Slackware
Stampede
StormLinux
SuSE
TurboLinux
 
Mandrake 8/12/2000 20:49


  • 8/12/2000 20:49 : Mandrake: MandrakeUpdate vulnerability
    - There is a possible race condition in MandrakeUpdate that has the potential for users to tamper with RPMs downloaded by MandrakeUpdate prior to them being installed.

  • 8/10/2000 15:49 : Mandrake: umb-scheme vulnerability
    - The umb-scheme package included with Red Hat Linux 6.2 included two world-writable files. Mandrake is NOT vulnerable.

  • 8/10/2000 15:37 : Mandrake: netscape vulnerability
    - There exists a problem in all versions of Netscape with Java enabled.

  • 8/9/2000 19:04 : Mandrake: perl vulnerability
    - setuidperl combined with other programs may make it possible to execute a command to create a suid shell.

  • 8/3/2000 16:52 : Mandrake: mailman NOT vulnerable
    - Linux-Mandrake does not ship with the mailman package and is therefore not vulnerable to this exploit.

  • 8/2/2000 16:22 : Mandrake: pam vulnerability
    - pam_console incorrectly identifies remote X logins for displays other than local ones.

  • 8/2/2000 0:27 : Mandrake: kon2 vulnerability
    - The program fld may make it possible to obtain a root shell by inputing arbitrary code into the stack.

  • 8/1/2000 16:45 : Mandrake: netscape vulnerability
    - Previous versions of Netscape, from version 3.0 to 4.73 contain a serious overflow flaw due to improper input verification in Netscape's JPEG processing code.

  • 7/28/2000 21:20 : Mandrake: Zope vulnerability
    - Previous versions of Zope have a serious security flaw in one of the base classes in the DocumentTemplate package that is inadequately protected.

  • 7/28/2000 15:53 : Mandrake: gpm vulnerability
    - Many security flaws fixed in gpm and gpmctl including denial of service attack.

  • 7/23/2000 3:27 : Mandrake: inn vulnerability
    - A vulnerability exists that could be used to gain root access. Many security fixes have been made.

  • 7/22/2000 0:17 : Mandrake: dhcp vulnerability
    - All versions of the ISC DHCP client program, dhclient, are vulnerable to a root attack by a corrupt DHCP server.

  • 7/19/2000 14:56 : Mandrake: nfs-utils vulnerability
    - A bug recently discovered in the nfs-utils package can theoretically be used for gaining remote root access.

  • 7/18/2000 17:00 : Mandrake: usermode vulnerability
    - Normal users may reboot or halt the system without having root access.

  • 7/14/2000 15:19 : Mandrake: cvsweb vulnerability
    - Cvsweb contains a hole that provides attackers who have write access to a cvs repository with shell access.

  • 7/12/2000 14:48 : Mandrake: dump vulnerability
    - A buffer overflow vulnerability has been fixed in the restore program

  • 7/8/2000 10:25 : Mandrake: BitchX update
    - An updated package now exists to fix a denial of service vulnerability

  • 7/7/2000 17:16 : Mandrake: inn vulnerability
    - An updated version of inn is available to fix a potential root compromise problem.

  • 7/7/2000 15:51 : Mandrake: man vulnerability
    - An updated man package is available to fix a makewhatis vulnerability

  • 7/2/2000 22:16 : Mandrake: dhcp update
    - Remote exploit leading to root compromise on the host running dhcp client remotely.

  • 7/2/2000 22:13 : Mandrake: wu-ftpd update
    - Wu-ftpd is vulnerable to a very serious remote attack in the SITE EXEC implementation.

  • 6/23/2000 23:16 : Mandrake: 2.2.16 kernel update
    - Fix for recent capabilities security bug

  • 6/23/2000 16:06 : Mandrake: Multiple Vulnerabilities
    - Updates available for bind, cdrecord, dump, fdutils, kdesu, xemacs, xlockmore

  • 6/4/2000 13:11 : Mandrake: Xlockmore vulnerability
    - This update fixes a buffer overflow vulnerability that was present in xlock that permitted a user to view parts of the shadowed passwd file.

  • 6/4/2000 0:38 : Mandrake: bind vulnerability
    - This updates bind to run as a normal user instead of root.

  • 6/3/2000 14:24 : Mandrake: cdrecord buffer overflow
    - The linux cdrecord binary is vulnerable to a locally exploitable buffer overflow attack.

  • 5/29/2000 15:47 : Mandrake: kdesu vulnerability
    - A vulnerability in kdesud will allow any user to exploit a buffer overflow.

  • 5/24/2000 18:54 : Mandrake 7: dump vulnerability
    - Dump may cause security problem due to a buffer overflow.

  • 5/24/2000 10:30 : Mandrake: xemacs vulnerability
    - Under some circumstances, users are able to snoop on other users' keystrokes.

  • 5/23/2000 22:21 : Mandrake 7: fdmount buffer overflow
    - A vulnerability in fdmount will allow any user to exploit a buffer overflow.

  • 5/17/2000 17:39 : Mandrake 7: xsoldier vulnerability
    - Buffer overflow in xsoldier exists and an update has been issued.

  • 4/22/2000 15:05 : Mandrake 7.0: OpenLDAP
    - Local users can destroy the contents of any file on any mounted filesystem.

  • 1/12/2000 23:15 : Mandrake: 2.2.x kernel are all affected by a networking security bug
    - Mandrake has released an updated kernel to address a network security bug.

  • 12/13/1999 17:53 : Mandrake 6.0: gnomehack
    - An exploit (buffer overflow attack) has been found in this package.

  • 12/13/1999 13:12 : Mandrake 6.1: lpr
    - A security hole has been found in the version of lpr shipped with Mandrake 6.1 that could allow users to print files for which they don't have read permissions.

  • 12/13/1999 13:11 : Mandrake 6.1: screen
    - By default, screen did not use Unix98 ptys (/dev/pts/*), which resulted in its controlling terminal being world-writable. This is a security bug, which this package cures. Credits go to Red Hat.

  • 12/13/1999 12:23 : Mandrake 6.1: wu-ftpd
    - This update cures two problems:

  • 12/13/1999 12:22 : Mandrake 6.1: am-utils
    - There is a potential buffer overflow / remote exploit in the am-utils package.

  • 12/13/1999 12:21 : Mandrake 6.1: ypserv
    - This package fixes several problems:

  • 12/13/1999 12:20 : Mandrake 6.1: kvirc
    - This package cures the "!nick ../../../etc/shadow" bug. Understand, it doesn't allow anymore users to get files you wouldn't like them to get.

  • 12/13/1999 12:20 : Mandrake 6.1: bind
    - If you are using Linux-Mandrake as a name server, you should upgrade to this package.

  • 12/13/1999 12:19 : Mandrake 6.0: kernel 2.2.9
    - 2.2.x kernel are all affected by a networking security bug.

  • 12/13/1999 12:17 : Mandrake 6.0: screensavers from kdebase
    - Upgrade to kdebase-1.1.1final-11mdk.i586.rpm

  • 12/13/1999 12:17 : Mandrake 6.0: net-tools
    - Upgrade to our new net-tools package which fixes potentional bufer overruns. This package also contains a patch for ESP and GRE protocols recognition in VPN masquerade.

  • 12/13/1999 12:15 : Mandrake 6.0: samba
    - Several security holes have been discovered in the latest release of Samba.

  • 12/13/1999 12:14 : Mandrake 6.0: Apache (Squid-related problem)
    - Squid was installing an HTML administration cgi in /cgi-bin, giving world access. It is moved in /protected-cgi-bin/, restricting access only to localhost.

  • 12/13/1999 12:13 : Mandrake 6.0: isdn4utils
    - xmonisdn as distributed in the isndutils package from Mandrake 6.0 has a security problem.

  • 12/13/1999 12:12 : Mandrake 6.0: wu-ftpd
    - the wu-ftpd deamon as distributed in the wu-ftpd package from Mandrake 6.0 has a security problem.

  • 12/13/1999 12:09 : Mandrake 6.0: BeroFTPD
    - the BeroFTPD deamon as distributed in the BeroFTPD package from Mandrake 6.0 has a security problem.

  • 12/13/1999 12:08 : Mandrake 6.0: lynx
    - lynx as distributed in the lynx package from Mandrake 6.0 has a security problem.

  • 12/13/1999 12:08 : Mandrake 6.0: vixie-cron
    - There is a possible exploit in MAILTO -C command and buffer overflow vulnerability.

  • 12/13/1999 12:07 : Mandrake 6.0: am-utils
    - There is a potential buffer overflow / remote exploit in the am-utils package.

  • Contact Us | Legal Notice | About Our Site
    © Guardian Digital, Inc., 2000