| ★ wanayoo — archive 1999 http://search.linuxsecurity.com/advisories/mandrake.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
- There is a possible race condition in MandrakeUpdate that has the potential for users to tamper with RPMs downloaded by MandrakeUpdate prior to them being installed. - The umb-scheme package included with Red Hat Linux 6.2 included two world-writable files. Mandrake is NOT vulnerable. - There exists a problem in all versions of Netscape with Java enabled. - setuidperl combined with other programs may make it possible to execute a command to create a suid shell. - Linux-Mandrake does not ship with the mailman package and is therefore not vulnerable to this exploit. - pam_console incorrectly identifies remote X logins for displays other than local ones. - The program fld may make it possible to obtain a root shell by inputing arbitrary code into the stack. - Previous versions of Netscape, from version 3.0 to 4.73 contain a serious overflow flaw due to improper input verification in Netscape's JPEG processing code. - Previous versions of Zope have a serious security flaw in one of the base classes in the DocumentTemplate package that is inadequately protected. - Many security flaws fixed in gpm and gpmctl including denial of service attack. - A vulnerability exists that could be used to gain root access. Many security fixes have been made. - All versions of the ISC DHCP client program, dhclient, are vulnerable to a root attack by a corrupt DHCP server. - A bug recently discovered in the nfs-utils package can theoretically be used for gaining remote root access. - Normal users may reboot or halt the system without having root access. - Cvsweb contains a hole that provides attackers who have write access to a cvs repository with shell access. - A buffer overflow vulnerability has been fixed in the restore program - An updated package now exists to fix a denial of service vulnerability - An updated version of inn is available to fix a potential root compromise problem. - An updated man package is available to fix a makewhatis vulnerability - Remote exploit leading to root compromise on the host running dhcp client remotely. - Wu-ftpd is vulnerable to a very serious remote attack in the SITE EXEC implementation. - Fix for recent capabilities security bug - Updates available for bind, cdrecord, dump, fdutils, kdesu, xemacs, xlockmore - This update fixes a buffer overflow vulnerability that was present in xlock that permitted a user to view parts of the shadowed passwd file. - This updates bind to run as a normal user instead of root. - The linux cdrecord binary is vulnerable to a locally exploitable buffer overflow attack. - A vulnerability in kdesud will allow any user to exploit a buffer overflow. - Dump may cause security problem due to a buffer overflow. - Under some circumstances, users are able to snoop on other users' keystrokes. - A vulnerability in fdmount will allow any user to exploit a buffer overflow. - Buffer overflow in xsoldier exists and an update has been issued. - Local users can destroy the contents of any file on any mounted filesystem. - Mandrake has released an updated kernel to address a network security bug. - An exploit (buffer overflow attack) has been found in this package. - A security hole has been found in the version of lpr shipped with Mandrake 6.1 that could allow users to print files for which they don't have read permissions. - By default, screen did not use Unix98 ptys (/dev/pts/*), which resulted in its controlling terminal being world-writable. This is a security bug, which this package cures. Credits go to Red Hat. - This update cures two problems: - There is a potential buffer overflow / remote exploit in the am-utils package. - This package fixes several problems: - This package cures the "!nick ../../../etc/shadow" bug. Understand, it doesn't allow anymore users to get files you wouldn't like them to get. - If you are using Linux-Mandrake as a name server, you should upgrade to this package. - 2.2.x kernel are all affected by a networking security bug. - Upgrade to kdebase-1.1.1final-11mdk.i586.rpm - Upgrade to our new net-tools package which fixes potentional bufer overruns. This package also contains a patch for ESP and GRE protocols recognition in VPN masquerade. - Several security holes have been discovered in the latest release of Samba. - Squid was installing an HTML administration cgi in /cgi-bin, giving world access. It is moved in /protected-cgi-bin/, restricting access only to localhost. - xmonisdn as distributed in the isndutils package from Mandrake 6.0 has a security problem. - the wu-ftpd deamon as distributed in the wu-ftpd package from Mandrake 6.0 has a security problem. - the BeroFTPD deamon as distributed in the BeroFTPD package from Mandrake 6.0 has a security problem. - lynx as distributed in the lynx package from Mandrake 6.0 has a security problem. - There is a possible exploit in MAILTO -C command and buffer overflow vulnerability. - There is a potential buffer overflow / remote exploit in the am-utils package. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |