★ wanayoo — archive 1999 http://search.linuxsecurity.com/advisories/turbolinux.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Caldera
Corel
Debian
FreeBSD
LinuxPPC
Mandrake
NetBSD
OpenBSD
Other
Red Hat
Slackware
Stampede
StormLinux
SuSE
TurboLinux
 
TurboLinux 2/22/2001 18:41


  • 2/22/2001 18:41 : TurboLinux: 'sendmail' segmentation fault
    - Sendmail may be exploited to gain root privileges due to segmentation fault vulnerability in "address test" mode.

  • 2/22/2001 18:40 : TurboLinux: 'bind' vulnerabilities
    - Buffer overflow and other vulnerabilities exist in previous versions of bind.

  • 2/16/2001 17:27 : TurboLinux: 'glibc' vulnerability
    - Previous versions may allow access to write or overwrite restricted files.

  • 2/8/2001 19:18 : TurboLinux: 'netscape' buffer overflow
    - A buffer overflow exists in Netscape's HTML parsing code.

  • 2/8/2001 16:16 : TurboLinux: 'slocate' vulnerability
    - There is a heap-corruption vulnerability existing in slocate.

  • 1/30/2001 18:37 : TurboLinux: 'LPRng' buffer overflow
    - The version of LPRng that ships with TurboLinux is vulnerable to a remotely exploitable buffer overflow.

  • 12/28/2000 10:34 : TurboLinux: 'fetchmail' vulnerability
    - The updated IMAP server released in errata advisory RHSA:102-04 exposes a bug in fetchmail's implementation of the AUTHENTICATE GSSAPI command.

  • 10/17/2000 14:47 : TurboLinux: 'traceroute' vulnerability
    - There is a bug in the traceroute command that can possibly be use by local users to obtain super user privileges.

  • 9/19/2000 6:52 : TurboLinux: 'sysklogd' vulnerability
    - Various vulnerabilities exist in syslogd/klogd. By exploiting these vulnerabilities, it could be possible for local users to gain root access.

  • 9/19/2000 6:50 : TurboLinux: 'xchat' vulnerability
    - There has been a well-known vulnerability existing with all un-patched xchat versions 1.4.2 and earlier.

  • 9/8/2000 18:03 : TurboLinux: glibc vulnerabilities
    - Several bugs were discovered in glibc which could allow local users to gain root privileges.

  • 8/31/2000 15:06 : TurboLinux: 'netscape' vulnerability
    - There is a serious problem in netscape's java libraries that allows an applet to act as a web server on the client machine

  • 8/11/2000 21:17 : TurboLinux: UPDATED: pam-0.70-2 and earlier vulnerability
    - A denial of service attack can be made against the PAM auth system.

  • 8/10/2000 3:05 : TurboLinux: perl vulnerability
    - The latest versions of perl as well as past shipping versions of perl in TurboLinux distributions are susceptible to a local root exploit.

  • 8/2/2000 16:41 : TurboLinux: netscape-4.73 and earlier
    - A web site could contain malicious code which would enable remote execution or other malicious behavior as the user of netscape on the client's machine.

  • 8/1/2000 16:45 : TurboLinux: cvsweb-1.90 and earlier
    - remote read/write access to arbitrary files owned by the default web user is possible via this exploit.

  • 7/28/2000 21:19 : TurboLinux: dhcp vulnerability
    - Remote root exploit present in versions earlier than 2.0.

  • 7/19/2000 22:19 : TurboLinux: wu-ftpd-2.6.0 and earlier
    - Improper bounds checking may lead to remote root execution on FTP server.

  • 6/19/2000 23:30 : TurboLinux: kernel vulnerability
    - Any local user with an account can use this vulnerability to obtain root priviledges by exploiting setuid root applications.

  • 5/30/2000 0:16 : TurboLinux: local users can view shadowed password file
    - An overflow in the -mode command line option exists

  • 5/26/2000 14:35 : TurboLinux: gpm-1.19.1 and earlier
    - A user with console access can use this vulnerability to execute arbitrary commands with elevated priviledges.

  • 5/17/2000 11:14 : TurboLinux: OpenLDAP vulnerability
    - Local users can destroy the contents of any file on any mounted filesystem.

  • 4/15/2000 10:07 : TurboLinux pam-0.70-2
    - "Both 'pam' and 'userhelper' (a setuid binary that comes with the 'usermode-1.15' rpm) follow .. paths. Since pam_start calls down to _pam_add_handler(), we can get it to dlopen any file on disk. 'userhelper' being setuid means we can get root."

  • 3/22/2000 1:00 : Package: nmh-1.0.2 and earlier
    - A buffer overrun exists in nmh versions 1.0.2 and prior. Due to improper MIME header parsing, an attacker could create a MIME message such that the mhshow utility may be used to execute shell code when the message is viewed.

  • 3/15/2000 21:11 : TurboLinux: dump local buffer overrun
    - Previous versions of dump did not handle permissions correctly. It may be possible to execute arbitrary code with the permissions of the process.

  • 3/9/2000 21:26 : TurboLinux: MySQL password auth vulnerability
    - The MySQL database server (prior to 3.22.32) has a flawed password authentication mechanism. Anyone who can connect to the server can access databases without knowing an exact password.

  • 3/8/2000 23:51 : TurboLinux: htdig vulnerability
    - Remote users can read any file on the server using htsearch. This affects TurboLinux versions 6.0 and earlier.

  • 3/8/2000 23:50 : TurboLinux: man vulnerability
    - Buffer overflow possibility in TurboLinux versions 6.0.2 and earlier.

  • 3/8/2000 21:16 : TurboLinux: mtr privilege problem
    - Older versions of mtr did not properly drop root privileges.

  • 2/18/2000 20:28 : TurboLinux: make-3.77-44 and earlier
    - GNU make creates temporary files in /tmp without checking for links if it is fed a Makefile via stdin.

  • 2/18/2000 19:47 : TurboLinux: gdm-2.0beta4-12 and earlier
    - Gdmlogin reveals authentication and account information that may be used to gain root priviledges.

  • Contact Us | Legal Notice | About Our Site
    © Guardian Digital, Inc., 2000