| ★ wanayoo — archive 1999 http://www.linuxsecurity.com/advisories/linuxppc.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
- Additional unspecified security fixes have resulted in another updated version of proftpd. - A bug in bind can allow remote users access to the systems as the bind user (typically root). A DoS attack using malformed TCP packets can pause bind. Several bugs can cause the server to crash due to remote attacks. If you are running bind it is recommended that you upgrade immediately. - Multiple problems were found in the ypserv RPM. It is recommended that LinuxPPC users running NIS upgrade as soon as possible. - Screen doesn't run suid root which can result in the creation of insecure PTY's. - Additional buffer overflows were found in wu-ftpd. - A misconfiguration in the default PAM setup can allow logins via rsh. - There is a race condition in lpr in which files were tested for permissions and then opened. Also, lpr doesn't do any checks before opening queued files as root which could allow somone to symlink to a file and print it regardless of access permissions. - In certain network configurations pam may allow access to locked NIS accounts. - A properly formatted E-mail can exploit a buffer overflow in the text/enriched code of this E-mail client. - A number of significant bugs and security issues have been fixed with XFREE86. (Note: This is a significant upgrade) - The current version of proftpd (1.2.0pre6) still contains vulnerabilities, users should look to wu-ftpd as an alternative. - There were several security flaws in older versions of Samba: a DOS attack could be performed against nmbd, a buffer overflow was present in nmbd and a race condition was present in smbmnt that could cause problems if installed suid root. Samba users should upgrade as soon as possible. - When Lynx calls external programs (i.e. - telnet) is does not check on passed options. This could cause local files to be created or modified. - A buffer overflow in the amd daemon was actively being exploited to obtain root access. This upgrade should be performed as soon as possible. - A vixie-cron buffer overflow exists that could allow users to gain root priveleges through the manipulation of environment variables. - A buffer overflow in a specific function of libtermcap could allow a user to execute arbitrary code if they were to supply their own termcap file. - A vulnerability to a denial-of-service attack in in.telnetd has been fixed. - proftpd-1.2.0pre6 has been released with fixed various unspecified security vulnerabilities in 1.2.0pre5. It is recommeneded that all users of proftpd upgrade. - Several buffer overflows were discovered in the mars-nwe package. Since this package runs as root it is recommended that anyone using it upgrade. - A buffer overflow vulnerabilty is present in proftpd. Anyonye running proftpd is advised to upgrade to the new RPM. - Unexploited Buffer overflow present in INN versions 2.2 and earlier - Package update for inews which fixes unexploited buffer overflow. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |