| ★ wanayoo — archive 1999 http://www.linuxsecurity.com/advisories/turbolinux.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
- A denial of service attack can be made against the PAM auth system. - The latest versions of perl as well as past shipping versions of perl in TurboLinux distributions are susceptible to a local root exploit. - A web site could contain malicious code which would enable remote execution or other malicious behavior as the user of netscape on the client's machine. - remote read/write access to arbitrary files owned by the default web user is possible via this exploit. - Remote root exploit present in versions earlier than 2.0. - Improper bounds checking may lead to remote root execution on FTP server. - Any local user with an account can use this vulnerability to obtain root priviledges by exploiting setuid root applications. - An overflow in the -mode command line option exists - A user with console access can use this vulnerability to execute arbitrary commands with elevated priviledges. - "Both 'pam' and 'userhelper' (a setuid binary that comes with the 'usermode-1.15' rpm) follow .. paths. Since pam_start calls down to _pam_add_handler(), we can get it to dlopen any file on disk. 'userhelper' being setuid means we can get root." - A buffer overrun exists in nmh versions 1.0.2 and prior. Due to improper MIME header parsing, an attacker could create a MIME message such that the mhshow utility may be used to execute shell code when the message is viewed. - Previous versions of dump did not handle permissions correctly. It may be possible to execute arbitrary code with the permissions of the process. - The MySQL database server (prior to 3.22.32) has a flawed password authentication mechanism. Anyone who can connect to the server can access databases without knowing an exact password. - Remote users can read any file on the server using htsearch. This affects TurboLinux versions 6.0 and earlier. - Buffer overflow possibility in TurboLinux versions 6.0.2 and earlier. - Older versions of mtr did not properly drop root privileges. - GNU make creates temporary files in /tmp without checking for links if it is fed a Makefile via stdin. - Gdmlogin reveals authentication and account information that may be used to gain root priviledges. |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |