★ wanayoo — archive 1999 http://www.linuxsecurity.com/advisories/turbolinux.htmlNouvelle recherche | Portail wanayoo
Advertise Here

   
Caldera
Corel
Debian
FreeBSD
LinuxPPC
Mandrake
NetBSD
OpenBSD
Other
Red Hat
Slackware
Stampede
StormLinux
SuSE
TurboLinux
 
TurboLinux 8/12/2000 3:05


  • 8/11/2000 21:17 : TurboLinux: UPDATED: pam-0.70-2 and earlier vulnerability
    - A denial of service attack can be made against the PAM auth system.

  • 8/10/2000 3:05 : TurboLinux: perl vulnerability
    - The latest versions of perl as well as past shipping versions of perl in TurboLinux distributions are susceptible to a local root exploit.

  • 8/2/2000 16:41 : TurboLinux: netscape-4.73 and earlier
    - A web site could contain malicious code which would enable remote execution or other malicious behavior as the user of netscape on the client's machine.

  • 8/1/2000 16:45 : TurboLinux: cvsweb-1.90 and earlier
    - remote read/write access to arbitrary files owned by the default web user is possible via this exploit.

  • 7/28/2000 21:19 : TurboLinux: dhcp vulnerability
    - Remote root exploit present in versions earlier than 2.0.

  • 7/19/2000 22:19 : TurboLinux: wu-ftpd-2.6.0 and earlier
    - Improper bounds checking may lead to remote root execution on FTP server.

  • 6/19/2000 23:30 : TurboLinux: kernel vulnerability
    - Any local user with an account can use this vulnerability to obtain root priviledges by exploiting setuid root applications.

  • 5/30/2000 0:16 : TurboLinux: local users can view shadowed password file
    - An overflow in the -mode command line option exists

  • 5/26/2000 14:35 : TurboLinux: gpm-1.19.1 and earlier
    - A user with console access can use this vulnerability to execute arbitrary commands with elevated priviledges.

  • 4/15/2000 10:07 : TurboLinux pam-0.70-2
    - "Both 'pam' and 'userhelper' (a setuid binary that comes with the 'usermode-1.15' rpm) follow .. paths. Since pam_start calls down to _pam_add_handler(), we can get it to dlopen any file on disk. 'userhelper' being setuid means we can get root."

  • 3/22/2000 1:00 : Package: nmh-1.0.2 and earlier
    - A buffer overrun exists in nmh versions 1.0.2 and prior. Due to improper MIME header parsing, an attacker could create a MIME message such that the mhshow utility may be used to execute shell code when the message is viewed.

  • 3/15/2000 21:11 : TurboLinux: dump local buffer overrun
    - Previous versions of dump did not handle permissions correctly. It may be possible to execute arbitrary code with the permissions of the process.

  • 3/9/2000 21:26 : TurboLinux: MySQL password auth vulnerability
    - The MySQL database server (prior to 3.22.32) has a flawed password authentication mechanism. Anyone who can connect to the server can access databases without knowing an exact password.

  • 3/8/2000 23:51 : TurboLinux: htdig vulnerability
    - Remote users can read any file on the server using htsearch. This affects TurboLinux versions 6.0 and earlier.

  • 3/8/2000 23:50 : TurboLinux: man vulnerability
    - Buffer overflow possibility in TurboLinux versions 6.0.2 and earlier.

  • 3/8/2000 21:16 : TurboLinux: mtr privilege problem
    - Older versions of mtr did not properly drop root privileges.

  • 2/18/2000 20:28 : TurboLinux: make-3.77-44 and earlier
    - GNU make creates temporary files in /tmp without checking for links if it is fed a Makefile via stdin.

  • 2/18/2000 19:47 : TurboLinux: gdm-2.0beta4-12 and earlier
    - Gdmlogin reveals authentication and account information that may be used to gain root priviledges.

  • Contact Us | Legal Notice | About Our Site
    © Guardian Digital, Inc., 2000