| ★ wanayoo — archive 1999 http://www.linuxsecurity.com/articles/forums_article-3633.html | Nouvelle recherche | Portail wanayoo |
![]() |
|
![]() |
|||
|
|
By |
|||||||||||||||||||||||||||||||||||
| Packages | Vendors |
| xinet | Mandrake |
| windowmaker | Mandrake |
| sendmail | Mandrake, NetBSD |
| fetchmail | Mandrake, Conectiva |
| xli | Mandrake |
| telnetd | SuSE |
| rmuser | FreeBSD |
| screen | SuSE |
| NetBSD kernel | NetBSD |
| fts | NetBSD |
Maximize your security with EnGarde! EnGarde was designed from the ground up as a secure solution, starting with the principle of least privilege, and carrying it through every aspect of its implementation. http://www.engardelinux.org
Linux Advisory Watch is a comprehensive newsletter that outlinesthe security vulnerabilities that have been announced throughout the week.It includes pointers to updated packages and descriptions of each vulnerability.
An audit has been performed on the xinetd 2.3.0 source code by Solar Designer for many different possible vulnerabilities. The 2.3.1 release incorporated his patches into the xinetd source tree. The audit was very thorough and found and fixed many problems. This xinetd update includes his audit patch.
Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php38.0/RPMS/xinetd-2.3.0-5.1mdk.i586.rpm
2f559b028fe14780460c37de5a521bce8.0/RPMS/xinetd-ipv6-2.3.0-5.1mdk.i586.rpm
81766c2104aa7e1f197dac9dce1c09afMandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1588.html
A buffer overflow exists in the WindowMaker window manager's window title handling code, as discovered by Alban Hertroys. Many programs, such as web browsers, set the window title to something obtained from the network, such as the title of the currently-viewed web page.
Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php38.0/RPMS/WindowMaker-0.64.0-8.1mdk.i586.rpm
10d20d21c895a09172fa0f32f6b7363b8.0/RPMS/WindowMaker-devel-0.64.0-8.1mdk.i586.rpm
da9ffdad57c2dd4362e383a79ebf59518.0/RPMS/libwraster2-0.64.0-8.1mdk.i586.rpm
644f90bf9a1fa1efb9a34599b761a4498.0/RPMS/libwraster2-devel-0.64.0-8.1mdk.i586.rpm
9ec21851b8e98f4a4a633addac5b81baMandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1589.html
An input validation error exists in sendmail that may allow local users to write arbitrary data to process memory. This could possibly allow the execute of code or commands with elevated privileges and may also allow a local attacker to gain access to the root account.
Mandrake Linux 8.0:fetchmail
http://www.linux-mandrake.com/en/ftp.php38.0/RPMS/sendmail-8.11.6-1.1mdk.i586.rpm
9ff57477c98a364588fa7a5ed95750b58.0/RPMS/sendmail-cf-8.11.6-1.1mdk.i586.rpm
7c53b2aa7fc6105892ddededf4e318988.0/RPMS/sendmail-doc-8.11.6-1.1mdk.i586.rpm
e3d814078cacf5e2cc2c40c2b104100eMandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1590.html
NetBSD
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/
SA2001-017-sendmail.patchNetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1599.html
A vulnerability was found by Salvatore Sanfilippo in both the IMAP and POP3 code of fetchmail where the input is not verified and no bounds checking is done. This can be exploited by a remote attacker to write arbitrary data into memory. The attacker must have control of the mail server the client is connecting to via fetchmail in order to exploit this vulnerability.
Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php38.0/RPMS/fetchmail-5.7.4-5.2mdk.i586.rpm
d3d60c3ff5b5a07869a10b3f9519a5928.0/RPMS/fetchmail-daemon-5.7.4-5.2mdk.i586.rpm
c7eb824dd7f7b4cd5144bf9d136083888.0/RPMS/fetchmailconf-5.7.4-5.2mdk.i586.rpm
dd686925435feb7777ff93e19e136897Mandrake Vendor Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1591.htmlConectiva 7.0: i386
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/
fetchmail-5.8.8-2U70_1cl.i386.rpmftp://atualizacoes.conectiva.com.br/7.0/RPMS/f
etchmailconf-5.8.8-2U70_1cl.i386.rpmftp://atualizacoes.conectiva.com.br/7.0/RPMS/
fetchmail-doc-5.8.8-2U70_1cl.i386.rpmConectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1595.html
A buffer overflow exists in xli due to missing boundary checks. This could be triggered by an external attacker to execute commands on the victim's machine. An exploit is publically available. xli is an image viewer that is used by Netscape's plugger to display TIFF, PNG, and Sun-Raster images.
Mandrake Linux 8.0:
http://www.linux-mandrake.com/en/ftp.php38.0/RPMS/xli-1.17.0-1.1mdk.i586.rpm
f1eff4c239eaebb0ff41f169de8ccd3eMandrake Vendot Advisory:
http://www.linuxsecurity.com/advisories/mandrake_advisory-1592.html
The telnet server which is shipped with SuSE distributions contains a remotely exploitable buffer-overflow within its telnet option negotiation code.
i386 Intel Platform: SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n1/
telnet-server-1.0-69.i386.rpm
0adc05af9762bd4c63eee464ca3131d1SuSE Vendor Advisory:
http://www.linuxsecurity.com/advisories/suse_advisory-1587.html
For a brief amount of time while running rmuser, a world-readable copy of /etc/master.passwd is available. A local attacker who reads this file can extract password hashes from the copy of /etc/master.passwd. This information could be used by attackers to escalate their privileges, possibly yielding root privileges on the local system, by mounting an offline dictionary attack in order to guess the plaintext passwords of the accounts on the local system.
FreeBSD:screen
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/packages/SA-01:59/
security-patch-rmuser-01.59.tgzFreeBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/freebsd_advisory-1593.html
The screen package allows a local attacker to obtain root privileges if the /usr/bin/screen command is installed setuid root and if a directory below /tmp/screens/ exists.
SuSE-7.2
ftp://ftp.suse.com/pub/suse/i386/update/7.2/ap1/
screen-3.9.8-115.i386.rpm
e85453f50170ecdabe97dd2b33b51e4aSuSE Vendor Avisory:
http://www.linuxsecurity.com/advisories/suse_advisory-1594.html
All mailman administrators should upgrade. It is recommended that the update be applied while the server is inactive, that is, the web interface should be disabled during this period as well as the MTA and crond, since many mailman processes are started at different times via cron.
Conectiva 7.0:
ftp://atualizacoes.conectiva.com.br/7.0/RPMS/
mailman-2.0.6-1U70_1cl.i386.rpmConectiva Vendor Advisory:
http://www.linuxsecurity.com/advisories/other_advisory-1596.html
A number of issues were found. In a number of places lengths or sizes passed from userland were used by the kernel without sufficient checks.
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/fts
SA2001-015-kernlen-current.patchNetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1597.html
If any directory (or symlink to a directory) above the current directory fts was processing was moved, the fts-using application could be made to descend the wrong directory sub-tree, and/or ascend above the original starting directory.Once it has ascended above the starting directory, the process could descend into an unintended file system hierarchy.
NetBSD
ftp://ftp.netbsd.org/pub/NetBSD/security/patches/
SA2001-016-fts.patchNetBSD Vendor Advisory:
http://www.linuxsecurity.com/advisories/netbsd_advisory-1598.html
| Contact Us | Legal Notice | About Our Site © Guardian Digital, Inc., 2000 |