Mandriva 1279 Published by Philipp Esselbach 0

Updated MySQL packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: MySQL
Advisory ID: MDKSA-2004:119
Date: November 1st, 2004

Affected versions: 10.0, 10.1, 9.2, Corporate Server 2.1
______________________________________________________________________

Problem Description:

A number of problems have been discovered in the MySQL database server:

Jeroen van Wolffelaar discovered an insecure temporary file vulnerability in the mysqlhotcopy script when using the scp method (CAN-2004-0457).

Oleksandr Byelkin discovered that the "ALTER TABLE ... RENAME" would check the CREATE/INSERT rights of the old table rather than the new one (CAN-2004-0835).

Lukasz Wojtow discovered a buffer overrun in the mysql_real_connect function (CAN-2004-0836).

Dean Ellis discovered that multiple threads ALTERing the same (or different) MERGE tables to change the UNION can cause the server to crash or stall (CAN-2004-0837).

The updated MySQL packages have been patched to protect against these issues.

Mandriva 1279 Published by Philipp Esselbach 0

Updated perl-Archive-Zip packages are available for Mandrakelinux 10.1
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: perl-Archive-Zip
Advisory ID: MDKSA-2004:118
Date: November 1st, 2004

Affected versions: 10.1
______________________________________________________________________

Problem Description:

Recently, it was noticed that several antivirus programs miss viruses that are contained in ZIP archives with manipulated directory data. The global archive directory of these ZIP file have been manipulated to indicate zero file sizes.

Archive::Zip produces files of zero length when decompressing this type of ZIP file. This causes AV products that use Archive::ZIP to fail to detect viruses in manipulated ZIP archives. One of these products is amavisd-new.

The updated packages are patched to fix this problem.

Mandriva 1279 Published by Philipp Esselbach 0

Updated gaim packages are available for Mandrakelinux 10.1

_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: gaim
Advisory ID: MDKSA-2004:117
Date: November 1st, 2004

Affected versions: 10.1
______________________________________________________________________

Problem Description:

A vulnerability in the MSN protocol handler in the gaim instant messenger application was discovered. When receiving unexpected sequences of MSNSLP messages, it is possible that an attacker could trigger an internal buffer overflow which could lead to a crash or even code execution as the user running gaim.

The updated packages are patched to fix this problem. This problem does not affect Mandrakelinux 10.0 installations.

Mandriva 1279 Published by Philipp Esselbach 0

A press release from Mandrakesoft

Moreno Valley, CA; Paris, France; October 27th, 2004 - Mandrakesoft announced today the release of Mandrakelinux 10.1 Official, the latest version of its leading Linux Operating System. Notable new features include extended support for mobile devices, better hardware compatibility, and major application upgrades. Following a successful "Community" release, 10.1 Official will be the basis for a large part of Mandrakesoft's range of products. The value-added packs (Discovery, PowerPack and PowerPack+) are available now for pre-orders and through the Mandrakeclub on-line service. Prices start at EUR 44.90 / $49.90.

Mandriva 1279 Published by Philipp Esselbach 0

Updated kdegraphics packages are available for Mandrakelinux 10.0
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: kdegraphics
Advisory ID: MDKSA-2004:115
Date: October 21st, 2004

Affected versions: 10.0
______________________________________________________________________

Problem Description:

Chris Evans discovered numerous vulnerabilities in the xpdf package, which also effect software using embedded xpdf code, such as kpdf:

Multiple integer overflow issues affecting xpdf-2.0 and xpdf-3.0. Also programs like kpdf which have embedded versions of xpdf. These can result in writing an arbitrary byte to an attacker controlled location which probably could lead to arbitrary code execution.

The updated packages are patched to protect against these vulnerabilities.

Mandriva 1279 Published by Philipp Esselbach 0

Updated CUPS packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: cups
Advisory ID: MDKSA-2004:116
Date: October 21st, 2004

Affected versions: 10.0, 9.2, Corporate Server 2.1,
Multi Network Firewall 8.2
______________________________________________________________________

Problem Description:

Chris Evans discovered numerous vulnerabilities in the xpdf package, which also effect software using embedded xpdf code:

Multiple integer overflow issues affecting xpdf-2.0 and xpdf-3.0. Also programs like cups which have embedded versions of xpdf. These can result in writing an arbitrary byte to an attacker controlled location which probably could lead to arbitrary code execution. (CAN-2004-0888)

Also, when CUPS debugging is enabled, device URIs containing username and password end up in error_log. This information is also visible via "ps". (CAN-2004-0923)

The updated packages are patched to protect against these vulnerabilities.

Mandriva 1279 Published by Philipp Esselbach 0

Updated gpdf packages are available for Mandrakelinux 10.0
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: gpdf
Advisory ID: MDKSA-2004:114
Date: October 21st, 2004

Affected versions: 10.0
______________________________________________________________________

Problem Description:

Chris Evans discovered numerous vulnerabilities in the xpdf package, which also effect software using embedded xpdf code, such as gpdf:

Multiple integer overflow issues affecting xpdf-2.0 and xpdf-3.0. Also programs like gpdf which have embedded versions of xpdf. These can result in writing an arbitrary byte to an attacker controlled location which probably could lead to arbitrary code execution.

The updated packages are patched to protect against these vulnerabilities.

Mandriva 1279 Published by Philipp Esselbach 0

Updated xpdf packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: xpdf
Advisory ID: MDKSA-2004:113
Date: October 21st, 2004

Affected versions: 10.0, Corporate Server 2.1
______________________________________________________________________

Problem Description:

Chris Evans discovered numerous vulnerabilities in the xpdf package:

Multiple integer overflow issues affecting xpdf-2.0 and xpdf-3.0. Also programs like cups which have embedded versions of xpdf. These can result in writing an arbitrary byte to an attacker controlled location which probably could lead to arbitrary code execution. (CAN-2004-0888)

Multiple integer overflow issues affecting xpdf-3.0 only. These can result in DoS or possibly arbitrary code execution. (CAN-2004-0889)

Chris also discovered issues with infinite loop logic error affecting xpdf-3.0 only.

The updated packages are patched to deal with these issues.

Mandriva 1279 Published by Philipp Esselbach 0

Updated squid packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: squid
Advisory ID: MDKSA-2004:112
Date: October 21st, 2004

Affected versions: 10.0, 9.2, Corporate Server 2.1,
Multi Network Firewall 8.2
______________________________________________________________________

Problem Description:

iDEFENSE discovered a Denial of Service vulnerability in squid version 2.5.STABLE6 and previous. The problem is due to an ASN1 parsing error where certain header length combinations can slip through the validations performed by the ASN1 parser, leading to the server assuming there is heap corruption or some other exceptional condition, and closing all current connections then restarting.

Squid 2.5.STABLE7 has been released to address this issue; the provided packages are patched to fix the issue.

Mandriva 1279 Published by Philipp Esselbach 0

Updated wxGTK2 packages are available for Mandrakelinux 10.0
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: wxGTK2
Advisory ID: MDKSA-2004:111
Date: October 21st, 2004

Affected versions: 10.0
______________________________________________________________________

Problem Description:

Several vulnerabilities have been discovered in the libtiff package; wxGTK2 uses a libtiff code tree, so it may have the same vulnerabilities:

Chris Evans discovered several problems in the RLE (run length encoding) decoders that could lead to arbitrary code execution. (CAN-2004-0803)

Matthias Clasen discovered a division by zero through an integer overflow. (CAN-2004-0804)

Dmitry V. Levin discovered several integer overflows that caused malloc issues which can result to either plain crash or memory corruption. (CAN-2004-0886)

Mandriva 1279 Published by Philipp Esselbach 0

Updated gaim packages are available for Mandrakelinux 10.0
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: gaim
Advisory ID: MDKSA-2004:110
Date: October 21st, 2004

Affected versions: 10.0
______________________________________________________________________

Problem Description:

More vulnerabilities have been discovered in the gaim instant messenger client. The vulnerabilities pertinent to version 0.75, which is the version shipped with Mandrakelinux 10.0, are: installing smiley themes could allow remote attackers to execute arbitrary commands via shell metacharacters in the filename of the tar file that is dragged to the smiley selector. There is also a buffer overflow in the way gaim handles receiving very long URLs.

The provided packages have been patched to fix these problems. These issues, amongst others, have been fixed upstream in version 0.82.

Mandriva 1279 Published by Philipp Esselbach 0

Updated cvs packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: cvs
Advisory ID: MDKSA-2004:108
Date: October 19th, 2004

Affected versions: 10.0, 9.2, Corporate Server 2.1
______________________________________________________________________

Problem Description:

iDEFENSE discovered a flaw in CVS versions prior to 1.1.17 in an undocumented switch implemented in CVS' history command. The -X switch specifies the name of the history file which allows an attacker to determine whether arbitrary system files and directories exist and whether or not the CVS process has access to them.

This flaw has been fixed in CVS version 1.1.17.

Mandriva 1279 Published by Philipp Esselbach 0

Updated libtiff packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: libtiff
Advisory ID: MDKSA-2004:109
Date: October 19th, 2004

Affected versions: 10.0, 9.2, Corporate Server 2.1,
Multi Network Firewall 8.2
______________________________________________________________________

Problem Description:

Several vulnerabilities have been discovered in the libtiff package:

Chris Evans discovered several problems in the RLE (run length encoding) decoders that could lead to arbitrary code execution. (CAN-2004-0803)

Matthias Clasen discovered a division by zero through an integer overflow. (CAN-2004-0804)

Dmitry V. Levin discovered several integer overflows that caused malloc issues which can result to either plain crash or memory corruption. (CAN-2004-0886)

Mandriva 1279 Published by Philipp Esselbach 0

Updated Mozilla packages are available for Mandrakelinux 10.0
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: mozilla
Advisory ID: MDKSA-2004:107
Date: October 19th, 2004

Affected versions: 10.0
______________________________________________________________________

Problem Description:

A number of vulnerabilities were fixed in mozilla 1.7.3, the following of which have been backported to mozilla packages for Mandrakelinux 10.0:

- "Send page" heap overrun
- javascript clipboard access
- buffer overflow when displaying VCard
- BMP integer overflow
- javascript: link dragging
- Malicious POP3 server III

The details of all of these vulnerabilities are available from the Mozilla website.

Mandriva 1279 Published by Philipp Esselbach 0

Updated cyrus-sasl packages are available for Mandrakelinux
_______________________________________________________________________

Mandrakelinux Security Update Advisory
_______________________________________________________________________

Package name: cyrus-sasl
Advisory ID: MDKSA-2004:106
Date: October 7th, 2004

Affected versions: 10.0, 9.2, Corporate Server 2.1
______________________________________________________________________

Problem Description:

A vulnerability was discovered in the libsasl library of cyrus-sasl. libsasl honors the SASL_PATH environment variable blindly, which could allow a local user to create a malicious "library" that would get executed with the effective ID of SASL when anything calls libsasl.

The provided packages are patched to protect against this vulnerability.