Security 10912 Published by Philipp Esselbach 0

MandrakeSoft S.A. has released three new security updates for Mandrake Linux:

MDKSA-2003:019 : php
A buffer overflow was discovered in the wordwrap() function in versions of PHP greater than 4.1.2 and less than 4.3.0. Under certain circumstances, this buffer overflow can be used to overwite heap memory and could potentially lead to remote system compromise.

Read more

MDKSA-2003:020 : openssl
In an upcoming paper, Brice Canvel (EPFL), Alain Hiltgen (UBS), Serge Vaudenay (EPFL), and Martin Vuagnoux (EPFL, Ilion) describe and demonstrate a timing-based attack on CBC ciphersuites in SSL and TLS. New versions of openssl have been released in response to this vulnerability (0.9.6i and 0.9.7a).

Read more

MDKSA-2003:021 : krb5
A vulnerability was discovered in the Kerberos FTP client. When the client retrieves a file that has a filename beginning with a pipe character, the FTP client will pass that filename to the command shell in a system() call. This could allow a malicious remote FTP server to write to files outside of the current directory or even execute arbitrary commands as the user using the FTP client.

Read more

Security 10912 Published by Philipp Esselbach 0

A new security update for Debian GNU/Linux has been released

DSA-252-1 slocate -- buffer overflow
A problem has been discovered in slocate, a secure locate replacement. A buffer overflow in the setuid program slocate can be used to execute arbitrary code as superuser.

For the stable distribution (woody) this problem has been fixed in version 2.6-1.3.1.
The old stable distribution (potato) is not affected by this problem.

For the unstable distribution (sid) this problem has been fixed in version 2.7-1.

We recommend that you upgrade your slocate package immediately.

Read more

Security 10912 Published by 0

New security updates for Gentoo Linux are available:

mod_php
PHP contains code for preventing direct access to the CGI binary with configure option "--enable-force-cgi-redirect" and php.ini option "cgi.force_redirect". In PHP 4.3.0 there is a bug which renders these options useless.

Read more

NetHack
Overflowing a buffer in nethack may lead to privelige escalation to games uid.

Read more

w3m
Hironori SAKAMOTO found another security vulnerability in w3m 0.3.2.x that w3m will miss to escape html tag in img alt attribute, so malicious frame html may deceive you to access your local files, cookies and so on.

Read more

SYSLINUX
Security flaws have been found in the SYSLINUX installer when running
setuid root.

Read more

Mailmain
The email variable and the default error page in mailmain 2.1 contains cross site scripting vulnerabilities.

Read more

bitchx
A denial of service vulnerability exists in BitchX. Sending a malformed RPL_NAMREPLY numeric 353 causes BitchX to segfault.

Read more

Security 10912 Published by Philipp Esselbach 0

MandrakeSoft has released two new security updates for Mandrake Linux

MDKSA-2003:018 : apcupsd

A remote root vulnerability in slave setups and some buffer overflows in the network information server code were discovered by the apcupsd developers. They have been fixed in the latest unstable version, 3.10.5 which contains additional enhancements like USB support, and the latest stable version, 3.8.6.

There are a few changes that need to be noted, such as the port has changed from port 7000 to post 3551 for NIS, and the new config only allows access from the localhost. Users may need to modify their configuration files appropriately, depending upon their configuration.

Read more

MDKSA-2003:017 : pam

Andreas Beck discovered that the pam_xauth module would forward authorization information from the root account to unprivileged users. This can be exploited by a local attacker to gain access to the root user's X session. In order for it to be successfully exploited, the attacker would have to somehow get the root user to su to the account belonging to the attacker.

Read more

Security 10912 Published by Philipp Esselbach 0

For the new software, called VirusSafe, Lindows.com took Central Command's Vexira Antivirus for Linux Workstation software and adjusted it to integrate it with the LindowsOS operating system, said John Bromhead, Lindows.com's marketing vice president.

Read more

Security 10912 Published by Philipp Esselbach 0

A new security update for Debian GNU/Linux has been released:

DSA-250-1 w3mmee-ssl -- missing HTML quoting

Hironori Sakamoto, one of the w3m developers, found two security vulnerabilities in w3m and associated programs. The w3m browser does not properly escape HTML tags in frame contents and img alt attributes. A malicious HTML frame or img alt attribute may deceive a user to send his local cookies which are used for configuration. The information is not leaked automatically, though.

Read more

Security 10912 Published by Philipp Esselbach 0

MandrakeSoft has released new updates for Mandrake Linux:

MDKSA-2003:012 : vim
A vulnerability was discovered in vim by Georgi Guninski that allows arbitrary command execution using the libcall feature found in modelines. A patch to fix this problem was introduced in vim 6.1 patchlevel 265. This patch has been applied to the provided update packages.
Read more

MDKSA-2003:013 : MYSQL
Aleksander Adamowski informed MandrakeSoft that the MySQL developers fixed a DoS vulnerability in the recently released 3.23.55 version of MySQL. A double free() pointer bug in the mysql_change_user() handling would allow a specially hacked mysql client to crash the main mysqld server. This vulnerability can only be exploited by first logging in with a valid user account.
Read more

MDKSA-2003:014 : kernel
An updated kernel for 9.0 is available with a number of bug fixes. Supermount has been completely overhauled and should be solid on all systems. Other fixes include XFS with high memory, a netfilter fix, a fix for Sony VAIO DMI, i845 should now work with UDMA, and new support for VIA C3 is included. Prism24 has been updated so it now works properly on HP laptops and a new ACPI is included, although it is disabled by default for broader compatibility.
Read more

MDKSA-2003:015 : slocate
A buffer overflow vulnerability was discovered in slocate by team USG. The overflow appears when slocate is used with the -c and -r parameters, using a 1024 (or 10240) byte string. This has been corrected in slocate version 2.7.
Read more