Section: .. / advisories / debian /
| /// File Name: |
debian.micq.txt |
Description:
|
Debian Security Advisory DSA-012-1 - A remotely exploitable buffer overflow has been found in micq v0.4.6.
| | Homepage: | http://www.debian.org/security | | File Size: | 3538 | | Last Modified: | Jan 25 22:45:44 2001 |
| MD5 Checksum: | 949cd8eb9ed79a73002f78af0b33262f |
|
| /// File Name: |
debian.modutils.txt |
Description:
|
Debian Security Advisory - A problem in the modprobe utility that can be exploited by local users to run arbitrary commands as root if the machine is running a kernel with kmod enabled has been discovered.
| | Homepage: | http://www.debian.org/security | | File Size: | 4190 | | Last Modified: | Nov 25 07:05:25 2000 |
| MD5 Checksum: | dcf44634a6c622fa1aa2981a6037b5d1 |
|
| /// File Name: |
debian.mtr.txt |
Description:
|
Debian Security Advisory - The version of mtr as distributed in Debian GNU/Linux 2l1 did not drop root privileges correctly. While there are no known exploits it is conceivable that a weakness in gtk or ncurses could be used to exploit this. Debian security homepage here.
| | File Size: | 3052 | | Last Modified: | Mar 9 20:25:34 2000 |
| MD5 Checksum: | 6d6789b193a9e0d9198b500b201e21db |
|
| /// File Name: |
debian.mysql.txt |
Description:
|
Debian Security Advisory DSA-013-1 - A buffer overflow has been discovered in the Mysql server v3.22.32 which allows remote attackers to gain mysqld privileges.
| | Homepage: | http://www.debian.org/security | | File Size: | 4708 | | Last Modified: | Jan 25 22:59:54 2001 |
| MD5 Checksum: | e5748a33f868012b89ca9355459b1930 |
|
| /// File Name: |
debian.nano.txt |
Description:
|
Debian Security Advisory - The problem that was previously reported for joe also occurs with other editors. When nano (a free pico clone) unexpectedly dies it tries a warning message to a new file with a predictable name. Unfortunately that file was not created safely which made nano vulnerable to a symlink attack. This has been fixed in version 0.9.23-1 (except for powerpc, which has version 0.9.23-1.1).
| | Homepage: | http://www.debian.org/security | | File Size: | 4431 | | Last Modified: | Dec 19 03:21:15 2000 |
| MD5 Checksum: | 92f15aef749f9005b0474ca16d4b58f2 |
|
| /// File Name: |
debian.ncurses.txt |
Description:
|
Debian Security Advisory - The version of the ncurses display library shipped with Debian GNU/Linux 2.2 is vulnerable to several buffer overflows in the parsing of terminfo database files. The problems are only exploitable in the presence of setuid binaries linked to ncurses which use these particular functions, including xmcd versions before 2.5pl1-7.1.
| | Homepage: | http://www.debian.org/security | | File Size: | 7266 | | Last Modified: | Nov 26 02:51:06 2000 |
| MD5 Checksum: | ffb4a5ae5913af306bf296cf5dbee114 |
|
| /// File Name: |
debian.netscape.txt |
Description:
|
Debian Security Advisory DSA 051-1 - The Netscape browser does not escape the GIF file comment in the image information page. This allows javascript execution in the "about:" protocol and can for example be used to upload the History (about:global) to a webserver, thus leaking private information. This problem has been fixed upstream in Netscape 4.77.
| | Homepage: | http://www.debian.org/security | | File Size: | 6564 | | Last Modified: | Apr 25 02:42:35 2001 |
| MD5 Checksum: | 984c52b183d287162a14a8af92a5cc7d |
|
| /// File Name: |
debian.nfs-common.txt |
Description:
|
Debian Security Advisory - The version of nfs-common distributed in Debian GNU/Linux 2.2 is vulnerable to a remote root compromise involving rpc.statd.
| | Homepage: | http://www.debian.org/security | | File Size: | 4097 | | Last Modified: | Jul 18 00:51:51 2000 |
| MD5 Checksum: | 5e0513b893db5539e05449413bad8c8f |
|
| /// File Name: |
debian.nfs-server.txt |
Description:
|
Debian Security Advisory: New version of nfs-server fixes remote exploit. Debian security homepage here.
| | File Size: | 3034 | | Last Modified: | Nov 11 21:26:23 1999 |
| MD5 Checksum: | 49b2e2eefb687de5bc34a50f4aebd09d |
|
| /// File Name: |
debian.nis.txt |
Description:
|
Debian Security Advisory - The version of nis as distributed in Debian GNU/Linux 2.1 and 2.2 contains a ypbind package with a security problem. A format string attack can be used to run arbitrary code as root.
| | Homepage: | http://www.debian.org/security | | File Size: | 4481 | | Last Modified: | Oct 15 21:22:06 2000 |
| MD5 Checksum: | c9d538d6e96ae072ee7d1fc8e8771778 |
|
| /// File Name: |
debian.nmh.txt |
Description:
|
Debian Security Advuisory - Remote exploit in nmh. The version of nmh that was distributed in Debian GNU/Linux 2.1 (aka slink) did not check incoming mail messages properly. This could be exploited by using carefully designed MIME headers to trick mhshow into executing arbitrary shell code. Debian security homepage here.
| | File Size: | 3144 | | Last Modified: | Feb 28 21:23:31 2000 |
| MD5 Checksum: | 0fee415db8b978d86bccedd0d047caf1 |
|
| /// File Name: |
debian.ntop.txt |
Description:
|
Debian Linux Security Advisories - The updated version of ntop (1.2a7-10) that was released on August 5 was found to still be insecure: it was still exploitable using buffer overflows. Using this technique it was possible to run arbitrary code as the user who ran ntop in web mode
| | Homepage: | http://www.debian.org/security/ | | File Size: | 3801 | | Last Modified: | Aug 30 10:50:14 2000 |
| MD5 Checksum: | 6ef19ccf964939d2ffcf1ea0c48ab0f5 |
|
| /// File Name: |
debian.ntp.txt |
Description:
|
Debian Security Advisory DSA-045-1 - A buffer overflow has been found in ntp which can lead to remote root compromise. Versions ntp-4.0.99k and prior are vulnerable.
| | Homepage: | http://www.debian.org/security | | File Size: | 5426 | | Last Modified: | Apr 10 04:17:15 2001 |
| MD5 Checksum: | a2e0f5d49258ef5d8fe7f5c317de6113 |
|
| /// File Name: |
debian.nvi.txt |
Description:
|
The version of nvi that was distributed with Debian GNU/Linux 2.1 has an error in the default /etc/init.d/nviboot script: it did not handle filenames with embedded spaces correctly. This made it possible to remove files in the root directory by creating entries in /var/tmp/vi.recover. Debian security homepage here.
| | File Size: | 3312 | | Last Modified: | Jan 10 20:26:41 2000 |
| MD5 Checksum: | 0b662942567330520d0aa2f42d879dc5 |
|
| /// File Name: |
debian.openssh.txt |
Description:
|
Debian Security Advisory DSA-027-1 - Versions of OpenSSH prior to v2.3.0p1 are vulnerable to a remote arbitrary memory overwrite attack which may eventually lead into a root exploit. New version available here.
| | Homepage: | http://www.debian.org/security | | File Size: | 4947 | | Last Modified: | Feb 14 06:48:49 2001 |
| MD5 Checksum: | 39de84b210c9d078847ff8c944021760 |
|
| /// File Name: |
debian.php3.txt |
Description:
|
Debian Security Advisory - In versions of the PHP 3 packages before version 3.0.17, several format string bugs could allow properly crafted requests to execute code as the user running PHP scripts on the web server, particularly if error logging was enabled.
| | Homepage: | http://www.debian.org/security | | File Size: | 23477 | | Last Modified: | Oct 15 21:26:43 2000 |
| MD5 Checksum: | 18253553df53dfe8b1817fbb1267eb33 |
|
| /// File Name: |
debian.php4-dos.txt |
Description:
|
Debian Security Advisory DSA-020-1 - A vulnerability has been found in PHP4 v4.0.4 and below which crashes PHP and sends the source to the client instead of executing it.
| | Homepage: | http://www.debian.org/security | | File Size: | 18270 | | Last Modified: | Jan 26 09:00:26 2001 |
| MD5 Checksum: | a119652d3773c86351c778714a10c380 |
|
| /// File Name: |
debian.php4.txt |
Description:
|
Debian Security Advisory - In versions of the PHP 4 packages before version 4.0.3, several format string bugs could allow properly crafted requests to execute code as the user running PHP scripts on the web server.
| | Homepage: | http://www.debian.org/security | | File Size: | 17412 | | Last Modified: | Oct 15 21:28:56 2000 |
| MD5 Checksum: | 2283301130af7e6d0a0b53bf93cb998c |
|
| /// File Name: |
debian.proftpd.txt |
Description:
|
Debian Security Advisory: New version of proftpd fixes remote exploits. Debian security homepage here.
| | File Size: | 2839 | | Last Modified: | Mar 9 20:43:33 2001 |
| MD5 Checksum: | 7d1b7e6614c3e12d4c576cf2b82c96e2 |
|
| /// File Name: |
debian.samba.txt |
Description:
|
Debian Security Advisory DSA-048-1 - Samba does not use temp files correctly, allowing local attackers to trick samba into overwriting arbitrary files. Both problems have been fixed in version 2.0.7-3.2.
| | Homepage: | http://www.debian.org/security | | File Size: | 7465 | | Last Modified: | Apr 19 23:45:08 2001 |
| MD5 Checksum: | 0c27853b96d028c8492f08fb1cfea918 |
|
| /// File Name: |
debian.sash.txt |
Description:
|
Debian Security Advisory DSA-015-1 - Versions of sash prior to 3.4-4 did not clone /etc/shadow properly which lead into readable files for anybody.
| | Homepage: | http://www.debian.org/security | | File Size: | 3652 | | Last Modified: | Jan 25 23:09:01 2001 |
| MD5 Checksum: | 55a09e98a3b57eea192a269d4c7ce7e9 |
|
| /// File Name: |
debian.screen.txt |
Description:
|
Debian Security Advisory - A format string bug was recently discovered in screen which allows local users to obtain root access if screen is setuid. This is fixed in version 3.7.4-9.1 and 3.9.5-9.
| | Homepage: | http://www.debian.org/security | | File Size: | 4500 | | Last Modified: | Sep 6 23:22:39 2000 |
| MD5 Checksum: | 68e60099188baca4cca9424730989d5c |
|
| /// File Name: |
debian.sendfile.txt |
Description:
|
Debian Security Advisory DSA-052-1 - A problem in sendfiled which caused the daemon not to drop privileges as expected when sending notification mails has been fixed. Exploiting this a local user can easily make it execute arbitrary code under root privileges.
| | Homepage: | http://www.debian.org/security | | File Size: | 3866 | | Last Modified: | Apr 25 02:45:02 2001 |
| MD5 Checksum: | 9e9bb2e39fe1af7fdc9076e1d579fd62 |
|
| /// File Name: |
debian.sendmail.txt |
Description:
|
The version of sendmail and sendmail-wide that was distributed with Debian GNU/Linux 2.1 has a slight problem in the code to regenerate the aliases database. Sendmail allowed any user to run sendmail with the -bi option to (re)initialize the aliases database. The user could then interrupt sendmail and leave the system with a broken aliases database. This has been fixed in version 8.9.3-3slink1 by only allowing root and trusted users to regenerate the aliases database. Debian security homepage here.
| | File Size: | 8204 | | Last Modified: | Dec 7 18:15:17 1999 |
| MD5 Checksum: | d724290163864d34d014fa8e4be217fc |
|
| /// File Name: |
debian.sgml-tools.txt |
Description:
|
Debian Security Advisory DSA-038-1 - Former versions of sgml-tools created temporary files directly in /tmp in an insecure fashion. Version 1.0.9-15 and higher create a subdirectory first and open temporary files within that directory. We recommend you upgrade your sgml-tools package.
| | Homepage: | http://www.debian.org/security | | File Size: | 3661 | | Last Modified: | Mar 14 00:53:29 2001 |
| MD5 Checksum: | 1237a93cab2783c04cd06a069e48ab5d |
|
|
|
|
|