Unix - Linux Vulnerabilities

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

Unix - Linux Vulnerabilities

Post by Tami »

As reported by Secunia:

UNIX/Linux:--

[SA26794] Fedora update for lighttpd

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-13

Fedora has issued an update for lighttpd. This fixes a vulnerability,
which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/26794/\"]http://secunia.com/advisories/26794/[/url]

--

[SA26792] Mandriva update for librpcsecgss

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-13

Mandriva has issued an update for librpcsecgss. This fixes a
vulnerability, which can be exploited by malicious people to compromise
a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/26792/\"]http://secunia.com/advisories/26792/[/url]

--

[SA26784] Debian update for phpwiki

Critical: Highly critical
Where: From remote
Impact: Security Bypass, System access
Released: 2007-09-12

Debian has issued an update for phpwiki. This fixes some
vulnerabilities, which can be exploited by malicious people to bypass
certain security restrictions or compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/26784/\"]http://secunia.com/advisories/26784/[/url]

--

[SA26783] Gentoo update for mit-krb5

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-12

Gentoo has issued an update for mit-krb5. This fixes some
vulnerabilities, which can be exploited by malicious users and
malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/26783/\"]http://secunia.com/advisories/26783/[/url]

--

[SA26751] Fedora update for clamav

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-10

Fedora has issued an update for clamav. This fixes some
vulnerabilities, which potentially can be exploited by malicious people
to cause a DoS (Denial of Service) or to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/26751/\"]http://secunia.com/advisories/26751/[/url]

--

[SA26746] Fedora update for snort

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-10

Fedora has issued an update for snort. This fixes a vulnerability,
which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/26746/\"]http://secunia.com/advisories/26746/[/url]

--

[SA26732] lighttpd mod_fastcgi PHP Header Overflow

Critical: Highly critical
Where: From remote
Impact: System access
Released: 2007-09-10

Mattias Bengtsson and Philip Olausson have reported a vulnerability in
lighttpd, which can be exploited by malicious people to compromise a
vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/26732/\"]http://secunia.com/advisories/26732/[/url]

--

[SA26728] Mandriva update for krb5

Critical: Highly critical
Where: From remote
Impact: DoS, System access
Released: 2007-09-07

Mandriva has issued an update for krb5. This fixes some
vulnerabilities, which can be exploited by malicious users and
malicious people to compromise a vulnerable system.

Full Advisory:
[url=\"http://secunia.com/advisories/26728/\"]http://secunia.com/advisories/26728/[/url]

--

[SA26796] Fedora update for wordpress

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data
Released: 2007-09-13

Fedora has issued an update for wordpress. This fixes some
vulnerabilities, which can be exploited by malicious users to conduct
script insertion attacks and by malicious people to conduct SQL
injection attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/26796/\"]http://secunia.com/advisories/26796/[/url]

--

[SA26773] Debian update for ktorrent

Critical: Moderately critical
Where: From remote
Impact: Manipulation of data
Released: 2007-09-12

Debian has issued an update for ktorrent. This fixes a vulnerability,
which potentially can be exploited by malicious people to overwrite
arbitrary files on a user's system.

Full Advisory:
[url=\"http://secunia.com/advisories/26773/\"]http://secunia.com/advisories/26773/[/url]

--

[SA26769] Debian update for jffnms

Critical: Moderately critical
Where: From remote
Impact: Cross Site Scripting, Manipulation of data, Exposure of
sensitive information
Released: 2007-09-12

Debian has issued an update for jffnms. This fixes some
vulnerabilities, which can be exploited by malicious people to disclose
sensitive information or conduct cross-site scripting and SQL injection
attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/26769/\"]http://secunia.com/advisories/26769/[/url]

--

[SA26766] Fedora update for gd

Critical: Moderately critical
Where: From remote
Impact: DoS
Released: 2007-09-10

Fedora has issued an update for gd. This fixes some vulnerabilities,
which can potentially be exploited to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/26766/\"]http://secunia.com/advisories/26766/[/url]

--

[SA26760] Red Hat update for kernel

Critical: Moderately critical
Where: From remote
Impact: Security Bypass, Exposure of sensitive information,
Privilege escalation, DoS
Released: 2007-09-13

Red Hat has issued an update for the kernel. This fixes some
weaknesses, a security issue, and some vulnerabilities, which can be
exploited by malicious, local users to cause a DoS (Denial of Service),
disclose potentially sensitive information, and gain escalated
privileges, and by malicious people to bypass certain security
restrictions and cause a DoS.

Full Advisory:
[url=\"http://secunia.com/advisories/26760/\"]http://secunia.com/advisories/26760/[/url]

--

[SA26748] Slackware update for php

Critical: Moderately critical
Where: From remote
Impact: Unknown, Security Bypass, Privilege escalation
Released: 2007-09-13

Slackware has issued an update for php. This fixes a weakness and some
vulnerabilities, where some have unknown impacts and others can be
exploited by malicious users and malicious, local users to bypass
certain security restrictions.

Full Advisory:
[url=\"http://secunia.com/advisories/26748/\"]http://secunia.com/advisories/26748/[/url]

--

[SA26727] Mandriva update for eggdrop

Critical: Moderately critical
Where: From remote
Impact: System access
Released: 2007-09-07

Mandriva has issued an update for eggdrop. This fixes a vulnerability,
which can be exploited by malicious people to compromise a vulnerable
system.

Full Advisory:
[url=\"http://secunia.com/advisories/26727/\"]http://secunia.com/advisories/26727/[/url]

--

[SA26744] Quagga Multiple Denial of Service Vulnerabilities

Critical: Less critical
Where: From remote
Impact: DoS
Released: 2007-09-11

Some vulnerabilities have been reported in Quagga, which can be
exploited by malicious users to cause a DoS (Denial of Service).

Full Advisory:
[url=\"http://secunia.com/advisories/26744/\"]http://secunia.com/advisories/26744/[/url]

--

[SA26742] DirectAdmin "user" Cross-Site Scripting Vulnerability

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-12

r0t has reported a vulnerability in DirectAdmin, which can be exploited
by malicious people to conduct cross-site scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/26742/\"]http://secunia.com/advisories/26742/[/url]

--

[SA26733] Debian update for phpmyadmin

Critical: Less critical
Where: From remote
Impact: Cross Site Scripting
Released: 2007-09-10

Debian has issued an update for phpmyadmin. This fixes some
vulnerabilities, which can be exploited by malicious users to conduct
script insertion attacks and by malicious people to conduct cross-site
scripting attacks.

Full Advisory:
[url=\"http://secunia.com/advisories/26733/\"]http://secunia.com/advisories/26733/[/url]

--

[SA26795] Fedora update for samba

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-13

Fedora has issued an update for samba. This fixes a security issue,
which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26795/\"]http://secunia.com/advisories/26795/[/url]

--

[SA26793] Mandriva update for id3lib

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-13

Mandriva has issued an update for id3lib. This fixes a security issue,
which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26793/\"]http://secunia.com/advisories/26793/[/url]

--

[SA26776] Slackware update for samba

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-13

Slackware has issued an update for samba. This fixes a security issue,
which can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26776/\"]http://secunia.com/advisories/26776/[/url]

--

[SA26764] Samba "winbind nss info" Privilege Escalation Security Issue

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-12

A security issue has been reported in Samba, which can be exploited by
malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26764/\"]http://secunia.com/advisories/26764/[/url]

--

[SA26763] Mandriva update for x11-server

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-12

Mandriva has issued an update for x11-server. This fixes a
vulnerability, which potentially can be exploited by malicious, local
users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26763/\"]http://secunia.com/advisories/26763/[/url]

--

[SA26755] Debian update for xorg-server

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-10

Debian has issued an update for xorg-server. This fixes a
vulnerability, which can be exploited by malicious, local users to gain
escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26755/\"]http://secunia.com/advisories/26755/[/url]

--

[SA26743] X.org X11 Composite Pixmap Privilege Escalation
Vulnerability

Critical: Less critical
Where: Local system
Impact: Privilege escalation
Released: 2007-09-10

A vulnerability has been reported in X.org X11, which potentially can
be exploited by malicious, local users to gain escalated privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26743/\"]http://secunia.com/advisories/26743/[/url]

--

[SA26759] IBM HTTP Server Multi-Processing Module Denial of Service

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-10

IBM has acknowledged a vulnerability in IBM HTTP Server, which can be
exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/26759/\"]http://secunia.com/advisories/26759/[/url]

--

[SA26738] Fedora update for qgit

Critical: Not critical
Where: Local system
Impact: Exposure of sensitive information, Privilege escalation
Released: 2007-09-11

Fedora has issued an update for qgit. This fixes a vulnerability, which
can be exploited by malicious, local users to gain escalated
privileges.

Full Advisory:
[url=\"http://secunia.com/advisories/26738/\"]http://secunia.com/advisories/26738/[/url]

--

[SA26731] Avaya CMS / IR Solaris Special File System "strfreectty()"
Security Issue

Critical: Not critical
Where: Local system
Impact: DoS
Released: 2007-09-07

Avaya has acknowledged a security issue in Avaya CMS and IR, which can
be exploited by malicious, local users to cause a DoS (Denial of
Service).

Full Advisory:
[url=\"http://secunia.com/advisories/26731/\"]http://secunia.com/advisories/26731/[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”