 |
Summary of Security Items from March 30 through April 5, 2005
Information in the US-CERT Cyber Security Bulletin is a compilation and includes information published by outside sources, so the information should not be considered the result of US-CERT analysis. Software vulnerabilities are categorized in the appropriate section reflecting the operating system on which the vulnerability was reported; however, this does not mean that the vulnerability only affects the operating system reported since this information is obtained from open-source information.
This bulletin provides a summary of new or updated vulnerabilities, exploits, trends, viruses, and trojans. Updates to vulnerabilities that appeared in previous bulletins are listed in bold text. The text in the Risk column appears in red for vulnerabilities ranking High. The risks levels applied to vulnerabilities in the Cyber Security Bulletin are based on how the "system" may be impacted. The Recent Exploit/Technique table contains a "Workaround or Patch Available" column that indicates whether a workaround or patch has been published for the vulnerability which the script exploits.
Vulnerabilities
The table below summarizes vulnerabilities that have been identified, even if they are not being exploited. Complete details about patches or workarounds are available from the source of the information or from the URL provided in the section. CVE numbers are listed where applicable. Vulnerabilities that affect both Windows and Unix Operating Systems are included in the Multiple Operating Systems section.
Note: All the information included in the following tables has been discussed in newsgroups and on web sites.
The Risk levels defined below are based on how the system may be impacted:
- High - A high-risk vulnerability is defined as one that will allow an intruder to immediately gain privileged access (e.g., sysadmin or root) to the system or allow an intruder to execute code or alter arbitrary system files. An example of a high-risk vulnerability is one that allows an unauthorized user to send a sequence of instructions to a machine and the machine responds with a command prompt with administrator privileges.
- Medium - A medium-risk vulnerability is defined as one that will allow an intruder immediate access to a system with less than privileged access. Such vulnerability will allow the intruder the opportunity to continue the attempt to gain privileged access. An example of medium-risk vulnerability is a server configuration error that allows an intruder to capture the password file.
- Low - A low-risk vulnerability is defined as one that will provide information to an intruder that could lead to further compromise attempts or a Denial of Service (DoS) attack. It should be noted that while the DoS attack is deemed low from a threat potential, the frequency of this type of attack is very high. DoS attacks against mission-critical nodes are not included in this rating and any attack of this nature should instead be considered to be a "High" threat.
Windows Operating Systems Only |
Vendor & Software Name |
Vulnerability - Impact
Patches - Workarounds
Attacks Scripts |
Common Name /
CVE Reference |
Risk |
Source |
Adaptive Hosting Solutions
ProductCart 2.7 |
Multiple vulnerabilities have been reported that could let remote malicious users conduct Cross-Site Scripting and SQL injection attacks. This is due to improper input validation in 'advSearch_h.asp,' 'NewCust.asp,' 'storelocator_submit.asp,' 'techErr.asp,' and 'advSearch_h.asp.'
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published.
|
Adaptive Hosting Solutions
ProductCart
Cross-Site Scripting and SQL Injection Vulnerabilities |
High |
Secunia SA14833,
April 5, 2005 |
ArGo Software Design
FTP Server 1.4.2 .8 |
A buffer overflow vulnerability exists in the 'DELE' command, which could let a remote malicious user cause a Denial of Service or execute arbitrary code.
No workaround or patch available at time of publishing.
An exploit script has been published. |
ArGoSoft
FTP Server
'DELE' Command
Remote
Buffer Overflow
CAN-2005-0696
|
Low/ High
(High if arbitrary code can be executed)
|
Security Focus, 12755, March 8, 2005
PacketStorm, April 4, 2005 |
ASP-DEv
XM Forum RC3 |
A vulnerability has been reported that could let a remote malicious user conduct Cross-Site Scripting attacks. This is because of an input validation error in the 'posts.asp' script.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
ASP-DEv
XM Forum
Cross-Site Scripting Vulnerability |
High |
Hackers Center Security Group, Zinho's Security Advisory, March 30, 2005 |
BakBone
NetVault 7.3 and prior versions |
Two vulnerabilities have been reported that could let a local or remote malicious user execute arbitrary code on the target system. This is due to a vulnerability when processing the 'configure.cfg' file.
No workaround or patch available at time of publishing.
A Proof of Concept exploit script has been published. |
BakBone
NetVault Buffer Overflows Permit Remote Code Execution |
High |
Security Focus 12967, April 1, 2005 |
Bjørnar Henden
'Yet Another Forum.net' 0.9.9 |
An input validation vulnerability has been reported that could let a remote malicious user conduct Cross-Site Scripting attacks. The 'name,' 'location,' and 'subject' fields are not properly validated.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
Bjørnar Henden 'Yet Another Forum.net' Input Validation Errors Permits Cross-Site Scripting
CAN-2005-0982
|
High |
Security Tracker Alert ID: 1013632, April 4, 2005 |
Comersus Open Technologies
Comersus 6 |
A input validation vulnerability has been reported in the 'username' field could let a remote malicious user conduct Cross-Site Scripting attacks.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
Comersus Cross-Site Scripting Vulnerability |
High |
Hackers Center Security Group, Zinho's Security Advisory, April 3, 2005 |
FastStone Soft
FastStone 4in1 1.2 |
A directory traversal vulnerability has been reported that could let a remote malicious user view files on the target system. This is due to an input validation error.
Update to version 1.3: http://www.faststone.org/FSBrowserDetail.htm
A Proof of Concept exploit has been published. |
FastStone 4in1 Browser Information Disclosure Vulnerability
CAN-2005-0950
|
Medium |
Secunia SA14743, March 30, 2005
|
Iatek
SiteEnable |
Multiple input validation vulnerabilities have been reported that could let a remote malicious user issue SQL commands or conduct Cross-Site Scripting attacks. The 'content.asp' script does not properly validate user-supplied input in the 'sortby' parameter; the 'contenttype' parameter is not properly validated; the title and description fields in the 'Submit a Quote' page are not properly validated.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
Iatek SiteEnable SQL Command Injection and Cross-Site Scripting Vulnerabilities |
High |
Hackers Center Security Group, Zinho's Security Advisory, April 1, 2005 |
Iatek
PortalApp |
An input validation vulnerability has been reported that could let a remote malicious user inject SQL commands and conduct Cross-Site Scripting attacks. The 'ad_click.asp' script does not correctly verify input to the 'banner_id' parameter. Also, the 'content.asp' script does not filter HTML code from user-supplied input in the 'contenttype' and 'keywords' parameters.
No workaround or patch available at time of publishing.
A Proof of Concept exploit script has been published. |
|
High |
Security Tracker Alert ID: 1013591, March 29, 2005 |
IVT Corporation
BlueSoleil Version PTP-1.4.9-Win2k/XP-04.08.27 with Stack Version 04.03.11.20040827
|
A vulnerability has been reported that could let a remote malicious user traverse the directory when sending files to the target device. This is because a user can exploit the Object Push Service.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
|
Medium |
Security Focus 12961, April 1, 2005 |
Kerio Technologies
Kerio Personal Firewall 4.1.2 and prior |
A vulnerability has been reported that could let local malicious users bypass the firewall rules by impersonating another process that is allowed to access the Internet.
Update to version 4.1.3: http://www.kerio.com/kpf_download.html
Currently we are not aware of any exploits for this vulnerability. |
|
Medium |
Kerio Security Advisory KSEC-2005-03-30-01, March 30, 2004 |
MailEnable
MailEnable Professional 1.54; Enterprise 1.04 |
A vulnerability was reported in the IMAP and SMTP services that could let a remote malicious user cause a Denial of Service in the SMTP service to crash. The IMAP impact was not specified.
An update is available at: http://www.mailenable.com/hotfix/MEIMSM-HF050404.zip
An exploit script has been published. |
MailEnable Denial of Service Vulnerability |
Low |
Security Focus 12994 and 12995, April 5, 2005 |
MaxWebPortal.com
MaxWebPortal 1.33 |
Some input validation vulnerabilities have been reported that could let a remote malicious user issue SQL commands and conduct Cross-Site Scripting attacks. This is because the EVENT_ID parameter in the Update_Events function in 'events_functions.asp' is not properly validated.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
MaxWebPortal SQL Injection and Cross-Site Scripting Vulnerabilities |
High |
Security Tracker
Alert ID: 1013617, March 31, 2005 |
Microsoft Jet Database
msjet40.dll library version 4.00.8618.0 |
A vulnerability was reported that could let a remote malicious user cause arbitrary code to be executed. This is because the 'msjet40.dll' component does not properly validate user-supplied input when parsing database files.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
Microsoft Jet Database Remote Code Execution Vulnerability
CAN-2005-0945
|
High |
Hexview Advisory, ID: HEXVIEW*
2005*03*31*1 |
Microsoft
Windows Explorer and Internet Explorer in Windows 2000 SP1 |
A vulnerability has been reported that could let remote malicious users cause a Denial of Service via a malformed Windows Metafile (WMF) file.
No workaround or patch available at time of publishing.
A Proof of Concept exploit has been published. |
Microsoft Windows Explorer and Internet Explorer Denial of Service Vulnerability
CAN-2005-0954
|
Low |
Bugtraq: 20050331, March 31, 2005 |
Microsoft
Microsoft Windows Server 2003 Datacenter Edition, Enterprise Edition, Standard Edition, Web Edition |
Multiple vulnerabilities have been reported that could let a local malicious users cause a Denial of Service. One vulnerability is caused due to an error when the SMB
redirector receives a browser announcement frame and tries to run code that is paged out. Another vulnerability is caused due to an error in the printer driver.
Update to Service Pack 1 for Windows Server 2003:
Windows Server 2003 SP1 (32-bit):
http://www.microsoft.com/downloads/
details.aspx?FamilyId=22CFC239-337C-
4D81-8354-72593B1C1F43
Windows Server 2003 SP1 (Itanium): http://www.microsoft.com/downloads/
details.aspx?FamilyId=890C5C44-815C-
45BD-8B08-4FE901BB8FDF
Currently we are not aware of any exploits for these vulnerabilities. |
Microsoft Windows Server 2003 Local Denial of Service Vulnerabilities |
Low |
Secunia SA14808,
April 5, 2005 |
NetManage
RUMBA 7.3 |
Multiple buffer overflow vulnerabilities have been reported when RTO and WPA profiles are loaded, which could let a remote malicious user cause a Denial of Service and possibly execute arbitrary code.
No workaround or patch available at time of publishing.
Proofs of Concept exploits have been published.
|
|
Low/ High
(High if arbitrary code can be executed)
|
Security Focus,
12965, April 1, 2005 |
Symantec
Norton System Works 2004 and 2005,
Norton Internet Security 2004 and 2005,
Norton AntiVirus 2004 and 2005 |
Two vulnerabilities were reported in the AutoProtect feature that could let a malicious user create a file or modify a filename to cause a Denial of Service. A user can create a special file of a specific file type that when scanned by the AutoProtect feature will cause a Denial of Service. Also, if a certain type of shared file has its filename modified, the SmartScan analysis of the filename modification may cause a Denial of Service.
A fix is available via LiveUpdate.
Currently we are not aware of any exploits for these vulnerabilities. |
|
Low |
Symantec Advisory, SYM05-006
March 28, 2005
US-CERT
VU#146020
US-CERT
VU#713620 |
[back to
top]
| UNIX / Linux Operating Systems Only |
Vendor & Software Name |
Vulnerability - Impact
Patches - Workarounds
Attacks Scripts |
Common Name /
CVE Reference |
Risk |
Source |
Andrew Church
IRC Services prior to 5.0.50 |
A vulnerability has been reported in NickServ LISTLINKS, which could let a remote malicious user obtain sensitive information.
Update available at:
http://www.ircservices.esper.net/
download.html
Currently, we are not aware of any exploits for this vulnerability. |
IRC Services LISTLINKS Information Disclosure
|
Medium |
Security Tracker
Alert, 1013622,
April 1, 2005 |
bzip2
bzip2 1.0.2 & prior |
A vulnerability has been reported when an archive is extracted into a world or group writeable directory, which could let a malicious user modify file permissions of target files.
No workaround or patch available at time of publishing.
There is no exploit code required. |
|
Medium |
Security Focus,
12954,
March 31, 2005 |
Carnegie Mellon University
Cyrus IMAP Server 2.x
|
Multiple vulnerabilities exist: a buffer overflow vulnerability exists in mailbox handling due to an off-by-one boundary error, which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exists in the imapd annotate extension due to an off-by-one boundary error, which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exists in 'fetchnews,' which could let a remote malicious user execute arbitrary code; a buffer overflow vulnerability exist because remote administrative users can exploit the backend; and a buffer overflow vulnerability exists in imapd due to a boundary error, which could let a remote malicious user execute arbitrary code.
Update available at:
http://ftp.andrew.cmu.edu/pub/
cyrus/cyrus-imapd-2.2.11.tar.gz
Gentoo:
http://security.gentoo.org/
glsa/glsa-200502-29.xml
SUSE:
ftp://ftp.SUSE.com/pub/SUSE
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/c/cyrus21-imapd/
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Conectiva:
ftp://atualizacoes.conectiva.
com.br/
ALT Linux:
http://lists.altlinux.ru/pipermail/
security-announce/2005-March
/000287.html
OpenPKG:
ftp://ftp.openpkg.org/release/
Currently we are not aware of any exploits for these vulnerabilities. |
|
High |
Secunia Advisory,
SA14383,
February 24, 2005
Gentoo Linux Security Advisory, GLSA 200502-29,
February 23, 2005
SUSE Security Announcement,
SUSE-SA:2005:009, February 24, 2005
Ubuntu Security
Notice USN-87-1,
February 28, 2005
Mandrakelinux
Security Update Advisory,
MDKSA-2005:051, March 4, 2005
Conectiva Linux Security
Announcement,
CLA-2005:937,
March 17, 2005
ALTLinux Security Advisory,
March 29, 2005
OpenPKG Security Advisory,
OpenPKG-SA-2005.005,
April 5, 2005 |
Dnsmasq
Dnsmasq 2.0-2.20 |
Multiple vulnerabilities have been reported: a buffer overflow vulnerability has been reported due to an off-by-one error when reading the DHCP lease file, which could let a remote malicious user cause a Denial of Service; and a vulnerability has been reported when receiving DNS replies due to insufficient validation, which could let a remote malicious user poison the DNS cache.
Upgrades available at:
http://www.thekelleys.org.uk/dnsmasq/
dnsmasq-2.21.tar.gz
Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-03.xml
Currently we are not aware of any exploits for these vulnerabilities. |
|
Low/ Medium
(Medium if the DNS cache can be poisoned)
|
Security Focus,
12897,
March 25, 2005
Gentoo Linux Security Advisory, GLSA 200504-03,
April 4, 2005 |
FreeBSD
FreeBSD 5.4 & prior |
A vulnerability has been reported in the 'sendfile()' system call due to a failure to secure sensitive memory before distributing it over the network, which could let a malicious user obtain sensitive information.
Patches available at:
ftp://ftp.FreeBSD.org/pub/FreeBSD/
CERT/patches/SA-05:02/
There is no exploit code required. |
|
Medium |
FreeBSD Security Advisory,
FreeBSD-SA-05:02, April 5, 2005 |
GNU
gzip 1.2.4, 1.3.3 |
A vulnerability has been reported when an archive is extracted into a world or group writeable directory, which could let a malicious user modify file permissions.
No workaround or patch available at time of publishing.
There is no exploit code required. |
GNU GZip File Permission Modification |
Medium |
Security Focus,
12996,
April 5, 2005 |
GNU
sharutils 4.2, 4.2.1 |
Multiple buffer overflow vulnerabilities exists due to a failure to verify the length of user-supplied strings prior to copying them into finite process buffers, which could let a remote malicious user cause a Denial of Service or execute arbitrary code.
Gentoo:
http://security.gentoo.org/
glsa/glsa-200410-01.xml
FedoraLegacy:
http://download.fedoralegacy.
org/fedora/
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/s/sharutils/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
We are not aware of any exploits for this vulnerability. |
|
Low/ High
(High if arbitrary code can be executed)
|
Gentoo Linux
Security Advisory, GLSA 200410-01, October 1, 2004
Fedora Legacy
Update Advisory, FLSA:2155,
March 24, 2005
Ubuntu Security
Notice, USN-102-1 March 29, 2005
Fedora Update Notifications,
FEDORA-2005-
280 & 281, April 1, 2005 |
GNU
sharutils 4.2, 4.2.1 |
A vulnerability has been reported in the 'unshar' utility due to the insecure creation of temporary files, which could let a malicious user create/overwrite arbitrary files.
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/s/sharutils/
There is no exploit code required. |
GNU Sharutils 'Unshar' Insecure Temporary File Creation |
Medium |
Ubuntu Security
Notice, USN-104-1, April 4, 2005 |
GNU
Xpdf prior to 3.00pl2 |
A buffer overflow vulnerability exists that could allow a remote user to execute arbitrary code on the target user's system. A remote user can create a specially crafted PDF file that, when viewed by the target user, will trigger an overflow and execute arbitrary code with the privileges of the target user.
A fixed version (3.00pl2) is available at:
http://www.foolabs.com/xpdf/
download.html
A patch is available:
ftp://ftp.foolabs.com/pub/xpdf/
xpdf-3.00pl2.patch
KDE:
http://www.kde.org/info/security/
advisory-20041223-1.txt
Gentoo:
http://security.gentoo.org/glsa
/glsa-200412-24.xml
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/core
/updates/
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/
Mandrakesoft (update for koffice):
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:165
Mandrakesoft (update for kdegraphics):
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:163
Mandrakesoft (update for gpdf):
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:162
Mandrakesoft (update for xpdf):
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:161
Mandrakesoft (update for tetex):
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:166
Debian:
http://www.debian.org/
security/2004/dsa-619
Fedora (update for tetex):
http://download.fedora.redhat.
com/pub/fedora/linux/
core/updates/
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/core/
updates/3/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200501-13.xml
TurboLinux:
ftp://ftp.turbolinux.co.jp/pub/
TurboLinux/TurboLinux/ia32/
SGI:
http://support.sgi.com/browse_
request/linux_patches_by_os
Conectiva:
ftp://atualizacoes.conectiva.
com.br/
SuSE:
ftp://ftp.suse.com/pub/suse/
FedoraLegacy:
http://download.fedoralegacy.
org/fedora/1/updates/
FedoraLegacy:
http://download.fedoralegacy.
org/redhat/
SUSE:
ftp://ftp.SUSE.com
/pub/SUSE
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-026.html
RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-354.html
Currently we are not aware of any exploits for this vulnerability. |
GNU Xpdf Buffer Overflow in doImage()
CAN-2004-1125 |
High |
iDEFENSE Security Advisory 12.21.04
KDE Security
Advisory,
December 23, 2004
Mandrakesoft,
MDKSA-2004:
161,162,
163,165, 166, December 29, 2004
Fedora Update Notification,
FEDORA-2004-585, January 6, 2005
Gentoo Linux
Security Advisory, GLSA 200501-13,
January 10, 2005
Conectiva Linux Security
Announcement,
CLA-2005:921,
January 25, 2005
SUSE Security Summary Report, SUSE-SR:2005:002, January 26, 2005
Avaya Security Advisory,
ASA-2005-027,
January 25, 2005
SUSE Security Summary Report, SUSE-SR:2005:003, February 4, 2005
SUSE Security Summary Report, SUSE-SR:2005:003, February 4, 2005
Fedora Legacy
Update Advisory, FLSA:2353,
February 10, 2005
Fedora Legacy
Update Advisory, FLSA:2127,
March 2, 2005
SUSE Security Announcement,
SUSE-SA:2005
:015, March 14, 2005
RedHat Security Advisory,
RHSA-2005:026-15,
March 16, 2005
SuSE Security Summary Report, SUSE-SR:2005:008, March 18, 2005
RedHat Security Advisory, RHSA-2005:354-03,
April 1, 2005
|
Grip
Grip 3.1.2, 3.2 .0 |
A buffer overflow vulnerability has been reported in the CDDB protocol due to a boundary error, which could let a remote malicious user cause a Denial of Service and possibly execute arbitrary code.
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/core/
updates
Gentoo:
http://security.gentoo.org/
glsa/glsa-200503-21.xml
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-304.html
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Currently we are not aware of any exploits for this vulnerability. |
|
Low/
High
(High if arbitrary code can be executed)
|
Fedora Update Notifications,
FEDORA-2005-
202 & 203,
March 9, 2005
Gentoo Linux
Security Advisory,
GLSA 200503-21,
March 17, 2005
RedHat Security Advisory, RHSA-2005:304-08,
March 28, 2005
Mandrakelinux Security Update Advisory,
MDKSA-2005:066,
April 3, 2005 |
IBM
AIX 5.1 L, 5.1, 5.2 L, 5.2, 5.3 L, 5.3 |
A vulnerability has been reported in the '/SBIN/RC.BOOT' script due to the insecure creation of temporary files, which could let a malicious user corrupt arbitrary files with superuser privileges.
Updates available at:
http://www-912.ibm.com/
eserver/support/fixes/
Currently we are not aware of any exploits for this vulnerability. |
IBM AIX 'RC.BOOT' Insecure Temporary File Creation |
High |
Security Focus,
12992,
April 4, 2005 |
ImageMagick
ImageMagick 5.3.3, 5.3.8, 5.4.3, 5.4.4 .5, 5.4.7, 5.4.8 .2-1.1.0 , 5.4.8, 5.5.3 .2-1.2.0, 5.5.4, 5.5.6 .0-20030409, 5.5.6, 5.5.7, 6.0, 6.0.1 |
Several vulnerabilities have been reported: a remote Denial of Service vulnerability has been reported in the decoder due to a failure to handle malformed TIFF tags; a remote Denial of Service vulnerability has been reported due to a failure to handle malformed TIFF images; a remote Denial of Service vulnerability has been reported due to a failure to handle malformed PSD files; and a buffer overflow vulnerability has been reported in the SGI parser, which could let a remote malicious user execute arbitrary code.
Upgrades available at:
http://www.imagemagick.org/
script/download.php?
SuSE:
ftp://ftp.suse.com/pub/suse
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-070.html
Debian:
http://security.debian.org/pool/
updates/main/i/imagemagick/
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Currently we are not aware of any exploits for these vulnerabilities. |
|
Low/ High
(High if arbitrary code can be executed)
|
Security Tracker
Alert, 1013550,
March 24, 2005
Debian Security Advisory,
DSA 702-1,
April 1, 2005
Mandrakelinux Security Update Advisory,
MDKSA-2005:065, April 3, 2005 |
ImageMagick
ImageMagick 5.3.3, 5.4.3, 5.4.4.5, 5.4.7, 5.4.8 .2-1.1.0, 5.4.8,
5.5.3 .2-1.2.0, 5.5.6 .0-20030409, 5.5.7, 6.0, 6.0.1, 6.0.3-6.0.8 |
A buffer overflow vulnerability exists in the 'EXIF' parsing routine due to a boundary error, which could let a remote malicious user execute arbitrary code.
Upgrades available at:
http://sourceforge.net/project/
showfiles.php?group_id=24099
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/i/imagemagick/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200411-11.xml
Debian:
http://security.debian.org/pool/
updates/main/i/imagemagick/
SUSE:
ftp://ftp.SUSE.com/pub/
SUSE/i386/update/
Mandrakesoft:
http://www.mandrakesoft.com/
security/advisories?name=
MDKSA-2004:143
(Red Hat has re-issued it's update.)
http://rhn.redhat.com/errata/
RHSA-2004-480.html
TurboLinux:
ftp://ftp.turbolinux.co.jp/pub/
TurboLinux/TurboLinux/ia32/
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/core/
updates/3/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Currently we are not aware of any exploits for this vulnerability. |
|
High |
Security Tracker
Alert ID, 1011946,
October 26, 2004
Gentoo Linux Security Advisory, GLSA 200411-11:01, November 6, 2004
Debian Security Advisory DSA 593-1, November 16, 2004
SUSE Security Announcement,
SUSE-SA:2004:041, November 17, 2004
SUSE Security Summary Report,
SUSE-SR:2004:001, November 24, 2004
Mandrakesoft
Security Advisory,
MDKSA-2004:143, December 6, 2004
Red Hat Security Advisory,
RHSA-2004:636-03, December 8, 2004
Turbolinux Security Advisory,
TLSA-2005-7,
January 26, 2005
Fedora Update Notification,
FEDORA-2005-221, March 15, 2005
Fedora Update Notifications,
FEDORA-2005-
234 & 235,
March 30, 2005 |
libexif
libexif 0.6.9, 0.6.11 |
A vulnerability exists in the 'EXIF' library due to insufficient validation of 'EXIF' tag structure, which could let a remote malicious user execute arbitrary code.
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/libe/libexif/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200503-17.xml
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-300.html
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Currently we are not aware of any exploits for this vulnerability. |
|
High |
Ubuntu Security
Notice USN-91-1, March 7, 2005
Fedora Update Notifications,
FEDORA-2005-
199 & 200,
March 8, 2005
Gentoo Linux
Security Advisory,
GLSA 200503-17, March 12, 2005
RedHat Security Advisory,
RHSA-2005:300-08, March 21, 2005
Mandrakelinux Security Update Advisory,
MDKSA-2005:064, March 31, 2005 |
libtiff.org
LibTIFF 3.6.1
Avaya MN100 (All versions), Avaya Intuity LX (version 1.1-5.x), Avaya Modular Messaging MSS (All versions)
|
Several buffer overflow vulnerabilities exist: a vulnerability exists because a specially crafted image file can be created, which could let a remote malicious user cause a Denial of Service or execute arbitrary code; a remote Denial of Service vulnerability exists in 'libtiff/tif_dirread.c' due to a division by zero error; and a vulnerability exists in the 'tif_next.c,' 'tif_thunder.c,' and 'tif_luv.c' RLE decoding routines, which could let a remote malicious user execute arbitrary code.
Debian:
http://security.debian.org/pool/
updates/main/t/tiff/
Gentoo:
http://security.gentoo.org/glsa/
glsa-200410-11.xml
Fedora:
http://download.fedora.redhat.com/
pub/fedora/
linux/core/updates/2/
OpenPKG:
ftp://ftp.openpkg.org/release/
Trustix:
ftp://ftp.trustix.org/pub/trustix/updates/
Mandrake:
http://www.mandrakesecure.net/en/ftp.php
SuSE:
ftp://ftp.suse.com/pub/suse/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2004-577.html
Slackware:
ftp://ftp.slackware.com/pub/slackware/
Conectiva:
ftp://atualizacoes.conectiva.com.br/
KDE: Update to version 3.3.2:
http://kde.org/download/
Apple Mac OS X:
http://www.apple.com/swupdates/
Gentoo: KDE kfax:
http://www.gentoo.org/security
/en/glsa/glsa-200412-17.xml
Avaya: No solution but workarounds available at:
http://support.avaya.com/elmodocs2/
security/ASA-2005-002_RHSA-2004-577.pdf
TurboLinux:
http://www.turbolinux.com/update/
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-354.html
Proofs of Concept exploits have been published.
|
|
Low/ High
(High if arbitrary code can be execute)
|
Gentoo Linux
Security Advisory,
GLSA 200410-11, October 13, 2004
Fedora Update Notification,
FEDORA-2004-334, October 14, 2004
OpenPKG Security Advisory,
OpenPKG-SA-2004.043,
October 14, 2004
Debian Security Advisory,
DSA 567-1,
October 15, 2004
Trustix Secure Linux Security Advisory, TSLSA-2004-0054, October 15, 2004
Mandrakelinux
Security Update Advisory, MDKSA-2004:109 &
MDKSA-2004:111, October 20 & 21,
2004
SuSE Security Announcement,
SUSE-SA:2004:038, October 22, 2004
RedHat Security Advisory,
RHSA-2004:577-16,
October 22, 2004
Slackware Security Advisory,
SSA:2004-305-02, November 1, 2004
Conectiva Linux Security
Announcement,
CLA-2004:888, November 8, 2004
US-CERT
Vulnerability Notes VU#687568 & VU#948752,
December 1, 2004
Gentoo Linux Security Advisory, GLSA 200412-02,
December 6, 2004
KDE Security
Advisory,
December 9, 2004
Apple Security
Update
SA-2004-12-02
Gentoo Security Advisory, GLSA 200412-17 / kfax, December 19, 2004
Avaya Advisory
ASA-2005-002,
January 5, 2005
Conectiva Linux Security
Announcement,
CLA-2005:914,
January 6, 2005
Turbolinux Security Announcement,
January 20, 2005
Mandrakelinux
Security Update Advisory,
MDKSA-2005:052, March 4, 2005
RedHat Security Advisory,
RHSA-2005:354-03,
April 1, 2005 |
Mailreader.com
Mailreader.com 2.3.29 |
A vulnerability has been reported in 'network.cgi' due to insufficient sanitization of user-supplied input, which could let a remote malicious user execute arbitrary HTML code.
Debian:
http://security.debian.org/pool/
updates/main/m/mailreader/
There is no exploit code required. |
|
High |
Debian Security Advisory DSA 700-1, March 30, 2005 |
Multiple Vendors
Carnegie Mellon University Cyrus IMAP Server 2.1.7, 2.1.9, 2.1.10, 2.1.16, 2.2 .0 ALPHA, 2.2.1 BETA, 2.2.2 BETA, 2.2.3-2.2.8; Trustix Secure Enterprise Linux 2.0, Secure Linux 2.0-2.2;
Ubuntu Linux 4.1 ppc, 4.1 ia64, 4.1 ia32 |
Multiple vulnerabilities exist: a buffer overflow vulnerability exists in the 'PROXY' and 'LOGIN' commands if the 'IMAPMAGICPLUS' option is enabled, which could let a remote malicious user execute arbitrary code; an input validation vulnerability exists in the argument parser for the 'PARTIAL' command, which could let a remote malicious user execute arbitrary code; an input validation vulnerability exists in the argument handler for the 'FETCH' command, which could let a remote malicious user execute arbitrary code; and a vulnerability exists in the handler for the 'APPEND' command, which could let a remote malicious user execute arbitrary code.
Carnegie Mellon University:
ftp://ftp.andrew.cmu.edu/
pub/cyrus/
Debian:
http://security.debian.org/
pool/updates
/main/c/cyrus-imapd/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200411-34.xml
Mandrake:
http://www.mandrakesecure.
net/en/ftp.php
Trustix:
http://http.trustix.org/pub/
trustix/updates/
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main
/c/cyrus21-imapd/
Conectiva:
ftp://atualizacoes.conectiva.
com.br/
Fedora:
http://download.fedora.redhat.
com/pub
/fedora/linux/core/updates/
OpenPKG:
ftp://ftp.openpkg.org/release/
SUSE:
ftp://ftp.SUSE.com/pub/SUSE/
Apple:
http://www.apple.com/support/
downloads/securityupdate
2005003client.html
An exploit script has been published. |
|
High |
Securiteam,
November 23, 2004
Debian Security Advisory, DSA 597-1, November 25, 2004
Gentoo Linux Security Advisory, GLSA 200411-34,
November 25, 2004
Mandrakelinux
Security Update Advisory,
MDKSA-2004:139, November 26, 2004
Trustix Secure Linux Advisory,
TSL-2004-0063. November 29, 2004
OpenPKG Security Advisory,
OpenPKG-SA-2004.051,
November 29, 2004
Conectiva Linux Security
Announcement,
CLA-2004:904, December 1, 2004
Fedora Update Notifications,
FEDORA-2004-
487 & 489,
December 1, 2004
SUSE Security Announcement,
SUSE-SA:2004:043, December 3, 2004
Apple Security
Update, APPLE-SA-2005-03-21,
March 21, 2005
PacketStorm,
March 30, 2005 |
Multiple Vendors
FreeNX 0.2 -0-0.2 -3, 0.2.4-0.2.7 |
A vulnerability exists in the 'XAUTHORITY' environment variable, which could let a malicious user bypass authentication.
Update available at:
http://debian.tu-bs.de/knoppix/
nx/freenx-0.2.8.tar.gz
SuSE:
ftp://ftp.suse.com/pub/suse/
Upgrade available at:
http://debian.tu-bs.de/knoppix/
nx/freenx-0.2.8.tar.gz
There is no exploit code required. |
|
Medium |
SUSE Security Summary Report, ID: SUSE-SR:2005:006, February 25, 2005
Security, 12663,
April 1, 2005 |
Multiple Vendors
ht//Dig Group ht://Dig 3.1.5 -8, 3.1.5 -7, 3.1.5, 3.1.6, 3.2 .0, 3.2 0b2-0b6; SuSE Linux 8.0, i386, 8.1, 8.2, 9.0, 9.0 x86_64, 9.1, 9.2 |
A Cross-Site Scripting vulnerability exists due to insufficient filtering of HTML code from the 'config' parameter, which could let a remote malicious user execute arbitrary HTML and script code.
SuSE:
ftp://ftp.suse.com/pub/suse/
Debian:
http://security.debian.org/pool/
updates/main/h/htdig/
Gentoo:
http://security.gentoo.org/glsa/
glsa-200502-16.xml
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Proof of Concept exploit has been published. |
|
High |
SUSE Security Summary Report, SUSE-SR:2005:003, February 4, 2005
Debian Security Advisory ,DSA 680-1, February 14, 2005
Gentoo Linux Security Advisory, GLSA 200502-16,
February 14, 2005
Mandrakelinux Security Update Advisory,
MDKSA-2005:063, March 31, 2005 |
Multiple Vendors
Linux kernel 2.4 .0-test1-test12, 2.4-2.4.29, 2.6, 2.6-test1-test11, 2.6.1-2.6.11 |
Multiple vulnerabilities have been reported in the ISO9660 handling routines, which could let a malicious user execute arbitrary code.
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/l/linux-source-2.6.8.1/
Currently we are not aware of any exploits for these vulnerabilities. |
Linux Kernel
Multiple ISO9660 Filesystem
Handling Vulnerabilities
CAN-2005-0815
|
High |
Security Focus,
12837,
March 18, 2005
Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005
Ubuntu Security Notice, USN-103-1, April 1, 2005 |
Multiple Vendors
RedHat Fedora Core3 & Core 2;
Sylpheed Sylpheed 0.8, 0.8.11, 0.9.4-0.9.12, 0.9.99, 1.0 .0-1.0.3, 1.9-1.9.4 |
A buffer overflow vulnerability has been reported when handling email messages that contain attachments with MIME-encoded file names, which could let a remote malicious user execute arbitrary code.
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Sylpheed:
http://sylpheed.good-day.net/
sylpheed/v1.0/sylpheed-1.0.4.tar.gz
Gentoo:
http://security.gentoo.org/
glsa/glsa-200504-02.xml
Currently we are not aware of any exploits for this vulnerability. |
Sylpheed MIME-Encoded
Attachment Name Buffer Overflow
CAN-2005-0926
|
High |
Fedora Update Notifications,
FEDORA-2005-
263 & 264,
March 29, 2005
Gentoo Linux Security Advisory, GLSA 200504-02,
April 2, 2005 |
Multiple Vendors
Squid Web Proxy Cache 2.5 .STABLE9, .STABLE8, .STABLE7 |
A vulnerability exists when using the Netscape Set-Cookie recommendations for handling cookies in caches due to a race condition, which could let a malicious user obtain sensitive information.
Patches available at:
http://www.squid-cache.org/Versions
/v2/2.5/bugs/squid-2.5.STABLE9-setcookie.patch
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/s/squid/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
There is no exploit code required.
|
Squid Proxy Set-Cookie Headers Information Disclosure
CAN-2005-0626
|
Medium |
Secunia Advisory, SA14451,
March 3, 2005
Ubuntu Security
Notice,
USN-93-1
March 08, 2005
Fedora Update Notifications,
FEDORA-2005-
275 & 276,
March 30, 2005 |
Multiple Vendors
Daniel Stenberg curl 6.0-6.4, 6.5-6.5.2, 7.1, 7.1.1, 7.2, 7.2.1, 7.3, 7.4, 7.4.1, 7.10.1, 7.10.3-7.10.7, 7.12.1 |
A buffer overflow vulnerability exists in the Kerberos authentication code in the 'Curl_krb_kauth()' and 'krb4_auth()' functions and in the NT Lan Manager (NTLM) authentication in the 'Curl_input_ntlm()' function, which could let a remote malicious user execute arbitrary code.
SUSE:
ftp://ftp.SUSE.com/pub/SUSE
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/c/curl/
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Updates available at:
http://curl.haxx.se/download/
curl-7.13.1.tar.gz
Gentoo:
http://security.gentoo.org/
glsa/glsa-200503-20.xml
Conectiva:
ftp://atualizacoes.conectiva.
com.br/10/
ALT Linux:
http://lists.altlinux.ru/pipermail/
security-announce/2005-March
/000287.html
RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-340.html
Currently we are not aware of any exploits for these vulnerabilities. |
Multiple Vendors cURL / libcURL Kerberos Authentication & 'Curl_input_ntlm()' Remote Buffer Overflows
CAN-2005-0490
|
High |
iDEFENSE
Security Advisory ,
February 21, 2005
Mandrakelinux
Security Update Advisory, MDKSA-2005:048, March 4, 2005
Gentoo Linux
Security Advisory, GLSA 200503-20,
March 16, 2005
Conectiva Linux Security
Announcement,
CLA-2005:940,
March 21, 2005
ALTLinux Security Advisory, March 29, 2005
RedHat Security Advisory,
RHSA-2005:340-09,
April 5, 2005 |
Multiple Vendors
Debian Linux 3.0, sparc, s/390, ppc, mipsel, mips, m68k, ia-64, ia-32, hppa, arm, alpha;
Easy Software Products CUPS 1.0.4 -8, 1.0.4, 1.1.1, 1.1.4 -5, 1.1.4 -3, 1.1.4 -2, 1.1.4, 1.1.6, 1.1.7, 1.1.10, 1.1.12-1.1.20;
Gentoo Linux;
GNOME GPdf 0.112;
KDE KDE 3.2-3.2.3, 3.3, 3.3.1, kpdf 3.2;
RedHat Fedora Core2;
Ubuntu ubuntu 4.1, ppc, ia64, ia32, Xpdf Xpdf 0.90-0.93; 1.0.1, 1.0 0a, 1.0, 2.0 3, 2.0 1, 2.0, 3.0, SUSE Linux - all versions |
Several integer overflow vulnerabilities exist in 'pdftops/Catalog.cc' and 'pdftops/XRef.cc,' which could let a remote malicious user execute arbitrary code.
Debian:
http://security.debian.org/pool
/updates/main/c/cupsys/
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/
core/updates/2/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200410-20.xml
KDE:
ftp://ftp.kde.org/pub/kde/
security_patches/
post-3.3.1-kdegraphics.diff
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/c/cupsys/
Conectiva:
ftp://atualizacoes.conectiva.com.br/
Debian:
http://security.debian.org/pool/
updates/main/t/tetex-bin/
SUSE: Update:
ftp://ftp.SUSE.com/pub/SUSE
Gentoo:
http://security.gentoo.org/
glsa/glsa-200501-31.xml
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
FedoraLegacy:
http://download.fedoralegacy.org/
fedora/1/updates/
RedHat:
https://rhn.redhat.com/errata/
RHSA-2005-132.html
FedoraLegacy:
http://download.fedoralegacy.
org/redhat/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-213.html
SGI:
ftp://patches.sgi.com/support/
free/security/advisories/
SUSE:
ftp://ftp.suse.com/pub/suse/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-354.html
Currently we are not aware of any exploits for these vulnerabilities. |
Multiple Vendors Xpdf PDFTOPS Multiple Integer Overflows
CAN-2004-0888
CAN-2004-0889 |
High |
Security Tracker
Alert ID, 1011865, October 21, 2004
Conectiva Linux Security
Announcement,
CLA-2004:886, November 8, 2004
Debian Security Advisory, DSA 599-1, November 25, 2004
SUSE Security Summary Report, SUSE-SR:2004:002, November 30, 2004
Gentoo Linux Security Advisory,
GLSA 200501-31,
January 23, 2005
Fedora Update Notifications,
FEDORA-2005-122, 123, 133-136,
February 8 & 9, 2005
Fedora Legacy
Update Advisory, FLSA:2353,
February 10, 2005
Mandrakelinux
Security Update Advisories,
MDKSA-2005:
041-044,
February 18, 2005
RedHat Security Advisory,
RHSA-2005:132-09,
February, 18. 2005
Fedora Legacy
Update Advisory,
FLSA:2127,
March 2, 2005
Mandrakelinux
Security Update Advisory, MDKSA-2005:052, March 4, 2005
RedHat Security Advisory, RHSA-2005:213-04,
March 4, 2005
SGI Security
Advisory,
20050204-01-U,
March 7, 2005
SUSE Security Summary Report, SUSE-SR:2005:008, March 18, 2005
RedHat Security Advisory,
RHSA-2005:354-03,
April 1, 2005 |
Multiple Vendors
Enlightenment Imlib2 1.0-1.0.5, 1.1, 1.1.1;
ImageMagick ImageMagick 5.4.3, 5.4.4 .5, 5.4.8 .2-1.1.0 , 5.5.3 .2-1.2.0, 5.5.6 .0- 2003040, 5.5.7,6.0.2;
Imlib Imlib 1.9-1.9.14 |
Multiple buffer overflow vulnerabilities exist in the Iimlib/Imlib2 libraries when handling malformed bitmap images, which could let a remote malicious user cause a Denial of Service or execute arbitrary code.
lmlib:
http://cvs.sourceforge.net/
viewcvs.py/enlightenment/e17/
ImageMagick:
http://www.imagemagick.org/
www/download.html
Gentoo:
http://security.gentoo.org/
glsa/glsa-200409-12.xml
Mandrake:
http://www.mandrakesecure.net/en/ftp.php
Fedora:
http://download.fedora.redhat.com/pub/
fedora/linux/core/updates/
Debian:
http://security.debian.org/pool/
updates/main/i/imagemagick/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2004-465.html
SUSE:
ftp://ftp.SUSE.com/pub/SUSE/
TurboLinux:
ftp://ftp.turbolinux.com/pub/TurboLinux/
TurboLinux/ia32/Desktop/
Conectiva:
ftp://atualizacoes.conectiva.com.br/
Sun:
http://sunsolve.sun.com/search/document.do?
assetkey=1-26-57648-1&searchclause=
http://sunsolve.sun.com/search/document.do?
assetkey=1-26-57645-1&searchclause=
TurboLinux:
ftp://ftp.turbolinux.com/pub/
TurboLinux/TurboLinux/ia32/
RedHat:
http://rhn.redhat.com/errata/RHSA-2004-480.html
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/i/imagemagick/i
RedHat:
http://rhn.redhat.com/errata/
RHSA-2004-636.html
SUSE:
ftp://ftp.SUSE.com/pub/SUSE/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Currently we are not aware of any exploits for these vulnerabilities.
|
IMLib/IMLib2 Multiple BMP Image
Decoding Buffer Overflows
CAN-2004-0817
CAN-2004-0802 |
Low/ High
(High if arbitrary code can be executed)
|
Security Focus, September 1, 2004
Gentoo Linux Security Advisory, GLSA 200409-12,
September 8, 2004
Mandrakelinux Security Update Advisory, MDKSA-2004:089, September 8, 2004
Fedora Update Notifications,
FEDORA-2004-300 &301, September 9, 2004
Turbolinux Security Advisory,
TLSA-2004-27, September 15, 2004
RedHat Security Advisory, RHSA-2004:465-08, September 15, 2004
Debian Security Advisories,
DSA 547-1 & 548-1, September 16, 2004
Conectiva Linux Security
Announcement,
CLA-2004:870, September 28, 2004
Sun(sm) Alert Notifications,
57645 & 57648,
September 20, 2004
Turbolinux Security Announcement,
October 5, 2004
RedHat Security Update, RHSA-2004:480-05,
October 20, 2004
Ubuntu Security
Notice USN-35-1, November 30, 2004
RedHat Security Advisory, RHSA-2004:636-03, December 8, 2004
SUSE Security Summary Report, SUSE-SR:2005:002, January 26, 2005
Fedora Update Notifications,
FEDORA-2005-
234 & 235,
March 30, 2005 |
Multiple Vendors
GNOME GdkPixbuf 0.22
GTK GTK+ 2.4.14
RedHat Fedora Core3
RedHat Fedora Core2 |
A remote Denial of Service vulnerability has been reported due to a double free error in the BMP loader.
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/
RedHat:
http://rhn.redhat.com/
errata/RHSA-2005-344.html
http://rhn.redhat.com/
errata/RHSA-2005-343.html
Currently we are not aware of any exploits for this vulnerability. |
GDK-Pixbuf BMP Image Processing Double Free Remote Denial of Service
CAN-2005-0891
|
Low |
Fedora Update Notifications,
FEDORA-2005-
265, 266, 267 & 268,
March 30, 2005
RedHat Security Advisories,
RHSA-2005:344-03 & RHSA-2005:343-03, April 1 & 4, 2005 |
Multiple Vendors
ImageMagick 5.3.3, 5.4.3, 5.4.4 .5, 5.4.7, 5.4.8 .2-1.1.0, 5.4.8, 5.5.3 .2-1.2.0, 5.5.6 .0-20030409, 5.5.7, 6.0-6.0.8, 6.1-6.1.7, 6.2 |
A format string vulnerability exists when handling malformed file names, which could let a remote malicious user cause a Denial of Service or execute arbitrary code.
Update available at:
http://www.imagemagick.org/script/
downloads.php
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/i/imagemagick/
Gentoo:
http://security.gentoo.org/
glsa/glsa-200503-11.xml
SUSE:
ftp://ftp.suse.com/pub/suse/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-320.html
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Debian:
http://security.debian.org/pool
/updates/main/i/imagemagick/
Mandrake:
http://www.mandrakesecure.net/
en/ftp.php
Currently we are not aware of any exploits for this vulnerability. |
ImageMagick File Name Handling Remote Format String
CAN-2005-0397
|
Low/ High
(High if arbitrary code can be executed)
|
Secunia Advisory,
SA14466, March 4, 2005
Ubuntu Security
Notice, USN-90-1, March 3, 2004
SUSE Security Announcement,
SUSE-SA:2005:017, March 23, 2005
RedHat Security Advisory, RHSA-2005:320-10,
March 23, 2005
Fedora Update Notifications,
FEDORA-2005-
234 & 235,
March 30, 2005
Debian Security Advisory,
DSA 702-1 ,
April 1, 2005
Mandrakelinux Security Update Advisory,
MDKSA-2005:065, April 3, 2005 |
Multiple Vendors
IPsec-Tools IPsec-Tools 0.5; KAME Racoon prior to 20050307 |
A remote Denial of Service vulnerability has been reported when parsing ISAKMP headers.
Upgrades available at:
http://www.kame.net/snap-users/
Fedora:
http://download.fedora.redhat.
com/pub/fedora/linux/core/
updates/
RedHat:
http://rhn.redhat.com/errata/
RHSA-2005-232.html
Gentoo:
http://security.gentoo.org/
glsa/glsa-200503-30.xml
ALTLinux:
http://lists.altlinux.ru/
pipermail/security-announce/
2005-March/000287.html
SUSE:
ftp://ftp.SUSE.com/pub/SUSE
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/i/ipsec-tools/
Currently we are not aware of any exploits for this vulnerability. |
KAME Racoon Malformed ISAKMP Packet Headers Remote Denial of Service
CAN-2005-0398
|
Low |
Fedora Update Notifications,
FEDORA-2005-
216 & 217,
March 14, 2005
RedHat Security Advisory,
RHSA-2005:232-10, March 23, 2005
Gentoo Linux
Security Advisory, GLSA 200503-33,
March 25, 2005
ALTLinux Security Advisory,
March 29, 2005
SUSE Security Announcement, SUSE-SA:2005:020, March 31, 2005
Ubuntu Security Notice, USN-107-1, April 05, 2005 |
Multiple Vendors
Linux kernel 2.4-2.4.29, 2.6 .10, 2.6-2.6.11 |
A vulnerability has been reported in the 'bluez_sock_create()' function when a negative integer value is submitted, which could let a malicious user execute arbitrary code with root privileges.
Patches available at:
http://www.kernel.org/pub/linux/
kernel/v2.4/testing/patch-2.4.30-rc3.bz2
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
SUSE:
ftp://ftp.SUSE.com/pub/SUSE
Trustix:
http://http.trustix.org/pub/
trustix/updates/
A Proof of Concept exploit script has been published. |
|
High |
Security Tracker
Alert, 1013567,
March 27, 2005
SUSE Security Announcement, SUSE-SA:2005
:021, April 4, 2005
Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005
US-CERT
VU#685461 |
Multiple Vendors
Linux kernel 2.4-2.4.30, 2.6-2.6.11 |
A vulnerability has been reported due to insufficient access control of the 'N_MOUSE' line discipline, which could let a malicious user inject mouse and keyboard events into an alternate X session or console.
Patches available at:
http://www.securityfocus.com/data
/vulnerabilities/patches/serport.patch
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1/
Currently we are not aware of any exploits for this vulnerability.
|
Linux Kernel Serial Driver Mouse And Keyboard Event Injection
CAN-2005-0839
|
Medium |
Security Focus,
12971,
April 1, 2005 |
Multiple Vendors
Linux kernel 2.4-2.4.30, 2.6-2.6.11; Ubuntu Linux 4.1 ppc, ia64, ia32 |
A Denial of Service vulnerability has been reported in the 'TmpFS' driver due to insufficient sanitization of the 'shm_nopage()' argument.
Patch available at:
http://www.securityfocus.com/data/
vulnerabilities/patches/shmem.patch
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1/
Currently we are not aware of any exploits for this vulnerability. |
|
Low |
Security Focus,
12970
April 1, 2005 |
Multiple Vendors
Linux kernel 2.5.0-2.5.69, 2.6-2.6.11 |
A Denial of Service vulnerability has been reported in 'kernel/futex.c.'
No workaround or patch available at time of publishing.
Currently we are not aware of any exploits for this vulnerability. |
|
Low |
Security Tracker
Alert, 1013616,
March 31, 2005 |
Multiple Vendors
Linux kernel 2.6 .10,
Linux kernel 2.6 -test1-test11, 2.6-2.6.8 |
A Denial of Service vulnerability has been reported in the Netfilter code due to a memory leak.
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/l/linux-
source-2.6.8.1/
SuSE:
ftp://ftp.suse.com/pub/suse/
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Conectiva:
ftp://atualizacoes.conectiva.
com.br/10/
Currently we are not aware of any exploits for this vulnerability. |
Linux Kernel
Netfilter Memory Leak
Denial of Service
CAN-2005-0210
|
Low |
Ubuntu Security
Notice, USN-95-1 March 15, 2005
SUSE Security Announcement,
SUSE-SA:2005:
018, March 24, 2005
Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005
Conectiva Linux Security Announcement,
CLA-2005:945,
March 31, 2005 |
Multiple Vendors
Linux Kernel 2.6.10, 2.6 -test1-test11, 2.6-2.6.11 |
A Denial of Service vulnerability has been reported in the 'load_elf_library' function.
Patches available at:
http://www.kernel.org/pub/
linux/kernel/v2.6/patch-2.6.11.6.bz2
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/
Trustix:
http://http.trustix.org/pub/
trustix/updates/
Currently we are not aware of any exploits for this vulnerability. |
|
Low |
Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005
Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005 |
Multiple Vendors
Linux kernel 2.6.10, 2.6 -test9-CVS, 2.6-test1- -test11, 2.6, 2.6.1-2.6.11 ; RedHat Desktop 4.0, Enterprise Linux WS 4, ES 4, AS 4 |
Multiple vulnerabilities exist: a vulnerability exists in the 'shmctl' function, which could let a malicious user obtain sensitive information; a Denial of Service vulnerability exists in 'nls_ascii.c' due to the use of incorrect table sizes; a race condition vulnerability exists in the 'setsid()' function; and a vulnerability exists in the OUTS instruction on the AMD64 and Intel EM64T architecture, which could let a malicious user obtain elevated privileges.
RedHat:
https://rhn.redhat.com/errata/
RHSA-2005-092.html
Ubuntu:
http://security.ubuntu.com/ubuntu/
pool/main/l/linux-source-2.6.8.1/
Conectiva:
ftp://atualizacoes.conectiva.
com.br/
SUSE:
ftp://ftp.SUSE.com/pub/SUSE
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/
Conectiva:
ftp://atualizacoes.conectiva.
com.br/10/
Currently we are not aware of any exploits for these vulnerabilities. |
|
Low/ Medium
(Low if a DoS)
|
Ubuntu Security
Notice, USN-82-1, February 15, 2005
RedHat Security Advisory,
RHSA-2005:092-14, February 18, 2005
SUSE Security Announcement,
SUSE-SA:2005:018, March 24, 2005
Fedora Security
Update Notification,
FEDORA-2005-262, March 28, 2005
Conectiva Linux Security Announcement,
CLA-2005:945,
March 31, 2005 |
Multiple Vendors
Linux kernel 2.6.10, 2.6, -test1-test 11, 2.6.1- 2.6.11;
RedHat Fedora Core2 |
A vulnerability has been reported in the EXT2 filesystem handling code, which could let malicious user obtain sensitive information.
Patches available at:
http://www.kernel.org/pub/linux/
kernel/v2.6/patch-2.6.11.6.bz2
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/2/
Trustix:
http://http.trustix.org/pub/
trustix/updates/
Currently we are not aware of any exploits for this vulnerability. |
|
Medium |
Security Focus,
12932,
March 29, 2005
Trustix Secure
Linux Security Advisory,
TSLSA-2005-0011, April 5, 2005 |
Multiple Vendors
Linux kernel 2.6.8 rc1-rc3, 2.6.8, 2.6.11 -rc2-rc4, 2.6.11
|
A Denial of Service vulnerability has been reported due to an error in the AIO (Asynchronous I/O) support in the "is_hugepage_only_range()" function.
No workaround or patch available at time of publishing.
Currently, we are not aware of any exploits for this vulnerability. |
Linux Kernel Asynchronous Input/Output Local Denial Of Service
CAN-2005-0916
|
Low |
Secunia Advisory, SA14718,
April 4, 2005 |
Multiple Vendors
RedHat Fedora Core3, Core2;
Rob Flynn Gaim 1.2; Ubuntu Linux 4.1 ppc, ia64, ia32 |
Two vulnerabilities have been reported: a remote Denial of Service vulnerability has been reported due to a buffer overflow in the
'gaim_markup_strip_html()' function; and a vulnerability has been reported in the IRC protocol plug-in due to insufficient sanitization of the 'irc_msg' data, which could let a remote malicious user execute arbitrary code.
Update available at:
http://gaim.sourceforge.net
/downloads.php
Fedora:
http://download.fedora.redhat.com/
pub/fedora/linux/core/updates/
Ubuntu:
http://security.ubuntu.com/
ubuntu/pool/main/g/gaim/
Currently we are not aware of any exploits for these vulnerabilities. |
Gaim 'Gaim_Markup_
Strip_HTML()' Function Remote
Denial of Service & IRC Protocol Plug-in Arbitrary Code Execution
CAN-2005-0965
CAN-2005-0966
|
Low/ High
(High if arbitrary code can be executed)
|
Fedora Update Notifications,
FEDORA-2005
-298 & 299,
April 5, 2005
Ubuntu Security
Notice, USN-106-1
| |
| |