Section: .. / 0606-advisories /
| /// File Name: |
glsa-200606-04.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-04 - Some integer overflows exist when adding elements to the smartlists. Non-printable characters received from the network are not properly sanitised before being logged. There are additional unspecified bugs in the directory server and in the internal circuits. Versions less than 0.1.1.20 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2838 | | Last Modified: | Jun 11 04:23:57 2006 |
| MD5 Checksum: | 894806c78f157fa8fe4724e5d95f2ebc |
|
| /// File Name: |
glsa-200606-05.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-05 - Pound fails to handle HTTP requests with conflicting Content-Length and Transfer-Encoding headers correctly. Versions less than 2.0.5 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2683 | | Last Modified: | Jun 11 04:24:03 2006 |
| MD5 Checksum: | 09eb8d13a1bbb9a20486643f75befc3e |
|
| /// File Name: |
glsa-200606-06.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-06 - Hendrik Weimer has found that if updating the statistics via the web frontend is enabled, it is possible to inject arbitrary code via a pipe character in the migrate parameter. Additionally, r0t has discovered that AWStats fails to properly sanitize user-supplied input in awstats.pl. Versions less than 6.5-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3142 | | Last Modified: | Jun 11 04:24:10 2006 |
| MD5 Checksum: | 205e539642523e01bb222fa57a5db1f9 |
|
| /// File Name: |
glsa-200606-07.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-07 - Roman Veretelnikov discovered that Vixie Cron fails to properly check whether it can drop privileges accordingly if setuid() in do_command.c fails due to a user exceeding assigned resource limits. Versions less than 4.1-r9 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2589 | | Last Modified: | Jun 11 04:23:25 2006 |
| MD5 Checksum: | 90634a07feebd4612158dfe42936f1ba |
|
| /// File Name: |
glsa-200606-08.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-08 - rgod discovered that WordPress insufficiently checks the format of cached username data. Versions less than 2.0.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2579 | | Last Modified: | Jun 11 04:23:31 2006 |
| MD5 Checksum: | e78bc0bd1e3b3d044b7c101dc2e66530 |
|
| /// File Name: |
glsa-200606-09.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-09 - When spamd is run with both the --vpopmail (-v) and --paranoid (-P) options, it is vulnerable to an unspecified issue. Versions less than 3.1.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2903 | | Last Modified: | Jun 14 06:07:33 2006 |
| MD5 Checksum: | ca603ae1be4859dec15806b36a3f5afd |
|
| /// File Name: |
glsa-200606-10.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-10 - Cscope does not verify the length of file names sourced in #include statements. Versions less than 15.5-r6 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2445 | | Last Modified: | Jun 12 10:24:36 2006 |
| MD5 Checksum: | e1488d4a059d73e3b5d1421f5fb00c92 |
|
| /// File Name: |
glsa-200606-11.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-11 - Tavis Ormandy of the Gentoo Linux Auditing Team discovered that the vulnerable JPEG library ebuilds compile JPEG without the --maxmem feature which is not recommended. Versions less than 6b-r7 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2360 | | Last Modified: | Jun 12 10:24:57 2006 |
| MD5 Checksum: | bc247a8a8c2a0953ffe8242a9d03dc09 |
|
| /// File Name: |
glsa-200606-12.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-12 - A number of vulnerabilities were found and fixed in Mozilla Firefox. For details please consult the references below. Versions less than 1.5.0.4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 4489 | | Last Modified: | Jun 12 10:25:15 2006 |
| MD5 Checksum: | 37b9e784bdab30a4220c187e7c70a5cf |
|
| /// File Name: |
glsa-200606-13.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-13 - MySQL is vulnerable to an injection flaw in mysql_real_escape() when used with multi-byte characters. Versions less than 4.1.20 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2854 | | Last Modified: | Jun 12 10:25:31 2006 |
| MD5 Checksum: | 25140000f00620f951d06c0b411bbd79 |
|
| /// File Name: |
glsa-200606-14.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-14 - GDM allows a normal user to access the configuration manager. Versions less than 2.8.0.8 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2910 | | Last Modified: | Jun 14 06:07:26 2006 |
| MD5 Checksum: | 180be18a39301caa519d0541c1b7493c |
|
| /// File Name: |
glsa-200606-15.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-15 - Asterisk fails to properly check the length of truncated video frames in the IAX2 channel driver which results in a buffer overflow. Versions less than 1.0.11_p1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2721 | | Last Modified: | Jun 21 09:55:04 2006 |
| MD5 Checksum: | a776446ad83d2deadfa96ca85e3cbf77 |
|
| /// File Name: |
glsa-200606-16.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-16 - Stefan Esser discovered that the DokuWiki spell checker fails to properly sanitize PHP's complex curly syntax. Versions less than 20060309-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2666 | | Last Modified: | Jun 21 09:55:20 2006 |
| MD5 Checksum: | 1e555e29bb47712aa872808d909dcd32 |
|
| /// File Name: |
glsa-200606-17.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-17 - slurpd contains a buffer overflow when reading very long hostnames from the status file. Versions less than 2.3.22 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2635 | | Last Modified: | Jun 26 06:14:08 2006 |
| MD5 Checksum: | 19d06c4dcafabd19e841345b92629096 |
|
| /// File Name: |
glsa-200606-18.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-18 - A flaw in handling the result of pam_get_item() as well as further unspecified flaws were discovered in PAM-MySQL. Versions less than 0.7_rc1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2619 | | Last Modified: | Jun 26 06:14:27 2006 |
| MD5 Checksum: | e39adb999231e2f3b44d7e2d23acf552 |
|
| /// File Name: |
glsa-200606-19.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-19 - Frank Sheiness discovered that the mime8to7() function can recurse endlessly during the decoding of multipart MIME messages until the stack of the process is filled and the process crashes. Versions less than 8.13.6-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3106 | | Last Modified: | Jun 26 06:14:49 2006 |
| MD5 Checksum: | d5494539ac2527afc3bf1cc2c7633219 |
|
| /// File Name: |
glsa-200606-20.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-20 - Niko Tyni discovered a buffer overflow in the addnewword() function of Typespeed's network code. Versions less than 0.5.0 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2623 | | Last Modified: | Jun 26 08:29:30 2006 |
| MD5 Checksum: | 31766c8d29b392c8887442ca97b2aae1 |
|
| /// File Name: |
glsa-200606-21.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-21 - Several vulnerabilities were found and fixed in Mozilla Thunderbird. For details, please consult the references below. Versions less than 1.5.0.4 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 4205 | | Last Modified: | Jun 27 05:42:34 2006 |
| MD5 Checksum: | 986d8a7013f4e8c27d3b40c08a3c82ab |
|
| /// File Name: |
glsa-200606-22.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-22 - artswrapper fails to properly check whether it can drop privileges accordingly if setuid() fails due to a user exceeding assigned resource limits. Versions less than 3.5.2-r1 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2685 | | Last Modified: | Jun 27 07:24:42 2006 |
| MD5 Checksum: | 1c2d619b57c35bedfa4e8cbc2a3f3ac2 |
|
| /// File Name: |
glsa-200606-23.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-23 - Ludwig Nussel discovered that KDM could be tricked into allowing users to read files that would otherwise not be readable. Versions less than 3.5.2-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 3375 | | Last Modified: | Jun 27 07:26:08 2006 |
| MD5 Checksum: | c265b9e8255d58fcf4ef9fe651b52435 |
|
| /// File Name: |
glsa-200606-24.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-24 - A boundary checking error was found in wv2, which could lead to an integer overflow. Versions less than 0.2.3 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2426 | | Last Modified: | Jun 27 08:11:39 2006 |
| MD5 Checksum: | 2c4bdfda5d18e136afb3a399bb35561d |
|
| /// File Name: |
glsa-200606-25.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-25 - Andreas Seltenreich has reported a possible heap overflow in the array_push() function in hashcash.c, as a result of an incorrect amount of allocated memory for the ARRAY structure. Versions less than 1.21 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2640 | | Last Modified: | Jun 27 09:01:19 2006 |
| MD5 Checksum: | 6d9528896759c6bf21c2b0d01df1c296 |
|
| /// File Name: |
glsa-200606-26.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-26 - A bug in EnergyMech fails to handle empty CTCP NOTICEs correctly, and will cause a crash from a segmentation fault. Versions less than 3.0.2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2410 | | Last Modified: | Jun 27 09:02:12 2006 |
| MD5 Checksum: | 9ce47d476ba6b5c0bb080b1c385edd11 |
|
| /// File Name: |
glsa-200606-27.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-27 - TAKAHASHI Tamotsu has discovered that Mutt contains a boundary error in the browse_get_namespace() function in browse.c, which can be triggered when receiving an overly long namespace from an IMAP server. Versions less than 1.5.11-r2 are affected.
| | Homepage: | http://security.gentoo.org | | File Size: | 2561 | | Last Modified: | Jun 29 05:21:18 2006 |
| MD5 Checksum: | e96b493ff65b46696a2230a05dbc4901 |
|
| /// File Name: |
glsa-200606-28.txt |
Description:
|
Gentoo Linux Security Advisory GLSA 200606-28 - Michael Marek discovered that the Horde Web Application Framework performs insufficient input sanitizing. Versions less than 3.1.1-r1 are affected.
| | Homepage: | http://security.gentoo.org/ | | File Size: | 2591 | | Last Modified: | Jul 2 09:21:43 2006 |
| MD5 Checksum: | 136a990b21ed079ea1a0d1d47561133c |
|
|
|
|
|