Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Linux and Unix
Tag Cloud
access audio black screen blue screen boot bsod connection crash dell desktop driver drivers dvd email error excel firefox hard drive hardware hijackthis internet keyboard laptop malware monitor network networking outlook problem processor recovery registry cleaner router safe mode slow sound spyware tdlwsp.dll trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Linux Security Updates: Feb

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator with 20,375 posts.
 
Join Date: Mar 2001
Location: Bradford, England
26-Feb-2004, 05:18 PM #1
Exclamation Linux Security Updates: Feb
Hiya

Thought I'd start these again. Just a few for now, but March will be the real start

mtools mformat utility creates files with insecure permissions

Description:

mtools is a freely available set of utilities that allows users to access MS-DOS files for Unix and Linux-based platforms. The mformat utility in mtools versions prior to 3.9.9 creates any file with Read/Execute permissions, if the utility is installed suid root. A local attacker could use this vulnerability to view files and obtain sensitive information.

Platforms Affected:

David Niemi and Alain Knaff mtools prior to 3.9.9
MandrakeSoft, Inc. Mandrake Linux 9.2
Remedy:

Upgrade to the latest version of mtools (3.9.9 or later), available from the mtools Web site. See References.

For Mandrake Linux 9.2:
Upgrade to the latest mtools package (3.9.9-2.1.92mdk or later), as listed in MandrakeSoft Security Advisory MDKSA-2004:016 : mtools. See References.

For other distributions:
Contact your vendor for upgrade or patch information.

Consequences:

Obtain Information

http://www.mandrakesecure.net/en/adv...MDKSA-2004:016

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Weekends I may be busy, so there may be a delay in replies.
eddie5659's Avatar
Computer Specs
Moderator with 20,375 posts.
 
Join Date: Mar 2001
Location: Bradford, England
28-Feb-2004, 01:11 PM #2
Hiya

Calife long password buffer overflow

Calife is freely available program that allows certain users, usually system administrators, to obtain super user privileges for Linux-based operating systems. Calife versions 2.8.4 and 2.8.5 are vulnerable to a buffer overflow, caused by improper bounds checking. By supplying a long password, a local attacker could overflow a buffer and cause a segmentation fault or possibly execute arbitrary code on the system.

Platforms Affected:

Calife Calife 2.8.4
Calife Calife 2.8.5
kernel.org Linux Any version
Remedy:

Upgrade to the latest version of Calife (2.8.6 or later), when it becomes available from the Calife Web page. See References.

Consequences:

Gain Privileges

http://xforce.iss.net/xforce/xfdb/15335

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Weekends I may be busy, so there may be a delay in replies.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 10:47 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.