There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Tag Cloud
access acer asus bios bsod computer crash driver drivers error ethernet excel freeze gaming google gpu hard drive hardware hdmi internet laptop malware memory missing monitor motherboard network operating system printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Linux vulnerabilities: Oct 19

Reply  
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator & Malware Removal Specialist with 25,163 posts.
 
Join Date: Mar 2001
Location: Bradford, England
19-Oct-2001, 09:03 PM #1
Wink Linux vulnerabilities: Oct 19
Hiya

There are some potential vulnerabilities in the most recent xinetd
package for EnGarde Secure Linux 1.0.1

Solar Designer did an audit of xinetd 2.3.0 and came up with a list
of potential vulnerabilities. This release fixes all known
vulnerabilities as a precautionary measure. Most of these fixes are
in the interest of robustness and are not known to be exploitable at
this time.

For more information on the results of this audit please refer to
the AUDIT file in the xinetd-2.3.3.tar.gz tarball (included with
the source package).

http://www.linuxsecurity.com/advisor...sory-1651.html

There are two vulnerabilities in the kernel which can allow a local
attacker to either obtain root privileges or lock the machine up for
an arbitrary amount of time

There is another local root exploit using the kernel's ptrace
capabilities.

2) The kernel can be forced to remain in path_walk() while
traversing a very deep tree of symbolic links for an arbitrary
amount of time, resulting in a local DoS attack

http://www.linuxsecurity.com/advisor...sory-1650.html

Yet another ptrace race condition has been found which allows local
attackers to get access to the root account

OpenLinux 2.3 All packages previous to
linux-2.2.10-13

OpenLinux eServer 2.3.1 All packages previous to
and OpenLinux eBuilder linux-2.2.14-12S

OpenLinux eDesktop 2.4 All packages previous to
linux-2.2.14-8
OpenLinux Server 3.1 All packages previous to
linux-2.4.2-13S

OpenLinux Workstation 3.1 All packages previous to
linux-2.4.2-13D

http://www.linuxsecurity.com/advisor...sory-1652.html

As reported on Bugtraq, there is a local root exploit in the Linux
kernel involving the ptrace call. In addition, it is possible to create
a Denial of Service attack in the kernel by creating a number of symlinks

http://www.linuxsecurity.com/advisor...sory-1653.html

This release fixes several issues; two of moderate severity, and one
of slight severity. First, Peter W found that command restrictions
placed on keys did not apply to subsystems such as sftp, essentially
allowing users to bypass the command restrictions placed upon the key.
Second, the OpenSSH team found that IP source restrictions could be
bypassed when the authorized_keys file contained both RSA and DSA
keys. Last, zen-parse found that any file named 'cookies' could be
deleted remotely.


http://www.linuxsecurity.com/advisor...sory-1654.html

A vulnerability has been found in the ptrace code of the kernel (ptrace is
the part that allows program debuggers to run) that could be abused by
local users to gain root privileges

http://www.linuxsecurity.com/advisor...sory-1655.html

Stephane Gaudreault told us that version 2.0.6a of gftp displays the
password in plain text on the screen within the log window when it is
logging into an ftp server. A malicious collegue who is watching the
screen could gain access to the users shell on the remote machine

http://www.linuxsecurity.com/advisor...sory-1656.html

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Proud Member of ASAP, Alliance of Security Analysis Professionals
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:06 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.