Mourning the loss of our friend, WhitPhil.
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
 
Linux and Unix
Tag Cloud
access audio blue screen boot bsod connection crash dell desktop driver drivers dvd email error excel firefox hard drive hardware hijackthis internet keyboard laptop malware monitor motherboard network networking outlook problem processor ram recovery router screen slow sound spyware tdlwsp.dll trojan upgrade vba video virus vista vundo windows windows 7 windows vista windows xp wireless
Search
Search for:
Tech Support Guy Forums > Operating Systems > Linux and Unix >
Linux vulnerabilities: Oct 19

Tip: Click here to scan for System Errors and Optimize PC performance
[ Sponsored Link ]

Closed Thread
 
Thread Tools
eddie5659's Avatar
Computer Specs
Moderator with 20,367 posts.
 
Join Date: Mar 2001
Location: Bradford, England
19-Oct-2001, 08:03 PM #1
Wink Linux vulnerabilities: Oct 19
Hiya

There are some potential vulnerabilities in the most recent xinetd
package for EnGarde Secure Linux 1.0.1

Solar Designer did an audit of xinetd 2.3.0 and came up with a list
of potential vulnerabilities. This release fixes all known
vulnerabilities as a precautionary measure. Most of these fixes are
in the interest of robustness and are not known to be exploitable at
this time.

For more information on the results of this audit please refer to
the AUDIT file in the xinetd-2.3.3.tar.gz tarball (included with
the source package).

http://www.linuxsecurity.com/advisor...sory-1651.html

There are two vulnerabilities in the kernel which can allow a local
attacker to either obtain root privileges or lock the machine up for
an arbitrary amount of time

There is another local root exploit using the kernel's ptrace
capabilities.

2) The kernel can be forced to remain in path_walk() while
traversing a very deep tree of symbolic links for an arbitrary
amount of time, resulting in a local DoS attack

http://www.linuxsecurity.com/advisor...sory-1650.html

Yet another ptrace race condition has been found which allows local
attackers to get access to the root account

OpenLinux 2.3 All packages previous to
linux-2.2.10-13

OpenLinux eServer 2.3.1 All packages previous to
and OpenLinux eBuilder linux-2.2.14-12S

OpenLinux eDesktop 2.4 All packages previous to
linux-2.2.14-8
OpenLinux Server 3.1 All packages previous to
linux-2.4.2-13S

OpenLinux Workstation 3.1 All packages previous to
linux-2.4.2-13D

http://www.linuxsecurity.com/advisor...sory-1652.html

As reported on Bugtraq, there is a local root exploit in the Linux
kernel involving the ptrace call. In addition, it is possible to create
a Denial of Service attack in the kernel by creating a number of symlinks

http://www.linuxsecurity.com/advisor...sory-1653.html

This release fixes several issues; two of moderate severity, and one
of slight severity. First, Peter W found that command restrictions
placed on keys did not apply to subsystems such as sftp, essentially
allowing users to bypass the command restrictions placed upon the key.
Second, the OpenSSH team found that IP source restrictions could be
bypassed when the authorized_keys file contained both RSA and DSA
keys. Last, zen-parse found that any file named 'cookies' could be
deleted remotely.


http://www.linuxsecurity.com/advisor...sory-1654.html

A vulnerability has been found in the ptrace code of the kernel (ptrace is
the part that allows program debuggers to run) that could be abused by
local users to gain root privileges

http://www.linuxsecurity.com/advisor...sory-1655.html

Stephane Gaudreault told us that version 2.0.6a of gftp displays the
password in plain text on the screen within the log window when it is
logging into an ftp server. A malicious collegue who is watching the
screen could gain access to the users shell on the remote machine

http://www.linuxsecurity.com/advisor...sory-1656.html

Regards

eddie
__________________
Just go with the flow, like a twig on the shoulders of a mighty stream

Weekends I may be busy, so there may be a delay in replies.
Closed Thread Bookmark and Share

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Smart Search

Find your solution!



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.

Thread Tools


You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -5. The time now is 02:46 AM.
Copyright © 1996 - 2009 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2009, Jelsoft Enterprises Ltd.
Powered by Cermak Technologies, Inc.