Debian Essential And Critical Security Patch Updates - Page 279
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
Steve Kemp discovered a buffer overflow in zblast-svgalib, when savingthe high score file.
A cross-site scripting vulnerability exists in the start_form()function in CGI.pm.
Steve Kemp discovered a buffer overflow in xpcd-svga which can betriggered by a long HOME environment variable. This vulnerabilitycould be exploited by a local attacker to gain root privileges.
The previous man-db update (DSA-364-1) introduced an error whichresulted in a segmentation fault in the "mandb" command, which runspart of the daily cron job. This error was caused by allocating amemory region which was one byte too small to hold the data writteninto it.
Another buffer overflow was discovered in xtokkaetama, involving the"-nickname" command line option. This vulnerability could beexploited by a local attacker to gain gid 'games'.
eroaster does nottake appropriate security precautions when creating a temporary filefor use as a lockfile.
Several vulnerabilities have been discovered in phpgroupware.
This advisory provides a correction to the previous kernel updates,which contained an error introduced in kernel-source-2.4.18 version2.4.18-7.
This advisory provides a correction to the previous kernel updates,which contained an error introduced in kernel-source-2.4.18 version2.4.18-7. This error could result in a kernel "oops" under certaincircumstances.
There are multiple vulnerabilities in suid install of man-db.
mindi, a program for creating boot/root disks, does not takeappropriate security precautions when creating temporary files.
Potential unauthorized access and man-in-the-middle attacks have been fixed.
A number of vulnerabilities have been discovered in the Linux kernel.
Steve Kemp discovered multiple buffer overflows in atari800, an Atariemulator.
iSEC Security Research reports that wu-ftpd contains an off-by-one bugin the fb_realpath function which could be exploited by a logged-in user(local or anonymous) to gain root privileges.
Larry Nguyen discovered a cross site scripting vulnerability in gallery,a web-based photo album written in php.
Steve Kemp discovered two buffer overflows in xtokkaetama, a puzzlegame, when processing the -display command line option and theXTOKKAETAMADIR environment variable.