Debian Essential And Critical Security Patch Updates - Page 282

Find the information you need for your favorite open source distribution .

Debian: 'ethereal' buffer/integer overflows

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

Timo Sirainen discovered several vulnerabilities in ethereal, a network traffic analyzer. These include one-byte buffer overflows in the AIM, GIOP Gryphon, OSPF, PPTP, Quake, Quake2, Quake3, Rsync, SMB, SMPP, and TSP dissectors, and integer overflows in the Mount and PPP dissectors.

Debian: xaos Improper setuid-root execution

data:image/svg+xml,%3Csvg%20xmlns=%22http://www.w3.org/2000/svg%22%20viewBox=%220%200%20100%20100%22%3E%3C/svg%3E

XaoS, a program for displaying fractal images, is installed setuidroot on certain architectures in order to use svgalib, which requiresaccess to the video hardware. However, it is not designed for securesetuid execution, and can be exploited to gain root privileges.