Gentoo Essential and Critical Security Patch Updates - Page 158
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
LutelWall is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.
gedit suffers from a format string vulnerability that could allow arbitrary code execution.
GNU shtool and ocaml-mysql are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files.
A format string vulnerability in Ettercap could allow a remote attacker to execute arbitrary code.
libextractor is affected by several overflow vulnerabilities in the PDF, Real and PNG extractors, making it vulnerable to execution of arbitrary code. [More...]
Executable files with insecure permissions can be modified causing an unsuspecting user to run arbitrary code.
Wordpress contains SQL injection and XSS vulnerabilities.
Dzip is vulnerable to a directory traversal attack.
GNU Mailutils is vulnerable to SQL command injection attacks.
Various utilities from the GNU Binutils and elfutils packages are vulnerable to a heap based buffer overflow, potentially resulting in the execution of arbitrary code. [More...]
The imap4d server and the mail utility from GNU Mailutils contain multiple vulnerabilities, potentially allowing a remote attacker to execute arbitrary code with root privileges. [More...]
A format string vulnerability in gxine could allow a remote attacker to execute arbitrary code.
Net-SNMP creates temporary files in an insecure manner, possibly allowing the execution of arbitrary code.
Qpopper contains two vulnerabilities allowing an attacker to overwrite arbitrary files and create files with insecure permissions.
ImageMagick and GraphicsMagick utilities can be abused to perform a Denial of Service attack.
Multiple vulnerabilities have been discovered in the GNU debugger, potentially allowing the execution of arbitrary code.
This advisory incorrectly described FreeRADIUS versions as being vulnerable to a remote compromise. After further verifications, it appears to only result in potential Denial of Service. The SQL injection issue is not affected by this. Many thanks to Nicolas Baradakis for [More...] [More...]
Cheetah contains a vulnerability in the module importing code that can allow a local user to gain escalated privileges.
The FreeRADIUS server is vulnerable to a buffer overflow and an SQL injection attack, possibly allowing the compromise of the system.
PostgreSQL is vulnerable to Denial of Service attacks and possibly allows unprivileged users to gain administrator rights.