Gentoo Essential and Critical Security Patch Updates - Page 168
Find the information you need for your favorite open source distribution .
Find the information you need for your favorite open source distribution .
unarj contains a buffer overflow and a directory traversal vulnerability. This could lead to overwriting of arbitrary files or the execution of arbitrary code. [More...]
libXpm contains several vulnerabilities that could lead to a Denial of Service and arbitrary code execution.
Multiple vulnerabilities in Fcron can allow a local user to potentially cause a Denial of Service.
Improper file ownership allows user-owned files to be run with root privileges by init scripts.
Squirrelmail fails to properly sanitize user input, which could lead to a compromise of webmail accounts.
BNC contains a buffer overflow vulnerability that may lead to Denial of Service and execution of arbitrary code.
The CGI module in Ruby can be sent into an infinite loop, resulting in a Denial of Service condition.
Davfs2 and the lvmcreate_initrd script (included in the lvm-user package) are both vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running them. [More...]
An input validation flaw in Samba may allow a remote attacker to cause a Denial of Service by excessive consumption of CPU cycles.
ez-ipupdate contains a format string vulnerability that could lead to execution of arbitrary code.
Pavuk contains multiple buffer overflows that can allow a remote attacker to run arbitrary code.
A flaw in Apache 2.0 could allow a remote attacker to cause a Denial of Service.
mtink is vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the utility. [More...]
zip contains a buffer overflow when creating a ZIP archive of files with very long path names. This could lead to the execution of arbitrary code. [More...]
groffer, included in the Groff package, and the der_chop script, included in the OpenSSL package, are both vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the utility. [More...]
dispatch-conf (included in Portage) and qpkg (included in Gentoolkit) are vulnerable to symlink attacks, potentially allowing a local user to overwrite arbitrary files with the rights of the user running the script. [More...]
Kaffeine and gxine both contain a buffer overflow that can be exploited when accessing content from a malicious HTTP server with specially crafted headers. [More...]
zgv contains multiple buffer overflows that can potentially lead to the execution of arbitrary code.
ImageMagick contains an error in boundary checks when handling EXIF information, which could lead to arbitrary code execution.
Gallery is vulnerable to cross-site scripting attacks.