The vulnerabilities have also been fixed in version 2.4.30-rc2.
Provided and/or discovered by: 1) Michal Zalewski
2) Ilja van Sprundel
3) Mathieu Lafon and Romain Francoise, Arkoon Network Security.
4) Yichen Xie
5) Patrick McHardy
Changelog: 2005-04-04: Added additional information about third vulnerability.
2005-04-06: Added link to US-CERT vulnerability note.
2005-04-14: Added information about fifth vulnerability.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.