|
Vulnerability Report: Mandrake Multi Network Firewall 8.x
|
This vulnerability report for Mandrake Multi Network Firewall 8.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.
If you have information about a new or an existing vulnerability in Mandrake Multi Network Firewall 8.x then you are more than welcome to contact us.
|
|
|
|
|
Vendor, Links, and Unpatched Vulnerabilities
|
|
|
|
77 Secunia Advisories in 2003-2009
|
Secunia has issued a total of 77 Secunia advisories in 2003-2009 for Mandrake Multi Network Firewall 8.x. Currently, 0% (0 out of 77) are marked as unpatched.
More information about the specific Secunia advisories affecting Mandrake Multi Network Firewall 8.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.
|
|
|
|
|
|
Release Date: 2005-07-01 |
Secunia Advisory ID: SA15886 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Privilege escalation DoS
|
Where: From remote |
|
Short Description: Mandriva has issued an update for kernel-2.4. This fixes some vulnerabilities, which can be exploited by malicious, local users to gain knowledge of potentially sensitive information, cause a DoS (Denial of Service), or gain escalated privileges, or by malicious people to cause a DoS. [Read More]
|
|
|
|
|
|
Release Date: 2005-01-26 |
Secunia Advisory ID: SA14002 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Exposure of sensitive information Privilege escalation DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for the kernel. This fixes multiple vulnerabilities, which can be exploited to gain knowledge of sensitive information, cause a DoS (Denial of Service), bypass certain security restrictions, or gain escalated privileges on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2005-01-07 |
Secunia Advisory ID: SA13746 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for libtiff. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-12-30 |
Secunia Advisory ID: SA13690 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for cups. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-12-14 |
Secunia Advisory ID: SA13444 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for iproute2. This fixes a vulnerability, which can be exploited by malicious, local users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-12-07 |
Secunia Advisory ID: SA13387 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for gzip. This fixes some vulnerabilities, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-12-07 |
Secunia Advisory ID: SA13383 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for openssl. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-18 |
Secunia Advisory ID: SA13229 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for apache. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-18 |
Secunia Advisory ID: SA13227 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for sudo. This fixes a vulnerability, which can be exploited by malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-11 |
Secunia Advisory ID: SA13168 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for ez-ipupdate. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-11 |
Secunia Advisory ID: SA13166 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for speedtouch. This fixes a vulnerability, which potentially can be exploited by malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-05 |
Secunia Advisory ID: SA13096 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact:
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for iptables. This fixes a security issue, where iptables under some circumstances fails to load required modules. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-05 |
Secunia Advisory ID: SA13095 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for shadow-utils. This fixes a vulnerability, which can be exploited by malicious, local users to bypass certain security restrictions. [Read More]
|
|
|
|
|
|
Release Date: 2004-11-02 |
Secunia Advisory ID: SA13050 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updates for mod_ssl/apache2-mod_ssl. This fixes a security issue, which can be exploited by malicious people to bypass certain security restrictions. [Read More]
|
|
|
|
|
|
Release Date: 2004-10-22 |
Secunia Advisory ID: SA12927 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From local network |
|
Short Description: MandrakeSoft has issued an update for squid. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-10-22 |
Secunia Advisory ID: SA12924 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for cups. This fixes some vulnerabilities, which potentially can be exploited to compromise a vulnerable system or gain knowledge of sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2004-10-20 |
Secunia Advisory ID: SA12885 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for libtiff. This fixes some vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system or cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-09-01 |
Secunia Advisory ID: SA12412 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for krb5. This fixes multiple vulnerabilities, where the most critical potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-08-27 |
Secunia Advisory ID: SA12391 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information Exposure of sensitive information
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for the kernel. This fixes a vulnerability, which can be exploited by malicious, local users to disclose sensitive information in kernel memory. [Read More]
|
|
|
|
|
|
Release Date: 2004-08-18 |
Secunia Advisory ID: SA12315 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Exposure of system information
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for rsync. This fixes a vulnerability, which potentially can be exploited by malicious users to read or write arbitrary files on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-08-10 |
Secunia Advisory ID: SA12252 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for shorewall. This fixes a vulnerability, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-08-05 |
Secunia Advisory ID: SA12220 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for libpng. This fixes multiple vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-07-28 |
Secunia Advisory ID: SA12172 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for mod_ssl. This fixes a vulnerability, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-07-23 |
Secunia Advisory ID: SA12141 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From local network |
|
Short Description: MandrakeSoft has issued an update for samba. This fixes two vulnerabilities, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-07-15 |
Secunia Advisory ID: SA12070 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access Security Bypass
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for php. This fixes two vulnerabilities, which can be exploited by malicious people to bypass certain security functionality or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-07-15 |
Secunia Advisory ID: SA12069 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updates for freeswan and super-freeswan. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or bypass certain security restrictions. [Read More]
|
|
|
|
|
|
Release Date: 2004-07-07 |
Secunia Advisory ID: SA12025 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Manipulation of data Exposure of system information Exposure of sensitive information Privilege escalation
|
Where: From local network |
|
Short Description: MandrakeSoft has issued an update for the kernel. This fixes multiple vulnerabilities, which can be exploited by malicious users to bypass certain security restrictions, gain knowledge of sensitive information or escalate privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-06-24 |
Secunia Advisory ID: SA11932 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for the kernel. This fixes two vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or gain knowledge of sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2004-06-04 |
Secunia Advisory ID: SA11765 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for krb5. This fixes some vulnerabilities, which can be exploited by malicious users to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-06-02 |
Secunia Advisory ID: SA11749 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for mod_ssl. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-05-18 |
Secunia Advisory ID: SA11630 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Spoofing Manipulation of data DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for apache. These fix various vulnerabilities, which can be exploited to inject potentially malicious characters into error logfiles, bypass certain restrictions, gain unauthorised access, or cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-05-11 |
Secunia Advisory ID: SA11583 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Manipulation of data
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for rsync. These fix a vulnerability, potentially allowing malicious people to write files outside the intended directory. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-28 |
Secunia Advisory ID: SA11491 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Exposure of system information Exposure of sensitive information Privilege escalation DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix some vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges, gain knowledge of sensitive information, or cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-04-20 |
Secunia Advisory ID: SA11425 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for utempter. These fix a security issue, which potentially can be exploited by malicious, local users to perform certain actions with higher privileges on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-20 |
Secunia Advisory ID: SA11418 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for Samba. These fix a vulnerability, which can be exploited by malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-15 |
Secunia Advisory ID: SA11376 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Privilege escalation DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix some vulnerabilities, which can be exploited by malicious, local users to escalate their privileges, cause a Denial of Service, and see sensitive information. [Read More]
|
|
|
|
|
|
Release Date: 2004-04-15 |
Secunia Advisory ID: SA11385 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updated packages for tcpdump. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-03-18 |
Secunia Advisory ID: SA11149 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for OpenSSL. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial-of-Service). [Read More]
|
|
|
|
|
|
Release Date: 2004-02-25 |
Secunia Advisory ID: SA10971 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Privilege escalation DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix various vulnerabilities, which can be exploited by malicious, local users to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2004-02-12 |
Secunia Advisory ID: SA10860 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued an update for netpbm. This fixes a vulnerability, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-02-05 |
Secunia Advisory ID: SA10792 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has released an updated package for glibc. This fixes an old vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-01-27 |
Secunia Advisory ID: SA10718 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for tcpdump. These fix multiple vulnerabilities, which can be exploited by malicious people to crash tcpdump and potentially compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2004-01-09 |
Secunia Advisory ID: SA10582 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix two vulnerabilities, which may disclose sensitive information to malicious, local users or allow them to gain escalated privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-12-09 |
Secunia Advisory ID: SA10387 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for screen. These fix a vulnerability, which potentially may allow users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-12-05 |
Secunia Advisory ID: SA10364 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for rsync. These fix a vulnerability, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-12-02 |
Secunia Advisory ID: SA10330 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix a vulnerability, which can be exploited by malicious users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-12-01 |
Secunia Advisory ID: SA10316 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Spoofing Exposure of sensitive information
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for gnupg. These fix a vulnerability, which expose the private key when using El-Gamal type 20 keys. [Read More]
|
|
|
|
|
|
Release Date: 2003-11-19 |
Secunia Advisory ID: SA10255 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for glibc. These fix a bug which could lead to local Denial of Service against certain applications [Read More]
|
|
|
|
|
|
Release Date: 2003-11-13 |
Secunia Advisory ID: SA10211 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for fileutils/coreutils. These fix two vulnerabilities in the "ls" program, which can be exploited by malicious users to cause a DoS (Denial of Service). [Read More]
|
|
|
|
|
|
Release Date: 2003-11-04 |
Secunia Advisory ID: SA10129 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation DoS
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for apache. These fix some vulnerabilities, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or escalate privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-10-01 |
Secunia Advisory ID: SA9893 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for OpenSSL. These fix some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-09-17 |
Secunia Advisory ID: SA9751 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: Mandrake has issued updated packages for ssh. These fix a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-08-04 |
Secunia Advisory ID: SA9435 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS Exposure of system information
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for Postfix. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system or use it to conduct bounce scans and Distributed DoS attacks against other systems. [Read More]
|
|
|
|
|
|
Release Date: 2003-08-04 |
Secunia Advisory ID: SA9430 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Cross Site Scripting System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for PHP. These fix a vulnerability, which can be exploited by a malicious person to conduct Cross-Site Scripting attacks against other people. [Read More]
|
|
|
|
|
|
Release Date: 2003-07-16 |
Secunia Advisory ID: SA9280 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Privilege escalation DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for the kernel. These fix multiple vulnerabilities, which are listed below. [Read More]
|
|
|
|
|
|
Release Date: 2003-07-08 |
Secunia Advisory ID: SA9202 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for unzip. These fix a vulnerability, which potentially can be exploited by malicious people to compromise a user's system by overwriting arbitrary files on it. [Read More]
|
|
|
|
|
|
Release Date: 2003-06-17 |
Secunia Advisory ID: SA9047 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has issued updated packages for gzip. These fix two vulnerabilities, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-06-03 |
Secunia Advisory ID: SA8936 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Three vulnerabilities have been identified in the Linux Kernel 2.4 branch. One can be exploited to cause a Denial of Service by a malicious person and is very similar to the recent Linux Kernel Denial of Service. The others are local Denial of Service vulnerabilities. [Read More]
|
|
|
|
|
|
Release Date: 2003-05-30 |
Secunia Advisory ID: SA8896 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From local network |
|
Short Description: Mandrake has issued updated packages for CUPS. These fix a vulnerability, which can be exploited by a malicious user to cause a DoS (Denial of Service) on a print server. [Read More]
|
|
|
|
|
|
Release Date: 2003-05-15 |
Secunia Advisory ID: SA8783 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updated packages for xinetd. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-05-07 |
Secunia Advisory ID: SA8736 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for mgetty. These fix two vulnerabilities, which can be exploited to compromise a vulnerable system or escalate privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-29 |
Secunia Advisory ID: SA8681 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued updated packages for Snort. These fix a vulnerability, which can be exploited by malicious people to compromise a system running Snort. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-16 |
Secunia Advisory ID: SA8605 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: A vulnerability was reported in Snort, which could be exploited by a malicious person to execute arbitrary code on the system running Snort. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-08 |
Secunia Advisory ID: SA8536 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From local network |
|
Short Description: MandrakeSoft has issued updated packages for samba. These fix some unspecified potential buffer overflow vulnerabilities as well as a vulnerability, which can be exploited by anonymous users to gain root privileges on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-01 |
Secunia Advisory ID: SA8483 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass Spoofing Exposure of system information DoS System access
|
Where: From remote |
|
Short Description: Mandrake has released updated packages for Kerberos. These fix several vulnerabilities, which can be exploited to disclose information, cause a Denial of Service or compromise a system. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-28 |
Secunia Advisory ID: SA8438 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: [Read More]
|
|
|
|
|
|
Release Date: 2003-03-26 |
Secunia Advisory ID: SA8413 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has released updated packages for netpbm. These fix multiple boundary errors, which theoretically could be exploited to compromise a user's system. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-26 |
Secunia Advisory ID: SA8410 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updates to RPC XDR. A vulnerability has been discovered allowing malicious users to cause an integer overflow, this could lead to a Denial of Service and possibly also execution of arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-26 |
Secunia Advisory ID: SA8409 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information
|
Where: From remote |
|
Short Description: Mandrake has issued updates to openssl. Two vulnerabilities has been discovered, one allowing malicious people to extract the premaster-secret, the other allowed malicious people to extract the RSA secret. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-13 |
Secunia Advisory ID: SA8278 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: Mandrake has issued updates for usermode. The problem is that any user is allowed to execute the /usr/bin/shutdown command, which can be used to close all services and enter a root shell. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-07 |
Secunia Advisory ID: SA8237 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has released an update for snort. This fixes a vulnerability, which can be exploited by a malicious person to compromise a system running snort. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-04 |
Secunia Advisory ID: SA8201 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updates for tcpdump to fix a Denial of Service vulnerability in the handling of ISAKMP packets. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-27 |
Secunia Advisory ID: SA8162 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: Local system |
|
Short Description: Mandrake has issued updates to shadow-utils, due to a bug that creates mailbox files with insecure permissions. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-25 |
Secunia Advisory ID: SA8138 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Manipulation of data
|
Where: Local system |
|
Short Description: Mandrake has issued updated packages to fix a vulnerability in lynx. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-24 |
Secunia Advisory ID: SA8114 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to kerberos to fix a vulnerability in the ftp client. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-22 |
Secunia Advisory ID: SA8112 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: From remote |
|
Short Description: MandrakeSoft has released updated packages for openssl. These eliminate an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of a used plaintext block in a SSL/TLS session. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-21 |
Secunia Advisory ID: SA7911 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for libpng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|