Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Mandrake Linux 8.x
This vulnerability report for Mandrake Linux 8.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Mandrake Linux 8.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Mandriva

Product Link View Here (Link to external site)

Affected By 105 Secunia advisories
0 Vulnerabilities

Monitor Product Receive alerts for this product





105 Secunia Advisories in 2003-2009
Secunia has issued a total of 105 Secunia advisories in 2003-2009 for Mandrake Linux 8.x. Currently, 1% (1 out of 105) are marked as unpatched with the most severe being rated Not critical

More information about the specific Secunia advisories affecting Mandrake Linux 8.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



Mandrake update for tcpdump
Vendor Patch. Secunia Advisory 1 of 1 in 2004. 5,497 views.
Release Date:
2004-04-15
Secunia Advisory ID:
SA11385
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updated packages for tcpdump. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service). [Read More]


Mandrake update for OpenSSL
Vendor Patch. Secunia Advisory 1 of 76 in 2003. 6,786 views.
Release Date:
2003-10-01
Secunia Advisory ID:
SA9893
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for OpenSSL. These fix some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system. [Read More]


Mandrake update for MySQL
Vendor Patch. Secunia Advisory 2 of 76 in 2003. 7,230 views.
Release Date:
2003-09-19
Secunia Advisory ID:
SA9783
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for MySQL. These fix a vulnerability, which can be exploited by malicious users to escalate their privileges on a vulnerable system. [Read More]


Mandrake update for sendmail
Vendor Patch. Secunia Advisory 3 of 76 in 2003. 7,116 views.
Release Date:
2003-09-18
Secunia Advisory ID:
SA9765
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for sendmail. These fixes two vulnerabilities which possibly could allow malicious people to gain system access. [Read More]


Mandrake update for OpenSSH
Vendor Patch. Secunia Advisory 4 of 76 in 2003. 7,956 views.
Release Date:
2003-09-17
Secunia Advisory ID:
SA9751
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for ssh. These fix a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service) or compromise a vulnerable system. [Read More]


Mandrake update for sendmail
Vendor Patch. Secunia Advisory 5 of 76 in 2003. 7,524 views.
Release Date:
2003-08-26
Secunia Advisory ID:
SA9603
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for Sendmail. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system or potentially compromise it. [Read More]


Mandrake update for Postfix
Vendor Patch. Secunia Advisory 6 of 76 in 2003. 6,976 views.
Release Date:
2003-08-04
Secunia Advisory ID:
SA9435
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Exposure of system information
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for Postfix. These fix two vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system or use it to conduct bounce scans and Distributed DoS attacks against other systems. [Read More]


Mandrake update for PHP
Vendor Patch. Secunia Advisory 7 of 76 in 2003. 8,020 views.
Release Date:
2003-08-04
Secunia Advisory ID:
SA9430
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for PHP. These fix a vulnerability, which can be exploited by a malicious person to conduct Cross-Site Scripting attacks against other people. [Read More]


Mandrake update for WU-FTPD
Vendor Patch. Secunia Advisory 8 of 76 in 2003. 6,916 views.
Release Date:
2003-08-01
Secunia Advisory ID:
SA9409
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for WU-FTPD. These fix a vulnerability, which can be exploited by malicious users to compromise a vulnerable system. [Read More]


Mandrake update for phpgroupware
Vendor Patch. Secunia Advisory 9 of 76 in 2003. 6,508 views.
Release Date:
2003-07-24
Secunia Advisory ID:
SA9342
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for phpgroupware. These fix a vulnerability, which can be exploited to execute arbitrary code on the web server. [Read More]


Mandrake update for nfs-utils
Vendor Patch. Secunia Advisory 10 of 76 in 2003. 7,068 views.
Release Date:
2003-07-22
Secunia Advisory ID:
SA9317
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Where:
From local network
Short Description:
Mandrake has issued updated packages for nfs-utils. These fix a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Linux Kernel 2.4 Multiple Vulnerabilities
Vendor Patch. Secunia Advisory 11 of 76 in 2003. 18,768 views.
Release Date:
2003-07-22
Secunia Advisory ID:
SA9316
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
DoS
Where:
From remote
Short Description:
Multiple vulnerabilities has been identified in the Linux Kernel. [Read More]


Mandrake update for kernel
Vendor Patch. Secunia Advisory 12 of 76 in 2003. 7,459 views.
Release Date:
2003-07-16
Secunia Advisory ID:
SA9280
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for the kernel. These fix multiple vulnerabilities, which are listed below. [Read More]


nfs-utils "xlog()" Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 13 of 76 in 2003. 14,420 views.
Release Date:
2003-07-14
Secunia Advisory ID:
SA9259
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been reported in nfs-utils, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mandrake update for unzip
Vendor Patch. Secunia Advisory 14 of 76 in 2003. 7,798 views.
Release Date:
2003-07-08
Secunia Advisory ID:
SA9202
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for unzip. These fix a vulnerability, which potentially can be exploited by malicious people to compromise a user's system by overwriting arbitrary files on it. [Read More]


Linux Kernel 2.4 execve() Vulnerability
Unpatched. Secunia Advisory 15 of 76 in 2003. 12,148 views.
Release Date:
2003-07-01
Secunia Advisory ID:
SA9154
Solution Status:
Unpatched
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
A vulnerability has been identified in the 2.4 version of the Linux kernel, which potentially can be exploited by malicious, local users to gain knowledge of sensitive information. [Read More]


Mandrake update for ypserv
Vendor Patch. Secunia Advisory 16 of 76 in 2003. 6,301 views.
Release Date:
2003-06-30
Secunia Advisory ID:
SA9142
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
MandrakeSoft has issued updated packages for ypserv. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable NIS server. [Read More]


Linux-PAM User Name Spoofing Vulnerability
Vendor Patch. Secunia Advisory 17 of 76 in 2003. 14,549 views.
Release Date:
2003-06-17
Secunia Advisory ID:
SA9057
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been identified in Linux-PAM, which allows malicious, local users to escalate their privileges. [Read More]


Mandrake update for gzip
Vendor Patch. Secunia Advisory 18 of 76 in 2003. 7,831 views.
Release Date:
2003-06-17
Secunia Advisory ID:
SA9047
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for gzip. These fix two vulnerabilities, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. [Read More]


Mandrake update for Ghostscript
Vendor Patch. Secunia Advisory 19 of 76 in 2003. 6,701 views.
Release Date:
2003-06-11
Secunia Advisory ID:
SA8993
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for ghostscript. These fix a vulnerability, which potentially could allow malicious people to compromise a user's system. [Read More]


Mandrake update for kon2
Vendor Patch. Secunia Advisory 20 of 76 in 2003. 6,153 views.
Release Date:
2003-06-06
Secunia Advisory ID:
SA8953
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updated packages for kon2. These fix a vulnerability, which can be exploited by malicious, local users to escalate their privileges on a vulnerable system. [Read More]


Linux Kernel Denial of Service Vulnerabilities
Vendor Patch. Secunia Advisory 21 of 76 in 2003. 14,027 views.
Release Date:
2003-06-03
Secunia Advisory ID:
SA8936
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Three vulnerabilities have been identified in the Linux Kernel 2.4 branch. One can be exploited to cause a Denial of Service by a malicious person and is very similar to the recent Linux Kernel Denial of Service. The others are local Denial of Service vulnerabilities. [Read More]


Mandrake update for CUPS
Vendor Patch. Secunia Advisory 22 of 76 in 2003. 6,533 views.
Release Date:
2003-05-30
Secunia Advisory ID:
SA8896
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Mandrake has issued updated packages for CUPS. These fix a vulnerability, which can be exploited by a malicious user to cause a DoS (Denial of Service) on a print server. [Read More]


Mandrake update for LPRng
Vendor Patch. Secunia Advisory 23 of 76 in 2003. 6,924 views.
Release Date:
2003-05-22
Secunia Advisory ID:
SA8837
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for LPRng. These fix a vulnerability in "psbanner", which can be exploited by malicious, local users to overwrite certain files on a vulnerable system. [Read More]


Mandrake update for lpr
Vendor Patch. Secunia Advisory 24 of 76 in 2003. 6,947 views.
Release Date:
2003-05-22
Secunia Advisory ID:
SA8839
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for lpr. These fix a vulnerability, which can be exploited by malicious, local users to escalate their privileges to root on a vulnerable system. [Read More]


Mandrake update for cdrecord
Vendor Patch. Secunia Advisory 25 of 76 in 2003. 6,729 views.
Release Date:
2003-05-16
Secunia Advisory ID:
SA8793
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for cdrecord. These fix three vulnerabilities allowing malicious, local users to gain root privileges. [Read More]


Mandrake update for xinetd
Vendor Patch. Secunia Advisory 26 of 76 in 2003. 7,616 views.
Release Date:
2003-05-15
Secunia Advisory ID:
SA8783
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updated packages for xinetd. These fix a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]


Mandrake update for mgetty
Vendor Patch. Secunia Advisory 27 of 76 in 2003. 5,643 views.
Release Date:
2003-05-07
Secunia Advisory ID:
SA8736
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for mgetty. These fix two vulnerabilities, which can be exploited to compromise a vulnerable system or escalate privileges. [Read More]


Mandrake update for Snort
Vendor Patch. Secunia Advisory 28 of 76 in 2003. 7,343 views.
Release Date:
2003-04-29
Secunia Advisory ID:
SA8681
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued updated packages for Snort. These fix a vulnerability, which can be exploited by malicious people to compromise a system running Snort. [Read More]


Xinetd Connection Reject Memory Leak
Vendor Patch. Secunia Advisory 29 of 76 in 2003. 11,261 views.
Release Date:
2003-04-22
Secunia Advisory ID:
SA8632
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been identified in Xinetd, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]


Snort TCP reassembly heap overflow
Vendor Patch. Secunia Advisory 30 of 76 in 2003. 10,954 views.
Release Date:
2003-04-16
Secunia Advisory ID:
SA8605
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
A vulnerability was reported in Snort, which could be exploited by a malicious person to execute arbitrary code on the system running Snort. [Read More]


Mandrake update for xfsdump
Vendor Patch. Secunia Advisory 31 of 76 in 2003. 5,794 views.
Release Date:
2003-04-16
Secunia Advisory ID:
SA8608
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has issued updated packages for xfsdump. These fix a vulnerability allowing local users to escalate their privileges on a vulnerable system. [Read More]


Mandrake update for samba
Vendor Patch. Secunia Advisory 32 of 76 in 2003. 6,294 views.
Release Date:
2003-04-08
Secunia Advisory ID:
SA8536
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
MandrakeSoft has issued updated packages for samba. These fix some unspecified potential buffer overflow vulnerabilities as well as a vulnerability, which can be exploited by anonymous users to gain root privileges on a vulnerable system. [Read More]


Samba exploitable buffer overflow
Vendor Patch. Secunia Advisory 33 of 76 in 2003. 15,366 views.
Release Date:
2003-04-07
Secunia Advisory ID:
SA8533
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Samba is vulnerable to a buffer overflow, which can be exploited by anonymous users. [Read More]


Mandrake update for Kerberos
Vendor Patch. Secunia Advisory 34 of 76 in 2003. 6,041 views.
Release Date:
2003-04-01
Secunia Advisory ID:
SA8483
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Spoofing
Exposure of system information
DoS
System access
Where:
From remote
Short Description:
Mandrake has released updated packages for Kerberos. These fix several vulnerabilities, which can be exploited to disclose information, cause a Denial of Service or compromise a system. [Read More]


Mandrake update for sendmail
Vendor Patch. Secunia Advisory 35 of 76 in 2003. 5,608 views.
Release Date:
2003-04-01
Secunia Advisory ID:
SA8484
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for sendmail. These fix a vulnerability in the address parsing, which potentially can be exploited to compromise a vulnerable mail server. [Read More]


Mandrake update for mutt
Vendor Patch. Secunia Advisory 36 of 76 in 2003. 4,976 views.
Release Date:
2003-04-01
Secunia Advisory ID:
SA8486
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for mutt. These fix a vulnerability, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Sendmail Address Parsing Buffer Overflow
Vendor Patch. Secunia Advisory 37 of 76 in 2003. 18,994 views.
Release Date:
2003-03-30
Secunia Advisory ID:
SA8446
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Sendmail, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mandrake update for kernel 2.4
Vendor Patch. Secunia Advisory 38 of 76 in 2003. 6,308 views.
Release Date:
2003-03-28
Secunia Advisory ID:
SA8438
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
[Read More]


Mandrake update for kernel 2.2
Vendor Patch. Secunia Advisory 39 of 76 in 2003. 5,740 views.
Release Date:
2003-03-28
Secunia Advisory ID:
SA8437
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
From remote
Short Description:
MandrakeSoft has released updated packages for kernel version 2.2. These fix three vulnerabilities: An information disclosure vulnerability, a Denial of Service vulnerability, and a privilege escalation vulnerability. [Read More]


Mandrake update for netpbm
Vendor Patch. Secunia Advisory 40 of 76 in 2003. 6,084 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8413
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Where:
From remote
Short Description:
MandrakeSoft has released updated packages for netpbm. These fix multiple boundary errors, which theoretically could be exploited to compromise a user's system. [Read More]


Mandrake updates for rxvt
Vendor Patch. Secunia Advisory 41 of 76 in 2003. 5,896 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8412
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages for rxvt. These eliminate a vulnerability allowing malicious people to manipulate actions taken by the system administrator and other users on a system. [Read More]


Mandrake updates for glibc
Vendor Patch. Secunia Advisory 42 of 76 in 2003. 7,099 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8410
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to RPC XDR. A vulnerability has been discovered allowing malicious users to cause an integer overflow, this could lead to a Denial of Service and possibly also execution of arbitrary code. [Read More]


Mandrake updates for openssl
Vendor Patch. Secunia Advisory 43 of 76 in 2003. 7,336 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8409
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Mandrake has issued updates to openssl. Two vulnerabilities has been discovered, one allowing malicious people to extract the premaster-secret, the other allowed malicious people to extract the RSA secret. [Read More]


Multiple Vendor RPC XDR Library Integer Overflow
Vendor Patch. Secunia Advisory 44 of 76 in 2003. 13,830 views.
Release Date:
2003-03-20
Secunia Advisory ID:
SA8347
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability identified in multiple *NIX operating systems and software can be exploited by malicious people to conduct a DoS attack (Denial of Service) on a vulnerable system or potentially compromise it. [Read More]


Samba Packet Fragment Re-assembly Buffer Overflow
Vendor Patch. Secunia Advisory 45 of 76 in 2003. 14,756 views.
Release Date:
2003-03-17
Secunia Advisory ID:
SA8299
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been identified in Samba, which can be exploited by a malicious person to compromise a vulnerable server. [Read More]


Mandrake updates for usermode
Vendor Patch. Secunia Advisory 46 of 76 in 2003. 6,248 views.
Release Date:
2003-03-13
Secunia Advisory ID:
SA8278
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates for usermode. The problem is that any user is allowed to execute the /usr/bin/shutdown command, which can be used to close all services and enter a root shell. [Read More]


Mandrake updates for snort
Vendor Patch. Secunia Advisory 47 of 76 in 2003. 5,412 views.
Release Date:
2003-03-07
Secunia Advisory ID:
SA8237
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has released an update for snort. This fixes a vulnerability, which can be exploited by a malicious person to compromise a system running snort. [Read More]


Mandrake updates for file
Vendor Patch. Secunia Advisory 48 of 76 in 2003. 6,224 views.
Release Date:
2003-03-07
Secunia Advisory ID:
SA8241
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has released updates for the utility "file". These fix a vulnerability exploitable by malicious, local users to escalate their privileges. [Read More]


File utility possible privilege escalation
Vendor Patch. Secunia Advisory 49 of 76 in 2003. 8,336 views.
Release Date:
2003-03-05
Secunia Advisory ID:
SA8224
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A boundary error identified in the utility "file" included in many *nix distributions can potentially be exploited by malicious users to escalate their privileges. [Read More]


Mandrake updates for tcpdump
Vendor Patch. Secunia Advisory 50 of 76 in 2003. 6,773 views.
Release Date:
2003-03-04
Secunia Advisory ID:
SA8201
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates for tcpdump to fix a Denial of Service vulnerability in the handling of ISAKMP packets. [Read More]


Mandrake updates for sendmail
Vendor Patch. Secunia Advisory 51 of 76 in 2003. 5,669 views.
Release Date:
2003-03-03
Secunia Advisory ID:
SA8196
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates for sendmail. Sendmail has been found vulnerable to an issue that could lead to remote root compromise. The problem is with parsing of certain headers. [Read More]


Mandrake updates for webmin
Vendor Patch. Secunia Advisory 52 of 76 in 2003. 6,740 views.
Release Date:
2003-02-27
Secunia Advisory ID:
SA8163
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates for WebTool which is derived from Webmin. A vulnerability exists which may allows users to bypass the authentication process by including a special metacharacter in the BASE64 encoded authentication string. [Read More]


Mandrake updates for shadow-utils
Vendor Patch. Secunia Advisory 53 of 76 in 2003. 5,563 views.
Release Date:
2003-02-27
Secunia Advisory ID:
SA8162
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
Local system
Short Description:
Mandrake has issued updates to shadow-utils, due to a bug that creates mailbox files with insecure permissions. [Read More]


Mandrake updates for VNC
Vendor Patch. Secunia Advisory 54 of 76 in 2003. 7,169 views.
Release Date:
2003-02-25
Secunia Advisory ID:
SA8139
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Mandrake has issued updates for VNC. These fix a vulnerability allowing attackers to perform a replay attack. [Read More]


Mandrake updates for lynx
Vendor Patch. Secunia Advisory 55 of 76 in 2003. 6,216 views.
Release Date:
2003-02-25
Secunia Advisory ID:
SA8138
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
Local system
Short Description:
Mandrake has issued updated packages to fix a vulnerability in lynx. [Read More]


Mandrake updates for Kerberos FTP client
Vendor Patch. Secunia Advisory 56 of 76 in 2003. 7,687 views.
Release Date:
2003-02-24
Secunia Advisory ID:
SA8114
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to kerberos to fix a vulnerability in the ftp client. [Read More]


Mandrake updates for openssl
Vendor Patch. Secunia Advisory 57 of 76 in 2003. 5,779 views.
Release Date:
2003-02-22
Secunia Advisory ID:
SA8112
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
MandrakeSoft has released updated packages for openssl. These eliminate an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of a used plaintext block in a SSL/TLS session. [Read More]


Mandrake updates for PHP
Vendor Patch. Secunia Advisory 58 of 76 in 2003. 4,661 views.
Release Date:
2003-02-20
Secunia Advisory ID:
SA8095
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated PHP packages to fix a vulnerability, which can be expoited to compromise a vulnerable system. [Read More]


Mandrake updates for apcupsd
Vendor Patch. Secunia Advisory 59 of 76 in 2003. 5,442 views.
Release Date:
2003-02-19
Secunia Advisory ID:
SA8085
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Mandrake has issued updates for apcupsd. A vulnerability in apcupsd can be exploited by malicious users to compromise a slave device. [Read More]


Mandrake updates for pam
Vendor Patch. Secunia Advisory 60 of 76 in 2003. 5,808 views.
Release Date:
2003-02-19
Secunia Advisory ID:
SA8084
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates for pam, due to a problem with pam_xauth cookies. [Read More]


Mandrake updates for util-linux
Vendor Patch. Secunia Advisory 61 of 76 in 2003. 5,513 views.
Release Date:
2003-02-14
Secunia Advisory ID:
SA8054
Solution Status:
Vendor Patch
Criticality:
Impact:
Brute force
Where:
Local system
Short Description:
Mandrake has issued updates for util-linux. The problem is that the mcookie utility which generates random cookies for use with X authentication, uses /dev/urandom instead of /dev/random. [Read More]


Mandrake updates to postgresql
Vendor Patch. Secunia Advisory 62 of 76 in 2003. 6,102 views.
Release Date:
2003-02-12
Secunia Advisory ID:
SA8034
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to postgresql as more buffer overflows has been identified. [Read More]


Mandrake updates to slocate
Vendor Patch. Secunia Advisory 63 of 76 in 2003. 6,324 views.
Release Date:
2003-02-06
Secunia Advisory ID:
SA8007
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates to slocate. These eliminate a vulnerability, which can be exploited by malicious, local users to escalate their privileges. [Read More]


Mandrake updates to mysql
Vendor Patch. Secunia Advisory 64 of 76 in 2003. 5,687 views.
Release Date:
2003-02-04
Secunia Advisory ID:
SA7989
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to mysql. A double free'd pointer bug in mysql_change_user allowed logged in users to crash mysqld. [Read More]


Mandrake updates to vim
Vendor Patch. Secunia Advisory 65 of 76 in 2003. 5,392 views.
Release Date:
2003-02-04
Secunia Advisory ID:
SA7988
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to vim. It is possible to create malicious text files that can execute arbitrary commands when loaded into vim. The problem is that vim reads the text file and looks for comments, these comments can be exploited to call external commands. [Read More]


Mandrake updates to fetchmail
Vendor Patch. Secunia Advisory 66 of 76 in 2003. 5,227 views.
Release Date:
2003-01-28
Secunia Advisory ID:
SA7958
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to fetchmail, to fix a remotely expoitable heap overflow. [Read More]


Mandrake updates to printing system
Vendor Patch. Secunia Advisory 67 of 76 in 2003. 5,629 views.
Release Date:
2003-01-22
Secunia Advisory ID:
SA7918
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates to their printer drivers, three different vulnerabilities has been identified, they all allow local user to escalate their privileges. [Read More]


Mandrake updates to CVS
Vendor Patch. Secunia Advisory 68 of 76 in 2003. 5,523 views.
Release Date:
2003-01-21
Secunia Advisory ID:
SA7912
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to fix the double-free vulnerability in CVS, allowing anonymous remote users to execute arbitrary code. [Read More]


Mandrake update for libpng
Vendor Patch. Secunia Advisory 69 of 76 in 2003. 5,838 views.
Release Date:
2003-01-21
Secunia Advisory ID:
SA7911
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued an update for libpng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mandrake updates to dhcp
Vendor Patch. Secunia Advisory 70 of 76 in 2003. 6,608 views.
Release Date:
2003-01-19
Secunia Advisory ID:
SA7896
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the dhcp,to fix the stack overflow in the minires library. [Read More]


Mandrake updates to leafnode
Vendor Patch. Secunia Advisory 71 of 76 in 2003. 6,040 views.
Release Date:
2003-01-15
Secunia Advisory ID:
SA7870
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to leafnode. leafnode does not handle cross posted newsgroup messages correct, when the group name of one group is also the prefix of the name of another group. [Read More]


Mandrake updates to openldap
Vendor Patch. Secunia Advisory 72 of 76 in 2003. 5,613 views.
Release Date:
2003-01-15
Secunia Advisory ID:
SA7869
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to openldap, several buffer overflows has been discovered which are remotely exploitable. [Read More]


Mandrake updates to KDE
Vendor Patch. Secunia Advisory 73 of 76 in 2003. 4,697 views.
Release Date:
2003-01-14
Secunia Advisory ID:
SA7859
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to KDE. KDE does not handle URLs properly, this can be exploited to run arbitrary commands. The problem is that URLs are not verified and quoted correctly. This allows malicious persons to include shell metacharacters. [Read More]


Mandrake updated to dhcpcd
Vendor Patch. Secunia Advisory 74 of 76 in 2003. 5,495 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7845
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages to dhcpcd. [Read More]


Mandrake updates to xpdf
Vendor Patch. Secunia Advisory 75 of 76 in 2003. 5,448 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7844
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to xpdf to fix an integer overflow. [Read More]


Mandrake updates to CUPS
Vendor Patch. Secunia Advisory 76 of 76 in 2003. 5,812 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7843
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to CUPS to fix multiple vulnerabilities. [Read More]


KDE arbitrary command execution
Vendor Patch. Secunia Advisory 1 of 28 in 2002. 9,102 views.
Release Date:
2002-12-23
Secunia Advisory ID:
SA7773
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
KDE does not handle URLs properly, this can be exploited to run arbitrary commands. The problem is that URLs are not verified and quoted correctly. This allows malicious persons to include shell metacharacters. [Read More]


CUPS multiple vulnerabilities
Vendor Patch. Secunia Advisory 2 of 28 in 2002. 9,818 views.
Release Date:
2002-12-20
Secunia Advisory ID:
SA7756
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
CUPS has been found vulnerable to multiple issues. [Read More]


Mandrake updates to mysql
Vendor Patch. Secunia Advisory 3 of 28 in 2002. 5,574 views.
Release Date:
2002-12-19
Secunia Advisory ID:
SA7750
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Privilege escalation
Where:
From remote
Short Description:
Mandrake has issued updates to address a Denial of Service and a privilege escalation vulnerability. [Read More]


Mandrake updates to wget
Vendor Patch. Secunia Advisory 4 of 28 in 2002. 5,461 views.
Release Date:
2002-12-12
Secunia Advisory ID:
SA7694
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to wget, which is used to retrieve files from remote web and ftp sites. [Read More]


Mandrake updates to WindowMaker
Vendor Patch. Secunia Advisory 5 of 28 in 2002. 5,625 views.
Release Date:
2002-12-03
Secunia Advisory ID:
SA7636
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Window Maker does not verify the size of images correctly, it allocates a buffer based on width and height, but does not check the actual size. [Read More]


Mandrake updates to pine
Vendor Patch. Secunia Advisory 6 of 28 in 2002. 6,316 views.
Release Date:
2002-12-03
Secunia Advisory ID:
SA7635
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to pine. [Read More]


Mandrake updates to sendmail smrsh issue
Vendor Patch. Secunia Advisory 7 of 28 in 2002. 5,476 views.
Release Date:
2002-11-29
Secunia Advisory ID:
SA7623
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates to the sendmail restricted shell problem. [Read More]


Mandrake updates to samba
Vendor Patch. Secunia Advisory 8 of 28 in 2002. 5,480 views.
Release Date:
2002-11-26
Secunia Advisory ID:
SA7599
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated samba packages to fix a potential remotely exploitable vulnerability. [Read More]


Mandrake updates to python
Vendor Patch. Secunia Advisory 9 of 28 in 2002. 6,095 views.
Release Date:
2002-11-26
Secunia Advisory ID:
SA7600
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued patches to an older issue in python, where python handled tmp files insecurely, this allowed local users to gain privileges. [Read More]


Mandrake updates to ypserv
Vendor Patch. Secunia Advisory 10 of 28 in 2002. 5,298 views.
Release Date:
2002-11-19
Secunia Advisory ID:
SA7550
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Mandrake has issued updates to ypserv. It is possible to cause a memory leak in ypserv which will cause the system to consume more and more memory. [Read More]


Mandrake updates to nss_ldap
Vendor Patch. Secunia Advisory 11 of 28 in 2002. 5,308 views.
Release Date:
2002-11-08
Secunia Advisory ID:
SA7468
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages to fix two issues in nss_ldap. [Read More]


Mandrake updates to perl-MailTools
Vendor Patch. Secunia Advisory 12 of 28 in 2002. 5,227 views.
Release Date:
2002-11-08
Secunia Advisory ID:
SA7467
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the vulnerabilities found by SuSE Security Team during a code audit of critical parts of perl-MailTools, it found vulnerabilities allowing remote execution of arbitrary code. [Read More]


Mandrake update to mozilla
Vendor Patch. Secunia Advisory 13 of 28 in 2002. 5,292 views.
Release Date:
2002-11-01
Secunia Advisory ID:
SA7427
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Exposure of sensitive information
Where:
From remote
Short Description:
Mandrake has issued new mozilla packages to fix multiple older vulnerabilities. [Read More]


Mandrake updates to kerberos issue
Vendor Patch. Secunia Advisory 14 of 28 in 2002. 5,269 views.
Release Date:
2002-10-30
Secunia Advisory ID:
SA7412
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the fix the stack overflow in kadmind. Exploit code is known to be in the wild, we recommend that you upgrade immediatedly. [Read More]


Mandrake updates to mod_ssl issue
Vendor Patch. Secunia Advisory 15 of 28 in 2002. 5,657 views.
Release Date:
2002-10-25
Secunia Advisory ID:
SA7390
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Mandrake has issued updates to the Cross Site Scripting vulnerability in mod_ssl and Apache. [Read More]


Mandrake updates to kde vulnerability
Vendor Patch. Secunia Advisory 16 of 28 in 2002. 5,383 views.
Release Date:
2002-10-25
Secunia Advisory ID:
SA7389
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
KGhostview which is part of KDE uses code derived from gv, this contains the same vulnerability as gv/ggv. [Read More]


Mandrake updates to the dvips / tetex vulnerability
Vendor Patch. Secunia Advisory 17 of 28 in 2002. 6,430 views.
Release Date:
2002-10-23
Secunia Advisory ID:
SA7373
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the dvips issue which allows remote print user to execute arbitrary code. [Read More]


Mandrake updates to gv/ggv issue
Vendor Patch. Secunia Advisory 18 of 28 in 2002. 5,633 views.
Release Date:
2002-10-22
Secunia Advisory ID:
SA7358
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued packages to fix a vulnerability in gv. [Read More]


Mandrake updates to apache issue
Vendor Patch. Secunia Advisory 19 of 28 in 2002. 5,690 views.
Release Date:
2002-10-16
Secunia Advisory ID:
SA7316
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Mandrake has issued new packages to address the local DoS vulnerability in Apache. [Read More]


Mandrake updates to unzip issue
Vendor Patch. Secunia Advisory 20 of 28 in 2002. 3,666 views.
Release Date:
2002-10-11
Secunia Advisory ID:
SA7284
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the directory traversal bug in unzip. [Read More]


Mandrake updates to tar issue
Vendor Patch. Secunia Advisory 21 of 28 in 2002. 3,741 views.
Release Date:
2002-10-11
Secunia Advisory ID:
SA7285
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the directory traversal bug in tar. [Read More]


Mandrake updates to kdelibs issue
Vendor Patch. Secunia Advisory 22 of 28 in 2002. 3,781 views.
Release Date:
2002-10-10
Secunia Advisory ID:
SA7267
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Mandrake has issued updated packages to deal with a recent problem in kdelibs. [Read More]


Mandrake issues fixes to postgresql issues
Vendor Patch. Secunia Advisory 23 of 28 in 2002. 3,806 views.
Release Date:
2002-10-02
Secunia Advisory ID:
SA7191
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Postgresql suffers various buffer overflows, these exists in the rpad(), lpad(), repeat() and cash_Word() functions plus others including time/date funtions. [Read More]


Mandrake issues updates to XDR decoder vulnerability
Vendor Patch. Secunia Advisory 24 of 28 in 2002. 3,548 views.
Release Date:
2002-09-24
Secunia Advisory ID:
SA7148
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Recently a heap buffer overflow was discovered in the XDR decoder library derived from Sun's RPC. [Read More]


Mandrake issues updates to Tcl/Tk which fixes local root privilege vulnerability
Vendor Patch. Secunia Advisory 25 of 28 in 2002. 4,659 views.
Release Date:
2002-09-24
Secunia Advisory ID:
SA7147
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
The mkpasswd utility searches /var/tmp for libraries prior to searching other directories, this allows an attacker to place a trojan library. [Read More]


Mandrake fix php vulnerability
Vendor Patch. Secunia Advisory 26 of 28 in 2002. 3,179 views.
Release Date:
2002-09-11
Secunia Advisory ID:
SA7092
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
PHP suffered a vulnerability in version 4.0.5 in the mail() function, which could be used to inject arbitrary code. [Read More]


KDE fails to properly verify SSL certificates
Vendor Patch. Secunia Advisory 27 of 28 in 2002. 3,340 views.
Release Date:
2002-09-10
Secunia Advisory ID:
SA7088
Solution Status:
Vendor Patch
Criticality:
Impact:
Spoofing
Where:
From remote
Short Description:
KDE (kdelibs) appears to be vulnerable to a similar flaw to that which MSIE suffers, regarding verification of SSL certificates. [Read More]


Mandrake: Kerberos suffer XDR decoder flaw
Vendor Patch. Secunia Advisory 28 of 28 in 2002. 3,050 views.
Release Date:
2002-09-10
Secunia Advisory ID:
SA7089
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages to deal with the XDR vulnerability. If Kerberos is enabled this is highly critical. [Read More]