|
Vulnerability Report: Mandrake Linux 7.x
|
This vulnerability report for Mandrake Linux 7.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.
If you have information about a new or an existing vulnerability in Mandrake Linux 7.x then you are more than welcome to contact us.
|
|
|
|
|
Vendor, Links, and Unpatched Vulnerabilities
|
|
|
|
45 Secunia Advisories in 2003-2009
|
Secunia has issued a total of 45 Secunia advisories in 2003-2009 for Mandrake Linux 7.x. Currently, 0% (0 out of 45) are marked as unpatched.
More information about the specific Secunia advisories affecting Mandrake Linux 7.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.
|
|
|
|
|
|
Release Date: 2003-07-14 |
Secunia Advisory ID: SA9259 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From local network |
|
Short Description: A vulnerability has been reported in nfs-utils, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-06-17 |
Secunia Advisory ID: SA9057 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: A vulnerability has been identified in Linux-PAM, which allows malicious, local users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-22 |
Secunia Advisory ID: SA8632 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: A vulnerability has been identified in Xinetd, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-04-07 |
Secunia Advisory ID: SA8533 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From local network |
|
Short Description: Samba is vulnerable to a buffer overflow, which can be exploited by anonymous users. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-30 |
Secunia Advisory ID: SA8446 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From remote |
|
Short Description: A vulnerability has been discovered in Sendmail, which can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-28 |
Secunia Advisory ID: SA8437 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information Privilege escalation DoS
|
Where: From remote |
|
Short Description: MandrakeSoft has released updated packages for kernel version 2.2. These fix three vulnerabilities: An information disclosure vulnerability, a Denial of Service vulnerability, and a privilege escalation vulnerability. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-26 |
Secunia Advisory ID: SA8410 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updates to RPC XDR. A vulnerability has been discovered allowing malicious users to cause an integer overflow, this could lead to a Denial of Service and possibly also execution of arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-26 |
Secunia Advisory ID: SA8409 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of system information
|
Where: From remote |
|
Short Description: Mandrake has issued updates to openssl. Two vulnerabilities has been discovered, one allowing malicious people to extract the premaster-secret, the other allowed malicious people to extract the RSA secret. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-20 |
Secunia Advisory ID: SA8347 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From local network |
|
Short Description: A vulnerability identified in multiple *NIX operating systems and software can be exploited by malicious people to conduct a DoS attack (Denial of Service) on a vulnerable system or potentially compromise it. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-17 |
Secunia Advisory ID: SA8299 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS System access
|
Where: From local network |
|
Short Description: A vulnerability has been identified in Samba, which can be exploited by a malicious person to compromise a vulnerable server. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-07 |
Secunia Advisory ID: SA8241 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: MandrakeSoft has released updates for the utility "file". These fix a vulnerability exploitable by malicious, local users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-05 |
Secunia Advisory ID: SA8224 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: A boundary error identified in the utility "file" included in many *nix distributions can potentially be exploited by malicious users to escalate their privileges. [Read More]
|
|
|
|
|
|
Release Date: 2003-03-03 |
Secunia Advisory ID: SA8196 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates for sendmail. Sendmail has been found vulnerable to an issue that could lead to remote root compromise. The problem is with parsing of certain headers. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-27 |
Secunia Advisory ID: SA8163 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates for WebTool which is derived from Webmin. A vulnerability exists which may allows users to bypass the authentication process by including a special metacharacter in the BASE64 encoded authentication string. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-25 |
Secunia Advisory ID: SA8139 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Security Bypass
|
Where: From remote |
|
Short Description: Mandrake has issued updates for VNC. These fix a vulnerability allowing attackers to perform a replay attack. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-25 |
Secunia Advisory ID: SA8138 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Manipulation of data
|
Where: Local system |
|
Short Description: Mandrake has issued updated packages to fix a vulnerability in lynx. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-22 |
Secunia Advisory ID: SA8112 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Exposure of sensitive information
|
Where: From remote |
|
Short Description: MandrakeSoft has released updated packages for openssl. These eliminate an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of a used plaintext block in a SSL/TLS session. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-12 |
Secunia Advisory ID: SA8034 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to postgresql as more buffer overflows has been identified. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-04 |
Secunia Advisory ID: SA7989 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updates to mysql. A double free'd pointer bug in mysql_change_user allowed logged in users to crash mysqld. [Read More]
|
|
|
|
|
|
Release Date: 2003-02-04 |
Secunia Advisory ID: SA7988 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to vim. It is possible to create malicious text files that can execute arbitrary commands when loaded into vim. The problem is that vim reads the text file and looks for comments, these comments can be exploited to call external commands. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-28 |
Secunia Advisory ID: SA7958 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to fetchmail, to fix a remotely expoitable heap overflow. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-21 |
Secunia Advisory ID: SA7912 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to fix the double-free vulnerability in CVS, allowing anonymous remote users to execute arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-21 |
Secunia Advisory ID: SA7911 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: MandrakeSoft has issued an update for libpng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-19 |
Secunia Advisory ID: SA7896 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the dhcp,to fix the stack overflow in the minires library. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-10 |
Secunia Advisory ID: SA7844 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to xpdf to fix an integer overflow. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-10 |
Secunia Advisory ID: SA7843 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to CUPS to fix multiple vulnerabilities. [Read More]
|
|
|
|
|
|
Release Date: 2003-01-10 |
Secunia Advisory ID: SA7845 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updated packages to dhcpcd. [Read More]
|
|
|
|
|
|
Release Date: 2002-12-20 |
Secunia Advisory ID: SA7756 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: CUPS has been found vulnerable to multiple issues. [Read More]
|
|
|
|
|
|
Release Date: 2002-12-19 |
Secunia Advisory ID: SA7750 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS Privilege escalation
|
Where: From remote |
|
Short Description: Mandrake has issued updates to address a Denial of Service and a privilege escalation vulnerability. [Read More]
|
|
|
|
|
|
Release Date: 2002-12-18 |
Secunia Advisory ID: SA7746 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: Linux Kernel 2.2 has been found vulnerable to a Denial of Service condition. It is possible for local users to read the memory used by certain programs by using "/proc/pid/mem" and "mmap()". [Read More]
|
|
|
|
|
|
Release Date: 2002-12-12 |
Secunia Advisory ID: SA7694 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to wget, which is used to retrieve files from remote web and ftp sites. [Read More]
|
|
|
|
|
|
Release Date: 2002-12-03 |
Secunia Advisory ID: SA7636 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: Window Maker does not verify the size of images correctly, it allocates a buffer based on width and height, but does not check the actual size. [Read More]
|
|
|
|
|
|
Release Date: 2002-12-03 |
Secunia Advisory ID: SA7635 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From remote |
|
Short Description: Mandrake has issued updates to pine. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-29 |
Secunia Advisory ID: SA7623 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: Mandrake has issued updates to the sendmail restricted shell problem. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-26 |
Secunia Advisory ID: SA7600 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Privilege escalation
|
Where: Local system |
|
Short Description: Mandrake has issued patches to an older issue in python, where python handled tmp files insecurely, this allowed local users to gain privileges. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-19 |
Secunia Advisory ID: SA7550 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: From local network |
|
Short Description: Mandrake has issued updates to ypserv. It is possible to cause a memory leak in ypserv which will cause the system to consume more and more memory. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-14 |
Secunia Advisory ID: SA7522 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the three recent BIND holes, one allowing attackers system access from remote. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-08 |
Secunia Advisory ID: SA7468 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updated packages to fix two issues in nss_ldap. [Read More]
|
|
|
|
|
|
Release Date: 2002-11-08 |
Secunia Advisory ID: SA7467 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the vulnerabilities found by SuSE Security Team during a code audit of critical parts of perl-MailTools, it found vulnerabilities allowing remote execution of arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-25 |
Secunia Advisory ID: SA7390 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: Cross Site Scripting
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the Cross Site Scripting vulnerability in mod_ssl and Apache. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-23 |
Secunia Advisory ID: SA7373 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the dvips issue which allows remote print user to execute arbitrary code. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-16 |
Secunia Advisory ID: SA7316 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: DoS
|
Where: Local system |
|
Short Description: Mandrake has issued new packages to address the local DoS vulnerability in Apache. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-11 |
Secunia Advisory ID: SA7285 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the directory traversal bug in tar. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-11 |
Secunia Advisory ID: SA7284 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Mandrake has issued updates to the directory traversal bug in unzip. [Read More]
|
|
|
|
|
|
Release Date: 2002-10-02 |
Secunia Advisory ID: SA7191 |
Solution Status: Vendor Patch |
|
Criticality:
 |
Impact: System access
|
Where: From remote |
|
Short Description: Postgresql suffers various buffer overflows, these exists in the rpad(), lpad(), repeat() and cash_Word() functions plus others including time/date funtions. [Read More]
|
|
|