Secunia Logo  


Secunia PSI WorldMap
 
Vulnerability Report: Mandrake Linux 7.x
This vulnerability report for Mandrake Linux 7.x contains a complete overview of all Secunia advisories affecting it. You can use this vulnerability report to ensure that you are aware of all vulnerabilities, both patched and unpatched, affecting this product allowing you to take the necessary precautions.

If you have information about a new or an existing vulnerability in Mandrake Linux 7.x then you are more than welcome to contact us.


Table of Contents

1. Product Summary Only

2. Secunia Advisory Statistics (All time)
2.1. Statistics for 2009
2.2. Statistics for 2008
2.3. Statistics for 2007
2.4. Statistics for 2006
2.5. Statistics for 2005
2.6. Statistics for 2004
2.7. Statistics for 2003

3. List of Secunia Advisories (All time)
3.1. List for 2009
3.2. List for 2008
3.3. List for 2007
3.4. List for 2006
3.5. List for 2005
3.6. List for 2004
3.7. List for 2003

4. Send Feedback
 
Vendor, Links, and Unpatched Vulnerabilities

Vendor Mandriva

Product Link View Here (Link to external site)

Affected By 45 Secunia advisories
0 Vulnerabilities

Monitor Product Receive alerts for this product





45 Secunia Advisories in 2003-2009
Secunia has issued a total of 45 Secunia advisories in 2003-2009 for Mandrake Linux 7.x. Currently, 0% (0 out of 45) are marked as unpatched.

More information about the specific Secunia advisories affecting Mandrake Linux 7.x can be found below. Each Secunia advisory is enclosed by a box highlighted with a color representing its current patch status. You can read the complete Secunia advisories for thorough descriptions of the issues covered and for solution suggestions by clicking either the Secunia advisory title or the "Read More" links available for each Secunia advisory.



nfs-utils "xlog()" Buffer Overflow Vulnerability
Vendor Patch. Secunia Advisory 1 of 27 in 2003. 14,458 views.
Release Date:
2003-07-14
Secunia Advisory ID:
SA9259
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been reported in nfs-utils, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Linux-PAM User Name Spoofing Vulnerability
Vendor Patch. Secunia Advisory 2 of 27 in 2003. 14,570 views.
Release Date:
2003-06-17
Secunia Advisory ID:
SA9057
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A vulnerability has been identified in Linux-PAM, which allows malicious, local users to escalate their privileges. [Read More]


Xinetd Connection Reject Memory Leak
Vendor Patch. Secunia Advisory 3 of 27 in 2003. 11,290 views.
Release Date:
2003-04-22
Secunia Advisory ID:
SA8632
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
A vulnerability has been identified in Xinetd, which can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system. [Read More]


Samba exploitable buffer overflow
Vendor Patch. Secunia Advisory 4 of 27 in 2003. 15,405 views.
Release Date:
2003-04-07
Secunia Advisory ID:
SA8533
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From local network
Short Description:
Samba is vulnerable to a buffer overflow, which can be exploited by anonymous users. [Read More]


Sendmail Address Parsing Buffer Overflow
Vendor Patch. Secunia Advisory 5 of 27 in 2003. 19,029 views.
Release Date:
2003-03-30
Secunia Advisory ID:
SA8446
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From remote
Short Description:
A vulnerability has been discovered in Sendmail, which can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mandrake update for kernel 2.2
Vendor Patch. Secunia Advisory 6 of 27 in 2003. 5,754 views.
Release Date:
2003-03-28
Secunia Advisory ID:
SA8437
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Privilege escalation
DoS
Where:
From remote
Short Description:
MandrakeSoft has released updated packages for kernel version 2.2. These fix three vulnerabilities: An information disclosure vulnerability, a Denial of Service vulnerability, and a privilege escalation vulnerability. [Read More]


Mandrake updates for glibc
Vendor Patch. Secunia Advisory 7 of 27 in 2003. 7,110 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8410
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to RPC XDR. A vulnerability has been discovered allowing malicious users to cause an integer overflow, this could lead to a Denial of Service and possibly also execution of arbitrary code. [Read More]


Mandrake updates for openssl
Vendor Patch. Secunia Advisory 8 of 27 in 2003. 7,355 views.
Release Date:
2003-03-26
Secunia Advisory ID:
SA8409
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of system information
Where:
From remote
Short Description:
Mandrake has issued updates to openssl. Two vulnerabilities has been discovered, one allowing malicious people to extract the premaster-secret, the other allowed malicious people to extract the RSA secret. [Read More]


Multiple Vendor RPC XDR Library Integer Overflow
Vendor Patch. Secunia Advisory 9 of 27 in 2003. 13,864 views.
Release Date:
2003-03-20
Secunia Advisory ID:
SA8347
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability identified in multiple *NIX operating systems and software can be exploited by malicious people to conduct a DoS attack (Denial of Service) on a vulnerable system or potentially compromise it. [Read More]


Samba Packet Fragment Re-assembly Buffer Overflow
Vendor Patch. Secunia Advisory 10 of 27 in 2003. 14,814 views.
Release Date:
2003-03-17
Secunia Advisory ID:
SA8299
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
System access
Where:
From local network
Short Description:
A vulnerability has been identified in Samba, which can be exploited by a malicious person to compromise a vulnerable server. [Read More]


Mandrake updates for file
Vendor Patch. Secunia Advisory 11 of 27 in 2003. 6,239 views.
Release Date:
2003-03-07
Secunia Advisory ID:
SA8241
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
MandrakeSoft has released updates for the utility "file". These fix a vulnerability exploitable by malicious, local users to escalate their privileges. [Read More]


File utility possible privilege escalation
Vendor Patch. Secunia Advisory 12 of 27 in 2003. 8,350 views.
Release Date:
2003-03-05
Secunia Advisory ID:
SA8224
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
A boundary error identified in the utility "file" included in many *nix distributions can potentially be exploited by malicious users to escalate their privileges. [Read More]


Mandrake updates for sendmail
Vendor Patch. Secunia Advisory 13 of 27 in 2003. 5,685 views.
Release Date:
2003-03-03
Secunia Advisory ID:
SA8196
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates for sendmail. Sendmail has been found vulnerable to an issue that could lead to remote root compromise. The problem is with parsing of certain headers. [Read More]


Mandrake updates for webmin
Vendor Patch. Secunia Advisory 14 of 27 in 2003. 6,766 views.
Release Date:
2003-02-27
Secunia Advisory ID:
SA8163
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates for WebTool which is derived from Webmin. A vulnerability exists which may allows users to bypass the authentication process by including a special metacharacter in the BASE64 encoded authentication string. [Read More]


Mandrake updates for VNC
Vendor Patch. Secunia Advisory 15 of 27 in 2003. 7,185 views.
Release Date:
2003-02-25
Secunia Advisory ID:
SA8139
Solution Status:
Vendor Patch
Criticality:
Impact:
Security Bypass
Where:
From remote
Short Description:
Mandrake has issued updates for VNC. These fix a vulnerability allowing attackers to perform a replay attack. [Read More]


Mandrake updates for lynx
Vendor Patch. Secunia Advisory 16 of 27 in 2003. 6,232 views.
Release Date:
2003-02-25
Secunia Advisory ID:
SA8138
Solution Status:
Vendor Patch
Criticality:
Impact:
Manipulation of data
Where:
Local system
Short Description:
Mandrake has issued updated packages to fix a vulnerability in lynx. [Read More]


Mandrake updates for openssl
Vendor Patch. Secunia Advisory 17 of 27 in 2003. 5,790 views.
Release Date:
2003-02-22
Secunia Advisory ID:
SA8112
Solution Status:
Vendor Patch
Criticality:
Impact:
Exposure of sensitive information
Where:
From remote
Short Description:
MandrakeSoft has released updated packages for openssl. These eliminate an information disclosure vulnerability, which can be exploited by malicious people to gain knowledge of a used plaintext block in a SSL/TLS session. [Read More]


Mandrake updates to postgresql
Vendor Patch. Secunia Advisory 18 of 27 in 2003. 6,135 views.
Release Date:
2003-02-12
Secunia Advisory ID:
SA8034
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to postgresql as more buffer overflows has been identified. [Read More]


Mandrake updates to mysql
Vendor Patch. Secunia Advisory 19 of 27 in 2003. 5,701 views.
Release Date:
2003-02-04
Secunia Advisory ID:
SA7989
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to mysql. A double free'd pointer bug in mysql_change_user allowed logged in users to crash mysqld. [Read More]


Mandrake updates to vim
Vendor Patch. Secunia Advisory 20 of 27 in 2003. 5,409 views.
Release Date:
2003-02-04
Secunia Advisory ID:
SA7988
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to vim. It is possible to create malicious text files that can execute arbitrary commands when loaded into vim. The problem is that vim reads the text file and looks for comments, these comments can be exploited to call external commands. [Read More]


Mandrake updates to fetchmail
Vendor Patch. Secunia Advisory 21 of 27 in 2003. 5,240 views.
Release Date:
2003-01-28
Secunia Advisory ID:
SA7958
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to fetchmail, to fix a remotely expoitable heap overflow. [Read More]


Mandrake updates to CVS
Vendor Patch. Secunia Advisory 22 of 27 in 2003. 5,539 views.
Release Date:
2003-01-21
Secunia Advisory ID:
SA7912
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to fix the double-free vulnerability in CVS, allowing anonymous remote users to execute arbitrary code. [Read More]


Mandrake update for libpng
Vendor Patch. Secunia Advisory 23 of 27 in 2003. 5,853 views.
Release Date:
2003-01-21
Secunia Advisory ID:
SA7911
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
MandrakeSoft has issued an update for libpng. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a vulnerable system. [Read More]


Mandrake updates to dhcp
Vendor Patch. Secunia Advisory 24 of 27 in 2003. 6,625 views.
Release Date:
2003-01-19
Secunia Advisory ID:
SA7896
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the dhcp,to fix the stack overflow in the minires library. [Read More]


Mandrake updates to xpdf
Vendor Patch. Secunia Advisory 25 of 27 in 2003. 5,463 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7844
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to xpdf to fix an integer overflow. [Read More]


Mandrake updates to CUPS
Vendor Patch. Secunia Advisory 26 of 27 in 2003. 5,835 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7843
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to CUPS to fix multiple vulnerabilities. [Read More]


Mandrake updated to dhcpcd
Vendor Patch. Secunia Advisory 27 of 27 in 2003. 5,513 views.
Release Date:
2003-01-10
Secunia Advisory ID:
SA7845
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages to dhcpcd. [Read More]


CUPS multiple vulnerabilities
Vendor Patch. Secunia Advisory 1 of 18 in 2002. 9,847 views.
Release Date:
2002-12-20
Secunia Advisory ID:
SA7756
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
CUPS has been found vulnerable to multiple issues. [Read More]


Mandrake updates to mysql
Vendor Patch. Secunia Advisory 2 of 18 in 2002. 5,592 views.
Release Date:
2002-12-19
Secunia Advisory ID:
SA7750
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Privilege escalation
Where:
From remote
Short Description:
Mandrake has issued updates to address a Denial of Service and a privilege escalation vulnerability. [Read More]


Linux Kernel 2.2 local Denial of Service
Vendor Patch. Secunia Advisory 3 of 18 in 2002. 8,080 views.
Release Date:
2002-12-18
Secunia Advisory ID:
SA7746
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Linux Kernel 2.2 has been found vulnerable to a Denial of Service condition. It is possible for local users to read the memory used by certain programs by using "/proc/pid/mem" and "mmap()". [Read More]


Mandrake updates to wget
Vendor Patch. Secunia Advisory 4 of 18 in 2002. 5,478 views.
Release Date:
2002-12-12
Secunia Advisory ID:
SA7694
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to wget, which is used to retrieve files from remote web and ftp sites. [Read More]


Mandrake updates to WindowMaker
Vendor Patch. Secunia Advisory 5 of 18 in 2002. 5,641 views.
Release Date:
2002-12-03
Secunia Advisory ID:
SA7636
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Window Maker does not verify the size of images correctly, it allocates a buffer based on width and height, but does not check the actual size. [Read More]


Mandrake updates to pine
Vendor Patch. Secunia Advisory 6 of 18 in 2002. 6,331 views.
Release Date:
2002-12-03
Secunia Advisory ID:
SA7635
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From remote
Short Description:
Mandrake has issued updates to pine. [Read More]


Mandrake updates to sendmail smrsh issue
Vendor Patch. Secunia Advisory 7 of 18 in 2002. 5,489 views.
Release Date:
2002-11-29
Secunia Advisory ID:
SA7623
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued updates to the sendmail restricted shell problem. [Read More]


Mandrake updates to python
Vendor Patch. Secunia Advisory 8 of 18 in 2002. 6,108 views.
Release Date:
2002-11-26
Secunia Advisory ID:
SA7600
Solution Status:
Vendor Patch
Criticality:
Impact:
Privilege escalation
Where:
Local system
Short Description:
Mandrake has issued patches to an older issue in python, where python handled tmp files insecurely, this allowed local users to gain privileges. [Read More]


Mandrake updates to ypserv
Vendor Patch. Secunia Advisory 9 of 18 in 2002. 5,307 views.
Release Date:
2002-11-19
Secunia Advisory ID:
SA7550
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
From local network
Short Description:
Mandrake has issued updates to ypserv. It is possible to cause a memory leak in ypserv which will cause the system to consume more and more memory. [Read More]


Mandrake updates to BIND
Vendor Patch. Secunia Advisory 10 of 18 in 2002. 5,129 views.
Release Date:
2002-11-14
Secunia Advisory ID:
SA7522
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the three recent BIND holes, one allowing attackers system access from remote. [Read More]


Mandrake updates to nss_ldap
Vendor Patch. Secunia Advisory 11 of 18 in 2002. 5,321 views.
Release Date:
2002-11-08
Secunia Advisory ID:
SA7468
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updated packages to fix two issues in nss_ldap. [Read More]


Mandrake updates to perl-MailTools
Vendor Patch. Secunia Advisory 12 of 18 in 2002. 5,236 views.
Release Date:
2002-11-08
Secunia Advisory ID:
SA7467
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the vulnerabilities found by SuSE Security Team during a code audit of critical parts of perl-MailTools, it found vulnerabilities allowing remote execution of arbitrary code. [Read More]


Mandrake updates to mod_ssl issue
Vendor Patch. Secunia Advisory 13 of 18 in 2002. 5,679 views.
Release Date:
2002-10-25
Secunia Advisory ID:
SA7390
Solution Status:
Vendor Patch
Criticality:
Impact:
Cross Site Scripting
Where:
From remote
Short Description:
Mandrake has issued updates to the Cross Site Scripting vulnerability in mod_ssl and Apache. [Read More]


Mandrake updates to the dvips / tetex vulnerability
Vendor Patch. Secunia Advisory 14 of 18 in 2002. 6,448 views.
Release Date:
2002-10-23
Secunia Advisory ID:
SA7373
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the dvips issue which allows remote print user to execute arbitrary code. [Read More]


Mandrake updates to apache issue
Vendor Patch. Secunia Advisory 15 of 18 in 2002. 5,709 views.
Release Date:
2002-10-16
Secunia Advisory ID:
SA7316
Solution Status:
Vendor Patch
Criticality:
Impact:
DoS
Where:
Local system
Short Description:
Mandrake has issued new packages to address the local DoS vulnerability in Apache. [Read More]


Mandrake updates to tar issue
Vendor Patch. Secunia Advisory 16 of 18 in 2002. 3,760 views.
Release Date:
2002-10-11
Secunia Advisory ID:
SA7285
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the directory traversal bug in tar. [Read More]


Mandrake updates to unzip issue
Vendor Patch. Secunia Advisory 17 of 18 in 2002. 3,683 views.
Release Date:
2002-10-11
Secunia Advisory ID:
SA7284
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Mandrake has issued updates to the directory traversal bug in unzip. [Read More]


Mandrake issues fixes to postgresql issues
Vendor Patch. Secunia Advisory 18 of 18 in 2002. 3,825 views.
Release Date:
2002-10-02
Secunia Advisory ID:
SA7191
Solution Status:
Vendor Patch
Criticality:
Impact:
System access
Where:
From remote
Short Description:
Postgresql suffers various buffer overflows, these exists in the rpad(), lpad(), repeat() and cash_Word() functions plus others including time/date funtions. [Read More]