Linux vendors Red Hat, Novell/SUSE, Mandrakesoft, Debian and Gentoo have issued advisories and patches this week for a number of different vulnerabilities that have hit them.
Red Hat The Xpdf
Red Hat packages were also updated to prevent the exploitation
of a buffer overflow that was found in the PDF viewer. Red Hat noted in
its advisory,
however, that the Exec-Shield technology (enabled by default
since Update 3) will block attempts to exploit this vulnerability on x86
architectures.
Red Hat Enterprise Linux Update 3, which was released in
September and also included NX (no execute) support, was a source of discussion
on the main Linux Kernel developers' list in June.
Red Hat also updated its
Mozilla packages
to fix a buffer overflow issue
(CAN-2004-1316) in the way the browser handles NNTP Novell's Both Debian
and Gentoo
issued updates for their respective exim
packages, which could have possibly been exploited to allow for a local
privilege escalation attack. Exim is a configurable message transfer
agent (MTA).
Additionally, Gentoo issued an
update
to cover the "multiple overflows [that] have been found in the imlib2 library image decoding routines,
potentially allowing the execution of arbitrary code."
Not to be left out of the patch bonanza, Mandrakesoft
issued a patch
for its imlib image handler packages. There was a heap overflow as well as
integer overflow vulnerability in the packages that could have allowed an
attacker to crash a system or execute arbitrary code when an image file
was opened. The same vulnerability also exists in Gentoo's imlib2
packages and has also had a patch issued for it.
Loading Comments...