French Security Incident Response Team

FrSIRT   

      

   français French  anglais English

 
Vulnerability Notification Service
FrSIRT Partner Program
14-Day Free Trial
Contact FrSIRT Sales Dept.
 

Security Advisories
Linux Security Advisories
Virus and Threats Advisories
Latest Security News
Latest Zero Day Threats
Advisories and vulnerabilities by Vendor
Advisories and vulnerabilities by Keyword
 

Report a security incident
Report a new vulnerability
Security Mailinglist
 

Our Company
FrSIRT in the News
Advertise on FrSIRT.COM
Security Researchers and Exploit Writers Jobs
Contact Us

Trustix Security Update Fixes Multiple Code Execution and Security Bypass Vulnerabilities


Title : Trustix Security Update Fixes Multiple Code Execution and Security Bypass Vulnerabilities
Advisory ID : FrSIRT/ADV-2007-1954
CVE ID : CVE-2007-1558 - CVE-2007-2052 - CVE-2007-2445 - CVE-2007-2754 - CVE-2007-2756
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-05-28

Advisory Details

 
  Description
  Affected Products
  Solution
  References
Technical Description    Receive FrSIRT alerts in a Text format  Receive FrSIRT alerts in a PDF format  Receive FrSIRT alerts in an XML format  Receive FrSIRT notifications by SMS 

Multiple vulnerabilities have been identified in Trustix, which could be exploited by attackers to bypass security restrictions, cause a denial of service or execute arbitrary code [...]

Solution

Upgrade the affected packages :

http://http.trustix.org/pub/trustix/updates/

7e7fca1269d3cef8364255068ca0f0eb 3.0.5/rpms/fetchmail-6.3.8-1tr.i586.rpm
b8253ea826e589446d340459bc0c8e19 3.0.5/rpms/freetype-2.2.1-4tr.i586.rpm
f3f5bc6cd33b050f3b20132ed962c569 3.0.5/rpms/freetype-devel-2.2.1-4tr.i586.rpm
25cb794e2a82cd79cbbacbc5b9a37e90 3.0.5/rpms/gd-2.0.33-9tr.i586.rpm
3ad81c1bb37200a1512548098cc058c5 3.0.5/rpms/gd-devel-2.0.33-9tr.i586.rpm
9ca0451a302ceb6ad281a1387aa0858c 3.0.5/rpms/gd-utils-2.0.33-9tr.i586.rpm
7ef7ade271351a872d36d07474a5df1c 3.0.5/rpms/libpng-1.2.8-7tr.i586.rpm
1f4800a01ce727e0762a03d6111e87e7 3.0.5/rpms/libpng-devel-1.2.8-7tr.i586.rpm
61ad38f6a3575f36373fce0a590a99c4 3.0.5/rpms/libpng-tools-1.2.8-7tr.i586.rpm
190ad056b4845b0a55871ba2a4dc0415 3.0.5/rpms/python24-2.4.3-3tr.i586.rpm
c9f6db6204a43e1dced98335ef2e707e 3.0.5/rpms/python24-devel-2.4.3-3tr.i586.rpm
cf8bc6fad6d1ebe2cbdcd82fa73cb7a5 3.0.5/rpms/python24-docs-2.4.3-3tr.i586.rpm
306f3bb8368df63bfc8d26f943086ed2 3.0.5/rpms/python24-gdbm-2.4.3-3tr.i586.rpm
2efe519b245c7a7ac0d3bf39658ae844 3.0.5/rpms/python24-idle-2.4.3-3tr.i586.rpm
f67994c30577317cd00cc2c7fa12b36e 3.0.5/rpms/python24-modules-2.4.3-3tr.i586.rpm
95d9d0b13dcf5eb4be9e6a244c103073 3.0/rpms/fetchmail-6.3.8-1tr.i586.rpm
4b3632b42bd1f44831553f7e6c0e18d0 3.0/rpms/freetype-2.2.1-3tr.i586.rpm
e8525aeb5dcd9b74803da0ca8cf5a038 3.0/rpms/freetype-devel-2.2.1-3tr.i586.rpm
1b3cc6c8410795d4f0928a00ee21a56e 3.0/rpms/gd-2.0.33-8tr.i586.rpm
74bb9464d9cdf55864d7b9107b411742 3.0/rpms/gd-devel-2.0.33-8tr.i586.rpm
4ddc9896fec17c94f493461a56da0c20 3.0/rpms/gd-utils-2.0.33-8tr.i586.rpm
86ebb35e3ac771671381c57dfa47499a 3.0/rpms/libpng-1.2.8-6tr.i586.rpm
be14341a8c739f36518a9c9be0b1aae3 3.0/rpms/libpng-devel-1.2.8-6tr.i586.rpm
6cdfac28461801d5017364aa3acfe9d7 3.0/rpms/libpng-tools-1.2.8-6tr.i586.rpm
999941386f1af1854592aaeb2527738d 2.2/rpms/freetype-2.2.1-3tr.i586.rpm
2c8e070510dc431d4912d4fd7a718e72 2.2/rpms/freetype-devel-2.2.1-3tr.i586.rpm
75fe49d9388dcd718419d9c7fa295f62 2.2/rpms/gd-2.0.33-6tr.i586.rpm
ffb27b795f47bae1b270d0602b9a8961 2.2/rpms/gd-devel-2.0.33-6tr.i586.rpm
8926492e1dad737d05de5703fa37dfae 2.2/rpms/gd-utils-2.0.33-6tr.i586.rpm
136a054c65e5106c00c1f6e39bb7614c 2.2/rpms/libpng-1.2.7-3tr.i586.rpm
c3f5efe104098c7484f704a6cc52f728 2.2/rpms/libpng-devel-1.2.7-3tr.i586.rpm
29c0926024f2b122073bf96955f3a46b 2.2/rpms/libpng-tools-1.2.7-3tr.i586.rpm

ChangeLog

2007-05-28 : Initial release

Vulnerability Management

Subscribe to FrSIRT VNS and receive real-time e-mail and SMS alerts when new vulnerabilities, exploits, or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form or by email to updates@frsirt.com.


 
 

Search

      

Mailinglist

    
 

Oracle Products Multiple Code Execution and Security Bypass Issues

Oracle Products Command Execution and SQL Injection Vulnerabilities

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle Database "PITRIG_DROPMETADATA" Buffer Overflow Vulnerability

Oracle Products Multiple Code Execution and SQL Injection Vulnerabilities

Oracle JInitiator ActiveX Control Multiple Remote Buffer Overflow Vulnerabilities

Oracle Products Multiple Remote Command Execution and SQL Injection Vulnerabilities

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple TV Multiple File Processing Code Execution Vulnerabilities

Apple Mac OS X Code Execution and Security Bypass Vulnerabilities

Apple iPhone Code Execution and Security Bypass Vulnerabilities

Apple QuickTime Multiple Remote Code Execution Vulnerabilities

Apple iTunes Driver Integer Overflow Privilege Escalation Vulnerability

Apple iPod touch Code Execution and Security Bypass Vulnerabilities

Sun Java System Web Proxy Server FTP Heap Overflow

Sun Solaris ACL UFS File Systems Denial of Service Vulnerability

Sun Solaris Text Editors Tag Files Local Code Execution Vulnerability

Sun Management Center Remote Denial of Service Vulnerability

Sun Solaris Bzip2 Archive Handling Denial of Service Vulnerability

Sun Solaris GNU Tar Headers Handling Buffer Overflow Vulnerability

Sun Solaris Covert Channel Local Security Bypass Vulnerability

Copyright 2003-2008 © FrSIRT.COM - Privacy Policy