Description: | Description:
The remote host is missing updates announced in advisory TSLSA-2004-0058.
gd: There has been found serveral overflows in gd. This can be used to execute arbitary code in programs using the gd library.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0941 and CVE-2004-0990 to these issues.
sqlgrey: Matt Linzbach made us aware that the maintainers of SQLgrey have issued a new release that fixes an SQL injection bug.
samba: From the Samba advisory: Invalid bounds checking in reply to certain trans2 requests could result in a buffer overrun in smbd. In order to exploit this defect, the attacker must be able to create files with very specific Unicode filenames on the Samba share.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0882 to this issue.
From the Samba advisory: A bug in the input validation routines used to match filename strings containing wildcard characters may allow a user to consume more than normal amounts of CPU cycles thus impacting the performance and response of the server. In some circumstances the server can become entirely unresponsive.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-0930 to this issue.
sudo: Bash exported functions and the CDPATH variable are now stripped from the environment passed to the program to be executed.
Solution: Update your system with the packages as indicated in the referenced security advisory.
http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2004-0058
Risk factor : Critical
CVSS Score: 10.0
|