Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.54302
Category:Trustix Local Security Checks
Title:Trustix Security Advisory TSLSA-2004-0058 (Multiple packages)
Summary:NOSUMMARY
Description:Description:

The remote host is missing updates announced in
advisory TSLSA-2004-0058.


gd:
There has been found serveral overflows in gd. This can be used to
execute arbitary code in programs using the gd library.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-0941 and CVE-2004-0990 to these issues.


sqlgrey:
Matt Linzbach made us aware that the maintainers of SQLgrey have issued
a new release that fixes an SQL injection bug.


samba:
From the Samba advisory:
Invalid bounds checking in reply to certain trans2 requests
could result in a buffer overrun in smbd. In order to exploit
this defect, the attacker must be able to create files with very
specific Unicode filenames on the Samba share.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-0882 to this issue.

From the Samba advisory:
A bug in the input validation routines used to match
filename strings containing wildcard characters may allow
a user to consume more than normal amounts of CPU cycles
thus impacting the performance and response of the server.
In some circumstances the server can become entirely
unresponsive.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CVE-2004-0930 to this issue.


sudo:
Bash exported functions and the CDPATH variable are now stripped from
the environment passed to the program to be executed.




Solution:
Update your system with the packages as indicated in
the referenced security advisory.

http://www.securityspace.com/smysecure/catid.html?in=TSLSA-2004-0058

Risk factor : Critical

CVSS Score:
10.0

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2004-0941
BugTraq ID: 11663
http://www.securityfocus.com/bid/11663
Computer Incident Advisory Center Bulletin: P-071
http://www.ciac.org/ciac/bulletins/p-071.shtml
Debian Security Information: DSA-601 (Google Search)
http://www.debian.org/security/2004/dsa-601
http://www.mandriva.com/security/advisories?name=MDKSA-2006:113
http://www.mandriva.com/security/advisories?name=MDKSA-2006:114
http://www.mandriva.com/security/advisories?name=MDKSA-2006:122
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11176
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1195
http://www.redhat.com/support/errata/RHSA-2004-638.html
http://www.redhat.com/support/errata/RHSA-2006-0194.html
http://secunia.com/advisories/13179/
http://secunia.com/advisories/18686
http://secunia.com/advisories/20824
http://secunia.com/advisories/21050
http://www.trustix.org/errata/2004/0058
https://www.ubuntu.com/usn/usn-25-1/
https://www.ubuntu.com/usn/usn-33-1/
XForce ISS Database: gd-graphics-gdmalloc-bo(18048)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18048
Common Vulnerability Exposure (CVE) ID: CVE-2004-0990
BugTraq ID: 11523
http://www.securityfocus.com/bid/11523
Bugtraq: 20041026 libgd integer overflow (Google Search)
http://marc.info/?l=bugtraq&m=109882489302099&w=2
Debian Security Information: DSA-589 (Google Search)
http://www.debian.org/security/2004/dsa-589
Debian Security Information: DSA-591 (Google Search)
http://www.debian.org/security/2004/dsa-591
Debian Security Information: DSA-602 (Google Search)
http://www.debian.org/security/2004/dsa-602
http://www.mandriva.com/security/advisories?name=MDKSA-2004:132
http://www.osvdb.org/11190
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1260
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9952
http://secunia.com/advisories/18717
http://secunia.com/advisories/20866
http://secunia.com/advisories/23783
SuSE Security Announcement: SUSE-SR:2006:003 (Google Search)
http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html
https://www.ubuntu.com/usn/usn-11-1/
XForce ISS Database: gd-png-bo(17866)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17866
Common Vulnerability Exposure (CVE) ID: CVE-2004-0882
http://lists.apple.com/archives/security-announce/2005/Mar/msg00000.html
Bugtraq: 20041115 Advisory 13/2004: Samba 3.x QFILEPATHINFO unicode filename buffer overflow (Google Search)
http://marc.info/?l=bugtraq&m=110054671403755&w=2
Bugtraq: 20041115 [SAMBA] CAN-2004-0882: Possiebl Buffer Overrun in smbd (Google Search)
http://marc.info/?l=bugtraq&m=110055646329581&w=2
Bugtraq: 20041217 [OpenPKG-SA-2004.054] OpenPKG Security Advisory (samba) (Google Search)
http://marc.info/?l=bugtraq&m=110330519803655&w=2
CERT/CC vulnerability note: VU#457622
http://www.kb.cert.org/vuls/id/457622
Computer Incident Advisory Center Bulletin: P-038
http://www.ciac.org/ciac/bulletins/p-038.shtml
Conectiva Linux advisory: CLA-2004:899
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000899
http://security.e-matters.de/advisories/132004.html
http://www.osvdb.org/11782
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9969
SCO Security Bulletin: SCOSA-2005.17
ftp://ftp.sco.com/pub/updates/UnixWare/SCOSA-2005.17/SCOSA-2005.17.txt
http://securitytracker.com/id?1012235
http://secunia.com/advisories/13189
SGI Security Advisory: 20041201-01-P
ftp://patches.sgi.com/support/free/security/advisories/20041201-01-P
SuSE Security Announcement: SUSE-SA:2004:040 (Google Search)
http://www.novell.com/linux/security/advisories/2004_40_samba.html
http://www.trustix.net/errata/2004/0058/
XForce ISS Database: samba-qfilepathinfo-bo(18070)
https://exchange.xforce.ibmcloud.com/vulnerabilities/18070
Common Vulnerability Exposure (CVE) ID: CVE-2004-0930
BugTraq ID: 11624
http://www.securityfocus.com/bid/11624
Bugtraq: 20041108 [SECURITY] CAN-2004-0930: Potential Remote Denial of Service Vulnerability (Google Search)
http://marc.info/?l=bugtraq&m=109993720717957&w=2
http://www.gentoo.org/security/en/glsa/glsa-200411-21.xml
http://www.idefense.com/application/poi/display?id=156&type=vulnerabilities&flashstatus=false
http://www.mandriva.com/security/advisories?name=MDKSA-2004:131
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10936
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101783-1
https://www.ubuntu.com/usn/usn-22-1/
XForce ISS Database: samba-msfnmatch-dos(17987)
https://exchange.xforce.ibmcloud.com/vulnerabilities/17987
CopyrightCopyright (c) 2005 E-Soft Inc. http://www.securityspace.com

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.