LWN.net Logo

Advertisement

E-Commerce & credit card processing - the Open Source way!

Advertise here

An OpenOffice.org vulnerability

April 13, 2005

This article was contributed by Joe 'Zonker' Brockmeier.

Many OpenOffice.org users have felt secure in using OpenOffice.org to open Microsoft Office files, assuming that the malware that attacks Microsoft Office would not affect the OpenOffice.org suite.

That may well be true, but it looks like the OpenOffice.org suite has a problem of its own. The OpenOffice.org suite has a vulnerability in its handling of .doc files. The flaw was discovered at the end of March, and was reported to the full-disclosure mailing list on Monday. The vulnerability affects the 1.1.4 and 2.0 series of the OpenOffice.org suite. It's unclear whether the vulnerability affects StarOffice, but it seems likely that it would.

According to the Secunia advisory the problem is a boundary error in the "StgCompObjStream::Load()" function used to process .doc files. Theoretically, this vulnerability could be exploited to execute code in almost all versions of OpenOffice.org if a user opens a specially-crafted document. The vulnerability has been labeled "moderately critical" by Secunia, because it could allow a system to be compromised, but requires user interaction.

We touched base with OpenOffice.org community manager Louis Suarez-Potts about the bug. According to Suarez-Potts, work "began immediately" when the vulnerability was discovered, and the project is testing the patch on all platforms and languages supported by the OpenOffice.org suite.

At this time, Suarez-Potts says that the project is not aware of any real-world exploits of this vulnerability. The vulnerability exists on all platforms, but he said that he has "no idea" if it would be possible to craft a document to do something harmful on all platforms, or if it would only be possible to target one platform with a malformed .doc file.

It does seem likely that the OpenOffice.org project will be targeted more frequently by malware authors as it gains in popularity, though Suarez-Potts says that OpenOffice.org is "not as fun a target as MSFT."

This should serve as a cautionary tale for users of the OpenOffice.org suite. While this particular vulnerability was discovered before any exploits appeared in the wild, it's possible that exploits for future vulnerabilities could appear before the first report. Even though OpenOffice.org has a much better track record than Microsoft Office, users should exercise caution when opening any document from an untrusted source.

The LWN vulnerability database entry for this bug will track updates as they become available.

Comments (2 posted)

New vulnerabilities

Axel: vulnerability in HTTP redirection handling

Package(s):axel CVE #(s):CAN-2005-0390
Created:April 12, 2005 Updated:April 13, 2005
Description: A possible buffer overflow has been reported in the HTTP redirection handling code in conn.c. A remote attacker could exploit this vulnerability by setting up a malicious site and enticing a user to connect to it. This could possibly lead to the execution of arbitrary code with the permissions of the user running Axel.
Alerts:
Gentoo 200504-09 2005-04-12
Debian DSA-706-1 2005-04-13

Comments (none posted)

gld: multiple vulnerabilities

Package(s):gld CVE #(s):
Created:April 13, 2005 Updated:April 13, 2005
Description: The Postfix graylisting daemon (gld), through version 1.4, contains several remotely exploitable buffer overflow vulnerabilities. See this advisory for details.
Alerts:
Gentoo 200504-10 2005-04-13

Comments (none posted)

junkbuster: heap corruption and settings modification

Package(s):junkbuster CVE #(s):CVE-2005-1108 CVE-2005-1109
Created:April 13, 2005 Updated:November 5, 2005
Description: JunkBuster through version 2.02-r2 contains two vulnerabilities: a heap corruption bug and a possible privacy violation.
Alerts:
Gentoo 200504-11 2005-04-13
Debian DSA-713-1 2005-04-21

Comments (1 posted)

kernel: arbitrary code execution, DoS

Package(s):kernel CVE #(s):CAN-2005-0867 CAN-2005-0937
Created:April 11, 2005 Updated:April 19, 2005
Description: Alexander Nyberg discovered an integer overflow in the sysfs_write_file() function. A local attacker could exploit this to crash the kernel or possibly even execute arbitrary code with root privileges by writing to an user-writable file in /sys under certain low-memory conditions. However, there are very few cases where a user-writeable sysfs file actually exists. (CAN-2005-0867)

Olof Johansson discovered a Denial of Service vulnerability in the futex functions, which provide semaphores for exclusive locking of resources. A local attacker could possibly exploit this to cause a kernel deadlock. (CAN-2005-0937)

Alerts:
Ubuntu USN-110-1 2005-04-11
Red Hat RHSA-2005:366-01 2005-04-19

Comments (none posted)

OpenOffice.org: .doc parser buffer overflow

Package(s):openoffice.org CVE #(s):CAN-2005-0941
Created:April 13, 2005 Updated:May 13, 2005
Description: OpenOffice.org suffers from a buffer overflow in the parsing code for MS Word files; see this advisory for details. Since this vulnerability could conceivably be exploited via files received in email messages, it should be taken seriously.
Alerts:
Fedora FEDORA-2005-316 2005-04-13
Gentoo 200504-13 2005-04-15
SuSE SUSE-SA:2005:025 2005-04-19
Red Hat RHSA-2005:375-01 2005-04-25
Mandriva MDKSA-2005:082 2005-05-06
Ubuntu USN-121-1 2005-05-06
Fedora-Legacy FLSA:154988 2005-05-12

Comments (none posted)

phpMyAdmin: cross-site scripting

Package(s):phpmyadmin CVE #(s):
Created:April 11, 2005 Updated:April 13, 2005
Description: phpMyAdmin versions before 2.6.2-rc1 are vulnerable to a cross-site scripting attack. An attacker sending a specially-crafted request could inject and execute malicious script code.
Alerts:
Gentoo 200504-08 2005-04-11

Comments (none posted)

rsnapshot: symlink vulnerability

Package(s):rsnapshot CVE #(s):
Created:April 13, 2005 Updated:April 13, 2005
Description: rsnapshot (prior to version 1.2.1) suffers from a symlink vulnerability.
Alerts:
Gentoo 200504-12 2005-04-13

Comments (none posted)

Updated vulnerabilities

OpenSSL: denial of service vulnerabilities

Package(s):OpenSSL CVE #(s):CAN-2004-0081 CAN-2003-0851
Created:March 17, 2004 Updated:November 2, 2005
Description: Versions 0.9.7a-c of the OpenSSL library suffer from two denial of service vulnerabilities; see the version 0.9.7d release announcement for details.
Alerts:
EnGarde ESA-20040317-003 2004-03-17
Red Hat RHSA-2004:119-01 2004-03-17
Red Hat RHSA-2004:120-01 2004-03-17
SuSE SuSE-SA:2004:007 2004-03-17
Mandrake MDKSA-2004:023 2004-03-17
Netwosix NW-2004-0005 2004-03-17
Debian DSA-465-1 2004-03-17
Gentoo 200403-03 2004-03-17
OpenPKG OpenPKG-SA-2004.007 2004-03-18
Red Hat RHSA-2004:121-01 2004-03-17
Slackware SSA:2004-077-01 2004-03-17
Trustix TSLSA-2004-0012 2004-03-17
Whitebox WBSA-2004:120-01 2004-03-22
Fedora FEDORA-2004-095 2004-03-19
Red Hat RHSA-2004:084-01 2004-03-23
Whitebox WBSA-2004:084-01 2004-03-23
Conectiva CLA-2004:834 2004-03-31
Fedora-Legacy FLSA:1395 2004-05-08
Fedora FEDORA-2005-1042 2005-10-31
Red Hat RHSA-2005:829-00 2005-11-02
Red Hat RHSA-2005:830-00 2005-11-02

Comments (1 posted)

a2ps: input validation error

Package(s):a2ps CVE #(s):CAN-2004-1170 CAN-2004-1377
Created:November 26, 2004 Updated:December 19, 2005
Description: The GNU a2ps utility fails to properly sanitize filenames, which can be abused by a malicious user to execute arbitrary commands with the privileges of the user running the vulnerable application. More information at Security Focus.
Alerts:
Mandrake MDKSA-2004:140 2004-11-25
Debian DSA-612-1 2004-12-20
Gentoo 200501-02 2005-01-04
OpenPKG OpenPKG-SA-2005.003 2005-01-17
Mandriva MDKSA-2005:097 2005-06-07
Fedora-Legacy FLSA:152870 2005-12-17

Comments (none posted)

cdrecord: insecure temp file

Package(s):cdrecord CVE #(s):CAN-2005-0866
Created:March 24, 2005 Updated:April 28, 2005
Description: The cdrecord utility makes insecure temp files if DEBUG is enabled in /etc/cdrecord/rscsi. This can allow a local user to launch a sym link attack and execute code with the user's privileges.
Alerts:
Ubuntu USN-100-1 2005-03-24
Mandriva MDKSA-2005:077 2005-04-20

Comments (1 posted)

cpio - file permissions error

Package(s):cpio CVE #(s):CAN-1999-1572
Created:February 2, 2005 Updated:July 19, 2005
Description: Some versions of cpio contain an ancient vulnerability where files created by that utility have overly generous access permissions.
Alerts:
Debian DSA-664-1 2005-02-02
Ubuntu USN-75-1 2005-02-04
Mandrake MDKSA-2005:032 2005-02-10
Mandrake MDKSA-2005:032-1 2005-02-11
Red Hat RHSA-2005:073-01 2005-02-15
Red Hat RHSA-2005:080-01 2005-02-18
Fedora-Legacy FLSA:152891 2005-07-15

Comments (none posted)

cURL: buffer overflow

Package(s):curl CVE #(s):CAN-2005-0490
Created:February 28, 2005 Updated:July 19, 2005
Description: Multiple stack-based buffer overflows in libcURL and cURL 7.12.1, and possibly other versions, allow remote malicious web servers to execute arbitrary code via base64 encoded replies that exceed the intended buffer lengths when decoded.
Alerts:
Ubuntu USN-86-1 2005-02-28
SuSE SUSE-SA:2005:011 2005-02-28
Mandrake MDKSA-2005:048 2005-03-04
Gentoo 200503-20 2005-03-16
Conectiva CLA-2005:940 2005-03-21
Red Hat RHSA-2005:340-01 2005-04-05
Fedora FEDORA-2005-325 2005-04-20
Fedora-Legacy FLSA:152917 2005-07-15

Comments (none posted)

cyrus-imapd: buffer overflows

Package(s):cyrus-imapd CVE #(s):CAN-2005-0546
Created:February 23, 2005 Updated:April 9, 2006
Description: Cyrus-imapd, prior to version 2.2.12, contains several buffer overflows which could be exploited by an (authenticated) attacker to run code on the server system.
Alerts:
Gentoo 200502-29 2005-02-23
SuSE SUSE-SA:2005:009 2005-02-24
Ubuntu USN-87-1 2005-02-28
Mandrake MDKSA-2005:051 2005-03-04
Conectiva CLA-2005:937 2005-03-17
OpenPKG OpenPKG-SA-2005.005 2005-04-05
Fedora FEDORA-2005-339 2005-04-27
Red Hat RHSA-2005:408-01 2005-05-17
Fedora-Legacy FLSA:156290 2006-04-04

Comments (none posted)

dhcp: format string vulnerability

Package(s):dhcp CVE #(s):CAN-2004-1006
Created:November 4, 2004 Updated:July 13, 2005
Description: Dhcp has a format string vulnerability in the log functions of dhcp 2.x that may be exploited via a malicious DNS server.
Alerts:
Debian DSA-584-1 2004-11-04
Red Hat RHSA-2005:212-01 2005-04-12
Fedora-Legacy FLSA:152835 2005-07-10

Comments (none posted)

Dnsmasq: poisoning and DoS

Package(s):dnsmasq CVE #(s):
Created:April 4, 2005 Updated:July 21, 2005
Description: Dnsmasq does not properly detect that DNS replies received do not correspond to any DNS query that was sent. Rob Holland of the Gentoo Linux Security Audit team also discovered two off-by-one buffer overflows that could crash DHCP lease files parsing.
Alerts:
Gentoo 200504-03 2005-04-04
Slackware SSA:2005-201-01 2005-07-21

Comments (none posted)

emacs21: format string vulnerability in "movemail"

Package(s):emacs21 CVE #(s):CAN-2005-0100
Created:February 7, 2005 Updated:May 15, 2006
Description: Max Vozeler discovered a format string vulnerability in the "movemail" utility of Emacs. By sending specially crafted packets, a malicious POP3 server could cause a buffer overflow, which could be exploited to execute arbitrary code with the privileges of the user and the "mail" group.
Alerts:
Ubuntu USN-76-1 2005-02-07
Debian DSA-670-1 2005-02-08
Debian DSA-671-1 2005-02-08
Fedora FEDORA-2005-115 2005-02-08
Fedora FEDORA-2005-116 2005-02-08
Red Hat RHSA-2005:112-01 2005-02-10
Red Hat RHSA-2005:134-01 2005-02-10
Red Hat RHSA-2005:110-01 2005-02-15
Red Hat RHSA-2005:133-01 2005-02-15
Fedora FEDORA-2005-145 2005-02-14
Fedora FEDORA-2005-146 2005-02-14
Gentoo 200502-20 2005-02-15
Mandrake MDKSA-2005:038 2005-02-15
Debian DSA-685-1 2005-02-17
Fedora-Legacy FLSA:152898 2006-05-12

Comments (none posted)

enscript: arbitrary code execution

Package(s):enscript CVE #(s):CAN-2004-1184 CAN-2004-1185 CAN-2004-1186
Created:January 21, 2005 Updated:May 27, 2006
Description: Erik Sjölund has discovered several security relevant problems in enscript, a program to convert ASCII text into Postscript and other formats. Unsanitized input can cause the execution of arbitrary commands via EPSF pipe support. Due to missing sanitizing of filenames it is possible that a specially crafted filename can cause arbitrary commands to be executed. Multiple buffer overflows can cause the program to crash.
Alerts:
Debian DSA-654-1 2005-01-21
Ubuntu USN-68-1 2005-01-24
Fedora FEDORA-2005-015 2005-01-26
Fedora FEDORA-2005-016 2005-01-26
Fedora FEDORA-2005-091 2005-01-28
Fedora FEDORA-2005-092 2005-01-28
Fedora FEDORA-2005-096 2005-01-31
Red Hat RHSA-2005:039-01 2005-02-01
Gentoo 200502-03 2005-02-02
Mandrake MDKSA-2005:033 2005-02-10
Red Hat RHSA-2005:040-01 2005-02-15
Fedora-Legacy FLSA:152892 2005-12-17
rPath rPSA-2006-0083-1 2006-05-26

Comments (none posted)

evolution: arbitrary code execution

Package(s):evolution CVE #(s):CAN-2005-0102
Created:January 24, 2005 Updated:May 19, 2005
Description: Max Vozeler discovered an integer overflow in camel-lock-helper. A user-supplied length value was not validated, so that a value of -1 caused a buffer allocation of 0 bytes; this buffer was then filled by an arbitrary amount of user-supplied data. A local attacker or a malicious POP3 server could exploit this to execute arbitrary code with root privileges (because camel-lock-helper is installed as setuid root).
Alerts:
Ubuntu USN-69-1 2005-01-24
Gentoo 200501-35 2005-01-24
Mandrake MDKSA-2005:024 2005-01-27
Debian DSA-673-1 2005-02-10
Conectiva CLA-2005:925 2005-02-16
Red Hat RHSA-2005:238-01 2005-05-19

Comments (1 posted)

evolution: message crash vulnerability

Package(s):evolution CVE #(s):CAN-2005-0806
Created:March 17, 2005 Updated:August 11, 2005
Description: The Evolution mail client can be crashed when reading certain types of messages.
Alerts:
Mandrake MDKSA-2005:059 2005-03-16
Fedora FEDORA-2005-338 2005-04-22
Conectiva CLA-2005:950 2005-04-27
Red Hat RHSA-2005:397-01 2005-05-04
Ubuntu USN-166-1 2005-08-11

Comments (none posted)

f2c: insecure temp files

Package(s):f2c CVE #(s):CAN-2005-0017 CAN-2005-0018
Created:January 27, 2005 Updated:April 20, 2005
Description: The f2c fortran to C translator has a vulnerability due to insecure opening of temporary files. A local attacker can use this to launch a symlink attack.
Alerts:
Debian DSA-661-1 2005-01-27
Gentoo 200501-43 2005-01-30
Debian DSA-661-2 2005-04-20

Comments (none posted)

Foomatic: Arbitrary command execution in foomatic-rip

Package(s):foomatic CVE #(s):CAN-2004-0801
Created:September 20, 2004 Updated:May 31, 2006
Description: There is a vulnerability in the foomatic-filters package. This vulnerability is due to insufficient checking of command-line parameters and environment variables in the foomatic-rip filter. This vulnerability may allow both local and remote attackers to execute arbitrary commands on the print server with the permissions of the spooler.
Alerts:
Gentoo 200409-24 2004-09-20
Fedora FEDORA-2004-303 2004-09-21
Conectiva CLA-2004:880 2004-10-27
Fedora-Legacy FLSA:2076 2004-11-05
SuSE SUSE-SA:2006:026 2006-05-30

Comments (none posted)

gaim: client freezes

Package(s):gaim CVE #(s):CAN-2005-0472 CAN-2005-0473
Created:February 22, 2005 Updated:April 27, 2005
Description: The Gaim client freezes when receiving certain invalid messages and crashes when receiving specific malformed HTML. See this Secunia Advisory for additional information.
Alerts:
Fedora FEDORA-2005-159 2005-02-21
Fedora FEDORA-2005-160 2005-02-21
Ubuntu USN-85-1 2005-02-25
Debian DSA-716-1 2005-04-27

Comments (none posted)

gaim: buffer overflow, DoS

Package(s):gaim CVE #(s):CAN-2005-0965 CAN-2005-0966
Created:April 5, 2005 Updated:May 15, 2005
Description: Jean-Yves Lefort discovered a buffer overflow in the gaim_markup_strip_html() function. This caused Gaim to crash when receiving certain malformed HTML messages. (CAN-2005-0965)

Jean-Yves Lefort also noticed that many functions that handle IRC commands do not escape received HTML metacharacters; this allowed remote attackers to cause a Denial of Service by injecting arbitrary HTML code into the conversation window, popping up arbitrarily many empty dialog boxes, or even causing Gaim to crash. (CAN-2005-0966)

Alerts:
Ubuntu USN-106-1 2005-04-05
Fedora FEDORA-2005-298 2005-04-05
Fedora FEDORA-2005-299 2005-04-05
Gentoo 200504-05 2005-04-06
Red Hat RHSA-2005:365-01 2005-04-12
Mandriva MDKSA-2005:071 2005-04-13
Slackware SSA:2005-111-03 2005-04-22
Conectiva CLA-2005:949 2005-04-27
Slackware SSA:2005-133-01 2005-05-15

Comments (none posted)

gtk-pixbuf, gtk2: denial of service

Package(s):gdk-pixbuf gtk2 CVE #(s):CAN-2005-0891
Created:March 30, 2005 Updated:December 19, 2005
Description: The BMP image processing code in gdk-pixbuf and gtk2 contains a denial of service vulnerability exploitable via a specially crafted image file.
Alerts:
Fedora FEDORA-2005-265 2005-03-30
Fedora FEDORA-2005-266 2005-03-30
Fedora FEDORA-2005-267 2005-03-30
Fedora FEDORA-2005-268 2005-03-30
Red Hat RHSA-2005:344-01 2005-04-01
Red Hat RHSA-2005:343-01 2005-04-05
Ubuntu USN-108-1 2005-04-05
Mandrake MDKSA-2005:068 2005-04-07
Mandrake MDKSA-2005:069 2005-04-07
SuSE SUSE-SR:2005:010 2005-04-08
Fedora-Legacy FLSA:154272 2005-07-15
Fedora-Legacy FLSA:155510 2005-12-17

Comments (none posted)

gettext: Insecure temporary file handling

Package(s):gettext CVE #(s):CAN-2004-0966
Created:October 11, 2004 Updated:March 1, 2006
Description: gettext insecurely creates temporary files in world-writeable directories with predictable names. A local attacker could create symbolic links in the temporary files directory, pointing to a valid file somewhere on the filesystem. When gettext is called, this would result in file access with the rights of the user running the utility, which could be the root user.
Alerts:
Gentoo 200410-10 2004-10-10
Ubuntu USN-5-1 2004-10-27
OpenPKG OpenPKG-SA-2004.055 2004-12-23
Gentoo 200410-10:02 2004-10-10
Fedora-Legacy FLSA:136323 2006-01-09
Mandriva MDKSA-2006:051 2006-02-28

Comments (1 posted)

gftp: missing input sanitizing

Package(s):gftp CVE #(s):CAN-2005-0372 CAN-2004-1376
Created:February 17, 2005 Updated:July 13, 2005
Description: gftp has a directory traversal vulnerability. A remote server could use specially crafted filenames to overwrite local files.
Alerts:
Debian DSA-686-1 2005-02-17
SuSE SUSE-SR:2005:005 2005-02-18
Gentoo 200502-27 2005-02-19
Mandrake MDKSA-2005:050 2005-03-04
Fedora FEDORA-2005-309 2005-04-07
Fedora FEDORA-2005-310 2005-04-07
Red Hat RHSA-2005:410-01 2005-06-13
Fedora-Legacy FLSA:152908 2005-07-10

Comments (none posted)

ghostscript: symlink vulnerabilities

Package(s):ghostscript CVE #(s):CAN-2004-0967
Created:October 20, 2004 Updated:September 28, 2005
Description: The ghostscript package (prior to version 7.07.1-r7) contains several scripts which are vulnerable to symlink attacks.
Alerts:
Gentoo 200410-18 2004-10-20
Ubuntu USN-3-1 2004-10-27
Red Hat RHSA-2005:081-01 2005-09-28

Comments (none posted)

glibc: Information leak with LD_DEBUG

Package(s):glibc CVE #(s):CAN-2004-1453
Created:August 17, 2004 Updated:May 26, 2005
Description: Silvio Cesare discovered a potential information leak in glibc. It allows LD_DEBUG on SUID binaries where it should not be allowed. This has various security implications, which may be used to gain confidential information. An attacker can gain the list of symbols a SUID application uses and their locations and can then use a trojaned library taking precedence over those symbols to gain information or perform further exploitation.
Alerts:
Gentoo 200408-16 2004-08-16
Red Hat RHSA-2005:256-01 2005-05-18

Comments (1 posted)

glibc: tempfile vulnerability in catchsegv script

Package(s):glibc CVE #(s):CAN-2004-0968
Created:October 21, 2004 Updated:November 14, 2005
Description: The catchsegv script in the glibc package has a symlink vulnerability that may allow a local user to overwrite arbitrary files with the permissions of the user that is running the script.
Alerts:
Gentoo 200410-19 2004-10-21
Ubuntu USN-4-1 2004-10-27
Fedora FEDORA-2004-356 2004-11-11
Red Hat RHSA-2004:586-01 2004-12-20
Mandrake MDKSA-2004:159 2004-12-29
Debian DSA-636-1 2005-01-12
Red Hat RHSA-2005:261-01 2005-04-28
Fedora-Legacy FLSA:152848 2005-11-13

Comments (none posted)

gnupg: information leak

Package(s):gnupg CVE #(s):CAN-2005-0366
Created:March 16, 2005 Updated:August 19, 2005
Description: GnuPG (and other PGP-like systems) suffers from an information leak which could, in some situations, be used by an attacker to obtain plain text from an encrypted message. See this message for a detailed explanation of the problem. "We know of no real-world application that is affected by this type of attack. It is an attack that requires the active participation of someone who holds the actual key required to decrypt a message. Thus, it is not something you are likely to see."
Alerts:
Mandrake MDKSA-2005:057 2005-03-15
Gentoo 200503-29 2005-03-24
Ubuntu USN-170-1 2005-08-19

Comments (none posted)

grip: buffer overflow

Package(s):grip CVE #(s):CAN-2005-0706
Created:March 10, 2005 Updated:September 16, 2005
Description: Grip, a CD ripper, has a buffer overflow vulnerability that can occur when the CDDB server returns more than 16 matches.
Alerts:
Fedora FEDORA-2005-202 2005-03-09
Fedora FEDORA-2005-203 2005-03-09
Gentoo 200503-21 2005-03-17
Red Hat RHSA-2005:304-01 2005-03-28
Mandrake MDKSA-2005:066 2005-04-01
Gentoo 200504-07 2005-04-08
Mandriva MDKSA-2005:075 2005-04-20
Mandriva MDKSA-2005:074 2005-04-20
Fedora-Legacy FLSA:152919 2005-09-15

Comments (none posted)

groff: insecure temporary directory

Package(s):groff CVE #(s):CAN-2004-0969
Created:November 1, 2004 Updated:February 9, 2006
Description: Recently, Trustix Secure Linux discovered a vulnerability in the groff package. The utility "groffer" created a temporary directory in an insecure way, which allowed exploitation of a race condition to create or overwrite files with the privileges of the user invoking the program.
Alerts:
Ubuntu USN-13-1 2004-11-01
Gentoo 200411-15 2004-11-08
Mandriva MDKSA-2006:038 2006-02-08

Comments (none posted)

gtkhtml: malformed messages cause crash

Package(s):gtkhtml CVE #(s):CAN-2003-0133 CAN-2003-0541
Created:April 14, 2003 Updated:April 18, 2005
Description: GtkHTML is the HTML rendering widget used by the Evolution mail reader.

GtkHTML supplied with versions of Evolution prior to 1.2.4 contain a bug when handling HTML messages. Alan Cox discovered that certain malformed messages could cause the Evolution mail component to crash.

Alerts:
Red Hat RHSA-2003:126-01 2003-04-14
Mandrake MDKSA-2003:046 2003-04-15
Red Hat RHSA-2003:264-01 2003-09-09
Conectiva CLA-2003:737 2003-09-12
Mandrake MDKSA-2003:093 2003-09-18
Debian DSA-710-1 2005-04-18

Comments (none posted)

htdig: cross site scripting

Package(s):htdig CVE #(s):CAN-2005-0085
Created:February 14, 2005 Updated:January 10, 2006
Description: Michael Krax discovered that ht://Dig fails to validate the 'config' parameter before displaying an error message containing the parameter. This flaw could allow an attacker to conduct cross-site scripting attacks.
Alerts:
Gentoo 200502-16 2005-02-13
Debian DSA-680-1 2005-02-14
Red Hat RHSA-2005:090-01 2005-02-15
Mandrake MDKSA-2005:063 2005-03-31
Fedora-Legacy FLSA:152907 2006-01-09

Comments (none posted)

imap: buffer overflow in c-client

Package(s):imap CVE #(s):CAN-2003-0297
Created:February 18, 2005 Updated:April 9, 2006
Description: A buffer overflow flaw was found in the c-client IMAP client. An attacker could create a malicious IMAP server that if connected to by a victim could execute arbitrary code on the client machine.
Alerts:
Red Hat RHSA-2005:114-01 2005-02-18
Fedora-Legacy FLSA:152912 2005-05-12
Fedora-Legacy FLSA:184074 2006-04-04

Comments (none posted)

imlib2: buffer overflows

Package(s):imlib2 CVE #(s):CAN-2004-0802 CAN-2004-0817
Created:September 8, 2004 Updated:October 26, 2005
Description: The imlib2 library contains buffer overflows in the BMP handling code.
Alerts:
Mandrake MDKSA-2004:089 2004-09-07
Fedora FEDORA-2004-300 2004-09-09
Fedora FEDORA-2004-301 2004-09-09
Gentoo 200409-12 2004-09-08
Red Hat RHSA-2004:465-01 2004-09-15
Debian DSA-548-1 2004-09-16
Debian DSA-552-1 2004-09-22
Conectiva CLA-2004:870 2004-09-28
Debian DSA-548-2 2005-10-26

Comments (none posted)

kdelibs: unsanitzied input

Package(s):kdelibs CVE #(s):CAN-2004-1165
Created:January 10, 2005 Updated:July 19, 2005
Description: Thiago Macieira discovered a vulnerability in the kioslave library, which is part of kdelibs, which allows a remote attacker to execute arbitrary FTP commands via an ftp:// URL that contains an URL-encoded newline before the FTP command.
Alerts:
Debian DSA-631-1 2005-01-10
Gentoo 200501-18 2005-01-11
Fedora FEDORA-2005-063 2005-01-25
Fedora FEDORA-2005-064 2005-01-25
Red Hat RHSA-2005:009-01 2005-02-10
Red Hat RHSA-2005:065-01 2005-02-15
Mandrake MDKSA-2005:045 2005-02-17
Fedora-Legacy FLSA:152769 2005-07-15

Comments (none posted)

kdelibs: dcopserver vulnerability

Package(s):kdelibs CVE #(s):CAN-2005-0396 CAN-2005-0237 CAN-2005-0365
Created:March 17, 2005 Updated:May 17, 2005
Description: The KDE Desktop Communication Protocol daemon (dcopserver) is vulnerable to lockup by a local user, leading to a denial of service.
Alerts:
Mandrake MDKSA-2005:058 2005-03-16
Gentoo 200503-22 2005-03-19
Red Hat RHSA-2005:325-01 2005-03-23
Fedora FEDORA-2005-244 2005-03-23
Fedora FEDORA-2005-245 2005-03-23
Red Hat RHSA-2005:307-01 2005-04-06
SuSE SUSE-SA:2005:022 2005-04-11
Conectiva CLA-2005:953 2005-05-17

Comments (none posted)

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CAN-2005-0400 CAN-2005-0749 CAN-2005-0750 CAN-2005-0815 CAN-2005-0839
Created:April 1, 2005 Updated:July 1, 2005
Description: More kernel vulnerabilities have been discovered including:
  • Mathieu Lafon discovered an information leak in the ext2 file system driver. (CAN-2005-0400)
  • Yichen Xie discovered a Denial of Service vulnerability in the ELF loader. (CAN-2005-0749)
  • Ilja van Sprundel discovered that the bluez_sock_create() function did not check its "protocol" argument for negative values. (CAN-2005-0750)
  • Michal Zalewski discovered that the iso9660 file system driver fails to check ranges properly in several cases. (CAN-2005-0815)
  • Previous kernels did not restrict the use of the N_MOUSE line discipline in the serial driver. (CAN-2005-0839)
Alerts:
Ubuntu USN-103-1 2005-04-01
SuSE SUSE-SA:2005:021 2005-04-04
Trustix TSLSA-2005-0011 2005-04-05
Fedora FEDORA-2005-313 2005-04-11
Red Hat RHSA-2005:293-01 2005-04-22
Red Hat RHSA-2005:283-01 2005-04-28
Red Hat RHSA-2005:284-01 2005-04-28
Conectiva CLA-2005:952 2005-05-02
Fedora-Legacy FLSA:152532 2005-06-04
Mandriva MDKSA-2005:111 2005-06-30
Mandriva MDKSA-2005:110 2005-06-30

Comments (1 posted)

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CAN-2005-0449 CAN-2005-0209 CAN-2005-0529 CAN-2005-0530 CAN-2005-0532 CAN-2005-0384 CAN-2005-0210 CAN-2005-0504 CAN-2005-0003
Created:March 24, 2005 Updated:May 31, 2006
Description: A number of vulnerabilities have been found in the Linux kernel, including a PPP-related denial of service problem, an integer overflow in the epoll() code, memory corruption in the ELF loader, and exploitable overflows in the ISO9660 code.
Alerts:
SuSE SUSE-SA:2005:018 2005-03-24
Fedora FEDORA-2005-262 2005-03-28
Conectiva CLA-2005:945 2005-03-31
Debian DSA-1067-1 2006-05-20
Debian DSA-1070-1 2006-05-21
Debian DSA-1069-1 2006-05-20
Debian DSA-1082-1 2006-05-29

Comments (none posted)

libXpm: new buffer overflows

Package(s):libXpm CVE #(s):CAN-2005-0605
Created:March 4, 2005 Updated:March 8, 2006
Description: A new vulnerability has been discovered in libXpm, which is included in OpenMotif and LessTif, that can potentially lead to remote code execution.
Alerts:
Gentoo 200503-08 2005-03-04
Ubuntu USN-92-1 2005-03-07
Gentoo 200503-15 2005-03-12
Ubuntu USN-97-1 2005-03-16
Fedora FEDORA-2005-272 2005-03-29
Fedora FEDORA-2005-273 2005-03-29
Red Hat RHSA-2005:331-01 2005-03-30
Red Hat RHSA-2005:044-01 2005-04-06
Mandriva MDKSA-2005:080 2005-04-28
Mandriva MDKSA-2005:081 2005-05-05
Debian DSA-723-1 2005-05-09
Red Hat RHSA-2005:412-01 2005-05-11
Red Hat RHSA-2005:473-01 2005-05-24
Red Hat RHSA-2005:198-01 2005-06-08
Fedora FEDORA-2005-808 2005-08-25
Fedora FEDORA-2005-815 2005-08-26
Fedora-Legacy FLSA:152803 2006-01-09
Fedora-Legacy FLSA:168264 2006-03-07

Comments (none posted)

libdbi-perl: insecure temporary file

Package(s):libdbi-perl CVE #(s):CAN-2005-0077
Created:January 25, 2005 Updated:March 2, 2006
Description: Javier Fernández-Sanguino Peña from the Debian Security Audit Project discovered that the DBI library, the Perl5 database interface, creates a temporary PID file in an insecure manner. This can be exploited by a malicious user to overwrite arbitrary files owned by the person executing the parts of the library.
Alerts:
Debian DSA-658-1 2005-01-25
Ubuntu USN-70-1 2005-01-25
Gentoo 200501-38 2005-01-26
Red Hat RHSA-2005:069-01 2005-02-01
Mandrake MDKSA-2005:030 2005-02-08
Red Hat RHSA-2005:072-01 2005-02-15
Gentoo 200501-38:03 2005-01-26
Fedora-Legacy FLSA:178989 2006-03-01

Comments (none posted)

libexif: improper validation

Package(s):libexif CVE #(s):CAN-2005-0664
Created:March 7, 2005 Updated:April 15, 2005
Description: Sylvain Defresne discovered that the EXIF library did not properly validate the structure of the EXIF tags. By tricking a user to load an image with a malicious EXIF tag, an attacker could exploit this to crash the process using the library, or even execute arbitrary code with the privileges of the process.
Alerts:
Ubuntu USN-91-1 2005-03-07
Fedora FEDORA-2005-199 2005-03-08
Fedora FEDORA-2005-200 2005-03-08
Gentoo 200503-17 2005-03-12
Red Hat RHSA-2005:300-01 2005-03-21
Mandrake MDKSA-2005:064 2005-03-31
Debian DSA-709-1 2005-04-15

Comments (none posted)

libgd2: buffer overflows in PNG handling

Package(s):libgd2 CVE #(s):CAN-2004-0990 CAN-2004-0941
Created:October 29, 2004 Updated:June 28, 2006
Description: Several buffer overflows have been discovered in libgd's PNG handling functions.
If an attacker tricked a user into loading a malicious PNG image, they could leverage this into executing arbitrary code in the context of the user opening image. Most importantly, this library is commonly used in PHP. One possible target would be a PHP driven photo website that lets users upload images. Therefore this vulnerability might lead to privilege escalation to a web server's privileges.
Multiple buffer overflows in the gd graphics library (libgd) 2.0.21 and earlier may allow remote attackers to execute arbitrary code via malformed image files that trigger the overflows due to improper calls to the gdMalloc function.
Alerts:
Ubuntu USN-11-1 2004-10-28
OpenPKG OpenPKG-SA-2004.049 2004-10-30
Gentoo 200411-08 2004-11-03
Debian DSA-589-1 2004-11-09
Debian DSA-591-1 2004-11-09
Ubuntu USN-21-1 2004-11-09
Fedora FEDORA-2004-411 2004-11-11
Fedora FEDORA-2004-412 2004-11-11
Ubuntu USN-25-1 2004-11-15
Mandrake MDKSA-2004:132 2004-11-15
Debian DSA-601-1 2004-11-29
Debian DSA-602-1 2004-11-29
Ubuntu USN-33-1 2004-11-29
Red Hat RHSA-2004:638-01 2004-12-17
Fedora-Legacy FLSA:152838 2005-07-15
Red Hat RHSA-2006:0194-01 2006-02-01
Mandriva MDKSA-2006:114 2006-06-27

Comments (none posted)

libtiff: buffer overflow

Package(s):libtiff CVE #(s):CAN-2004-1308
Created:December 22, 2004 Updated:May 19, 2005
Description: The libtiff image manipulation library contains several exploitable buffer overflows.
Alerts:
Ubuntu USN-46-1 2004-12-22
Fedora FEDORA-2004-576 2004-12-22
Fedora FEDORA-2004-577 2004-12-22
Debian DSA-617-1 2004-12-24
Debian DSA-626-1 2005-01-06
Gentoo 200501-06 2005-01-05
Mandrake MDKSA-2005:001 2005-01-06
Mandrake MDKSA-2005:002 2005-01-06
Ubuntu USN-54-1 2005-01-06
Fedora FEDORA-2005-597 2005-01-07
Fedora FEDORA-2005-598 2005-01-07
SuSE SUSE-SA:2005:001 2005-01-10
Red Hat RHSA-2005:019-01 2005-01-13
Conectiva CLA-2005:920 2005-01-20
Red Hat RHSA-2005:035-01 2005-02-15
Fedora-Legacy FLSA:152815 2005-05-18

Comments (none posted)

limewire: input validation errors

Package(s):limewire CVE #(s):CAN-2005-0788 CAN-2005-0789
Created:March 31, 2005 Updated:April 6, 2005
Description: LimeWire, a Java-based peer-to-peer client that works with the Gnutella file-sharing protocol, has two input validation errors that can allow a remote attacker to read arbitrary files with the permissions that LimeWire is running under.
Alerts:
Gentoo 200503-37 2005-03-31

Comments (none posted)

lvm10: creates insecure temporary directory

Package(s):lvm10 CVE #(s):CAN-2004-0972
Created:November 1, 2004 Updated:July 25, 2005
Description: Trustix Secure Linux discovered a vulnerability in a supplemental script of the lvm10 package. The program "lvmcreate_initrd" created a temporary directory in an insecure way, which could allow a symlink attack to create or overwrite arbitrary files with the privileges of the user invoking the program.
Alerts:
Ubuntu USN-15-1 2004-11-01
Debian DSA-583-1 2004-11-03
Gentoo 200411-22 2004-11-11
Mandrake MDKSA-2004:144 2004-12-06
Fedora-Legacy FLSA:152842 2005-07-24

Comments (none posted)

mailman: path traversal

Package(s):mailman CVE #(s):CAN-2005-0202
Created:February 9, 2005 Updated:July 13, 2005
Description: The "private" module in the mailman mailing list manager fails to sanitize path names adequately. An attacker could exploit this vulnerability to retrieve private information, including passwords and private list archives.

This vulnerability was used to compromise the Full-Disclosure list.

Alerts:
Ubuntu USN-78-1 2005-02-09
Fedora FEDORA-2005-131 2005-02-10
Fedora FEDORA-2005-132 2005-02-10
Gentoo 200502-11 2005-02-10
Red Hat RHSA-2005:136-01 2005-02-10
Debian DSA-674-2 2005-02-11
SuSE SUSE-SA:2005:007 2005-02-14
Red Hat RHSA-2005:137-01 2005-02-15
Mandrake MDKSA-2005:037 2005-02-14
Debian DSA-674-3 2005-02-21
Ubuntu USN-78-2 2005-02-17
Fedora-Legacy FLSA:152895 2005-07-10

Comments (none posted)

mc: buffer overflow

Package(s):mc CVE #(s):CAN-2005-0763
Created:March 29, 2005 Updated:August 11, 2005
Description: An unfixed buffer overflow has been discovered by Andrew V. Samoilov in mc, the midnight commander, a file browser and manager.
Alerts:
Debian DSA-698-1 2005-03-29
Red Hat RHSA-2005:512-01 2005-06-16
Fedora-Legacy FLSA:152889 2005-08-10

Comments (none posted)

MediaWiki: multiple vulnerabilities

Package(s):mediawiki CVE #(s):CAN-2005-0534 CAN-2005-0535 CAN-2005-0536
Created:February 28, 2005 Updated:June 13, 2005
Description: A security audit of the MediaWiki project discovered that MediaWiki is vulnerable to several cross-site scripting and cross-site request forgery attacks, and that the image deletion code does not sufficiently sanitize input parameters.
Alerts:
Gentoo 200502-33 2005-02-28
Gentoo 200506-12 2005-06-13

Comments (none posted)

mikmod: buffer overflow

Package(s):mikmod CVE #(s):CAN-2003-0427
Created:June 16, 2003 Updated:June 16, 2005
Description: Ingo Saitz discovered a bug in mikmod whereby a long filename inside an archive file can overflow a buffer when the archive is being read by mikmod.
Alerts:
Debian DSA-320-1 2003-06-13
Gentoo 200307-01 2003-07-02
Fedora FEDORA-2005-404 2005-06-09
Red Hat RHSA-2005:506-01 2005-06-13
Fedora FEDORA-2005-405 2005-06-16

Comments (none posted)

mod_python: remote access vulnerability

Package(s):mod_python CVE #(s):CAN-2005-0088
Created:February 10, 2005 Updated:April 9, 2006
Description: mod_python has a vulnerability in the publisher handler that may allow a remote user to use a specially crafted URL to allow access to objects that should be protected. An information leak can result.
Alerts:
Fedora FEDORA-2005-139 2005-02-10
Fedora FEDORA-2005-140 2005-02-10
Red Hat RHSA-2005:104-01 2005-02-10
Ubuntu USN-80-1 2005-02-11
Trustix TSLSA-2005-0003 2005-02-11
Gentoo 200502-14 2005-02-13
Red Hat RHSA-2005:100-01 2005-02-15
Debian DSA-689-1 2005-02-23
Conectiva CLA-2005:926 2005-03-02
Fedora-Legacy FLSA:152896 2006-04-04

Comments (none posted)

mysql: several vulnerabilities

Package(s):mysql CVE #(s):CAN-2004-0835 CAN-2004-0836 CAN-2004-0837
Created:October 11, 2004 Updated:April 6, 2005
Description: Several problems have been discovered in MySQL. Oleksandr Byelkin noticed that ALTER TABLE ... RENAME checks CREATE/INSERT rights of the old table instead of the new one. (CAN-2004-0835) Lukasz Wojtow noticed a buffer overrun in the mysql_real_connect function. (CAN-2004-0836) Dean Ellis noticed that multiple threads ALTERing the same (or different) MERGE tables to change the UNION can cause the server to crash or stall. (CAN-2004-0837)
Alerts:
Debian DSA-562-1 2004-10-11
Red Hat RHSA-2