|
||
Linux Heavies Issue Patches
Linux vendors Red Hat, Novell/SUSE, Mandrakesoft, Debian and Gentoo have issued advisories and patches this week for a number of different vulnerabilities that have hit them.
Red Hat The Xpdf Red Hat packages were also updated to prevent the exploitation of a buffer overflow that was found in the PDF viewer. Red Hat noted in its advisory, however, that the Exec-Shield technology (enabled by default since Update 3) will block attempts to exploit this vulnerability on x86 architectures.
Red Hat Enterprise Linux Update 3, which was released in September and also included NX (no execute) support, was a source of discussion on the main Linux Kernel developers' list in June.
Red Hat also updated its Mozilla packages to fix a buffer overflow issue (CAN-2004-1316) in the way the browser handles NNTP Novell's Both Debian and Gentoo issued updates for their respective exim packages, which could have possibly been exploited to allow for a local privilege escalation attack. Exim is a configurable message transfer agent (MTA).
Additionally, Gentoo issued an update to cover the "multiple overflows [that] have been found in the imlib2 library image decoding routines, potentially allowing the execution of arbitrary code."
Not to be left out of the patch bonanza, Mandrakesoft issued a patch for its imlib image handler packages. There was a heap overflow as well as integer overflow vulnerability in the packages that could have allowed an attacker to crash a system or execute arbitrary code when an image file was opened. The same vulnerability also exists in Gentoo's imlib2 packages and has also had a patch issued for it.
|
||
|