Register a free account
ne nw
Crawlability Inc. Files for SEO Technology Patent
se sw

Go Back   Forum Index > Operating Systems > Linux
The Software Store

Linux All distros and thier applications

Reply
 
Thread Tools Display Modes
  #1  
Old 06-05-2007, 10:23 PM
Mandriva's Avatar
Mandriva Mandriva is offline
Senior Member
 
Join Date: Oct 2006
Posts: 720
Mandriva- Advisories MDKSA-2007:114: Updated file packages fix vulnerabilities

Advisories MDKSA-2007:114: Updated file packages fix vulnerabilities
The update to correct CVE-2007-1536 (MDKSA-2007:067), a buffer overflow
in the file_printf() function, introduced a new integer overflow as
reported by Colin Percival. This flaw, if an atacker could trick a
user into running file on a specially crafted file, could possibly
lead to the execution of arbitrary code with the privileges of the
user running file (CVE-2007-2799).

As well, in file 4.20, flawed regular expressions to identify OS/2
REXX files could lead to a denial of service via CPU consumption
(CVE-2007-2026).

The updated packages have been patched to correct these issues.
http://mandrivausers.org/index.php?showtopic=41969
Array
Wed, 06 Jun 2007 00:05:18 +0000
Reply With Quote
Sponsored Links

Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -5. The time now is 10:09 AM.


234x60
Bulletin Board Custom Version by Mobo
Copyright © 2004-2007 Cyberanswers.org All rights reserved