Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Trustix Security Update Fixes Multiple Package Security Bypass and DoS Issues

Title : Trustix Security Update Fixes Multiple Package Security Bypass and DoS Issues
VUPEN ID : VUPEN/ADV-2006-3646
CVE ID : CVE-2005-2490 - CVE-2005-2708 - CVE-2005-2709 - CVE-2005-3180 - CVE-2006-0039 - CVE-2006-1524 - CVE-2006-1525 - CVE-2006-1528 - CVE-2006-1857 - CVE-2006-1858 - CVE-2006-1864 - CVE-2006-2271 - CVE-2006-2272 - CVE-2006-2274 - CVE-2006-3745 - CVE-2006-4093 - CVE-2006-4095 - CVE-2006-4096 - CVE-2006-4145
Rated as : Moderate Risk 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2006-09-18


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

Trustix has released updated packages to address multiple vulnerabilities identified in bind, Kernel, and openssl. These flaws could be exploited by attackers to cause a denial of service, bypass security restrictions, or obtain elevated privileges. For additional information, see : VUPEN/ADV-2006-3473 - VUPEN/ADV-2006-3308 - VUPEN/ADV-2006-3358 - VUPEN/ADV-2006-3453

Affected Products

Trustix Secure Linux 2.2
Trustix Secure Linux 3.0
Trustix Operating System - Enterprise Server 2

Solution

Upgrade the affected packages :

http://http.trustix.org/pub/trustix/updates/

8a2c2f1f1da74781b4ecc088ccc76c62 3.0/rpms/bind-9.3.2-4tr.i586.rpm
ac17273772c921b947efaa4bbf045828 3.0/rpms/bind-devel-9.3.2-4tr.i586.rpm
5d0f66272575fcd9d4b4ac8696edfd2e 3.0/rpms/bind-libs-9.3.2-4tr.i586.rpm
4dc5e7726e88ee9071861eb35a14e44c 3.0/rpms/bind-light-9.3.2-4tr.i586.rpm
8a014940633e0a29375c62c3708a4e63 3.0/rpms/bind-light-devel-9.3.2-4tr.i586.rpm
d4da9d9e490b24e847434b47238107dd 3.0/rpms/bind-utils-9.3.2-4tr.i586.rpm
9c69891182a0c1c60870e89b41642f62 3.0/rpms/openssl-0.9.7k-1tr.i586.rpm
f5b5390d931bc5ebd9c4e0d8aadd9286 3.0/rpms/openssl-devel-0.9.7k-1tr.i586.rpm
deb2d3a044994706727989f07f84e70a 3.0/rpms/openssl-support-0.9.7k-1tr.i586.rpm
edcfc0e0b33e584772b3ab38c2ecc120 2.2/rpms/bind-9.3.2-4tr.i586.rpm
7c10280e5e0e85decd471c740651fcf7 2.2/rpms/bind-devel-9.3.2-4tr.i586.rpm
0b31ab1242338a21373a5b5677b38d15 2.2/rpms/bind-libs-9.3.2-4tr.i586.rpm
8715527a40ead4ce8e279ea85e96945b 2.2/rpms/bind-light-9.3.2-4tr.i586.rpm
a6e53d9494c395aa0b9964e91504063f 2.2/rpms/bind-light-devel-9.3.2-4tr.i586.rpm
fc9730b297ec56db37babc9d69f0777f 2.2/rpms/bind-utils-9.3.2-4tr.i586.rpm
2cb53a6092ab2de443576fc493c7c61f 2.2/rpms/kernel-2.4.33.3-1tr.i586.rpm
99ebf5b654d17918297f3ade9a188797 2.2/rpms/kernel-BOOT-2.4.33.3-1tr.i586.rpm
9d2325bf115bc51b97f3a1b7858950cd 2.2/rpms/kernel-doc-2.4.33.3-1tr.i586.rpm
22425048536337cfa6a78b50bc50b227 2.2/rpms/kernel-smp-2.4.33.3-1tr.i586.rpm
13aa3038815b939c4385c48738027097 2.2/rpms/kernel-source-2.4.33.3-1tr.i586.rpm
969b1acbb169f601348b429a1cd65d4b 2.2/rpms/kernel-utils-2.4.33.3-1tr.i586.rpm
d45c46c044c54a836b0a3e8b0ea61bd8 2.2/rpms/openssl-0.9.7e-7tr.i586.rpm
3d60834f48d77853e81606d2bcfbda81 2.2/rpms/openssl-devel-0.9.7e-7tr.i586.rpm
2bc39b5e84a862657dd28999fdddf43c 2.2/rpms/openssl-python-0.9.7e-7tr.i586.rpm
be83cfcd1ceae92288cbaf3d510a0482 2.2/rpms/openssl-support-0.9.7e-7tr.i586.rpm

References

http://www.vupen.com/english/advisories/2006/3646
http://lists.trustix.org/pipermail/tsl-announce/2006-September/000427.html

ChangeLog

2006-09-18 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy