Contact | Site en Français               

 


 

Vulnerabilities & Threats

 
  VUPEN Security Advisories
  Linux Security Advisories

  Malware Advisories

  Security Research
  Threat Watch Blog
  Zero-Day Monitor
  Search Engine
  Mailing List & RSS
 
   

>> Trustix Security Update Fixes Multiple Code Execution and Denial of Service Vulnerabilities

Title : Trustix Security Update Fixes Multiple Code Execution and Denial of Service Vulnerabilities
VUPEN ID : VUPEN/ADV-2007-0261
CVE ID : CVE-2005-0953 - CVE-2006-6101 - CVE-2006-6102 - CVE-2006-6103 - CVE-2006-6143 - CVE-2006-6719 - CVE-2007-0247
Rated as : Critical 
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2007-01-22


Technical Description    Receive VUPEN Security alerts in a Text format  Receive VUPEN Security alerts in a PDF format  Receive VUPEN Security alerts in an XML format  Receive VUPEN Security notifications by SMS 

Trustix has released updated packages to address multiple vulnerabilities identified in bzip2, kerberos5, squid, wget, and xorg-x11. These issues could be exploited by attackers to cause a denial of service or execute arbitrary commands. For additional information, see : VUPEN/ADV-2007-0111 - VUPEN/ADV-2007-0199 - VUPEN/ADV-2007-0201 - VUPEN/ADV-2007-0108

Affected Products

Trustix Secure Linux 2.2
Trustix Secure Linux 3.0
Trustix Operating System - Enterprise Server 2

Solution

Upgrade the affected packages :

http://http.trustix.org/pub/trustix/updates/

fe7ecb95a9a6f6d416dd094392c949a3 3.0/rpms/bzip2-1.0.3-5tr.i586.rpm
4ca273ff50829042fc05af99e77043a4 3.0/rpms/bzip2-devel-1.0.3-5tr.i586.rpm
1120e40b652adcaf0904ba6468135a04 3.0/rpms/bzip2-libs-1.0.3-5tr.i586.rpm
399892b75bdb07266d9875b5732e8b11 3.0/rpms/kerberos5-1.4.1-7tr.i586.rpm
0e71777994740c7442c02b44ebd2f92f 3.0/rpms/kerberos5-devel-1.4.1-7tr.i586.rpm
5908022e3f1af696a9f4dfc8fab96374 3.0/rpms/kerberos5-libs-1.4.1-7tr.i586.rpm
5bafb3a10443f4db613adb6e5a387043 3.0/rpms/squid-2.5.STABLE14-1tr.i586.rpm
ff34dd1e35b711058b1c49a0922159a4 3.0/rpms/wget-1.10.2-3tr.i586.rpm
d9c827e23c22b1959559f03b9bcfa029 3.0/rpms/xorg-x11-6.8.2-13tr.i586.rpm
08501e3d6af75b7f0667f15dd5b91699 3.0/rpms/xorg-x11-devel-6.8.2-13tr.i586.rpm
3b5046737825c5d5bf2040a2d82d342b 3.0/rpms/xorg-x11-doc-6.8.2-13tr.i586.rpm
4f2b3e7920bc8323c626f095a4c83e5d 3.0/rpms/xorg-x11-fonts-100dpi-6.8.2-13tr.i586.rpm
9b4acaf57db6ce286a79b2f7c9a7733c 3.0/rpms/xorg-x11-fonts-6.8.2-13tr.i586.rpm
09436523f4bd9bf89a76cf6d57451d8f 3.0/rpms/xorg-x11-fonts-75dpi-6.8.2-13tr.i586.rpm
fcb9cbb97a1d6c72bc562be5ada529af 3.0/rpms/xorg-x11-fonts-cid-6.8.2-13tr.i586.rpm
14e4cac1b9e73f4f41904aceedd04263 3.0/rpms/xorg-x11-fonts-cyrillic-6.8.2-13tr.i586.rpm
d83fbb25db379888e9d9f5b58a9c31dd 3.0/rpms/xorg-x11-fonts-otf-6.8.2-13tr.i586.rpm
d15b6873d14f3e48dc0c1a78e2132307 3.0/rpms/xorg-x11-fonts-speedo-6.8.2-13tr.i586.rpm
aa9f70e561a0c1526fa5b1e6282f978b 3.0/rpms/xorg-x11-fonts-ttf-6.8.2-13tr.i586.rpm
685eeccb0d6b5d9cad0f8b1b9e1b436b 3.0/rpms/xorg-x11-fonts-type1-6.8.2-13tr.i586.rpm
d3c5bd8804263fa76a56275f806f9d7e 3.0/rpms/xorg-x11-libs-6.8.2-13tr.i586.rpm
912762ff505961c45976bad623bd6533 3.0/rpms/xorg-x11-sdk-6.8.2-13tr.i586.rpm
273b5eeaf4deb1bdd48727e3ba54440b 2.2/rpms/bzip2-1.0.3-4tr.i586.rpm
75b9d8dd81a0f629b0536bb5bd75a707 2.2/rpms/bzip2-devel-1.0.3-4tr.i586.rpm
2c5abc363e957263d3d658f565048d81 2.2/rpms/bzip2-libs-1.0.3-4tr.i586.rpm
8d1e074fe8e3964eb74811304d6e1eb4 2.2/rpms/squid-2.5.STABLE14-2tr.i586.rpm
d8a38ee2fc6ccd5fdeb9d9a19d0fc431 2.2/rpms/wget-1.10.2-2tr.i586.rpm

References

http://www.vupen.com/english/advisories/2007/0261
http://lists.trustix.org/pipermail/tsl-announce/2007-January/000455.html

ChangeLog

2007-01-22 : Initial release

Vulnerability Management

Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.

Feedback

If you have additional information or corrections for this security advisory please submit them via our contact form.

 

Vulnerability Alerting

Free 14-Day Trial

 
  Latest News

 

  >> 2009-06-10

     

  VUPEN Security Research
  Discovered Critical Flaws
  in Adobe Acrobat and MS

  Office Word


  >> 2009-06-02

     

  VUPEN Security Research
  Discovered Critical Flaws
  in ACDSee Products


  >> 2009-05-22

     

  VUPEN Discovered Two
  Critical Vulnerabilities in
  Novell GroupWise 8 / 7


  >> 2009-05-12

     

  Microsoft Patched 14
  Office PowerPoint Flaws

 

  >> 2009-04-28

     

  Adobe Reader / Acrobat
  Vulnerabilities
Disclosed

 

 

More Informations    
    








Copyright 2003-2009 © VUPEN.COM - Privacy Policy