Security Advisories Week: 30 May - 6 June 2002
by Berislav Kucan
Bookmark and Share
Problem description: Versions of BIND 9 prior to 9.2.1 have a bug that causes certain requests to the BIND name server (named) to fail an internal consistency check, causing the name server to stop responding to requests.



Title: Ghostscript command execution vulnerability
Date: June 5 2002
Vendor: Red Hat
Vulnerable systems: Red Hat Linux 6.2 and 7.x
Full advisory: http://www.net-security.org/advisory.php?id=743
Problem description: An untrusted PostScript file can cause ghostscript to execute arbitrary commands due to insufficient checking. Since ghostscript is often used during the course of printing a document (and is run as user 'lp'), all users should install these fixed packages.



Title: snmpdx(1M) and mibiisa(1M) fixes available
Date: June 5 2002
Vendor: SUN
Vulnerable systems: SunOS 5.8, 5.8_x86, 5.7, 5.7_x86, 5.6, 5.6_x86
Full advisory: http://www.net-security.org/advisory.php?id=744
Problem description: A format string vulnerability has been discovered in snmpdx and a buffer overflow found in mibiisa which may be exploited by a local or a remote attacker to gain root access on the affected system.




Title: Multiple Vulnerabilities in Yahoo! Messenger
Date: June 6 2002
Vendor: Yahoo
Vulnerable systems: Yahoo! Messenger version 5,0,0,1064 and prior for Microsoft Windows
Full advisory: http://www.net-security.org/advisory.php?id=745
Problem description: There are multiple vulnerabilities in Yahoo! Messenger. Attackers that are able to exploit these vulnerabilities may be able to execute arbitrary code with the privileges of the victim user.



Title: Buffer Overflow when parsing NFS traffic
Date: June 6 2002
Vendor: Conectiva
Vulnerable systems: Conectiva Linux 6.0, 7.0, 8
Full advisory: http://www.net-security.org/advisory.php?id=746
Problem description: There is a buffer overflow vulnerability in tcpdump when it is parsing NFS traffic. A remote attacker could exploit this to at least crash the tcpdump process.



Title: tcpdump AFS RPC and NFS packet vulnerabilities
Date: June 6 2002
Vendor: Caldera
Vulnerable systems: OpenLinux 3.1.1 Server prior to tcpdump-3.6.2-2.i386.rpm, OpenLinux 3.1.1 Workstation prior to tcpdump-3.6.2-2.i386.rpm, OpenLinux 3.1 Server prior to tcpdump-3.6.2-2.i386.rpm, OpenLinux 3.1 Workstation prior to tcpdump-3.6.2-2.i386.rpm

Spotlight

Is it time to professionalize information security?

Posted on 23 May 2013.  |  The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.


Daily digest

By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
  

Weekly newsletter

With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.
  

 
DON'T
MISS

Fri, May 24th
    COPYRIGHT 1998-2013 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //