The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root privileges by causing sendmail to execute with arbitrary command line arguments, as demonstrated using the -C option to specify a configuration file.
Buffer overflow in the man program in Linux allows local users to gain privileges via the MANPAGER environmental variable.
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which allows local attackers to conduct brute force password guessing.
snmpd server in cmu-snmp SNMP package before 3.3-1 in Red Hat Linux 4.0 is configured to allow remote attackers to read and write sensitive information.
rcp on various Linux systems including Red Hat 4.0 allows a "nobody" user or other user with UID of 65535 to overwrite arbitrary files, since 65535 is interpreted as -1 by chown and other system calls, which causes the calls to fail to modify the ownership of the file.
Buffer overflow in run-time linkers (1) ld.so or (2) ld-linux.so for Linux systems allows local users to gain privileges by calling a setuid program with a long program name (argv[0]) and forcing ld.so/ld-linux.so to report an error.
ucbmail allows remote attackers to execute commands via shell metacharacters that are passed to it from INN.
Buffer overflow in Vixie cron allows local users to gain root access via a long MAILTO environment variable in a crontab file.
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental variable.
Buffer overflow in Dosemu Slang library in Linux.
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environmental variable.
Local users can start Sendmail in daemon mode and gain root privileges.
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Buffer overflow in NLS (Natural Language Service).
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Buffer overflow in NFS mountd gives root access to remote attackers, mostly in Linux systems.
From Bugzilla Helper: User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; iOpus-I-M; SV1)
Description of problem: The x8664 bit version of AS4 (fully patched) appears to ignore tcpwrappers completely when using gdm with XDMCP. The 32 bit version of AS4 works perfectly so this bug appears to be restricted to the 64bit version. I suspect the problem with the wrappers on the 64 bit version may be a bit more general than just XDMCP access as I tested a telnet server and while the wrappers are not completely ignored connections are not refused cleanly (You donât get the login prompt but you are still hooked up to the machine). The 32 bit version again works perfectly.
Version-Release number of selected component (if applicable): tcpwrappers
How reproducible: Always
Steps to Reproduce: 1. Instll the OS 2. Configure gdmsetup to allow remote XDMCP conectivity 3. configure hosts.deny to restrict conections all:all
Actual Results: no restriction to remote desktop
Expected Results: remote desktop should have been refused
Additional info:
Dirk Mueller reported an off by one buffer overflow flaw in the way QT parses certain unicode strings.
To quote Dirk:
Ive found a off-by-one buffer overflow in QUtf8Decoder::toUnicode(). It is not exploitable with Qt 4.x or above because there is an additional QChar(0) being allocated in QString, however it is still a bug there, as the array returned by utf16() etc is no longer terminated properly.
Unspecified vulnerability in the kernel in Red Hat Enterprise Linux (RHEL) 4 on the x8664 platform allows local users to cause a denial of service (OOPS) via unspecified vectors related to the getgatevma function and the fuser command.