We have received reports that the lsof package is distributed in
Debian GNU/Linux 2.0 contains a buffer overflow. Using this overflow
it is possible for local users to gain root-access. We have fixed
this problem in version 4.37-3.
The maintainer of Debian GNU/Linux cfengine package found a error
in the way cfengine handles temporary files when it runs the tidy
action on homedirectories, which makes it suspectible to a symlink
attack. The author has been notified of the problem but has not
released a fix yet.
We have received reports that the wu-ftpd-academ package as distributed
in Debian GNU/Linux 2.0 is vulnerable to a buffer overflow. Using this
vulnerability, known as palmetto, it is possible to gain shell access or
otherwise circumvent normal login access and logging mechanisms.
We have received reports that the proftpd package as distributed
in Debian GNU/Linux 2.0 is vulnerable to a buffer overflow. Using this
vulnerability, known as palmetto, it is possible to gain shell access or
otherwise circumvent normal login access and logging mechanisms.
We have received reports that the netstd suffered from two buffer
overflows. The first problem is an exploitable buffer overflow in the
bootp server. The second problem is an overflow in the FTP client. Both
problems are fixed in a new netstd package, version 3.07-2hamm.4 .