Search: "debian"

239 CVEs found

CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

Published: 2005-04-27
Products: 18
Vendors:
cvs
CVE-2005-0159
4.6 MEDIUM

The tpkg-* scripts in the toolchain-source 3.0.4 package on Debian GNU/Linux 3.0 allow local users to overwrite arbitrary files via a symlink attack on temporary files.

Published: 2005-04-27
Products: 16
Vendors:
debian
CVE-2005-2214
4.6 MEDIUM

apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords.

Published: 2005-07-11
Products: 1
Vendors:
debian

Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server.

Published: 2005-08-05
Products: 2
Vendors:
debian
CVE-2005-3254
10.0 HIGH

The CGIwrap program before 3.9 on Debian GNU/Linux uses an incorrect minimum value of 100 for a UID to determine whether it can perform a seteuid operation, which could allow attackers to execute code...

Published: 2005-10-18
Products: 29
Vendors:
nathan_neulinger
CVE-2005-3255
5.0 MEDIUM

The (1) cgiwrap and (2) php-cgiwrap packages before 3.9 in Debian GNU/Linux provide access to debugging CGIs under the web document root, which allows remote attackers to obtain sensitive information ...

Published: 2005-10-18
Products: 29
Vendors:
nathan_neulinger

yiff server (yiff-server) 2.14.2 on Debian GNU/Linux runs as root and does not properly verify ownership of files that it opens, which allows local users to read arbitrary files.

Published: 2005-10-20
Products: 1
Vendors:
raphael_bossek
CVE-2005-4347
5.0 MEDIUM

The Linux 2.4 kernel patch in kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux does not correctly set the "chroot barrier" with util-vserver, which allows attackers to acces...

Published: 2005-12-31
Products: 4
Vendors:
debian

util-vserver before 0.30.208-1 with kernel-patch-vserver before 1.9.5.5 and 2.x before 2.3 for Debian GNU/Linux sets a default policy that trusts unknown capabilities, which could allow local users to...

Published: 2005-12-31
Products: 2
Vendors:
vserver
CVE-2005-4693
5.0 MEDIUM

Gaim-Encryption 2.38-1 on Debian Linux allows remote attackers to cause a denial of service (crash) via a crafted message from an ICQ buddy, possibly involving the GE_received_key function in keys.c.

Published: 2005-12-31
Products: 1
Vendors:
gaim-encryption
CVE-2005-4728
4.6 MEDIUM

Untrusted search path vulnerability (RPATH) in amaya 9.2.1 on Debian GNU/Linux allows local users to gain privileges via a malicious Mesa library in the /home/anand directory.

Published: 2005-12-31
Products: 1
Vendors:
debian

Unspecified vulnerability in certain versions of xpdf after 3.00, as used in various products including (a) pdfkit.framework, (b) gpdf, (c) pdftohtml, and (d) libextractor, has unknown impact and user...

Published: 2006-03-15
Products: 39
Vendors:
debian xpdf libextractor gnome
CVE-2006-1319
6.2 MEDIUM

chpst in runit 1.3.3-1 for Debian GNU/Linux, when compiled on little endian i386 machines against dietlibc, does not properly handle when multiple groups are specified in the -u option, which causes c...

Published: 2006-03-20
Products: 1
Vendors:
runit

util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.c...

Published: 2006-03-20
Products: 1
Vendors:
rssh

snmptrapfmt in Debian 3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary log file.

Published: 2006-03-23
Products: 25
Vendors:
debian

The installation of Debian GNU/Linux 3.1r1 from the network install CD creates /var/log/debian-installer/cdebconf with world writable permissions, which allows local users to cause a denial of service...

Published: 2006-03-24
Products: 1
Vendors:
debian
CVE-2006-1564
4.6 MEDIUM

Untrusted search path vulnerability in libapache2-svn 1.3.0-4 for Subversion in Debian GNU/Linux includes RPATH values under the /tmp/svn directory for the (1) mod_authz_svn.so and (2) mod_dav_svn.so ...

Published: 2006-03-31
Products: 13
Vendors:
debian
CVE-2006-1565
4.6 MEDIUM

Untrusted search path vulnerability in libgpib-perl 3.2.06-2 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the LinuxGpib.so module, which might allow local users to g...

Published: 2006-03-31
Products: 13
Vendors:
debian
CVE-2006-1566
4.6 MEDIUM

Untrusted search path vulnerability in libtunepimp-perl 0.4.2-1 in Debian GNU/Linux includes an RPATH value under the /tmp/buildd directory for the tunepimp.so module, which might allow local users to...

Published: 2006-03-31
Products: 13
Vendors:
debian

debconf in Debian GNU/Linux, when configuring mnogosearch in the mnogosearch-common 3.2.31-1 package, uses the world-readable config.dat file instead of the restricted passwords.dat for storing the cl...

Published: 2006-04-13
Products: 13
Vendors:
debian