stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Symlink Vulnerability in GNU automake <1.8.3







Symlink Vulnerability in GNU automake
<1.8.3

Symlink Vulnerability in GNU automake
<1.8.3
03/08/2004 11:20 PM

Stefan Nordhausen (Mar 08 2004)




This is a GrokNews Entry: (what is grok?)





Similar Items

Symlink Vulnerability in GNU automake <1.8.3

Grok Headline matches for Symlink Vulnerability in GNU automake <1.8.3

[ GLSA 200405-05 ] Utempter symlink
vulnerability


[ GLSA 200405-05 ] Utempter symlink
vulnerability
05/13/2004 01:47 PM
Kurt Lieber (May 13 2004)

MDKSA-2004:060 - Updated ksymoops
packages fix symlink vulnerability


MDKSA-2004:060 - Updated ksymoops
packages fix symlink vulnerability
06/10/2004 08:35 PM
Mandrake Linux Security Team (Jun 10 2004)

GNU Automake 1.8


GNU Automake 1.8 12/14/2003 02:20 AM
A tool for automatically generating Makefiles.

Win32-Symlink-0.01


Win32-Symlink-0.01 09/18/2004 05:15 PM

Win32-Symlink-0.02


Win32-Symlink-0.02 09/19/2004 12:17 AM

PerlIO-via-symlink-0.01


PerlIO-via-symlink-0.01 07/21/2004 01:01 AM

Win32-Symlink-0.03


Win32-Symlink-0.03 09/25/2004 12:19 AM

Make Symlink 1.0.2


Make Symlink 1.0.2 12/03/2003 09:49 PM
Make unix-styled symbolic links using hierarchical CM.

PerlIO-via-symlink-0.02


PerlIO-via-symlink-0.02 08/09/2004 12:39 AM

Symlink vulnerabilities in mailmgr


Symlink vulnerabilities in mailmgr 02/13/2004 12:47 AM
Marco van Berkum (Feb 12 2004)

Networker 6.0 - possible symlink attack


Networker 6.0 - possible symlink attack 01/19/2004 03:07 PM
Rene (Jan 19 2004)

Re: [SuSE 9.0] possible symlink attacks
in some scripts


Re: [SuSE 9.0] possible symlink attacks
in some scripts
01/22/2004 02:07 PM
Thomas Biege (Jan 22 2004)

Notes and Tips: Symlink Backup Bug


Notes and Tips: Symlink Backup Bug 09/16/2004 09:42 AM
Read this if you're doing incremental backups in Mac OS X and you don't want to lose data....

symlink vul for Antivir / Linux Version
2.0.9-9 (maybe lower)


symlink vul for Antivir / Linux Version
2.0.9-9 (maybe lower)
01/16/2004 10:59 AM
Rene (Jan 13 2004)

Re: symlink vul for Antivir / Linux
Version 2.0.9-9 (maybe lower)


Re: symlink vul for Antivir / Linux
Version 2.0.9-9 (maybe lower)
01/27/2004 01:49 PM
AntiVir Support (Jan 27 2004)

OpenServer 5.0.6 OpenServer 5.0.7 :
uudecode does not check for symlink or
pipe


OpenServer 5.0.6 OpenServer 5.0.7 :
uudecode does not check for symlink or
pipe
07/31/2004 07:29 AM
please_reply_to_security_at_sco.com (Jul 30 2004)

Open source outfit releases
vulnerability for IE vulnerability


Open source outfit releases
vulnerability for IE vulnerability
12/19/2003 01:10 PM
The Register Dec 19 2003 11:57AM ET

NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP


NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP
04/20/2004 02:16 PM
David Ahmad (Apr 20 2004)

Re: NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP


Re: NISCC Vulnerability Advisory 236929:
Vulnerability Issues in TCP
05/11/2004 06:04 PM
Florian Weimer (May 11 2004)

PHP Vulnerability N. 1


PHP Vulnerability N. 1 09/15/2004 03:20 PM
Stefano Di Paola (Sep 15 2004)

Vulnerability with XP SP2


Vulnerability with XP SP2 08/18/2004 06:29 AM
Just to bare in mind, Microsoft are dealing with this and are holding off SP2s release on Automatic Update because of it. There's a bug in the implementation of a new security feature; it'd be hard to criticize Microsoft too hard for this problem.

"With Service Pack 2, Microsoft introduces a new security feature which warns users before executing files that originate from an untrusted location (zone) such as the Internet. There are two flaws in the implementation of this feature: a cmd issue and the caching of ZoneIDs in Windows Explorer. The Windows command shell cmd ignores zone information and starts executables without warnings. Virus authors could use this to spread viruses despite the new security features of SP2.

Windows Explorer does not update zone information properly when files are overwritten. So it can be tricked to execute files from the internet without warning."

Heise do concede that it would take a fair amount of user interaction for a virus writer to use this vulnerability. However, as they point out, the powers of social engineering and playing on less IT adept people do mean that it's not that in-conceivable it could happen. With Service Pack 2, Microsoft had clearly been hoping for less vulnerabilities, and will no doubt be disappointed with this news.

View: More info @ Heise.de

Read full story...

802.11 Has DoS Vulnerability


802.11 Has DoS Vulnerability 05/13/2004 08:11 PM
Internet News May 13 2004 11:39PM GMT

[USN-52-1] vim vulnerability


[USN-52-1] vim vulnerability 12/24/2004 12:36 PM
Martin Pitt (Dec 23 2004)

[USN-108-1] GDK vulnerability


[USN-108-1] GDK vulnerability 04/06/2005 05:45 PM
Posted by Martin Pitt, Apr 05 2005

KDE Vulnerability


KDE Vulnerability 08/12/2004 06:18 AM

Direct and Related Links for 'KDE Vulnerability'

“Two vulnerabilities have been discovered in KDE, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges. 1) Certain directories and files are created insecurely when a user runs a KDE application outside the KDE environment or as another user. This can be exploited via symlink attacks to overwrite or truncate arbitrary files or prevent KDE applications from accessing certain directories. This vulnerability affects KDE 3.2.3…

PHP CGI Vulnerability


PHP CGI Vulnerability 02/20/2003 10:46 AM
PHP CGI Vulnerability I don't know how many folks are actually doing php as a CGI but if so ... [17-Feb-2003] The PHP Group today announced the details of a serious CGI vulnerability in PHP version 4.3.0. A security update, PHP 4.3.1, fixes the issue. Everyone running affected version of PHP (as CGI) are encouraged to upgrade immediately. The new 4.3.1 release does not include any other changes, so upgrading from 4.3.0 is safe and painless. [_Go_] I have to commend the php team for NOT including any other changes thereby making it much more likely that affected systems get patched. Good going!

Vulnerability in 2.6 and 2.61


Vulnerability in 2.6 and 2.61 03/13/2003 10:15 AM
If you upgraded to 2.6 or 2.61, you need to upgrade immediately to 2.62. There is a security vulnerability in...

Php Vulnerability N. 2


Php Vulnerability N. 2 09/16/2004 01:29 PM
Stefano Di Paola (Sep 15 2004)

Vulnerability in man < 1.5l


Vulnerability in man < 1.5l 03/13/2003 10:22 AM
Jack Lloyd (Mar 11 2003)

Re: [USN-52-1] vim vulnerability


Re: [USN-52-1] vim vulnerability 12/25/2004 05:09 PM
Liu Die Yu (Dec 23 2004)

IE6 + XP SP2 Vulnerability


IE6 + XP SP2 Vulnerability 09/17/2004 12:37 AM
cns (Sep 15 2004)

Nasty new IE vulnerability


Nasty new IE vulnerability 12/09/2003 02:34 PM

Most people reading are probably aware of the common trick whereby spammers and other assorted ne'er-do-wells publish URLs with usernames that look like hostnames to fool people in to trusting a malicious site - for example, http://www.microsoft.com&session%123123123@simon.incutio.com . This trick is frequently used by spammers to steal people's PayPal accounts, by tricking them in to "resetting" their password at a site owned by the spammer but disguised as PayPal.com.

Today's new Internet Explorer vulnerability makes the problem a hundred times worse. By including an 0x01 character after the @ symbol in the fake URL, IE can be tricked in to not displaying the rest of the URL at all. Don't expect a patch for a while either; the guy who discovered the bug released it to BugTraq on the same day he notified the vendor.


WebArtFactory CMS Vulnerability


WebArtFactory CMS Vulnerability 12/17/2003 02:31 PM
Noticias (Dec 16 2003)

OS X security vulnerability


OS X security vulnerability 12/16/2003 06:33 PM
A new Mac OS X security vulnerability has been discovered. Apparantly this vulnerability can allow execution of arbitrary code with "root" priviledges. The issue is considered a "Less Critical" vulnerability, and affects Mac OS X 10.3.1 and possibly other versions of the operating system.

TCP Vulnerability Published


TCP Vulnerability Published 04/20/2004 03:23 PM

Re: Moodle XSS Vulnerability


Re: Moodle XSS Vulnerability 07/17/2004 01:07 PM
Martin Dougiamas (Jul 17 2004)

IMWheel Vulnerability


IMWheel Vulnerability 08/27/2004 09:14 PM

Direct and Related Links for 'IMWheel Vulnerability'

“I)ruid has reported a vulnerability in IMWheel, which can be exploited by malicious, local users to perform certain actions on a vulnerable system with escalated privileges or cause a DoS (Denial of Service)….

[USN-100-1] cdrecord vulnerability


[USN-100-1] cdrecord vulnerability 03/25/2005 01:50 AM
Martin Pitt (Mar 24 2005)

Vulnerability Issues in TCP


Vulnerability Issues in TCP 04/20/2004 01:57 PM

Grok Description matches for Symlink Vulnerability in GNU automake <1.8.3
GrokA matches for Symlink Vulnerability in GNU automake <1.8.3

Symlink Vulnerability in GNU automake <1.8.3

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

[OpenPKG-SA-2004.004
] OpenPKG Security
Advisory (libtool)

directory traversal
in PWebServer 0.3.3

RE: VirtuaNews Admin
Panel 1.0.3 Pro
Cross Site Scripting
Vulnerabillity

[ GLSA 200403-01 ]
Libxml2 URI Parsing
Buffer Overflow
Vulnerabilities

[ GLSA 200403-02 ]
Linux kernel
do_mremap local
privilege escalation
vulnerability

Z***ING EMAILS !
Antivir for Freebsd
doesn't work on 5.X

RE: "Divide and
Conquer" - cross
site response header
tampering, cookie
manipulation, and
session fixation

RE: Desert Rats vs.
Afrika Korps
(Haegemonia bug)

Re: Invision Power
Board v1.3 Final
Cross Site Scripting
Vulnerabillity

More me elsewhere
The Weblog: An
Extremely Democratic
Form in Journalism

Horrifying,
Beautiful

Nitrogen head
The New World of PR
Handhelden: Retro
Plastic Electronic
Games

Platters Throwdown!
The Electronic Knee
New Smartphone OS:
Saveje OS

'Toothing!
O-ZONELite
What's in Your
Gadget Bag, Glenn?

Mobile Phone Kleptos
in Kenya

The Global Village
Cometh, Chapter
XXXVII

ZigBee Home
Automation

The iClock
DVD Players Bulk Up
Motorola MPx
Pictures

Student Builds
Seeing Eye Robot For
Schoolchum

The Technology of
Hedonism Redux

Camera Obscura
Lomo Anniversary
The Wailing Wall
The Confusion
Samsung getting
Motorola's number

New agreement with
Motorola for the
supply of headsets

GN to deliver mobile
headsets to Motorola

Motorola joins push
to get out young
voters

Motorola intros
E680, E398 and C650

New Motorola
handsets dance to
the beat

Motorola to close
its Singapore chip
design centre

Motorola camera
phone delayed again

Motorola moving chip
design units to
China, India

New Google Look
Publishing, Coffee,
Contracts

Fujitsu announces
new enterprise hard
drives

U.K. health agency
faces legal action
over canceled EDS
contract

ICANN president
wants group to focus
on Internet basics

The way to
best-in-class
greatness

Managing IT risk at
Delta Air Lines

what is grok?