Re: Arcoread7 secutiry vulnerability

From: Boris Samorodov (bsam_at_ipt.ru)
Date: 08/28/05

  • Next message: Simon L. Nielsen: "Re: Arcoread7 secutiry vulnerability"
    To: Ian Moore <imoore@swiftdsl.com.au>
    Date: Sun, 28 Aug 2005 14:56:11 +0400
    
    

    Hi!

    cc'd to freebsd-security@ as somebody there may correct me,
    cc'd to secteam@ as maintaner of security/portaudit.

    On Sun, 28 Aug 2005 10:14:21 +0930 Ian Moore wrote:

    > I've just updated my acroread port to 7.0.1 & was surprised when portaudit
    > still listed it as a vulnerability.

    I think it is portaudit problem.

    > According to http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/85093, the
    > upgrade to 7.0.1 is suppoed to fix the problem, but according to
    > http://www.freebsd.org/ports/portaudit/02bc9b7c-e019-11d9-a8bd-000cf18bbe54.html
    > and Adobe's web site at http://www.adobe.com/support/techdocs/331710.html,
    > the problem exists in 7.0.1 as well, but is fixed in 7.0.2.

    > I'm just wondering who is right here, or am I missing something?

    It looks like you missed the platfom to pay attention to. For Linux
    and Solaris "users should upgrade to Adobe Reader 7.0.1"...

    WBR

    -- 
    bsam
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Simon L. Nielsen: "Re: Arcoread7 secutiry vulnerability"

    Relevant Pages

    • Re: Bad sectors... how bad?
      ... > complexity contains bugs and software written to fix bugs will contain ... >> and the $100 upgrade is that the upgrade looks for previous installs. ... online to fully update all the patches. ... > So when a vulnerability is found you want to remain vulnerable for 6 ...
      (alt.comp.hardware.pc-homebuilt)
    • [Full-disclosure] [SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware
      ... Vulnerability: remote command execution ... execution of arbitrary commands on the server running phpgroupware. ... We recommend that you upgrade your phpgroupware package. ... If you are using the apt-get package manager, ...
      (Full-Disclosure)
    • RE: ALOM Question
      ... The Upgrade worked great and now I can connect remotely via ssh. ... You are running a version of OpenSSH older than OpenSSH 3.2.1 ... vulnerability may be avoided by enabling UsePrivilegeSeparation. ...
      (SunManagers)
    • [SECURITY] [DSA 746-1] New packages fix remote command execution in phpgroupware
      ... Vulnerability: remote command execution ... execution of arbitrary commands on the server running phpgroupware. ... We recommend that you upgrade your phpgroupware package. ... If you are using the apt-get package manager, ...
      (Bugtraq)
    • [CLA-2003:614] Conectiva Security Announcement - sendmail
      ... SUMMARY: Buffer overflow vulnerability ... All sendmail users should upgrade immediately. ... UPDATED PACKAGES ... Detailed instructions reagarding the use of apt and upgrade examples ...
      (Bugtraq)