Mandriva Security http://www.mandriva.com/en/security/advisories Mandriva security advisories en-us MDVSA-2008:209-1: pam_krb5 http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:209-1 Stéphane Bertin discovered a flaw in the pam_krb5 existing_ticket<br /> configuration option where, if enabled and using an existing credential<br /> cache, it was possible for a local user to gain elevated privileges<br /> by using a different, local user's credential cache (CVE-2008-3825).<br /> <br /> The updated packages have been patched to prevent this issue.<br /> <br /> Update:<br /> <br /> An updated package for Mandriva Linux 2009.0 is now available. MDVSA-2008:210: mono http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:210 CRLF injection vulnerability in Sys.Web in Mono 2.0 and earlier allows<br /> remote attackers to inject arbitrary HTTP headers and conduct HTTP<br /> response splitting attacks via CRLF sequences in the query string.<br /> <br /> The updated packages have been patched to fix the issue. MDVSA-2008:209: pam_krb5 http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:209 Stéphane Bertin discovered a flaw in the pam_krb5 existing_ticket<br /> configuration option where, if enabled and using an existing credential<br /> cache, it was possible for a local user to gain elevated privileges<br /> by using a different, local user's credential cache (CVE-2008-3825).<br /> <br /> The updated packages have been patched to prevent this issue. MDVA-2008:132: mandriva-release http://www.mandriva.com/en/security/advisories?name=MDVA-2008:132 mandriva-release for Mandriva 2008 Spring should contain a<br /> product_branch set to Official, and not devel, otherwise it could<br /> lead to an error with the new mdkonline.<br /> <br /> The updated package fixes it. MDVA-2008:131: rpmdrake http://www.mandriva.com/en/security/advisories?name=MDVA-2008:131 This update fixes several minor issues in rpmdrake:<br /> - it fixes a crash due to bad timing with the X server (#41010)<br /> - it fix empty per importance lists of updates in rpmdrake (list<br /> of all updates was OK, MandrivaUpdate was OK) (#41331) (regression<br /> introduced in 3.95 on 2007-09-14)<br /> - it makes rpmdrake only warn once per session when media XML metadata<br /> are newer than synthesis: in that case rpmdrake complained for every<br /> unsyncrhonized package (#42737)<br /> - it fixes a crash when selecting all packages (#40025)<br /> - it fixes a rare crash when canceling (#41970) MDVA-2008:130: drakxtools http://www.mandriva.com/en/security/advisories?name=MDVA-2008:130 This update fixes several minor issues in drakxtools:<br /> - it fixes management of XEN kernels in bootloader-config, when adding<br /> a new kernel, a xen entry should not replace an existing 'linux'<br /> (#40865)<br /> - it fixes a crash in rpmdrake when description begins by<br /> Gtk2::.. (#43802)<br /> <br /> It also really enable draksnapashot to use Gtk+-2's new<br /> FileChooserDialog in future. MDVSA-2008:208: pam_mount http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:208 pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify<br /> mountpoint and source ownership before mounting a user-defined volume,<br /> which allows local users to bypass intended access restrictions via<br /> a local mount.<br /> <br /> The updated packages have been patched to fix the issue. MDVSA-2008:207: openafs http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:207 A race condition in OpenAFS 1.3.40 through 1.4.5 allowed remote<br /> attackers to cause a denial of service (daemon crash) by simultaneously<br /> acquiring and giving back file callbacks (CVE-2007-6599).<br /> <br /> The updated packages have been patched to prevent this issue. MDVSA-2008:206: mozilla-thunderbird http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:206 A number of security vulnerabilities have been discovered and<br /> corrected in the latest Mozilla Thunderbird program, version 2.0.0.17<br /> (CVE-2008-0016, CVE-2008-3835, CVE-2008-4058, CVE-2008-4059,<br /> CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4065,<br /> CVE-2008-4066, CVE-2008-4067, CVE-2008-4068, CVE-2008-4070).<br /> <br /> This update provides the latest Thunderbird to correct these issues. MDVSA-2008:205: mozilla-firefox http://www.mandriva.com/en/security/advisories?name=MDVSA-2008:205 Security vulnerabilities have been discovered and corrected in the<br /> latest Mozilla Firefox program, version 2.0.0.17 (CVE-2008-0016,<br /> CVE-2008-3835, CVE-2008-3836, CVE-2008-3837, CVE-2008-4058,<br /> CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062,<br /> CVE-2008-4065, CVE-2008-4066, CVE-2008-4067, CVE-2008-4068,<br /> CVE-2008-4069).<br /> <br /> This update provides the latest Firefox to correct these issues.