* Red Hat, Novell, Mandrakesoft fix Linux vulnerabilities
endif; ?>Several prominent Linux distributors released critical patches last week for their respective operating systems. Red Hat, Novell (formerly SuSE) and Mandrakesoft all issued updates to their software deemed as “highly critical” by security Web site Secunia.com.
Red Hat had two advisories, warning that users’ systems could be compromised by maliciously altered PDF or TIFF image files. One concerned an update that fixes a potential vulnerability in the LibTIFF library on Red Hat systems. The vulnerability could allow a malicious user to execute arbitrary code on a Linux machine via a specially crafted TIFF image file. An application linked to the LibTIFF library could be tricked into running code. The vulnerabilities affect several versions of Red Hat Enterprise Server, Advanced Server and Advanced Workstation for 32- and 64-bit Intel processors.
The other vulnerability, also on Advanced Server, Workstation and Enterprise Server, is in the xpdf library. This could allow an attacker to trick a user into opening PDF file that would cause a buffer overflow and leave the system open to having arbitrary code run on it.
SuSE’s security notices includes several vulnerability fixes, including the XPDF problem found in Red Hat, as well as a bug in the ViewCVS that could allow an attacker to execute HTTP or script code on a machine. The problems affect SuSE Linux Versions 7.x through 9.x, as well as SuSE Linux Enterprise Server 7-9, SuSE Linux Office Server and eMail Server 3.1.
Mandrake said its Mandrakelinux 9.x and 10.x, as well as its Corporate Server could be exploited by a faulty imlib library related to image viewing. Again, this is exploited by tricking users into viewing an altered image file, which causes a buffer overflow on the system, opening up holes for arbitrary code.




