Gentoo Archives: gentoo-announce

From: aliz@gentoo.org (Daniel Ahlberg)
To: gentoo-announce@g.o
Subject: GLSA: ypserv (200307-04)
Date: Fri, 11 Jul 2003 14:39:59
Message-Id: 20030711142712.B0E2F24F808@noc.internal.fairytale.se
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - - ---------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200307-04
6 - - - ---------------------------------------------------------------------
7
8           PACKAGE : ypserv
9           SUMMARY : denial of service
10              DATE : 2003-07-11 14:27 UTC
11           EXPLOIT : remote
12 VERSIONS AFFECTED : <ypserv-2.8
13     FIXED VERSION : >=ypserv-2.8
14               CVE : CAN-2003-0251
15
16 - - - ---------------------------------------------------------------------
17
18 quote from CVE:
19
20 "ypserv NIS server before 2.7 allows remote attackers to cause a denial
21 of service via a TCP client request that does not respond to the server,
22 which causes ypserv to block."
23
24 SOLUTION
25
26 It is recommended that all Gentoo Linux users who are running
27 net-nds/ypserv upgrade to ypserv-2.8 as follows
28
29 emerge sync
30 emerge ypserv
31 emerge clean
32
33 - - - ---------------------------------------------------------------------
34 aliz@g.o - GnuPG key is available at http://dev.gentoo.org/~aliz
35 - - - ---------------------------------------------------------------------
36 -----BEGIN PGP SIGNATURE-----
37 Version: GnuPG v1.2.2 (GNU/Linux)
38
39 iD8DBQE/DslAfT7nyhUpoZMRAlifAKCJuEv32S1Tsb5ErNVsfHrkxcmIuACfa8Fo
40 avi3km4Y6pngjxw9QCPcSHs=
41 =o3G/
42 -----END PGP SIGNATURE-----