Gentoo Archives: gentoo-announce

From: Seemant Kulleen <seemant@g.o>
To: gentoo-announce@g.o, gentoo-security@g.o, lwn@×××.net
Subject: [gentoo-announce] Buffer overflow in Exim
Date: Thu, 18 Apr 2002 22:51:39
Message-Id: 20020418205138.08e61abe.seemant@gentoo.org
1 - -----------------------------------------------------------------------
2 GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
3 - -----------------------------------------------------------------------
4 PACKAGE : exim
5 SUMMARY : security vulnerability in exim
6 DATE : Apr 19 03:02:46 UTC 2002
7 - -----------------------------------------------------------------------
8
9 OVERVIEW
10
11 A security vulnerability has been found that might allow a local attacker
12 to gain elevated priveleges. This affects Gentoo's exim-3.34-r1 and prior
13 packages.
14
15
16 DETAIL
17
18 Fix for a security vulnerability that could allow local attackers to gain
19 elevated privileges though a buffer overflow exploit.
20 http://www.securiteam.com/unixfocus/5CP0H206AI.html
21
22
23 SOLUTION
24
25 It is recommended that all Gentoo Linux users who are running exim update
26 their systems as follows.
27
28 emerge --clean rsync
29 emerge exim
30 emerge clean
31
32 - ------------------------------------------------------------------------
33 rphillips@g.o
34 seemant@g.o
35 drobbins@g.o
36 - ------------------------------------------------------------------------