Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: libmcrypt
Date: Sun, 05 Jan 2003 14:00:53
Message-Id: 20030105121130.134AA33762@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200301-4
6 - - --------------------------------------------------------------------
7
8 PACKAGE : libmcrypt
9 SUMMARY : buffer overflows and memory exhaustion
10 DATE    : 2003-01-05 12:01 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 Post by Ilia Alshanetsky <ilia@×××××××.org>:
16
17 "limbcrypt versions prior to 2.5.5 contain a number of buffer
18 overflow vulnerabilities that stem from imporper or lacking input
19 validation. By passing a longer then expected input to a number of
20 functions (multiple functions are affected) the user can successful
21 make libmcrypt crash.
22
23 Another vulnerability is due to the way libmcrypt loads algorithms via
24 libtool. When the algorithms are loaded dynamically the each time the
25 algorithm is loaded a small (few kilobytes) of memory are leaked. In a
26 persistant enviroment (web server) this could lead to a memory
27 exhaustion attack that will exhaust all avaliable memory by launching
28 repeated requests at an application utilizing the mcrypt library.
29
30 The solution to both of these problem is to upgrade to the latest
31 release of libmcrypt, 2.5.5."
32
33 SOLUTION
34
35 It is recommended that all Gentoo Linux users who are running
36 dev-libs/libmcrypt-2.5.1-r4 or earlier update their systems as
37 follows:
38
39 emerge rsync
40 emerge libmcrypt
41 emerge clean
42
43 - - --------------------------------------------------------------------
44 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
45 - - --------------------------------------------------------------------
46 -----BEGIN PGP SIGNATURE-----
47 Version: GnuPG v1.2.1 (GNU/Linux)
48
49 iD8DBQE+GCDqfT7nyhUpoZMRAgLTAJ9wkfPJg1Z4f0d5krJpObWVGtPwJgCfYQ7o
50 a7jfaOOalcN+xeBczQjxAds=
51 =vxQ0
52 -----END PGP SIGNATURE-----