Gentoo Archives: gentoo-user-es

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-security@g.o, gentoo-announce@g.o
Subject: [gentoo-user-es] [gentoo-announce] GLSA: amavis
Date: Thu, 05 Sep 2002 08:04:04
Message-Id: 200209051503.47164.aliz@gentoo.org
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT
6 - - --------------------------------------------------------------------
7
8 PACKAGE :amavis
9 SUMMARY :possible dos
10 DATE :2002-09-05 10:30 UTC
11
12 - - --------------------------------------------------------------------
13
14 OVERVIEW
15
16 possible DoS attack by a special crafted TAR archive file
17
18 DETAIL
19
20 The AMaViS shell script version (AMaViS 0.1.x / 0.2.x) uses securetar.
21 securetar removes the pathes of files in a tar archive and makes each
22 file name a unique name. Links, character devices, block devices and named
23 pipes will be removed from the archive.
24 A special-crafted TAR file may hung securetar forever, using up to
25 100% CPU time.
26
27 More information can be found at:
28
29 http://marc.theaimsgroup.com/?l=amavis-announce&m=103121272122242&w=2
30
31 SOLUTION
32
33 It is recommended that all Gentoo Linux users who are running
34 net-mail/amavis-0.2.1-r2 and earlier update their systems
35 as follows:
36
37 emerge rsync
38 emerge amavis
39 emerge clean
40
41 - - --------------------------------------------------------------------
42 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
43 - - --------------------------------------------------------------------
44 -----BEGIN PGP SIGNATURE-----
45 Version: GnuPG v1.0.7 (GNU/Linux)
46
47 iD8DBQE9d1YyfT7nyhUpoZMRAj3/AJ9L+OrIwfyK5ggEaDdUpCrytgD7fQCgrqRe
48 Rk8XxSZB7m90juAR/qZ+gAQ=
49 =cbs4
50 -----END PGP SIGNATURE-----
51
52 _______________________________________________
53 gentoo-announce mailing list
54 gentoo-announce@g.o
55 http://lists.gentoo.org/mailman/listinfo/gentoo-announce