Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: GLSA: canna
Date: Fri, 20 Dec 2002 17:32:18
Message-Id: 20021220172452.4227D33BD4@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200212-8
6 - - --------------------------------------------------------------------
7
8 PACKAGE : canna
9 SUMMARY : multiple vulnerabilities in canna
10 DATE    : 2002-12-20 17:12 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 Quotes from advisory:
16
17 "hsj" of Shadow Penguin Security discovered a heap overflow
18 vulnerability in the irw_through function in canna server
19 version 3.6 and earlier."
20
21 "AIDA Shinra of Canna project found lack of validations of requests
22 in canna version 3.6 and earlier."
23
24 Read the full advisory at
25 http://canna.sourceforge.jp/sec/Canna-2002-01.txt
26
27 SOLUTION
28
29 It is recommended that all Gentoo Linux users who are running
30 app-i18n/canna-3.6 and earlier update their systems as follows:
31
32 emerge rsync
33 emerge canna
34 emerge clean
35
36 - - --------------------------------------------------------------------
37 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
38 nakano@g.o
39 - - --------------------------------------------------------------------
40 -----BEGIN PGP SIGNATURE-----
41 Version: GnuPG v1.2.1 (GNU/Linux)
42
43 iD8DBQE+A1JhfT7nyhUpoZMRAsxKAJ9fIr90urulT6eyWNwVgfVNIRM/eQCgvUIU
44 u9tWg29qZEi5iFEpBhDmNfg=
45 =Plpf
46 -----END PGP SIGNATURE-----