Gentoo Archives: gentoo-announce

From: Daniel Ahlberg <aliz@g.o>
To: gentoo-announce@g.o
Subject: [gentoo-announce] GLSA: ypserv
Date: Mon, 28 Oct 2002 08:09:44
Message-Id: 20021028140940.1420F3368D@mail1.tamperd.net
1 -----BEGIN PGP SIGNED MESSAGE-----
2 Hash: SHA1
3
4 - - --------------------------------------------------------------------
5 GENTOO LINUX SECURITY ANNOUNCEMENT 200210-010
6 - - --------------------------------------------------------------------
7
8 PACKAGE : ypserv
9 SUMMARY : information leak
10 DATE    : 2002-10-28 14:10 UTC
11 EXPLOIT : remote
12
13 - - --------------------------------------------------------------------
14
15 Thorsten Kukuck discovered a problem in the ypserv program which is
16 part of the Network Information Services (NIS). A memory leak in all
17 versions of ypserv prior to 2.5 is remotely exploitable. When a
18 malicious user could request a non-existing map the server will leak
19 parts of an old domainname and mapname.
20
21 SOLUTION
22
23 It is recommended that all Gentoo Linux users who are running
24 net-nds/ypserv-1.3.12 and earlier update their systems as follows:
25
26 emerge rsync
27 emerge ypserv
28 emerge clean
29
30 - - --------------------------------------------------------------------
31 aliz@g.o - GnuPG key is available at www.gentoo.org/~aliz
32 - - --------------------------------------------------------------------
33 -----BEGIN PGP SIGNATURE-----
34 Version: GnuPG v1.0.7 (GNU/Linux)
35
36 iD8DBQE9vUUjfT7nyhUpoZMRAv7wAJ4hQ2QqPozFTcLkIr3ddJCHwIqiOQCcC89e
37 CW28lSsCnFemMc4lTReoiao=
38 =IWUR
39 -----END PGP SIGNATURE-----