Gentoo Archives: gentoo-server

From: Lisa Seelye <lisa@g.o>
To: gentoo-server@l.g.o
Cc: lisa@g.o
Subject: Re: [gentoo-server] Distccd vulnerability ??
Date: Tue, 14 Sep 2004 03:14:03
Message-Id: 1095131508.17535.3.camel@lisa.thedoh.com
In Reply to: [gentoo-server] Distccd vulnerability ?? by linux-lists@web.de
1 On Mon, 2004-09-13 at 12:50, linux-lists@×××.de wrote:
2 > hi,
3 >
4 > I'm manging 6 clients and a server [nis, nfs, etc.] in an office.
5 > today, while updating one client I found in
6 > /tmp/.tmp an downloaded ftpd.tar and an unpacked openftpd-0.29.4.tar.gz
7 > and additionally and ftproot which looks strongly like binary-sharing:
8
9 Due to Evolution crashing and me losing an email I'm going to make this
10 short and sweet:
11
12 I highly suggest updating distcc to 2.17-r1 or at the very least take
13 the config and init files from /usr/portage/sys-devel/distcc/files/2.17.
14
15 They incorporate the --allow and --listen daemon flag settings to remind
16 users that they /can/ tighten the security of their distcc daemons.
17 --
18 Regards,
19 Lisa Seelye
20 Key fingerprint = 09CF 52D6 B82B 72B9 97A7 601B CB46 B556 1E49 6FC5

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-server] Distccd vulnerability ?? Andrew Gaffney <agaffney@×××××××××××.com>