ImmunixOS 7.0 update for xinetd

From: Immunix Security Team (security@wirex.com)
Date: 08/30/01


Date: Wed, 29 Aug 2001 18:31:09 -0700
From: Immunix Security Team <security@wirex.com>
To: security-alerts@linuxsecurity.com, bugtraq@securityfocus.com, linux-security-announce@seifried.org, immunix-announce@immunix.org
Subject: ImmunixOS 7.0 update for xinetd
Message-ID: <20010829183109.B11991@wirex.com>



-----------------------------------------------------------------------
        Immunix OS Security Advisory

Packages updated: xinetd
Affected products: Immunix OS 7.0
Bugs fixed: immunix/1698
Date: Wed Aug 29 2001
Advisory ID: IMNX-2001-70-033-01
Author: Seth Arnold <sarnold@wirex.com>
-----------------------------------------------------------------------

Description:
  Solar Designer has audited the xinetd 2.3.0 source code for many
  different possible vulnerabilities; the 2.3.1 release represents his
  patches being merged into the standard xinetd source. His audit
  was fairly thorough and found too many problems to report them
  all here. 2.3.2 fixes a heap overrun, with the fix due to Trond
  Eivind Glomsrød. Steve Grubb contributed many other fixes, though
  none appear to be directly security-related.

  Suffice it to say that it is only a matter of time before the
  problems fixed here are turned into exploits; we recommend all
  users running xinetd upgrade soon.

Package names and locations:
  Precompiled binary packages for Immunix 7.0 are available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/xinetd-2.3.3-1_imnx.i386.rpm

  Source package for Immunix 7.0 is available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/SRPMS/xinetd-2.3.3-1_imnx.src.rpm

Immunix OS 7.0 md5sums:
  654c1aa4337fbb5752e80d173b186266 RPMS/xinetd-2.3.3-1_imnx.i386.rpm
  2e992bf61ab5439f18e3740a502dc050 SRPMS/xinetd-2.3.3-1_imnx.src.rpm

GPG verification:
  Our public key is available at <http://wirex.com/security/GPG_KEY>.
  *** NOTE *** This key is different from the one used in advisories
  IMNX-2001-70-020-01 and earlier.

Online version of all Immunix 6.2 updates and advisories:
  http://immunix.org/ImmunixOS/6.2/updates/

Online version of all Immunix 7.0-beta updates and advisories:
  http://immunix.org/ImmunixOS/7.0-beta/updates/

Online version of all Immunix 7.0 updates and advisories:
  http://immunix.org/ImmunixOS/7.0/updates/

NOTE:
  Ibiblio is graciously mirroring our updates, so if the links above are
  slow, please try:
    ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
  or one of the many mirrors available at:
    http://www.ibiblio.org/pub/Linux/MIRRORS.html

  ImmunixOS 6.2 is no longer officially supported.

Contact information:
  To report vulnerabilities, please contact security@wirex.com. WireX
  attempts to conform to the RFP vulnerability disclosure protocol
  <http://www.wiretrip.net/rfp/policy.html>.






Relevant Pages

  • Immunix OS 7.0 glibc update
    ... nscd) fixes two security problems. ... We recommend all Immunix 7.0 users upgrade glibc and nscd with these ... Precompiled binary packages for Immunix 7.0 are available at: ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • ImmunixOS 7.0 sendmail update
    ... This update fixes two problems with sendmail. ... we have not researched this issue -- Immunix OS ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • Immunix OS update for OpenSSH
    ... Immunix OS update for OpenSSH ... placed on keys did not apply to subsystems such as sftp, ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • squid update -- Immunix OS 6.2, 7.0-beta, and 7.0
    ... Paul Nasrat has discovered a bug in squid's httpd_accel mode that ... scanning because squid does not properly use ACLs in the config file. ... Precompiled binary packages for Immunix 6.2 are available at: ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • Immunix Secured OS 7+ MySQL update
    ... There have been a number of vulnerabilities found in MySQL and the MySQL ... Immunix does not protect against all of these problems. ... Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL ...
    (Bugtraq)