Immunix OS 7.0 wu-ftpd update

From: Immunix Security Team (security@wirex.com)
Date: 11/29/01


Date: Wed, 28 Nov 2001 18:01:48 -0800
From: Immunix Security Team <security@wirex.com>
To: bugtraq@securityfocus.com, security-alerts@linuxsecurity.com, linux-security-announce@seifried.org, immunix-announce@immunix.org
Subject: Immunix OS 7.0 wu-ftpd update
Message-ID: <20011128180148.G7800@wirex.com>



-----------------------------------------------------------------------
        Immunix OS Security Advisory

Packages updated: wu-ftpd
Affected products: Immunix 7.0
Bugs fixed: immunix/1861
Date: Wed Nov 28 2001
Advisory ID: IMNX-2001-70-036-01
Author: Seth Arnold <sarnold@wirex.com>
-----------------------------------------------------------------------

Description:
  CORE Security Technologies has found an heap overflow problem in
  wu-ftpd, related to the internal globbing functions. Because this is a
  heap overflow, StackGuard does not prevent any possible exploits from
  working.

  Thomas Biege from SuSE has also discovered several format-string
  problems that may or may not be remotely exploitable; these problems
  were also found independently by someone else, who sadly is unknown to
  WireX.

  The wu-ftpd packages provided here fix these problems, as well as
  other lesser problems.

  References: http://www.securityfocus.com/archive/1/242750

Package names and locations:
  Precompiled binary packages for Immunix 7.0 are available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/RPMS/wu-ftpd-2.6.1-6_imnx_4.i386.rpm

  Source package for Immunix 7.0 is available at:
  http://download.immunix.org/ImmunixOS/7.0/updates/SRPMS/wu-ftpd-2.6.1-6_imnx_4.src.rpm

Immunix OS 7.0 md5sums:
  c6c2fa2fa60f2cfe5b496ad0281fa486 RPMS/wu-ftpd-2.6.1-6_imnx_4.i386.rpm
  e8a2e0a1f8abe59ad058b6fecc8a1c72 SRPMS/wu-ftpd-2.6.1-6_imnx_4.src.rpm

GPG verification:
  Our public key is available at <http://wirex.com/security/GPG_KEY>.
  *** NOTE *** This key is different from the one used in advisories
  IMNX-2001-70-020-01 and earlier.

Online version of all Immunix 6.2 updates and advisories:
  http://immunix.org/ImmunixOS/6.2/updates/

Online version of all Immunix 7.0-beta updates and advisories:
  http://immunix.org/ImmunixOS/7.0-beta/updates/

Online version of all Immunix 7.0 updates and advisories:
  http://immunix.org/ImmunixOS/7.0/updates/

NOTE:
  Ibiblio is graciously mirroring our updates, so if the links above are
  slow, please try:
    ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
  or one of the many mirrors available at:
    http://www.ibiblio.org/pub/Linux/MIRRORS.html

  ImmunixOS 6.2 is no longer officially supported.

Contact information:
  To report vulnerabilities, please contact security@wirex.com. WireX
  attempts to conform to the RFP vulnerability disclosure protocol
  <http://www.wiretrip.net/rfp/policy.html>.






Relevant Pages

  • Immunix OS 7.0 glibc update
    ... nscd) fixes two security problems. ... We recommend all Immunix 7.0 users upgrade glibc and nscd with these ... Precompiled binary packages for Immunix 7.0 are available at: ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • Immunix OS update Linux Kernel
    ... Immunix OS update Linux Kernel ... Precompiled binary packages for Immunix 7.0 are available at: ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • ImmunixOS 7.0 sendmail update
    ... This update fixes two problems with sendmail. ... we have not researched this issue -- Immunix OS ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • Immunix OS update for OpenSSH
    ... Immunix OS update for OpenSSH ... placed on keys did not apply to subsystems such as sftp, ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)
  • squid update -- Immunix OS 6.2, 7.0-beta, and 7.0
    ... Paul Nasrat has discovered a bug in squid's httpd_accel mode that ... scanning because squid does not properly use ACLs in the config file. ... Precompiled binary packages for Immunix 6.2 are available at: ... Online version of all Immunix 7.0-beta updates and advisories: ...
    (Bugtraq)