GLSA: monkeyd (200304-07.1)

From: Daniel Ahlberg (aliz_at_gentoo.org)
Date: 04/28/03

  • Next message: nesumin: "[Opera 7/6] Long File Extension Heap Buffer Overrun Vulnerability in Download."
    Date: Mon, 28 Apr 2003 10:49:41 +0200
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - - ---------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200304-07.1
    - - - ---------------------------------------------------------------------

              PACKAGE : monkeyd
              SUMMARY : buffer overflow
                 DATE : 2003-04-28 08:49 UTC
              EXPLOIT : remote
    VERSIONS AFFECTED : <monkeyd-0.6.2
        FIXED VERSION : >=monkeyd-0.6.2
                  CVE :

    - - - ---------------------------------------------------------------------

    Previous issue contained some errors.

    - - From advisory:

    "A buffer overflow vulnerability exists in Monkey's handling of forms
    submitted with the POST request method. The unchecked buffer lies in the
    PostMethod() procedure."

    Read the full advisory at:
    http://marc.theaimsgroup.com/?l=bugtraq&m=105094204204166&w=2

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-www/monkeyd upgrade to monkeyd-0.6.3 as follows:

    emerge sync
    emerge monkeyd
    emerge clean

    - - - ---------------------------------------------------------------------
    aliz@gentoo.org - GnuPG key is available at http://cvs.gentoo.org/~aliz
    - - - ---------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.1 (GNU/Linux)

    iD8DBQE+rOsifT7nyhUpoZMRAlreAJ0UQiyUWazha/M0pN7I4Y0D7RHKDACfeoD6
    hmP5rw4B1A62fmge6y6OiP8=
    =FGfW
    -----END PGP SIGNATURE-----


  • Next message: nesumin: "[Opera 7/6] Long File Extension Heap Buffer Overrun Vulnerability in Download."

    Relevant Pages

    • [Full-Disclosure] GLSA: monkeyd (200304-07.1)
      ... "A buffer overflow vulnerability exists in Monkey's handling of forms ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge monkeyd ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: monkeyd (200304-07)
      ... "A buffer overflow vulnerability exists in Monkey's handling of forms ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge monkeyd ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: netscape-flash (200303-9)
      ... GENTOO LINUX SECURITY ANNOUNCEMENT 200303-9 ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge netscape-flash ...
      (Full-Disclosure)
    • [Full-Disclosure] GLSA: man (200303-13)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge sync ...
      (Full-Disclosure)
    • GLSA: rxvt (200303-16)
      ... Read the full advisory at: ... It is recommended that all Gentoo Linux users who are running ... emerge sync ...
      (Bugtraq)