Immunix Secured OS 7+ nfs-utils update -- bugtraq

From: Immunix Security Team (security_at_immunix.com)
Date: 07/16/03

  • Next message: KF: "SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows"
    Date: Tue, 15 Jul 2003 17:10:25 -0700
    To: bugtraq@securityfocus.com
    
    
    

    [Please do not set vacation autoreplies to public mail lists. It is
    very rude. Please do not tell us our gpg signature is a virus. It is
    not. Thank you.]

    -----------------------------------------------------------------------
            Immunix Secured OS Security Advisory

    Packages updated: nfs-utils
    Affected products: Immunix OS 7+
    Bugs fixed: CAN-2003-0252
    Date: Mon Jul 14 2003
    Advisory ID: IMNX-2003-7+-018-01
    Author: Seth Arnold <sarnold@immunix.com>
    -----------------------------------------------------------------------

    Description:
      Janusz Niewiadomski has discovered an off-by-one overflow in xlog() in
      the nfs-utils package. It is rumoured this bug is exploitable, however
      as it writes a single zero byte to memory, an exploit may be difficult
      to write.

      Because the overflow is so small, StackGuard may not be able to
      prevent exploitation of this flaw.

      References: http://www.securityfocus.com/archive/1/328946
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2003-0252

    Package names and locations:
      Precompiled binary packages for Immunix 7+ are available at:
      http://download.immunix.org/ImmunixOS/7+/Updates/RPMS/nfs-utils-0.3.1-7_imnx_3.i386.rpm
      Source packages for Immunix 7+ are available at:
      http://download.immunix.org/ImmunixOS/7+/Updates/SRPMS/nfs-utils-0.3.1-7_imnx_3.src.rpm

    Immunix OS 7+ md5sums:
      61b6c75291f772e6b6fa7f53284a6021 RPMS/nfs-utils-0.3.1-7_imnx_3.i386.rpm
      8f1067f0acfe49ba0bb8d88da5bd7f30 SRPMS/nfs-utils-0.3.1-7_imnx_3.src.rpm

    GPG verification:
      Our public key is available at http://download.immunix.org/GPG_KEY

    NOTE:
      Ibiblio is graciously mirroring our updates, so if the links above are
      slow, please try:
        ftp://ftp.ibiblio.org/pub/Linux/distributions/immunix/
      or one of the many mirrors available at:
        http://www.ibiblio.org/pub/Linux/MIRRORS.html

      ImmunixOS 6.2 is no longer officially supported.
      ImmunixOS 7.0 is no longer officially supported.

    Contact information:
      To report vulnerabilities, please contact security@immunix.com.
      Immunix attempts to conform to the RFP vulnerability disclosure protocol
      http://www.wiretrip.net/rfp/policy.html.

    
    



  • Next message: KF: "SRT2003-07-08-1223 - IBM U2 UniVerse uvadm can take root via buffer overflows"

    Relevant Pages

    • Immunix Secured OS 7+ openssh update
      ... public mail lists. ... A vulnerability has been reported in OpenSSH that is rumoured to be ... Immunix, Inc., has changed policy with GPG keys. ... Immunix 7.3 package signing, and 1B7456DA for general security issues. ...
      (Bugtraq)
    • Immunix Secured OS 7+ MySQL update
      ... There have been a number of vulnerabilities found in MySQL and the MySQL ... Immunix does not protect against all of these problems. ... Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL ...
      (Bugtraq)
    • Immunix Secured OS 7+ MySQL update
      ... There have been a number of vulnerabilities found in MySQL and the MySQL ... Immunix does not protect against all of these problems. ... Signed integer vulnerability in the COM_TABLE_DUMP package for MySQL ...
      (Bugtraq)
    • Immunix Secured OS 7.3, 7+ rsync update
      ... Please whitelist public mail lists. ... StackGuard offers no protection to this vulnerability. ... Immunix 7.3 users may use our up2date service to install fixed ... Precompiled binary packages for Immunix 7.3 are available at: ...
      (Bugtraq)
    • Immunix Secured OS 7+ bind update
      ... mail lists; perhaps, creating such a reply that works only within the ... A vulnerability has been found in BIND that ".. ... Our options were limited by ISC, the package maintainer. ... Precompiled binary packages for Immunix 7+ are available at: ...
      (Bugtraq)

  • Quantcast