GLSA: libnids (200311-07)

From: Andrea Barisani (lcars_at_gentoo.org)
Date: 11/24/03

  • Next message: Andrea Barisani: "GLSA: phpsysinfo (200311-06)"
    Date: Mon, 24 Nov 2003 18:05:17 +0000
    To: bugtraq@securityfocus.com
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - ---------------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT 200311-07
    - - ---------------------------------------------------------------------------

    GLSA: 200311-07
    package: net-libs/libnids
    summary: Libnids remote code execution
    severity: normal
    Gentoo bug: 32724
    date: 2003-11-22
    CVE: CAN-2003-0850
    exploit: remote
    affected: <=1.17
    fixed: >=1.18

    DESCRIPTION:

    There is a bug in the part of libnids code responsible for TCP reassembly.
    The flaw probably allows remote code execution.

    SOLUTION:

    It is recommended that all Gentoo Linux users who are running
    net-libs/libnids update their systems as follows:

    emerge sync
    emerge '>=net-libs/libnids-1.18'
    emerge clean

    - --
    Andrea Barisani <lcars@gentoo.org> .*.
    Gentoo Linux Infrastructure Developer V
                                                                 ( )
    GPG-Key 0xC9EE0905 http://dev.gentoo.org/~lcars/pubkey.asc ( )
        491D E9E0 3875 0EC9 10DD 150B CAA9 2C7D C9EE 0905 ^^_^^

    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.3 (GNU/Linux)

    iD8DBQE/wi78yqksfcnuCQURAmKjAJ0Y/K8Q8mbiwIvQCx44fgpNP0izoACfe4J0
    q9x9uKfldu1ES92a1WP9Dyg=
    =t5vz
    -----END PGP SIGNATURE-----


  • Next message: Andrea Barisani: "GLSA: phpsysinfo (200311-06)"

    Relevant Pages

    • GLSA: glibc (200311-05)
      ... Glibc getgrouplist buffer overrun vulnerability ... Gentoo bug: 33383 ... It is recommended that all Gentoo Linux users update their systems as ...
      (Bugtraq)
    • GLSA: phpsysinfo (200311-06)
      ... Gentoo bug: 26782 ... It is recommended that all Gentoo Linux users who are running ... dev-php/phpsysinfo upgrade to the fixed version: ...
      (Bugtraq)