Nitro Bodhisattva
Joined: 08 Apr 2002 Posts: 661 Location: San Francisco
|
Posted: Sun Jul 14, 2002 5:19 am Post subject: [gentoo-announce] GLSA: glibc |
|
|
Seemant Kulleen wrote: | - -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : glibc
SUMMARY : buffer overflow vulnerability in glibc
DATE : Sat Jul 13 21:36:11 UTC 2002
- -----------------------------------------------------------------------
OVERVIEW
The DNS resolver code in glibc may allow a remote attacker to send
malicious dns responses to execute arbitrary code or cause a denial of
service attack on affected systems.
DETAIL
Any code run by the attacker would run with the same privileges as the
process which calls the resolver library. Additionally, the attacker may
cause one of the services on the victim machine to make DNS requests to a
server under the attacker's control and execute more arbitrary code.
http://www.cert.org/advisories/CA-2002-19.html
https://bugs.gentoo.org/show_bug.cgi?id=4923
SOLUTION
It is recommended that all Gentoo Linux users update their systems as
follows.
emerge --clean rsync
emerge glibc
emerge clean
|
Mailing list archive: http://lists.gentoo.org/pipermail/gentoo-announce/2002-July/000176.html _________________ - Kyle Manna
Please, please SEARCH before posting.
There are three kinds of people in the world: those who can count, and those who can't. |
|