LWN.net Logo

Gentoo alert syslog-ng-20021012 (app-admin syslog-ng)

From:  Seemant Kulleen <seemant@gentoo.org>
To:  gentoo-dev@gentoo.org, gentoo-core@gentoo.org, lwn@lwn.net, contribute@linuxsecurity.com
Subject:  GLSA: syslog-ng
Date:  Sat, 12 Oct 2002 03:44:13 -0700

- ----------------------------------------------------------------------- GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT - ----------------------------------------------------------------------- PACKAGE : app-admin/syslog-ng VERSION : 1.5.20 and below SUMMARY : buffer overflow vulnerability DATE : Sat Oct 12 10:31:38 UTC 2002 - ----------------------------------------------------------------------- OVERVIEW Macros can be used to identify message destinations and also to specify contents of destination files. Macros are expanded in a fixed length buffer with no bounds-checking. This is not a problem with the default configuration. DETAIL The full advisory may be found here: http://www.balabit.hu/static/zsa/ZSA-2002-014-en.txt SOLUTION It is recommended that all Gentoo Linux users who are running app-admin/syslog-ng-1.5.20* and earlier update their systems as follows. emerge rsync emerge syslog-ng emerge clean - ------------------------------------------------------------------------ blocke@gentoo.org seemant@gentoo.org drobbins@gentoo.org - ------------------------------------------------------------------------ -- Seemant Kulleen Developer and Project Co-ordinator, Gentoo Linux http://www.gentoo.org/~seemant - ----------------------------------------------------------------------- GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT - ----------------------------------------------------------------------- PACKAGE : net-dns/bind and net-dns/bind-tools VERSION : 9.2.1 SUMMARY : buffer overflow vulnerability DATE : Mon Aug 12 18:52:32 UTC 2002 - ----------------------------------------------------------------------- OVERVIEW A buffer overflow exists in bind and bind-tools versions 9.2.1 which may allow an attacker to execute arbitrary code, if s/he controls the DNS responses. DETAIL The full advisory may be found here: http://www.kb.cert.org/vuls/id/803539 SOLUTION It is recommended that all Gentoo Linux users who are running net-dns/bind-9.2.1-r2 and/or net-dns/bind-9.2.1 and earlier update their systems as follows. emerge rsync emerge bind (and/or emerge bind-tools) emerge clean - ------------------------------------------------------------------------ kevin@aptbasilicata.it seemant@gentoo.org drobbins@gentoo.org - ------------------------------------------------------------------------ -- Seemant Kulleen Developer and Project Co-ordinator, Gentoo Linux http://www.gentoo.org/~seemant


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds