| From: |
| Seemant Kulleen <seemant@gentoo.org> |
| To: |
| gentoo-dev@gentoo.org, gentoo-core@gentoo.org, lwn@lwn.net,
contribute@linuxsecurity.com |
| Subject: |
| GLSA: syslog-ng |
| Date: |
| Sat, 12 Oct 2002 03:44:13 -0700 |
- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : app-admin/syslog-ng
VERSION : 1.5.20 and below
SUMMARY : buffer overflow vulnerability
DATE : Sat Oct 12 10:31:38 UTC 2002
- -----------------------------------------------------------------------
OVERVIEW
Macros can be used to identify message destinations and also to specify
contents of destination files. Macros are expanded in a fixed length
buffer with no bounds-checking. This is not a problem with the default
configuration.
DETAIL
The full advisory may be found here:
http://www.balabit.hu/static/zsa/ZSA-2002-014-en.txt
SOLUTION
It is recommended that all Gentoo Linux users who are running
app-admin/syslog-ng-1.5.20* and earlier update their
systems as follows.
emerge rsync
emerge syslog-ng
emerge clean
- ------------------------------------------------------------------------
blocke@gentoo.org
seemant@gentoo.org
drobbins@gentoo.org
- ------------------------------------------------------------------------
--
Seemant Kulleen
Developer and Project Co-ordinator,
Gentoo Linux http://www.gentoo.org/~seemant
- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE : net-dns/bind and net-dns/bind-tools
VERSION : 9.2.1
SUMMARY : buffer overflow vulnerability
DATE : Mon Aug 12 18:52:32 UTC 2002
- -----------------------------------------------------------------------
OVERVIEW
A buffer overflow exists in bind and bind-tools versions 9.2.1 which may
allow an attacker to execute arbitrary code, if s/he controls the DNS
responses.
DETAIL
The full advisory may be found here:
http://www.kb.cert.org/vuls/id/803539
SOLUTION
It is recommended that all Gentoo Linux users who are running
net-dns/bind-9.2.1-r2 and/or net-dns/bind-9.2.1 and earlier update their
systems as follows.
emerge rsync
emerge bind (and/or emerge bind-tools)
emerge clean
- ------------------------------------------------------------------------
kevin@aptbasilicata.it
seemant@gentoo.org
drobbins@gentoo.org
- ------------------------------------------------------------------------
--
Seemant Kulleen
Developer and Project Co-ordinator,
Gentoo Linux http://www.gentoo.org/~seemant
(
Log in to post comments)