| From: |
| Eridani Star System <linux@eridani.co.uk> |
| To: |
| eridani-announce@eridani.co.uk |
| Subject: |
| [Eridani-Announce] ERISA-2002:028 - glibc |
| Date: |
| Thu, 25 Jul 2002 18:44:13 +0100 (BST) |
=========================================================================
ERIDANI LINUX - SECURITY ANNOUNCEMENT
=========================================================================
Package: glibc
Summary: Vulnerabilities in glibc DNS resolver
Date: 2002-07-25
ID: ERISA-2002:028
=========================================================================
Problem description:
The glibc libraries have been found to contain a buffer overflow condition
in the code that glibc uses to resolve network names and addresses using
DNS. A system would be vulnerable to this issue if the "networks" database
in /etc/nsswitch.conf includes the "dns" entry. By default Eridani Linux
does not ship with this, instead it is set only to "files".
-------------------------------------------------------------------------
Updated packages:
8260cf54509542b2356ef47f48572797 glibc-2.1.3-24.src.rpm
31a1b42d46b55dab99529bcf2cdba05b glibc-2.1.3-24.i386.rpm
3f02c3865376b9790795cbd06de58c12 glibc-devel-2.1.3-24.i386.rpm
c764ee961319dc90512792de1f7d336b glibc-profile-2.1.3-24.i386.rpm
ad05be16eb485a09cf4f8f2e514e9452 nscd-2.1.3-24.i386.rpm
-------------------------------------------------------------------------
References:
CAN-2002-0684
=========================================================================
Packages available from ftp://ftp.eridani.co.uk/pub/Aeryn/
or by HTTP from http://ftp.eridani.co.uk/
Packages are signed with our GNU GPG key, also on our FTP site.
Users of releases of Eridani Linux prior to 6.3 are advised to download
the source RPM and rebuild for their system.
Copyright (C)2002 Eridani Star System
-- Michael "Soruk" McConnell http://www.eridani.co.uk
Eridani Linux -- The Most Up-to-Date Red Hat-based Linux CDROMs Available
Email: linux@eridani.co.uk -- Also Debian, Slackware, Mandrake and more...
_______________________________________________
Eridani-Announce mailing list
To be removed from this list email linux@eridani.co.uk requesting removal.
(
Log in to post comments)