LWN.net Logo

apcupsd - remote root vulnerability and buffer overflows

Package(s):apcupsd CVE #(s):CAN-2003-0098 CAN-2003-0099
Created:February 24, 2003 Updated:April 3, 2003
Description: From the MandrakeSoft advisory:

A remote root vulnerability in slave setups and some buffer overflows in the network information server code were discovered by the apcupsd developers. They have been fixed in the latest unstable version, 3.10.5 which contains additional enhancements like USB support, and the latest stable version, 3.8.6.

There are a few changes that need to be noted, such as the port has changed from port 7000 to post 3551 for NIS, and the new config only allows access from the localhost. Users may need to modify their configuration files appropriately, depending upon their configuration.

Alerts:
Debian DSA-277-1 2003-04-03
SuSE SuSE-SA:2003:022 2003-03-26
SCO Group CSSA-2003-015.0 2003-03-25
Mandrake MDKSA-2003:018 2003-02-18
Gentoo 200302-13 2003-02-24

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds