[LWN Logo]
[LWN.net]
From:	 Eridani Star System <linux@eridani.co.uk>
To:	 eridani-announce@eridani.co.uk
Subject: [Eridani-Announce] ERISA-2002:020 - tcpdump
Date:	 Thu, 30 May 2002 15:58:31 +0100 (BST)

=========================================================================
		ERIDANI LINUX - SECURITY ANNOUNCEMENT
=========================================================================

Package:	tcpdump
Summary:	Buffer overflow when handling NFS packets
Date:		2002-05-30
ID:		ERISA-2002:020

=========================================================================

Problem description:

  A buffer overflow condition can be triggered by tracing a bad NFS
  packet. Whether this vulnerability is exploitable is not known at this
  time, however Eridani Linux users are advised to upgrade.

-------------------------------------------------------------------------
Updated packages:

  496a0b6f5d15934e8b9e8b2c97f5ab5f  tcpdump-3.6.2-11.src.rpm

  cefe0f7b694065c01180d17a41372f5b  arpwatch-2.1a11-11.i386.rpm
  213652784196ade9895f469aabe0de24  libpcap-0.6.2-11.i386.rpm
  6f7cb41176360fae84ced152c05da161  tcpdump-3.6.2-11.i386.rpm

-------------------------------------------------------------------------
References:

  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2002-0380

=========================================================================

Packages available from ftp://ftp.eridani.co.uk/pub/Aeryn/
or by HTTP from http://ftp.eridani.co.uk/

Packages are signed with our GNU GPG key, also on our FTP site.

Users of releases of Eridani Linux prior to 6.3 are advised to download   
the source RPM and rebuild for their system.

Copyright (C)2002 Eridani Star System

-- Michael "Soruk" McConnell                       http://www.eridani.co.uk
Eridani Linux  --  The Most Up-to-Date Red Hat-based Linux CDROMs Available
Email: linux@eridani.co.uk -- Also Debian, Slackware, Mandrake and more...


_______________________________________________
Eridani-Announce mailing list
To be removed from this list email linux@eridani.co.uk requesting removal.