YPServ Remote Network Information Leakage Vulnerability Solution:
This issue has been addressed in the latest release of ypserv. Users are advised to upgrate to ypserv v2.5.
HP has released an advisory for HP Secure OS 1.0, and has recommended users of the operating system apply the fixes described in Red Hat Security Advisory RHSA-2002:223 titled "Updated ypserv packages fixes memory leak".
SCO has made fixes available for Caldera Linux.
Debian has released an advisory. Fixes are available.
Gentoo Linux has released an advisory. Users who have installed net-nds/ypserv-1.3.12 are urged to update systems by issuing the following commands:
emerge rsync
emerge ypserv
emerge clean
Conectiva Linux has released a security advisory containing fixes. Further information can be obtained from the referenced advisory.
Mandrake has release a security advisory containing fixes. Information about obtaining and applying fixes can be found in the referenced advisory.
Sun has released an advisory containing fixes.
Fixes:
Sun Solaris 8
Sun Solaris 2.6_x86
RedHat ypserv-1.3.9-3.i386.rpm
Sun Solaris 7.0
RedHat ypserv-2.2-9.i386.rpm
Sun Solaris 9
Sun Solaris 7.0_x86
Sun Solaris 2.6
Sun Solaris 8_x86
Debian Linux 2.2 powerpc
Debian Linux 2.2
Debian Linux 2.2 arm
Debian Linux 2.2 alpha
Debian Linux 2.2 sparc
Debian Linux 2.2 68k
Thorsten Kukuk ypserv 2.4
Debian Linux 3.0 s/390
Debian Linux 3.0 alpha
Debian Linux 3.0 mips
Debian Linux 3.0 mipsel
Debian Linux 3.0 m68k
Debian Linux 3.0 hppa
Debian Linux 3.0 arm
Debian Linux 3.0 sparc
Debian Linux 3.0 ia-64
Debian Linux 3.0 ppc
Debian Linux 3.0
Caldera OpenLinux Server 3.1
Caldera OpenLinux Workstation 3.1
Caldera OpenLinux Server 3.1.1
Caldera OpenLinux Workstation 3.1.1
Conectiva Linux 6.0
RedHat Linux 6.2
Conectiva Linux 7.0
RedHat Linux 7.0
RedHat Linux 7.1
MandrakeSoft Linux Mandrake 7.2
RedHat Linux 7.2
RedHat Linux 7.3
MandrakeSoft Linux Mandrake 8.0 ppc
Conectiva Linux 8.0
MandrakeSoft Linux Mandrake 8.0
MandrakeSoft Linux Mandrake 8.1 ia64
MandrakeSoft Linux Mandrake 8.1
MandrakeSoft Linux Mandrake 8.2
MandrakeSoft Linux Mandrake 8.2 ppc
MandrakeSoft Linux Mandrake 9.0