BugTraq
GLSA: libnids (200311-07) Nov 24 2003 06:05PM
Andrea Barisani (lcars gentoo org)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ------------------------------------------------------------------------
---
GENTOO LINUX SECURITY ANNOUNCEMENT 200311-07
- - ------------------------------------------------------------------------
---

GLSA: 200311-07
package: net-libs/libnids
summary: Libnids remote code execution
severity: normal
Gentoo bug: 32724
date: 2003-11-22
CVE: CAN-2003-0850
exploit: remote
affected: <=1.17
fixed: >=1.18

DESCRIPTION:

There is a bug in the part of libnids code responsible for TCP reassembly.
The flaw probably allows remote code execution.

SOLUTION:

It is recommended that all Gentoo Linux users who are running
net-libs/libnids update their systems as follows:

emerge sync
emerge '>=net-libs/libnids-1.18'
emerge clean

- --
Andrea Barisani <lcars (at) gentoo (dot) org [email concealed]> .*.
Gentoo Linux Infrastructure Developer V
( )
GPG-Key 0xC9EE0905 http://dev.gentoo.org/~lcars/pubkey.asc ( )
491D E9E0 3875 0EC9 10DD 150B CAA9 2C7D C9EE 0905 ^^_^^

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)

iD8DBQE/wi78yqksfcnuCQURAmKjAJ0Y/K8Q8mbiwIvQCx44fgpNP0izoACfe4J0
q9x9uKfldu1ES92a1WP9Dyg=
=t5vz
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus