Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: DSA 193-1 Critical: Kdenetwork Buffer Overflow Attack

debian
Calendar Grey November 11, 2002
Debian Logo
A critical buffer overflow vulnerability in Debian's kdenetwork requires immediate user updates to mitigate local attacks.
It is possible for a local attackerto exploit a buffer overflow condition in resLISa, a restrictedversion of KLISa.

Summary

iDEFENSE reports a security vulnerability in the klisa package, that
provides a LAN information service similar to "Network Neighbourhood",
which was discovered by Texonet. It is possible for a local attacker
to exploit a buffer overflow condition in resLISa, a restricted
version of KLISa. The vulnerability exists in the parsing of the
LOGNAME environment variable, an overly long value will overwrite the
instruction pointer thereby allowing an attacker to seize control of
the executable.

This problem has been fixed in version 2.2.2-14.2 the current stable
distribution (woody) and in version 2.2.2-14.3 for the unstable
distribution (sid). The old stable distribution (potato) is not
affected since it doesn't contain a kdenetwork package

We recommend that you upgrade your klisa package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get up...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: kdenetwork

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here