Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

Gentoo: 200212-8 Critical Advisory on Canna Heap Overflow Remote Exploit

gentoo
Calendar Grey December 20, 2002
Dist Gentoo Esm H88
A critical overview of the Gentoo security advisory 200213-9 underscores multiple vulnerabilities present in the canna application affecting versions up to 3.7.
A heap overflow vulnerability was discovered in the irw_through function in canna server version 3.6 and earlier.

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200212-8
- --------------------------------------------------------------------
DATE    : 2002-12-20 17:12 UTC

- --------------------------------------------------------------------
Quotes from advisory:
"hsj" of Shadow Penguin Security discovered a heap overflow vulnerability in the irw_through function in canna server version 3.6 and earlier."
"AIDA Shinra of Canna project found lack of validations of requests in canna version 3.6 and earlier."
Read the full advisory at

SOLUTION
It is recommended that all Gentoo Linux users who are running app-i18n/canna-3.6 and earlier update their systems as follows:
emerge rsync emerge canna emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at nakano@gentoo.org - --------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : canna
SUMMARY : multiple vulnerabilities in canna
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here