Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Gentoo: 200301-9 Critical: fnord Buffer Overrun Exploit Threat

gentoo
Calendar Grey January 17, 2003
Dist Gentoo Esm H88
Upgrade fnord on Gentoo to mitigate buffer overrun exploits identified in Advisory 200301-9.
fnord 1.6 contained a buffer overrun in the CGI code

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-9
- --------------------------------------------------------------------
DATE    : 2003-01-17 10:01 UTC

- --------------------------------------------------------------------
From http://www.fefe.de/fnord/ :
"fnord 1.6 contained a buffer overrun in the CGI code. However, since the function does not return, this does not appear to be exploitable."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/fnord upgrade to fnord-1.7 as follows:
emerge sync emerge -u fnord emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

PACKAGE : fnord
SUMMARY : buffer overrun
EXPLOIT : remote

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here