- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-9
- --------------------------------------------------------------------

PACKAGE : fnord
SUMMARY : buffer overrun
DATE    : 2003-01-17 10:01 UTC
EXPLOIT : remote

- --------------------------------------------------------------------

From  http://www.fefe.de/fnord/ :

"fnord 1.6 contained a buffer overrun in the CGI code. However, since
the function does not return, this does not appear to be exploitable."

SOLUTION

It is recommended that all Gentoo Linux users who are running
net-www/fnord upgrade to fnord-1.7 as follows:

emerge sync
emerge -u fnord
emerge clean

- --------------------------------------------------------------------
aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------


Gentoo: fnord buffer overflow vulnerability

fnord 1.6 contained a buffer overrun in the CGI code

Summary


- --------------------------------------------------------------------
GENTOO LINUX SECURITY ANNOUNCEMENT 200301-9
- --------------------------------------------------------------------
DATE    : 2003-01-17 10:01 UTC

- --------------------------------------------------------------------
From http://www.fefe.de/fnord/ :
"fnord 1.6 contained a buffer overrun in the CGI code. However, since the function does not return, this does not appear to be exploitable."
SOLUTION
It is recommended that all Gentoo Linux users who are running net-www/fnord upgrade to fnord-1.7 as follows:
emerge sync emerge -u fnord emerge clean
- -------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at - --------------------------------------------------------------------

Resolution

References

Availability

Concerns

Severity
PACKAGE : fnord
SUMMARY : buffer overrun
EXPLOIT : remote

Synopsis

Background

Affected Packages

Impact

Workaround

Related News