Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Gentoo: GLSA-202310-02 Critical: Remote Code Execution in librpcsecgss

gentoo
Calendar Grey October 4, 2007
Dist Gentoo Esm H88
Uncover a significant memory corruption vulnerability in Gentoo's librpcsecgss library that jeopardizes secure RPC interactions.
A buffer overflow vulnerability has been discovered in librpcsecgss.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200710-01
                                            https://security.gentoo.org/

Severity: High Title: RPCSEC_GSS library: Buffer overflow Date: October 04, 2007 Bugs: #191479 ID: 200710-01

Synopsis ======= A buffer overflow vulnerability has been discovered in librpcsecgss.
Background ========= librpcsecgss is an implementation of RPCSEC_GSS for secure RPC communications.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 net-libs/librpcsecgss < 0.16 >= 0.16
========== A stack based buffer overflow has been discovered in the svcauth_gss_validate() function in file lib/rpc/svc_auth_gss.c when processing an overly long s...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
critical
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here