Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Malcolm Scott discovered a remote-exploitable buffer overflow in the rfc1413 (ident) client of cfingerd, a configurable finger daemon. This vulnerability was introduced in a previously applied patch to the cfingerd package in 1.4.3-3. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DSA-2635-1
Buffer overflow and format string attack vulnerabilities exist in previous versions of cfingerd.. ------------------------------------------------------------------------ Debian Security Advisory DSA-066-1
Megyer Laszlo report on Bugtraq that the cfingerd Debian as distributed with Debian GNU/Linux 2.2 was not careful in its logging code.. ------------------------------------------------------------------------ Debian Security Advisory DSA-048-1
We have received a report that the all versions of cfingerd prior to 1.4.0 and 1.3.2-18.1 are vulnerable to a root exploit - as posted on bugtraq. . We have received a report that the all versions of cfingerd prior to 1.4.0 and 1.3.2-18.1 are vulnerable to a root exploit - as posted on bugtraq. We recommend you upgrade your cfingerd package immediately or disable ALLOW_EXECUTION. The latter is turned off in the default Debian configuration. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink ------------------------------- Source archives: MD5 checksum: 01f1f08cb22716f3188370bb827557e4 MD5 checksum: 8fd375da499ec3e0198981a97c11d5fe Sun Sparc architecture: MD5 checksum: 7edc36abd55c18c0c8f9e90837ab15cb Intel architecture: MD5 checksum: 515bdcc9e579ce8b886341658bacaefd Motorola 680x0 architecture: MD5 checksum: ec6f1388f5a7b407637aabc4de29a0c5 Alpha architecture: MD5 checksum: 97123d5b5eed85c74788d0c35c20b03b Debian GNU/Linux unstable alias potato -------------------------------------- Source archives: .4.0-1.diff.gz MD5 checksum: ad4cf97b7c3f679e3b4133320cac769c -1.dsc MD5 checksum: c5b5448968db444ee70075087e35a294 Sun Sparc architecture: MD5 checksum: 8aa7fd61b8db6f76cb8120df3082a54e Intel ia32 architecture: MD5 checksum: a33ea81eb429c7b734a2769685c1131a Motorola 680x0 architecture: MD5 checksum: 09b035f723bb9dd831e7d3a23f80f2f7 Alpha architecture: MD5 checksum: a3ecf841a966487fa888a6b4e9f92bc7 PowerPC architecture: MD5 checksum: 011da6d4cacaaf78304559606ff2f05e For not yet released architectures please refer to the appropriate directory . -- Debian GNU/Linux . Security Managers .
Get the latest Linux and open source security news straight to your inbox.