Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 431
Alerts This Week
Warning Icon 1 431

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
200

Scientific Linux: ypbind SL3.x Bug Fix Update for Connection Issues

Low: ypbind bug fix update. Date: Wed, 28 May 2008 15:35:52 -0500 Reply-To: Troy Dawson Sender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for ypbind on SL3.x i386/x86_64 Comments: To: "This email address is being protected from spambots. You need JavaScript enabled to view it." Synopsis: Low: ypbind bug fix update Issue date: 2008-05-27 This updated package fixes the following bugs: * after a NIS server change, for example, after a server failure, ypbind corrupted files in the "/var/yp/binding/" directory. As well, these files were not updated, possibly causing old information to be retained. In these situations, glibc attempted to read the incorrect information, resulting in errors such as "RPC: Unable to receive; errno = Connection refused". * by default, NIS clients pinged NIS servers every 20 seconds. In large deployments, this added extra load, and could possibly cause a denial of service. In this updated package, a new "ypbind" option, "-ping-interval", has been added, which allows administrators to configure the ping interval value. SL 3.0.x SRPMS: ypbind-1.12-6.src.rpm i386: ypbind-1.12-6.i386.rpm x86_64: ypbind-1.12-6.x86_64.rpm -Connie Sieh -Troy Dawson . Resolving ypbind issues on Scientific Linux with crucial patches and solutions for existing problems.. ypbind, bug fix, Scientific Linux, network issue, security errata. . Severity: Low. LinuxSecurity.com Team

Calendar%202 May 28, 2008 Low Scientific Linux
98

CentOS 7.x, 8.x RHSA-2001:034-08 Severe: nfsd Local Escalation

ypbind as shipped in Red Hat Linux 5.x and 6.x is vulnerable to a localroot exploit.. ` --------------------------------------------------------------------- Red Hat, Inc. Security Advisory Synopsis: ypbind for Red Hat Linux 5.x, 6.x has a local root exploit Advisory ID: RHSA-2000:086-05 Issue date: 2000-10-16 Updated on: 2000-10-23 Product: Red Hat Linux Keywords: ypbind string format buffer overflow syslog Cross references: N/A --------------------------------------------------------------------- 1. Topic: ypbind as shipped in Red Hat Linux 5.x and 6.x is vulnerable to a local root exploit. All systems making use of NIS services are encouraged to upgrade. 2. Relevant releases/architectures: Red Hat Linux 5.0 - i386, alpha, sparc Red Hat Linux 5.1 - i386, alpha, sparc Red Hat Linux 5.2 - i386, alpha, sparc Red Hat Linux 6.0 - i386, alpha, sparc Red Hat Linux 6.1 - i386, alpha, sparc Red Hat Linux 6.2 - i386, alpha, sparc Red Hat Linux 6.2EE - i386, alpha, sparc 3. Problem description: Systems using Network Information Service, or NIS, use a daemon called ypbind to request information from a NIS server. This information is then used by the local machine. The logging code in ypbind is vulnerable to a printf string format attack which an attacker could exploit by passing ypbind a carefully crafted request. This attack can successfully lead to local root access. This problem has been corrected with these new packages. 4. Solution: If you do not use NIS, you should remove ypbind: rpm -e ypbind Otherwise, for each RPM for your particular architecture, run: rpm -Fvh [filename] where filename is the name of the RPM. You should then make sure that the new ypbind is running by issuing: /etc/rc.d/init.d/ypbind restart 5. Bug IDs fixed ( for more info): N/A 6. RPMs required: Red Hat Linux 5.x: alpha: sparc: i386: sources: Red Hat Linux 6.x: alpha: sparc: i386: sources: 7. Verification: MD5 sum Package Name -------------------------------------------------------------------------- 507ff0e63468e829b2c917789ba2fedd 5.2/SRPMS/ypbind-3.3-10.src.rpm 127274f9828d27f895e8d8eee8d38db6 5.2/alpha/ypbind-3.3-10.alpha.rpm 7bbf68a42a3c996c6f69b5ffaf2911f7 5.2/i386/ypbind-3.3-10.i386.rpm 3d0cd8b8700182b9b815525e1f99c82d 5.2/sparc/ypbind-3.3-10.sparc.rpm d8caa439a1b6c7b26f843bacd01c65f8 6.2/SRPMS/ypbind-1.7-0.6.x.src.rpm 3a426e3060d31aa37b2a41d973ac3f63 6.2/alpha/ypbind-1.7-0.6.x.alpha.rpm 411017238af9a0a8891bd3078547336c 6.2/i386/ypbind-1.7-0.6.x.i386.rpm 3beff51d6a0292fd9d50fe24d07097ac 6.2/sparc/ypbind-1.7-0.6.x.sparc.rpm These packages are GPG signed by Red Hat, Inc. for security. Our key is available at: You can verify each package with the following command: rpm --checksig If you only wish to verify that each package has not been corrupted or tampered with, examine only the md5sum with the following command: rpm --checksig --nogpg 8. References: N/A Copyright(c) 2000 Red Hat, Inc. `. Red Hat Linux warns of a critical ypbind local root exploit, advising immediate upgrades to prevent access risks.. local Access, Red Hat Linux, ypbind Exploit, Privilege Escalation, NIS Service. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 23, 2000 Critical Red Hat
100

OpenSUSE 7.x: 2002:051 High: nfsserver/rpc.lockd Exploit Risk

Security problems have been found in the client code of the NIS (Network Information System, aka yp - yellow pages) subsytem.. ______________________________________________________________________________ SuSE Security Announcement Package: ypbind/ypclient Announcement-ID: SuSE-SA:2000:042 Date: Wednesday, October 18th, 2000 19:15 MEST Affected SuSE versions: 6.0, 6.1, 6.2, 6.3, 6.4, 7.0 Vulnerability Type: possible remote root compromise Severity (1-10): 8 SuSE default package: yes (starting with SuSE-6.4) Other affected systems: Linux systems using this NIS implementation Content of this advisory: 1) security vulnerability resolved: ypbind/ypclient problem description, discussion, solution and upgrade information 2) pending vulnerabilities, solutions, workarounds 3) standard appendix (further information) ______________________________________________________________________________ 1) problem description, brief discussion, solution, upgrade information Security problems have been found in the client code of the NIS (Network Information System, aka yp - yellow pages) subsytem. SuSE distributions before SuSE-6.1 came with the original ypbind program, SuSE-6.2 and later included the ypbind-mt NIS client implementation. ypbind-3.3 (the earlier version) has a format string parsing bug if it is run in debug mode, and (discovered by Olaf Kirch ) leaks file descriptors under certain circumstances which can lead to a DoS. In addition, ypbind-3.3 may suffer from buffer overflows. ypbind-mt, the software shipped with SuSE distributions starting with SuSE-6.2, suffers from a single format string parsing bug. Some of these bugs could allow remote attackers to execute arbitrary code as root. During code audit and testing it turned out that the ypbind-3.x softwarein the SuSE-6.1 distribution and earlier needs a major overhaul to make it work both reliable and secure with respect to errors in the code. Basically, this is what happened when Thorsten Kukuk wrote ypbind-mt from scratch in 1998. For the same reason, we are currently unable to produce a working security update package which fixes the known and yet unknown (there may be more) problems in the ypclient packages in the SuSE-6.1 distribution and older. The only efficient workaround for the SuSE-6.1 distribution and older against these bugs for an untrusted, hostile environment is to upgrade to a new distribution base (SuSE-7.0 is recommended) and use the ypclient update packages for this distribution. As of today, there is no exploit known to exist in the wild. For SuSE-6.2 and later distributions we provide update packages as listed below. We recommend to download and install these packages on systems that are NIS/yp clients. Please note that the sources for the ypclient package are contained within the ypserv source rpm. Download the update package from locations described below and install the package with the command `rpm -Uhv file.rpm'. The md5sum for each file is in the line below. You can verify the integrity of the rpm files using the command `rpm --checksig --nogpg file.rpm', independently from the md5 signatures below. i386 Intel Platform: SuSE-7.0 76e4e7f60791db16c5e36fb5dbf60b65 source rpm: e2b1dccaec003f54e4ebbdef84d99a10 SuSE-6.4 e485ea27264fb9c4f890cdf7605ffa30 source rpm: c61c6df2ba1fef2369406b2dcbcd25f1 SuSE-6.3 c1a10cc0a3f72242b136be921f9ae0c1 source rpm: 6f47a880d5e7175dc2b5ff0116d7de4d SuSE-6.2 9050e63cb9f7fac4997968760292a6f1 source rpm: 7ecfaffd8cdb68f73adfd1d6fd27ed39 SuSE-6.1 and older: Please see the problem description above. Sparc Platform: SuSE-7.0 1a38d25c8647f010e2a9879f28de4adf source rpm: 6ba9200e49210f98ca845107b034b981 AXP Alpha Platform: SuSE-6.4 6aea95ca27245eb3df72da7596af3321 source rpm: a4bf635b9ee4bdefc29b7e6e1cf0cf41 SuSE-6.3 b68f8690b7dc554ac9098c83f9c633cd source rpm: ef0a026d078847d0958118bbbc46b99e PPC Power PC Platform: SuSE-6.4 26080b1443a3daa1de64c876ae36e6f2 source rpm: 4f0904d73c98c8b9737d5ac34b7a4dd5 ______________________________________________________________________________ 2) Pending vulnerabilities in SuSE Distributions and Workarounds: Another security announcement is following this advisory. ______________________________________________________________________________ 3) standard appendix: SuSE runs two security mailing lists to which any interested party may subscribe: This email address is being protected from spambots. You need JavaScript enabled to view it. - general/linux/SuSE security discussion. All SuSE security announcements are sent to this list. To subscribe, send an email to . This email address is being protected from spambots. You need JavaScript enabled to view it. - SuSE's announce-only mailing list. Only SuSE's security annoucements are sent to this list. To subscribe, send an email to . For general information or the frequently asked questions (faq) send mail to: or respectively. ============================================== SuSE's security contact is . ============================================== Regards, Roman Drahtmüller. - - -- - - | Roman Drahtmüller // "Caution: Cape does | SuSE GmbH - Security Phone: // not enable user to fly." | Nürnberg, Germany +49-911-740530 // (Batman Costume warning label) | - - ______________________________________________________________________________ The information in this advisory may be distributed or reproduced, provided that the advisory is not modified in any way. SuSE GmbH makes no warranties of any kind whatsoever with respect to the information contained in this security advisory. Type Bits/KeyID Date User ID pub 2048/3D25D3D9 1999/03/06 SuSE Security Team - -----BEGIN PGP PUBLIC KEY BLOCK----- Version: 2.6.3i mQENAzbhLQQAAAEIAKAkXHe0lWRBXLpn38hMHy03F0I4Sszmoc8aaKJrhfhyMlOA BqvklPLE2f9UrI4Xc860gH79ZREwAgPt0pi6+SleNFLNcNFAuuHMLQOOsaMFatbz JR9i4m/lf6q929YROu5zB48rBAlcfTm+IBbijaEdnqpwGib45wE/Cfy6FAttBHQh 1Kp+r/jPbf1mYAvljUfHKuvbg8t2EIQz/5yGp+n5trn9pElfQO2cRBq8LFpf1l+U P7EKjFmlOq+Gs/fF98/dP3DfniSd78LQPq5vp8RL8nr/o2i7jkAQ33m4f1wOBWd+ cZovrKXYlXiR+Bf7m2hpZo+/sAzhd7LmAD0l09kABRG0JVN1U0UgU2VjdXJpdHkg VGVhbSA8c2VjdXJpdHlAc3VzZS5kZT6JARUDBRA24S1H5Fiyh7HKPEUBAVcOB/9b yHYji1/+4Xc2GhvXK0FSJN0MGgeXgW47yxDL7gmR4mNgjlIOUHZj0PEpVjWepOJ7 tQS3L9oP6cpj1Fj/XxuLbkp5VCQ61hpt54coQAvYrnT9rtWEGN+xmwejT1WmYmDJ xG+EGBXKr+XP69oIUl1E2JO3rXeklulgjqRKos4cdXKgyjWZ7CP9V9daRXDtje63 Om8gwSdU/nCvhdRIWp/Vwbf7Ia8iZr9OJ5YuQl0DBG4qmGDDrvImgPAFkYFzwlqo choXFQ9y0YVCV41DnR+GYhwl2qBd81T8aXhihEGPIgaw3g8gd8B5o6mPVgl+nJqI BkEYGBusiag2pS6qwznZiQEVAwUQNuEtBHey5gA9JdPZAQFtOAf+KVh939b0J94u v/kpg4xs1LthlhquhbHcKNoVTNspugiC3qMPyvSX4XcBr2PC0cVkS4Z9PY9iCfT+ x9WM96g39dAF+le2CCx7XISk9XXJ4ApEy5g4AuK7NYgAJd39PPbERgWnxjxir9g0 Ix30dS30bW39D+3NPU5Ho9TD/B7UDFvYT5AWHl3MGwo3a1RhTs6sfgL7yQ3U+mvq MkTExZb5mfN1FeaYKMopoI4VpzNVeGxQWIz67VjJHVyUlF20ekOz4kWVgsxkc8G2 saqZd6yv2EwqYTi8BDAduweP33KrQc4KDDommQNDOXxaKOeCoESIdM4p7Esdjq1o L0oixF12Cg==pIeS - -----END PGP PUBLIC KEY BLOCK----- . Uncover crucial guidance from SuSE concerning security flaws in ypbind and ypclient that impact Network Information Service (NIS), emphasizing the importance of swift updates.. NIS Vulnerability, ypbind Update, SuSE Security Advisory, Remote Root Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 18, 2000 Critical SuSE
87

Debian 2.1, 2.2 Security Advisory: Critical Ypbind Local Exploit

The version of nis as distributed in Debian GNU/Linux 2.1 and 2.2 contains an ypbind package with a security problem.. - ------------------------------------------------------------------------ Debian Security Advisory This email address is being protected from spambots. You need JavaScript enabled to view it. Debian -- Security Information Wichert Akkerman October 14, 2000 - ------------------------------------------------------------------------ Package : nis Problem type : local exploit Debian-specific: no The version of nis as distributed in Debian GNU/Linux 2.1 and 2.2 contains an ypbind package with a security problem. ypbind is used to request information from a nis server which is then used by the local machine. The logging code in ypbind was vulnerable to a printf formating attack which can be exploited by passing ypbind a carefully crafted request. This way ypbind can be made to run arbitrary code as root. This has been fixed in version 3.5-2.1 for Debian GNU/Linux 2.1 and version 3.8-0.1 for Debian GNU/Linux 2.2 . We recommend you upgrade your nis package immediately. wget url will fetch the file for you dpkg -i file.deb will install the referenced file. Debian GNU/Linux 2.1 alias slink - -------------------------------- Slink was released for alpha, i386, m68k and sparc. At this moment security updates for alpha and sparc are no longer being made. Support for i386 and m68k will continue until the end of this month. Source archives: MD5 checksum: 979ec602bf463eae2b25c1a7d6828806 MD5 checksum: 69510c35dbca3a0be81f67fc9af0e8be MD5 checksum: 368167b1e16eb25ac639935310a26daa Intel ia32 architecture: MD5 checksum: 8400a6695d570315106391cab7108347 Motorola 680x0 architecture: MD5 checksum: d330f7a091a215f63181b9acee69661b Debian GNU/Linux 2.2 alias potato - --------------------------------- Potato was released for alpha, arm, i386, m68k, powerpc and sparc. Alpha architecture: MD5checksum: 1e361e5a9671c02eafdddeee4071f2cb Source archives: MD5 checksum: e15a7c09037c25fbd30c4721d683d068 MD5 checksum: 53d579eafd697b23cc0dba76a4566c2e MD5 checksum: 69bd8aa6b24cb22266cdc04354d3e287 ARM architecture: MD5 checksum: a1ba8db1065c56a1d18c063f6a69218b Intel ia32 architecture: MD5 checksum: b1a4588f81c0fda4815172d5a2bee134 PowerPC architecture: MD5 checksum: 5ac411b1d68da664649c1828962ee985 Sun Sparc architecture: MD5 checksum: 063c6e424da6ad714a3be5e85be034b9 These files will be moved into soon. For not yet released architectures please refer to the appropriate directory . - -- - ---------------------------------------------------------------------------- apt-get: deb Debian -- Security Information stable/updates main dpkg-ftp: dists/stable/updates/main . Critical flaw identified in the ypbind module on Debian releases 2.1 and 2.2 necessitates immediate action and updates. Safeguard your system now!. Debian Security, ypbind Exploit, nis Vulnerability. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 16, 2000 Critical Debian
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":1,"type":"x","order":1,"pct":16.67,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":50,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":33.33,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200