public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-dev] GLSA: glibc
@ 2002-07-13 21:45 Seemant Kulleen
  0 siblings, 0 replies; only message in thread
From: Seemant Kulleen @ 2002-07-13 21:45 UTC (permalink / raw
  To: gentoo-announce, lwn, gentoo-user, gentoo-dev, gentoo-desktop,
	gentoo-newbies, gentoo-security, gentoo-sparc, gentoo-user,
	gentoo-user-es, gentooppc-dev, gentooppc-user

- -----------------------------------------------------------------------
GLSA: GENTOO LINUX SECURITY ANNOUNCEMENT
- -----------------------------------------------------------------------
PACKAGE         : glibc
SUMMARY         : buffer overflow vulnerability in glibc
DATE            : Sat Jul 13 21:36:11 UTC 2002
- -----------------------------------------------------------------------

OVERVIEW

The DNS resolver code in glibc may allow a remote attacker to send
malicious dns responses to execute arbitrary code or cause a denial of
service attack on affected systems.

DETAIL

Any code run by the attacker would run with the same privileges as the
process which calls the resolver library.  Additionally, the attacker may
cause one of the services on the victim machine to make DNS requests to a
server under the attacker's control and execute more arbitrary code.

http://www.cert.org/advisories/CA-2002-19.html
http://bugs.gentoo.org/show_bug.cgi?id=4923


SOLUTION

It is recommended that all Gentoo Linux users update their systems as
follows.

emerge --clean rsync
emerge glibc
emerge clean

- ------------------------------------------------------------------------
MichaelThompson@tx.slr.com
azarah@gentoo.org
seemant@gentoo.org
drobbins@gentoo.org
- ------------------------------------------------------------------------


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2002-07-13 21:46 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-07-13 21:45 [gentoo-dev] GLSA: glibc Seemant Kulleen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox