Home
| Calendar
| Mail Lists
| List Archives
| Desktop SIG
| Hardware Hacking SIG
Wiki | Flickr | PicasaWeb | Video | Maps & Directions | Installfests | Keysignings Linux Cafe | Meeting Notes | Linux Links | Bling | About BLU |
This was in Linux Today... ---------------------------------------------------------------------------------------------------- SuSE Security Announcement Package: INN 2.0 and higher Date: Wed May 19 15:20:33 CEST 1999 Affected: Unix operating systems using INN >= 2.0 Some security holes were discovered in the package mentioned above. Please update as soon as possible or disable the service if you are using this software on your SuSE Linux installation(s). Other Linux distributions or operating systems might be affected as well, please contact your vendor for information about this issue. Please note, that we provide this information on as "as-is" basis only. There is no warranty whatsoever and no liability for any direct, indirect or incidental damage arising from this information or the installation of the update package. 1. Problem Description The innd wrapper inndstart could be tricked to execute arbitrary code by editing the environment (INNCONF), by modifing the inn.conf file or by overflowing a buffer. 2. Impact As long as /usr/lib/news/bin/inndstart is SUID root a attacker could gain local root access to your system. 3. Solution Remove the SUID bit of inndstart by executing /bin/chmod 700 /usr/lib/news/bin/inndstart Disallow other users than news to access /usr/lib/news /bin/chmod go-rwx /usr/lib/news Install a patch (update the package) as soon as the bug is fixed! ----------------------------------------------------------------------------------------------- This was in Linux Today... --Blake -------------- next part -------------- An HTML attachment was scrubbed... URL: <http://lists.blu.org/pipermail/discuss/attachments/19990520/74106cc2/attachment.html>
BLU is a member of BostonUserGroups | |
We also thank MIT for the use of their facilities. |