|
|
|
| Top White Papers
Current Newswire:
Debian releases updated cronAug 30, 1999, 15:44 (2 Talkback[s])---------------------------------------------------------------------------- Debian Security Advisory security@debian.org http://www.debian.org/security/ Martin Schulze August 30, 1999 ---------------------------------------------------------------------------- Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. Further investigation of Caldera and Debian discovered that it was even worse. Red Hat did find a root exploit but didn' notice. When sending a mail to the user Vixie Cron ran as root, not checking the mail address that was passed to sendmail on the commandline. We recommend you upgrade your cron package immediately. wget url dpkg -i file.deb Debian GNU/Linux 2.1 alias slink This version of Debian was released only for the Intel, the Motorola 68xxx, the alpha and the Sun sparc architecture. Source archives:
http://security.debian.org/dists/stable/updates/source/cron_3.0pl1-50.2.diff.gz Alpha architecture:
http://security.debian.org/dists/stable/updates/binary-alpha/cron_3.0pl1-50.2_alpha.deb Intel ia32 architecture:
http://security.debian.org/dists/stable/updates/binary-i386/cron_3.0pl1-50.2_i386.deb Motorola 680x0 architecture:
http://security.debian.org/dists/stable/updates/binary-m68k/cron_3.0pl1-50.2_m68k.deb Sun Sparc architecture:
http://security.debian.org/dists/stable/updates/binary-sparc/cron_3.0pl1-50.2_sparc.deb Debian GNU/Linux pre2.2 alias potato Source archives:
http://security.debian.org/dists/unstable/updates/source/cron_3.0pl1-52.diff.gz Alpha architecture:
http://security.debian.org/dists/unstable/updates/binary-alpha/cron_3.0pl1-52_alpha.deb ARM architecture:
http://security.debian.org/dists/unstable/updates/binary-arm/cron_3.0pl1-52_arm.deb Intel ia32 architecture:
http://security.debian.org/dists/unstable/updates/binary-i386/cron_3.0pl1-52_i386.deb Motorola 680x0 architecture:
http://security.debian.org/dists/unstable/updates/binary-m68k/cron_3.0pl1-52_m68k.deb PowerPC architecture:
http://security.debian.org/dists/unstable/updates/binary-powerpc/cron_3.0pl1-52_powerpc.deb Sun Sparc architecture:
http://security.debian.org/dists/unstable/updates/binary-sparc/cron_3.0pl1-52_sparc.deb For not yet released architectures please refer to the appropriate directory ftp://ftp.debian.org/debian/dists/sid/binary-$arch/ . Related Stories:
0 Talkback[s]
(click to add your comment)
|