|
|
|
| Top White Papers
Current Newswire:
Conectiva Linux Advisories: mpg123, ucd-snmpJul 16, 2003, 15:59 (0 Talkback[s])CONECTIVA LINUX SECURITY ANNOUNCEMENT
DESCRIPTION A vulnerability[1] in the way mpg123 handles mp3 files with a bitrate of zero may allow attackers to execute arbitrary code using a specially crafted mp3 file. This update fixes the problem. SOLUTION REFERENCES: UPDATED PACKAGES ADDITIONAL INSTRUCTIONS
Detailed instructions reagarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en Copyright (c) 2003 Conectiva Inc. http://www.conectiva.com CONECTIVA LINUX SECURITY ANNOUNCEMENT
DESCRIPTION Axioma Security Research found[1] a remote heap overflow vulnerability[2] in snmpnetstat (a tool used to retrieve information about a remote host). When a list of interfaces is requested, a malicious server can return information in a way that will cause a heap overflow in snmpnetstat. A remote atacker able to control a snmp server can exploit this vulnerability to execute arbitrary code with the privileges of the user running snmpnetstat. SOLUTION REFERENCES: UPDATED PACKAGES ADDITIONAL INSTRUCTIONS
Detailed instructions reagarding the use of apt and upgrade examples can be found at http://distro.conectiva.com.br/atualizacoes/#apt?idioma=en All packages are signed with Conectiva's GPG key. The key and instructions on how to import it can be found at http://distro.conectiva.com.br/seguranca/chave/?idioma=en Instructions on how to check the signatures of the RPM packages can be found at http://distro.conectiva.com.br/seguranca/politica/?idioma=en All our advisories and generic update instructions can be viewed at http://distro.conectiva.com.br/atualizacoes/?idioma=en Copyright (c) 2003 Conectiva Inc. http://www.conectiva.com 0 Talkback[s]
(click to add your comment)
|