OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Daniel Ahlberg (aliz_at_gentoo.org)
Date: Thu Sep 05 2002 - 08:03:57 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - - --------------------------------------------------------------------
    GENTOO LINUX SECURITY ANNOUNCEMENT
    - - --------------------------------------------------------------------

    PACKAGE :amavis
    SUMMARY :possible dos
    DATE :2002-09-05 10:30 UTC

    - - --------------------------------------------------------------------

    OVERVIEW

    possible DoS attack by a special crafted TAR archive file

    DETAIL

    The AMaViS shell script version (AMaViS 0.1.x / 0.2.x) uses securetar.
    securetar removes the pathes of files in a tar archive and makes each
    file name a unique name. Links, character devices, block devices and named
    pipes will be removed from the archive.
    A special-crafted TAR file may hung securetar forever, using up to
    100% CPU time.

    More information can be found at:

    http://marc.theaimsgroup.com/?l=amavis-announce&m=103121272122242&w=2

    SOLUTION

    It is recommended that all Gentoo Linux users who are running
    net-mail/amavis-0.2.1-r2 and earlier update their systems
    as follows:

    emerge rsync
    emerge amavis
    emerge clean

    - - --------------------------------------------------------------------
    alizgentoo.org - GnuPG key is available at www.gentoo.org/~aliz
    - - --------------------------------------------------------------------
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.0.7 (GNU/Linux)

    iD8DBQE9d1Y9fT7nyhUpoZMRAiXrAJsFH2TeGxyZx6jGO03PbUYDzaPu7QCfayd3
    beUbZ/ZtN7EAjcRXdhTS34E=
    =M8tO
    -----END PGP SIGNATURE-----