OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
[SA10239] OpenLinux update for nfs-utils

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Tue Nov 18 2003 - 02:58:50 CST


TITLE:
OpenLinux update for nfs-utils

SECUNIA ADVISORY ID:
SA10239

VERIFY ADVISORY:
http://www.secunia.com/advisories/10239/

CRITICAL:
Moderately critical

IMPACT:
System access, DoS

WHERE:
From local network

OPERATING SYSTEM:
OpenLinux Workstation 3.x
OpenLinux Server 3.x

DESCRIPTION:
SCO has issued updated packages for nfs-utils. These fix a
vulnerability, which potentially can be exploited by malicious people
to compromise a vulnerable system.

For more information:
SA9259

SOLUTION:
Updates are available:

OpenLinux 3.1.1 Server
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Server/CSSA-2003-037.0/RPMS

30ea43154970596e70e4fe28d975384e nfs-0.2.1-12.i386.rpm
680b5214c57a02e1265229458ae881d3 nfs-lockd-0.2.1-12.i386.rpm
32ee130750f4502fc5bfb51ed46bbbd9 nfs-server-0.2.1-12.i386.rpm

OpenLinux 3.1.1 Workstation
ftp://ftp.sco.com/pub/updates/OpenLinux/3.1.1/Workstation/CSSA-2003-037.0/RPMS

40c11bad18969b6587a9d94b79c2e41c nfs-0.2.1-12.i386.rpm
f98629ebc8412a30a1ab6fe16ea55f77 nfs-lockd-0.2.1-12.i386.rpm
6407294bbb284c9e42f2769ef9941e8a nfs-server-0.2.1-12.i386.rpm

ORIGINAL ADVISORY:
OpenLinux: Linux NFS utils package contains remotely exploitable
off-by-one bug
ftp://ftp.sco.com/pub/security/OpenLinux/CSSA-2003-037.0.txt

OTHER REFERENCES:
SA9259:
http://www.secunia.com/advisories/9259/

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://www.secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://www.secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------