Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 2.1, 2.2 Security Advisory: Critical Ypbind Local Exploit

debian
Calendar Grey October 16, 2000
Debian Logo
Critical flaw identified in the ypbind module on Debian releases 2.1 and 2.2 necessitates immediate action and updates. Safeguard your system now!
The version of nis as distributed in Debian GNU/Linux 2.1 and 2.2 contains an ypbind package with a security problem.

Summary

Package : nis
Problem type : local exploit
Debian-specific: no

The version of nis as distributed in Debian GNU/Linux 2.1 and 2.2
contains an ypbind package with a security problem.

ypbind is used to request information from a nis server which is then
used by the local machine. The logging code in ypbind was vulnerable to a
printf formating attack which can be exploited by passing ypbind a
carefully crafted request. This way ypbind can be made to run arbitrary
code as root.

This has been fixed in version 3.5-2.1 for Debian GNU/Linux 2.1 and
version 3.8-0.1 for Debian GNU/Linux 2.2 .

We recommend you upgrade your nis package immediately.

wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.

Debian GNU/Linux 2.1 alias slink

Slink was released for alpha, i386, m68k and sparc. At this moment
security updates for alpha and sparc are no longer being made.
Support for i386 and m68k will continue until the end of this month.

Source archives:

...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here