LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Advisory Watch: December 12th, 2014
Linux Security Week: December 9th, 2014
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Debian: New libnss-ldap packages fix denial of service Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Debian It was reported that a race condition exists in libnss-ldap, an NSS module for using LDAP as a naming service, which could cause denial of service attacks when applications use pthreads.
- ------------------------------------------------------------------------
Debian Security Advisory DSA-1430-1                  security@debian.org
http://www.debian.org/security/                               Steve Kemp
December 11, 2007                     http://www.debian.org/security/faq
- ------------------------------------------------------------------------

Package        : libnss-ldap
Vulnerability  : denial of service
Problem type   : local
Debian-specific: no
CVE Id(s)      : CVE-2007-5794
Debian Bug     : 453868

It was reported that a race condition exists in libnss-ldap, an
NSS module for using LDAP as a naming service, which could cause
denial of service attacks when applications use pthreads.

This problem was spotted in the dovecot IMAP/POP server but
potentially affects more programs.

For the stable distribution (etch), this problem has been fixed in version
251-7.5etch1.

For the old stable distribution (sarge), this problem has been fixed in
version 238-1sarge1.

For the unstable distribution (sid), this problem has been fixed in
version 256-1.

We recommend that you upgrade your libnss-ldap package.


Upgrade instructions
- --------------------

wget url
        will fetch the file for you
dpkg -i file.deb
        will install the referenced file.

If you are using the apt-get package manager, use the line for
sources.list as given below:

apt-get update
        will update the internal database
apt-get upgrade
        will install corrected packages

You may use an automated update by adding the resources from the
footer to the proper configuration.


Debian GNU/Linux 3.1 alias sarge
- --------------------------------

Source archives:

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238.orig.tar.gz
    Size/MD5 checksum:   219945 97fd929b381329b972b3c3ddca5a4bbf
  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1.diff.gz
    Size/MD5 checksum:    26236 c7191ee3845dc23ccf2712e78daed8f1
  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1.dsc
    Size/MD5 checksum:      681 3176fefa1d8d04afa9d3b458e40694a6

alpha architecture (DEC Alpha)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_alpha.deb
    Size/MD5 checksum:    86756 30a9c1691dcec614e36fdea923ba3906

amd64 architecture (AMD x86_64 (AMD64))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_amd64.deb
    Size/MD5 checksum:    80218 18d9da468326040f466c10cac6f50734

arm architecture (ARM)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_arm.deb
    Size/MD5 checksum:    79216 adf473266dd1de600cc0360f697ec7d2

hppa architecture (HP PA RISC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_hppa.deb
    Size/MD5 checksum:    86324 f98ade45a20c5426ef30cb1290e34164

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_i386.deb
    Size/MD5 checksum:    78894 7bb744d57899867a0b1c326372de76ce

ia64 architecture (Intel ia64)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_ia64.deb
    Size/MD5 checksum:    91930 d25cce59d45f8b8dc90b0fe3fcbf3ce0

m68k architecture (Motorola Mc680x0)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_m68k.deb
    Size/MD5 checksum:    76894 3c574bc294eb02c337664de43e814f7f

mips architecture (MIPS (Big Endian))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_mips.deb
    Size/MD5 checksum:    80482 0e54d051dde87e3b7984650c47bc3b3e

mipsel architecture (MIPS (Little Endian))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_mipsel.deb
    Size/MD5 checksum:    80594 9f3f4b5d6d7c9e6f84edd9ab40767e04

powerpc architecture (PowerPC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_powerpc.deb
    Size/MD5 checksum:    81652 7ca152887a041fc3dc674a77e707d23f

s390 architecture (IBM S/390)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_s390.deb
    Size/MD5 checksum:    83806 eab2386a51d35e31a4dd7fd0ed832a6d

sparc architecture (Sun SPARC/UltraSPARC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_238-1sarge1_sparc.deb
    Size/MD5 checksum:    79224 7d2ec91b89037fd137e98d3640ba1bb4


Debian GNU/Linux 4.0 alias etch
- -------------------------------

Source archives:

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1.diff.gz
    Size/MD5 checksum:   149322 04aa24732e69f40e5c3ab629b7e412d4
  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251.orig.tar.gz
    Size/MD5 checksum:   228931 a80718b3f7cf46f2579a26f9d6fbcd46
  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1.dsc
    Size/MD5 checksum:      683 007acb586d8bf61058c446a08aae4804

alpha architecture (DEC Alpha)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_alpha.deb
    Size/MD5 checksum:   108812 1150911f5446d2bc7838fd3d9d56329d

amd64 architecture (AMD x86_64 (AMD64))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_amd64.deb
    Size/MD5 checksum:   105206 7f2e2292e5c213a4d59e0c7240a9ca7e

arm architecture (ARM)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_arm.deb
    Size/MD5 checksum:   103946 bb4984bf517834f0278f00e8ba32a4ba

hppa architecture (HP PA RISC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_hppa.deb
    Size/MD5 checksum:   111288 2a7f758efdf03c296b2feea08205cdc7

i386 architecture (Intel ia32)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_i386.deb
    Size/MD5 checksum:   103732 0f29d1991d204b4a710e5f74bf056984

ia64 architecture (Intel ia64)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_ia64.deb
    Size/MD5 checksum:   120362 e5649299793b90c3987305ac2212afad

mips architecture (MIPS (Big Endian))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_mips.deb
    Size/MD5 checksum:   105148 1f42e34610dc974a6a5ff19a2dff1b24

mipsel architecture (MIPS (Little Endian))

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_mipsel.deb
    Size/MD5 checksum:   105360 af1ff4fd5a543b50f704a022798ebed0

powerpc architecture (PowerPC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_powerpc.deb
    Size/MD5 checksum:   106458 13b702d831bde6e52507fdd466573122

s390 architecture (IBM S/390)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_s390.deb
    Size/MD5 checksum:   108466 10bc9129adbc56dd6c75569fc27a221c

sparc architecture (Sun SPARC/UltraSPARC)

  http://security.debian.org/pool/updates/main/libn/libnss-ldap/libnss-ldap_251-7.5etch1_sparc.deb
    Size/MD5 checksum:   103134 12c84546a715bca647b86943a226b361


  These files will probably be moved into the stable distribution on
  its next update.

- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce@lists.debian.org
 
< Prev   Next >
    
Partner

 

Latest Features
Peter Smith Releases Linux Network Security Online
Securing a Linux Web Server
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Yesterday's Edition
University of California, Berkeley Hacked, Data Compromised
London teen pleads guilty to Spamhaus DDoS
New England security group shares threat intelligence, strives to bolster region
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2014 Guardian Digital, Inc. All rights reserved.