TUCoPS :: Linux :: Apps N-Z :: dsa180-1.txt

nis information leak

Debian Security Advisory DSA 180-1                                        Martin Schulze
October 21st, 2002            
Package        : nis
Vulnerability  : information leak
Problem-Type   : remote
Debian-specific: no

Thorsten Kukuck discovered a problem in the ypserv program which is
part of the Network Information Services (NIS).  A memory leak in all
versions of ypserv prior to 2.5 is remotely exploitable.  When a
malicious user could request a non-existing map the server will leak
parts of an old domainname and mapname.

This problem has been fixed in version 3.9-6.1 for the current stable
distribution (woody), in version 3.8-2.1 for the old stable
distribution (potato) and in version 3.9-6.2 for the unstable
distribution (sid).

We recommend that you upgrade your nis package.

Debian GNU/Linux 2.2 alias potato
- ---------------------------------
  Source archives:
  These files will probably be moved into the stable distribution on
  its next revision.

