Bill Jonas on Sun, 11 Jun 2000 10:37:11 -0400 (EDT)


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] 2.2.16


For those of you who don't know, 2.2.16 was released at the end of last
week, fixing a local vulnerability regarding SUID executables and a
remote vulnerability regarding the sunrpc port (used for the r-commands,
NFS, and others).  I've heard reports, though, that have shed some doubt
on its stability.  Has anyone tried this?

BTW, I don't know about the SUID vulnerability, but the rpc port
vulnerability is a 2.2-specific issue.  If you're running 2.0, I don't
believe it affects you (although you've got other issues like a DoS
vulnerability).

Bill
-- 
>Ever heard of .cshrc?             | "Linux means never having to delete
That's a city in Bosnia. Right?    |  your love mail." -- Don Marti
(Discussion in comp.os.linux.misc  |  http://www.netaxs.com/~bj/
on the intuitiveness of commands.) |  http://www.harrybrowne.org/


______________________________________________________________________
Philadelphia Linux Users Group       -       http://plug.nothinbut.net
Announcements - http://lists.nothinbut.net/mail/listinfo/plug-announce
General Discussion   -   http://lists.nothinbut.net/mail/listinfo/plug