Novell is now a part of Micro Focus

Security Bugfix for INN and mininews

Knowledgebase

(Last modified: 26MAR2002)


solutions Security Bugfix for INN and mininews SuSE Linux Maintenance Web (653b829760cd76995cf7fabb6d391fa6)

Applies to

Product(s): SuSE Linux Enterprise Server 7 for PowerPC
SuSE Linux Enterprise Server 7 for IA32
SuSE Linux Enterprise Server 7 for IA64
SuSE Linux Enterprise Server 7 for S/390 and zSeries
SuSE Linux Enterprise Server for S/390
SuSE Linux Connectivity Server

Package: inn
mininews
Release: 20020326
Obsoletes: none

Indications

Everybody using INN or mininews should install this package.

Contraindications

None.

Problem description

A format string error exists in inews that can allow a local attacker to obtain increased privileges. In particular, the attacker can get the effective group-ID 'news', which will allow him to change files that hold configuration data of the news (inn) subsystem. As a consequence, it may be possible for the attacker to get root privileges on the local host.

Solution

Please install the updates provided at the location noted below.

Installation notes

First find out whether you have installed INN or mininews:
rpm -q inn mininews
If any of the packages is installed, download that package and install it with 'rpm -Uhv':
  • For INN: rpm -Uhv inn.rpm
  • For mininews: rpm -Uhv mininews.rpm

links to download packages

Download Source Packages

Download the source code of the patches for maintained products.


Disclaimer

The Origin of this information may be internal or external to Novell. Novell makes all reasonable efforts to verify this information. However, the information provided in this document is for your information only. Novell makes no explicit or implied claims to the validity of this information.

Any trademarks referenced in this document are the property of their respective owners. Consult your product manuals for complete trademark information.

© Copyright Micro Focus or one of its affiliates