Red Hat Security
Advisory: security problems with ypserv
Oct 28, 1999, 18:18 UTC (3 Talkbacks)
Date: Thu, 28 Oct 1999 12:35:00 -0400
From: Bill Nottingham <notting@redhat.com>
Red Hat, Inc. Security Advisory
Synopsis: security problems with ypserv
Advisory ID: RHSA-1999:046-01
Issue date: 1999-10-27
Updated on: 1999-10-27
Keywords:
Cross references: ypserv yppasswdd rpc.yppasswdd
1. Topic:
The ypserv package, which contains the ypserv NIS server
and the yppasswdd password-change server, has been discovered
to have security holes.
2. Problem description:
With ypserv, local administrators in the NIS domain could
possibly inject password tables. In rpc.yppasswdd, users
could change GECOS and login shells of other users, and
there is a buffer overflow in the md5 hash generation.
It is recommended that all users of the ypserv package upgrade
to the new packages.
|