ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/ http://www.linuxsecurity.com/advisories/freebsd_advisory-734.html
September 20th, 2000 -- SuSE: 'syslogd/klogd' vulnerability -- Errors in both the klogd and the syslogd can cause both daemons do die when specially designed strings get passed to the kernel by the user, eg. with a malformed structure in a system call.
Package Name: syslogd-1.3.33-161
URL: ftp://ftp.suse.com/pub/suse/
http://www.linuxsecurity.com/advisories/suse_advisory-732.html
September 19th, 2000 -- Mandrake: 'sysklogd' vulnerability -- A problem exists with the kernel logging daemon (klogd) in the sysklogd package. A "format bug" makes klogd vulnerable to local root compromise, as well as the possibility for remote vulnerabilities under certain circumstances, which are unprobable. There is also a more probable semi-remote exploit via knfsd. This update provides a patched version of klogd that fixes these vulnerabilities.
Package Name: sysklogd-1.3.31-15
URL: ftp://ftp.free.fr/pub/Distributions_Linux/Mandrake/updates
http://www.linuxsecurity.com/advisories/mandrake_advisory-730.html
September 19th, 2000 -- Trustix: 'sysklogd' vulnerability -- Trustix Secure Linux also suffers from a security hole in sysklogd. Everybody running 1.0x or 1.1 should upgrade. The hole is already fixed in the new beta (1.1.80).
Package Name: sysklogd-1.3.31-18tr.i586.rpm
URL: ftp://ftp.trustix.com/pub/Trustix/updates/1.1/RPMS
http://www.linuxsecurity.com/advisories/other_advisory-731.html
September 19th, 2000 -- Slackware: 'sysklogd' vunlerability -- A string format / buffer overflow bug has been discovered in klogd, the kernel logging daemon. Please upgrade to the new sysklogd 1.4 package available on the Slackware FTP site.
Package Name: sysklogd.tgz
URL:ftp://ftp.slackware.com/pub/slackware/slackware-current/slakware/a1/
http://www.linuxsecurity.com/advisories/slackware_advisory-729.html
* Debian: Info: Phasing out support for 2.1
Debian is phasing out support for Debian 2.1 (slink). We believe that this will have a minimal impact on our user community as we expect that most slink users have already upgraded to potato. We had originally announced that support would end Sep 30, 2000.
http://www.linuxsecurity.com/advisories/debian_advisory-720.html
September 19th, 2000 -- Debian: 'sysklogd' vulnerability -- Multiple vulnerabilities have been reported in syslogd and klogd. A local root exploit is possible, and remote exploits may be possible in some cases (though we are not currently aware of a remote exploit.)
Package Name: sysklogd_1.3-33
URL: ftp://security.debian.org/debian-security
http://www.linuxsecurity.com/advisories/debian_advisory-727.html
September 19th, 2000 -- TurboLinux: 'xchat' vulnerability -- There has been a well-known vulnerability existing with all un-patched xchat versions 1.4.2 and earlier. By supplying commands enclosed in backticks (``) in URL's sent to X-Chat, it is possible to execute arbitrary commands should the X-Chat user decide to view the link by clicking on it. This is due to the manner in which X-Chat launches pages for viewing.
http://www.linuxsecurity.com/advisories/turbolinux_advisory-723.html
September 19th, 2000 -- TurboLinux: 'sysklogd' vulnerability -- Package Name: sysklogd-1.3.31-6
URL: ftp://ftp.turbolinux.com/pub/updates/6.0/
http://www.linuxsecurity.com/advisories/turbolinux_advisory-725.html
September 18th, 2000 -- RedHat: 'syslogd' vulnerabilities -- Various vulnerabilities exist in syslogd/klogd. By exploiting these vulnerabilities, it could be possible for local users to gain root access. No remote exploit exists at this time, but it remains theoretically possible that this vulnerability could be exploited remotely under certain rare circumstances.
Package Name: sysklogd-1.3.31-1.6
URL: ftp://updates.redhat.com/5.2/
ftp://updates.redhat.com/6.2/
http://www.linuxsecurity.com/advisories/redhat_advisory-722.html