drucken bookmarks versenden konfigurieren admin pdf Sicherheit: DOS-Attacke auf amavis
| Name: |
DOS-Attacke auf amavis
|
|
| ID: |
|
|
| Distribution: |
Gentoo |
|
| Plattformen: |
Keine Angabe |
|
| Datum: |
Sa, 7. September 2002, 13:00 |
|
| Referenzen: |
Keine Angabe |
|
Originalnachricht |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
-------------------------------------------------------------------- GENTOO LINUX SECURITY ANNOUNCEMENT --------------------------------------------------------------------
PACKAGE :amavis SUMMARY :possible dos DATE :2002-09-05 10:30 UTC
--------------------------------------------------------------------
OVERVIEW
possible DoS attack by a special crafted TAR archive file
DETAIL
The AMaViS shell script version (AMaViS 0.1.x / 0.2.x) uses securetar. securetar removes the pathes of files in a tar archive and makes each file name a unique name. Links, character devices, block devices and named pipes will be removed from the archive. A special-crafted TAR file may hung securetar forever, using up to 100% CPU time.
More information can be found at:
http://marc.theaimsgroup.com/?l=amavis-announce&m=103121272122242&w=2
SOLUTION
It is recommended that all Gentoo Linux users who are running net-mail/amavis-0.2.1-r2 and earlier update their systems as follows:
emerge rsync emerge amavis emerge clean
-------------------------------------------------------------------- aliz@gentoo.org - GnuPG key is available at www.gentoo.org/~aliz -------------------------------------------------------------------- -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux)
iD8DBQE9d1YyfT7nyhUpoZMRAj3/AJ9L+OrIwfyK5ggEaDdUpCrytgD7fQCgrqRe Rk8XxSZB7m90juAR/qZ+gAQ= =cbs4 -----END PGP SIGNATURE-----
_______________________________________________ gentoo-security mailing list gentoo-security@gentoo.org http://lists.gentoo.org/mailman/listinfo/gentoo-security
|
|
|
|