-----BEGIN PGP SIGNED MESSAGE----- ______________________________________________________________________________ Caldera Systems, Inc. Security Advisory Subject: DoS attack on inn Advisory number: CSSA-1999-038.0 Issue date: 1999 December, 11 Cross reference: ______________________________________________________________________________ 1. Problem Description There are two problems in INN that can be exploited in a denial of service attack. In both cases, an article with bad formatting will cause the INN daemon (innd) to crash. Neither of the bugs appears to be exploitable, however. 2. Vulnerable Versions Systems : up to COL 2.3 Packages: previous to inn-2.2.1-3.i386.rpm 3. Solutions Workaround: not known The proper solution is to upgrade to the latest packages rpm -U inn-2.2.1-3.i386.rpm 4. Location of Fixed Packages The upgrade packages can be found on Caldera's FTP site at: ftp://ftp.calderasystems.com/pub/OpenLinux/updates/2.3/current/RPMS/ The corresponding source code package can be found at: ftp://ftp.calderaystems.com/pub/OpenLinux/updates/2.3/current/SRPMS 5. Installing Fixed Packages Upgrade the affected packages with the following commands: rpm -U inn-2.2.1-3.i386.rpm 6. Verification 06e73562ab23f5a2948ab51f00900fa6 RPMS/inn-2.2.1-3.i386.rpm e5f37f4af323b7735ad8567f25c79a93 SRPMS/inn-2.2.1-3.src.rpm 7. References This and other Caldera security resources are located at: http://www.calderasystems.com/support/security/index.html This security fix closes Caldera's internal Problem Report 5257 8. Disclaimer Caldera Systems, Inc. is not responsible for the misuse of any of the information we provide on this website and/or through our security advisories. Our advisories are a service to our customers intended to promote secure installation and use of Caldera OpenLinux. ______________________________________________________________________________ -----BEGIN PGP SIGNATURE----- Version: 2.6.3i Charset: noconv iQCVAwUBOFKI3en+9R4958LpAQFqLwP8CZyUqSpMH/zbXcE/3vXXxBsRZAyRfc6X GEhxwJx4JaK/lTeUA1i8DclS/0mRIny4naFTX2dKoKcYzhcUdf6+8kwh9o+4PtrA Zn0tSdAVNnwJCZ0UJ4cqGo03Z7PDUJl+iDwtk1wpLFoH+foco/z2HyRo8XquqfxM bU1rb6sBMWs= =gG7M -----END PGP SIGNATURE-----