From owner-freebsd-security Thu Dec 14 22:31:49 2000 From owner-freebsd-security@FreeBSD.ORG Thu Dec 14 22:31:47 2000 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from citusc.usc.edu (citusc.usc.edu [128.125.38.123]) by hub.freebsd.org (Postfix) with ESMTP id 7EF7E37B400 for ; Thu, 14 Dec 2000 22:31:47 -0800 (PST) Received: (from kris@localhost) by citusc.usc.edu (8.9.3/8.9.3) id WAA02173; Thu, 14 Dec 2000 22:31:11 -0800 Date: Thu, 14 Dec 2000 22:31:11 -0800 From: Kris Kennaway To: Chris Faulhaber Cc: Cy Schubert - ITSD Open Systems Group , desmo@bandwidth.org, freebsd-security@FreeBSD.ORG Subject: Re: LPRng remote root exploit (fwd) Message-ID: <20001214223111.D2040@citusc.usc.edu> References: <200012150131.eBF1VPa05764@cwsys.cwsent.com> <20001214205749.A48180@peitho.fxp.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-sha1; protocol="application/pgp-signature"; boundary="IMjqdzrDRly81ofr" Content-Disposition: inline User-Agent: Mutt/1.2i In-Reply-To: <20001214205749.A48180@peitho.fxp.org>; from jedgar@fxp.org on Thu, Dec 14, 2000 at 08:57:49PM -0500 Sender: kris@citusc.usc.edu Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --IMjqdzrDRly81ofr Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Thu, Dec 14, 2000 at 08:57:49PM -0500, Chris Faulhaber wrote: > On Thu, Dec 14, 2000 at 05:30:52PM -0800, Cy Schubert - ITSD Open Systems= Group wrote: > > This is just a heads up. > >=20 > > Anyone care to test this with our LPRng port? > >=20 > *snip* > >=20 > > LPRng-3.6.22/23/24 remote root exploit, enjoy. > >=20 > *snip* >=20 >=20 > It won't hurt to try, however, ports/sysutils/LPRng is > at 3.6.26, which is supposed to fix this problem. Yes, I believe so. See the advisory of a month or so ago. Kris --IMjqdzrDRly81ofr Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (GNU/Linux) Comment: For info see http://www.gnupg.org iD8DBQE6ObqtWry0BWjoQKURAuF/AJ9cy9cp4Gb3dT8W4LwzBXO9Bm5LhgCg3gp8 4hyw7YzhZFETzdkVg8nA1OQ= =NHDD -----END PGP SIGNATURE----- --IMjqdzrDRly81ofr-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message