SciLinux: CVE-2007-3999 nfs-utils-lib SL4.x i386/x86_64
Summary
Date: Wed, 19 Sep 2007 16:46:34 -0500Reply-To: Troy DawsonSender: Security Errata for Scientific Linux From: Troy Dawson Subject: Security ERRATA for nfs-utils-lib on SL4.x i386/x86_64Comments: To: scientific-linux-errata@fnal.govSynopsis: Important: nfs-utils-lib security updateIssue date: 2007-09-19CVE Names: CVE-2007-3999Tenable Network Security discovered a stack buffer overflow flaw in the RPClibrary used by nfs-utils-lib. A remote unauthenticated attacker who canaccess an application linked against nfs-utils-lib could trigger this flawand cause the application to crash. On Red Hat Enterprise Linux 4 it is notpossible to exploit this flaw to run arbitrary code as the overflow isblocked by FORTIFY_SOURCE. (CVE-2007-3999)SL 4.x SRPMS:nfs-utils-lib-1.0.6-8.z1.src.rpm i386:nfs-utils-lib-1.0.6-8.z1.i386.rpmnfs-utils-lib-devel-1.0.6-8.z1.i386.rpm x86_64:nfs-utils-lib-1.0.6-8.z1.x86_64.rpmnfs-utils-lib-devel-1.0.6-8.z1.x86_64.rpm-Connie Sieh-Troy Dawson