Security Fix for Linux Universal NFS Daemon

Olaf Kirch (okir@MONAD.SWB.DE)
Wed, 27 Aug 1997 13:07:12 +0200

-----BEGIN PGP SIGNED MESSAGE-----

Recently, a security problem with many rpc.mountd implementations was
reported on bugtraq which also affected the Linux UNFSD rpc.mountd.
An otherwise unauthorized client was able to get different error
codes depending on whether the file existed or not, allowing an
attacker to get an overview of installed software.

A fixed release of the Linux Universal NFS Server is now available
from ftp://ftp.mathematik.th-darmstadt.de/pub/linux/okir:

703b50114fb10813c9c863a54585ac74 nfs-server-2.2beta29.tar.gz

Olaf
- --
Olaf Kirch | --- o --- Nous sommes du soleil we love when we play
okir@monad.swb.de | / | \ sol.dhoop.naytheet.ah kin.ir.samse.qurax
okir@lst.de +-------------------- Why Not?! -----------------------

-----BEGIN PGP SIGNATURE-----
Version: 2.6.2i

iQCVAwUBNAQKDeFnVHXv40etAQES/gP/e6tiMXhfcf3R8WFPOcixcs0gwiguqENL
3k7Yjphb23sn2iVV3BKR+Mfep2yCV1mdMEHtWA3dEKrca8/q0XFRdBKlBx/BXQze
h6exph4DC4xU8dJPH8mfWQXHTpkP9hxK4kbJzSFNSAh/QyB48ndWJWRDRcY0AzDd
o7op7Lx/FnM=
=utpI
-----END PGP SIGNATURE-----