Security Advisory Revised advisory: Updated package for nfs-utils available

Advisory: RHSA-2000:043-03
Type: Security Advisory
Severity: N/A
Issued on: 2000-07-17
Last updated on: 2000-07-21
Affected Products: Red Hat Linux 6.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2000-0666

Details

This is an updated of RHSA-2000:043 that contains further
upgrade instructions.

The rpc.statd daemon in the nfs-utils package shipped in Red Hat
Linux 6.0, 6.1, and 6.2 contains a flaw that could lead to a
remote root break-in.

The rpc.statd daemon shipped in Red Hat Linux 6.0, 6.1, and 6.2
contains a flaw that could lead to a remote root break-in.
Version 0.1.9.1 of the nfs-utils package corrects the problem.
Although there is no known exploit for the flaw in rpc.statd,
Red Hat urges all users running rpc.statd to upgrade to
the new nfs-utils package.

Users should note that in Red Hat Linux 6.0 and 6.1 the rpc.statd
daemon was in the knfsd-clients package. The nfs-utils package
replaces both the knfsd and knfsd-clients packages shipped in
Red Hat Linux 6.0 and 6.1.

On systems running a kernel older than 2.2.16-3, users should
also take this opportunity to upgrade to the latest kernel
release.


Solution

For each RPM for your particular architecture, run:

rpm -Fvh [filename]

where filename is the name of the RPM.

After installing the new nfs-utils package, the rpc.statd service
must be restarted. To do this, run:

/etc/rc.d/init.d/nfslock restart

Updated packages

Red Hat Linux 6.2

Alpha:
nfs-utils-0.1.9.1-1.alpha.rpm
File outdated by:  RHSA-2001:047
    9ffff59f1ac1dbe09694d70abaf356d2
 
i386:
ftp://updates.redhat.com/6.2/en/os/i386/nfs-utils-0.1.9.1-1.i386.rpm
Missing file
    c8fb4d05baca53e48e94c77593047262
 

References


Keywords

compromise


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/