The Canna server, used for Japanese character input, has two security
vulnerabilities including an exploitable buffer overflow that allows a local
user to gain 'bin' user privileges. Updated packages for Red Hat Linux
7.1 for iSeries and pSeries are available.
Canna is a kana-kanji conversion server, which is necessary for Japanese
language character input.
A buffer overflow bug in the Canna server up to and including version 3.5b2
allows a local user to gain the privileges of the user 'bin' which can
lead to further exploits. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CAN-2002-1158 to this issue.
Additionally, it was discovered that request validation was lacking in
Canna server versions 3.6 and earlier. A malicious remote user could
exploit this vulnerability to leak information or cause a denial of service
attack.(CAN-2002-1159)
Red Hat Linux ships with a Canna package vulnerable to these issues;
however, the package is normally only installed when Japanese language
support is selected during installation.
All users of Canna are advised to upgrade to these errata packages which
contain a backported security fix and are not vulnerable to this issue.
Red Hat would like to thank hsj and AIDA Shinra for the responsible
disclosure of these issues.
| Red Hat Linux 7.1 for iSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/iSeries/SRPMS/Canna-3.5b2-50.ppc.src.rpm
Missing file |
ee21b261ee821ef8304023433670751c |
| |
| iSeries: |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/Canna-3.5b2-50.ppc.ppc.rpm
Missing file |
899685518edb14e16e28730b1418ecbe |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/Canna-devel-3.5b2-50.ppc.ppc.rpm
Missing file |
f492191f6b550950a4fed91108617dd5 |
ftp://updates.redhat.com/7.1/en/os/iSeries/ppc/Canna-libs-3.5b2-50.ppc.ppc.rpm
Missing file |
435c463b4171f1b939d97eccca3b7689 |
| |
| Red Hat Linux 7.1 for pSeries |
|
| SRPMS: |
ftp://updates.redhat.com/7.1/en/os/pSeries/SRPMS/Canna-3.5b2-50.ppc.src.rpm
Missing file |
ee21b261ee821ef8304023433670751c |
| |
| pSeries: |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/Canna-3.5b2-50.ppc.ppc.rpm
Missing file |
899685518edb14e16e28730b1418ecbe |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/Canna-devel-3.5b2-50.ppc.ppc.rpm
Missing file |
f492191f6b550950a4fed91108617dd5 |
ftp://updates.redhat.com/7.1/en/os/pSeries/ppc/Canna-libs-3.5b2-50.ppc.ppc.rpm
Missing file |
435c463b4171f1b939d97eccca3b7689 |
| |
78108 - AS2.1: Canna vulnerabilities