Secunia Logo
 
SuSE update for pptpd
Secunia Advisory: SA8965
Release Date: 2003-06-09
Popularity: 7,690 views

Critical:
Highly critical
Impact: System access
Where: From remote
Solution Status: Vendor Patch

OS:SuSE eMail Server 3.x
SuSE Linux 7.x
SuSE Linux 8.x
SuSE Linux Connectivity Server
SuSE Linux Database Server
SuSE Linux Enterprise Server 7
SuSE Linux Enterprise Server 8
SuSE Linux Office Server

Subscribe: Instant alerts on relevant vulnerabilities


Description:
SuSE has issued an update for pptpd to fix a vulnerability allowing malicious people to gain system access.

The problem is that it is possible to cause an integer overflow in the third argument passed to the "read()" call. This could be exploited to execute arbitrary code on the system.

Solution:
Updated packages:

i386 Intel Platform:

SuSE-8.2:
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/i586/pptpd-1.1.2-418.i586.rpm
5caa610c56180b7597886cd919362fb3
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...m/i586/pptpd-1.1.2-418.i586.patch.rpm
d28db868016ac2ce61fd7234a47d1502
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.2/rpm/src/pptpd-1.1.2-418.src.rpm
d69f971343f9d1cb5eef5f57ce16fffa

SuSE-8.1:
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/i586/pptpd-1.1.2-413.i586.rpm
be9e2f5a26fcf3f95bf9ffcc206e926c
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/upda...m/i586/pptpd-1.1.2-413.i586.patch.rpm
448c505376cce08bdfa2e6b46f333db7
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.1/rpm/src/pptpd-1.1.2-413.src.rpm
067bd6274148e41b65d00e46674994a7

SuSE-8.0:
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/pptpd-1.1.2-412.i386.rpm
60f1550b7f19cb9a6184dc60d43da431
patch rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.0/n4/pptpd-1.1.2-412.i386.patch.rpm
870a38bd3256b196779e8e1e52cf2e5f
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/8.0/zq1/pptpd-1.1.2-412.src.rpm
78985af877c69ca16ee0ca652548aa79

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/i386/update/7.3/n3/pptpd-1.1.2-412.i386.rpm
598676ca6ba8fad2cc79ca722a2387c4
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/7.3/zq1/pptpd-1.1.2-412.src.rpm
c5871ca7d894338530db9fc2882744c0

SuSE-7.2:
ftp://ftp.suse.com/pub/suse/i386/update/7.2/n3/pptpd-1.1.2-411.i386.rpm
89bd9ceacaad198b9436f6fc95433f04
source rpm(s):
ftp://ftp.suse.com/pub/suse/i386/update/7.2/zq1/pptpd-1.1.2-411.src.rpm
96541c1e7ef7dfa6ce82ea4d3455e601


Sparc Platform:

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/n3/pptpd-1.1.2-132.sparc.rpm
5a868893c50a332b46fb50efd426db44
source rpm(s):
ftp://ftp.suse.com/pub/suse/sparc/update/7.3/zq1/pptpd-1.1.2-132.src.rpm
5654f0e078319165beee722d8250625d

PPC Power PC Platform:

SuSE-7.3:
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/n3/pptpd-1.1.2-262.ppc.rpm
6b8826e29930cfa077cfc6db18fd07f1
source rpm(s):
ftp://ftp.suse.com/pub/suse/ppc/update/7.3/zq1/pptpd-1.1.2-262.src.rpm
55208931a1240ca324fbefb155976bd6

Original Advisory:
http://suse.de/de/security/2003_029.html


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 56 views
2. Linksys WRT160N Cross-Site Scripting Vulnerability // 49 views
3. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 48 views
4. IBM Rational ClearQuest Multiple Vulnerabilities // 41 views
5. Mozilla Firefox 3 Multiple Vulnerabilities // 41 views
6. Sun Java JDK / JRE Multiple Vulnerabilities // 40 views
7. DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability // 39 views
8. Rumpus Multiple Vulnerabilities // 38 views
9. bcoos "cid" SQL Injection Vulnerability // 38 views
10. Debian update for flamethrower // 38 views