Skip to the content of the web site.

Vulnerabilities (2000)

Vulnerabilities identified during the 2000 calendar year.
  1. RedHat/Linux: LPRng printing service, 18-Dec-2000.
    Vulnerable Systems (Access Controlled)

    CERT Advisory CA-2000-22 reports that the LPRng printer daemon can be exploited if not patched. Systems which offer print services should apply the appropriate RPM; systems which rely on print services offered by other systems do not need a printer daemon -- disable the service.

    The RedHat Support site includes patches, security advisories and much more. We maintain a local mirror of RedHat Updates.

  2. SGI/IRIX: Telnet Note, 27-Oct-2000.
    Vulnerable Systems (Access Controlled)

    CERT Incident note IN-2000-09 reports an exploit of the telnetd daemon on SGI/IRIX systems -- we have seen several compromised systems. Systems must be patched (if a patch is available); alternatively the service should be disabled (ssh and rlogin services are acceptable alternatives).

    The SGI Security Site includes patches, security advisories and much more.

  3. RedHat/Linux: FTP daemon, 2-Oct-2000.
    Vulnerable Systems (Access Controlled)

    CERT Advisory CA-2000-13 reports a vulnerability with the WU-FTP server -- some RedHat Linux systems are vulnerable. We have seen systems compromised using this vulnerability. Systems which offer an FTP service should verify that they have applied the appropriate RPM update; others are encouraged to disable the service.

    The RedHat Support site includes patches, security advisories and much more. We maintain a local mirror of RedHat Updates.

  4. RedHat/Linux: RPC statd NFS service, 27-Sep-2000.
    Vulnerable Systems (Access Controlled)

    CERT Advisory CA-2000-17 reports a vulnerability with the RPC statd component of NFS services. Sites which use NFS services should make sure the appropriate RPM update is applied; sites which do not require NFS services should disable the daemons.

    The RedHat Support site includes patches, security advisories and much more. We maintain a local mirror of RedHat Updates.

(ed)Reg Quinton, Information Systems and Technology,
2000/09/27-2000/12/18