radvd: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201111-08 / radvd |
| Release Date |
November 20, 2011 |
| Latest Revision |
November 20, 2011: 1 |
| Impact |
high |
| Exploitable |
local, remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-misc/radvd |
<
1.8.2 |
>=
1.8.2 |
All supported architectures
|
Related bugreports:
#385967
Synopsis
Multiple vulnerabilities have been found in radvd which could
potentially lead to privilege escalation, data loss, or a Denial of
Service.
2.
Impact Information
Background
radvd is an IPv6 router advertisement daemon for Linux and BSD.
Description
Multiple vulnerabilities have been discovered in radvd. Please review
the CVE identifiers referenced below for details.
Impact
A remote unauthenticated attacker may be able to gain escalated
privileges, escalate the privileges of the radvd process, overwrite files
with specific names, or cause a Denial of Service. Local attackers may be
able to overwrite the contents of arbitrary files using symlinks.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All radvd users should upgrade to the latest stable version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-misc/radvd-1.8.2"
|
4.
References
|