Submitted by KeesCook on Thu, 2007-08-30 00:04
Referenced CVEs:
CVE-2007-4601
Description:
===========================================================
Ubuntu Security Notice USN-507-1 August 30, 2007
tcp-wrappers vulnerability
CVE-2007-4601
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 7.04:
libwrap0 7.6.dbs-11ubuntu0.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
It was discovered that the TCP wrapper library was incorrectly allowing
connections to services that did not specify server-side connection
details. Remote attackers could connect to services that had been
configured to block such connections. This only affected Ubuntu Feisty.


