[LON-CAPA-dev] linux.slapper notice

Scott Harrison lon-capa-dev@mail.lon-capa.org
Tue, 17 Sep 2002 13:24:17 -0400


Dear All:

If you haven't upgraded your RPMs in the last two months, you
face vulnerability to the linux.slapper.worm (which, speaking
from experience, is attacking everywhere hard this week).

"it exploits a buffer overflow
        vulnerability within OpenSSL, often used in Apache Web servers"

http://www.informationweek.com/news/IWK20020916S0001


To upgrade your RPMs:
* checkout/update the latest loncapa from CVS or the website (unstable)
* cd loncapa/loncom/build
* perl CHECKRPMS --download; cd /tmp/loncapa_rpm_updates; rpm -Fvh *.rpm


* If you are running lilo, you likely need to double check kernel version
  rpm -q kernel
  /etc/lilo.conf

  and run
           /sbin/lilo -v

More info on manual kernel upgrades is at:
http://www.redhat.com/support/resources/howto/kernel-upgrade/

Regards,
Scott

-- 
Scott Harrison, sharrison@users.sourceforge.net