Important No-IP Linux Update Client Security Update

Bug #301908 reported by Bremm
330
This bug affects 9 people
Affects Status Importance Assigned to Milestone
no-ip (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

As long as it packaged for use in Ubuntu and derivates, someone should warn about it.

Current version in repos is 2.1.7-9

====================

No-IP has determined that the following advisory is applicable to
one or more of the systems you have registered.

Security Advisory - 2008-11-22
------------------------------------------------------------------------------
Summary:
Important: No-IP Linux DUC (Dynamic Update Client)

An updated version of the No-IP Linux Dynamic Update Client that fixes
a security issue is now available.

This update has been rated as having important security impact.

Description:
Versions 2.1.1- > 2.1.8 are prone to a stack-based buffer-overflow due to
a boundary error when processing HTTP responses received from the update
server. This can be exploited and cause a stack-based buffer overflow when
performing an update.

A malicious user could exploit this by faking the No-IP update server
via DNS poisoning or a man in the middle attack. This can cause a denial of
service (client crash) or
potentially execute arbitrary code on the computer the client is running on.

Users running versions 2.1.8 and older are encouraged to upgrade to the most
recent version, 2.1.9
at http://www.no-ip.com/downloads?page=linux&av=1

Regards,

The No-IP Team

Note: This email was sent from an unmonitored account. If you have any
questions or comments please open a trouble ticket at
http://www.no-ip.com/ticket

Changed in no-ip:
status: New → Confirmed
Revision history for this message
Joey Stanford (joey) wrote :

I got this warning today from them as well.

On Intrepid I show:
noip2 2.1.7-9 client for dynamic DNS service

Revision history for this message
Hassan El Jacifi (waver) wrote :

still 2.1.7-7ubuntu1 on intrepid

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thank you for using Ubuntu and taking the time to report a bug. no-ip is a universe package and community supported. As such, to get an updated package into Ubuntu, please follow https://wiki.ubuntu.com/SecurityUpdateProcedures.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.