Bug 5278 - [UPDATE REQUEST] ypbind
: [UPDATE REQUEST] ypbind
Status: RESOLVED FIXED
Product: Desktop Bugs
Classification: ROSA Desktop
Component: Main Packages
: Fresh
: All Linux
: Normal normal
: ---
Assigned To: ROSA Linux Bugs
: ROSA Linux Bugs
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2015-03-26 11:21 MSK by Zombie Ryushu
Modified: 2015-03-26 17:17 MSK (History)
2 users (show)

See Also:
RPM Package: ypbind-mt
ISO-related:
Bad POT generating:
Upstream:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Zombie Ryushu 2015-03-26 11:21:32 MSK
The current version of ypbind-mt is: 2.2
The last ipv4 only version of ypbind-mt is: 1.38. Rosa carries version 1.37

The ypbind-mt package contains a multithreaded ypbind daemon for Linux. It uses threads for better response and supports the ypbind protocols version 1, 2 and 3. A list of features from this new implementation:

Supports protocol v3 and IPv6.
Supports bindings to multiple domains.
Supports /var/yp/binding/* file for Linux libc 4/5 and glibc 2.x.
Supports a list of known secure NIS server (/etc/yp.conf)

ypbind-mt needs on Linux a TI-RPC library and libnis from yp-tools.

It may be a security vulnerability to have a version that old still in circulation.
Comment 1 Denis Silakov 2015-03-26 11:27:50 MSK
Yes, we should update all our YP packages.

Maybe we should also move these packages from main to contrib repository? NIS doesn't seem to be very popular nowadays.
Comment 2 Zombie Ryushu 2015-03-26 11:35:44 MSK
Thats probably prudent. The only thing still used is the NIS LDAP Schema, which is part of OpenLDAP  to simulate that functionality to the Name Service Switch (Netgroups, Automounts, etc.) but the YP Protocol is almost never used. Regardless. I don't want Sun RPC Attack vectors (Port 111) Left Vectors left unpatched. One of the first times I ever had a machine truly comprimised was on RedHat 6.2 because of Sun RPC Port 111 in NIS/YP.
Comment 3 Denis Silakov 2015-03-26 17:17:27 MSK
Done. Updated and moved to contrib.