In response to a security hole in ez-ipupdate (the DynDNS client used
in m0n0wall) being reported on Full Disclosure, an update to m0n0wall
1.1 has been released. Systems with DynDNS enabled should be upgraded
as soon as possible. The workaround is to disable the DynDNS client.
No other changes have been made between 1.1 and 1.11. The images are
currently being distributed to the mirrors (some already carry them).
Note that 1.2b1/b2 are affected as well.
Details:
<http://lists.netsys.com/pipermail/full-disclosure/2004-November/028590.html>
- Manuel |