RedHat and SuSE release an updated 'ypserv' package
29 Oct. 1999
Summary
The ypserv package, which contains the ypserv NIS server and the yppasswd password-change server, contains several security holes.
With ypserv, local administrators in the NIS domain can inject password tables. In rpc. yppasswd, users can change GECOS and login shells of other users, and there is also a buffer overflow in the md5 hash generation.
It is recommended that all users of the ypserv package upgrade to the new packages.