First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 74443
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Sune Kloppenborg Jeppesen <jaervosz@gentoo.org>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 74443 depends on: Show dependency tree
Show dependency graph
Bug 74443 blocks:

Additional Comments: (this is where you put emerge --info)







View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2004-12-14 21:37 0000
Ethereal 0.10.8 is scheduled to be released tomorrow (December 15).  It
will address the following issues:

  Matthew Bing discovered a bug in DICOM dissection that could make
  Ethereal crash.
  Versions affected: 0.10.4 - 0.10.7
  Revision fixed: 12504

  An invalid RTP timestamp could make Ethereal hang and create a large
  temporary file, possibly filling available disk space.
  Versions affected: 0.9.16 - 0.10.7
  Revision fixed: 12656

  The HTTP dissector could access previously-freed memory, causing
  a crash.
  Versions affected: 0.10.1 - 0.10.7
  Revision fixed: 12640 & 12668

  Brian Caswell discovered that an improperly formatted SMB packet
  could make Ethereal hang, maximizing CPU utilization.
  Versions affected: 0.9.0 - 0.10.7
  Revision fixed: 12706


Ethereal's SVN repository can be browsed online at

    http://anonsvn.ethereal.com/viewcvs/viewcvs.py/

Information on checking out the source code directly can be found at

    http://www.ethereal.com/development.html#source

------- Comment #1 From Sune Kloppenborg Jeppesen 2004-12-14 21:41:48 0000 -------
eldad please be ready to bump when the update is released later today.

------- Comment #2 From Eldad Zack (RETIRED) 2004-12-14 23:44:14 0000 -------
I'm available, ping me at IRC as soon as 0.10.8 gets out.

------- Comment #3 From Sune Kloppenborg Jeppesen 2004-12-15 00:56:44 0000 -------
> 

------- Comment #4 From Sune Kloppenborg Jeppesen 2004-12-15 00:56:44 0000 -------
>  Matthew Bing discovered a bug in DICOM dissection that could make
>  Ethereal crash.
>  Versions affected: 0.10.4 - 0.10.7
>  Revision fixed: 12504

CAN-2004-1139

>  An invalid RTP timestamp could make Ethereal hang and create a large
>  temporary file, possibly filling available disk space.
>  Versions affected: 0.9.16 - 0.10.7
>  Revision fixed: 12656

CAN-2004-1140

>  The HTTP dissector could access previously-freed memory, causing
>  a crash.
>  Versions affected: 0.10.1 - 0.10.7
>  Revision fixed: 12640 & 12668

CAN-2004-1141

>  Brian Caswell discovered that an improperly formatted SMB packet
>  could make Ethereal hang, maximizing CPU utilization.<br>
>  Versions affected: 0.9.0 - 0.10.7
>  Revision fixed: 12706

CAN-2004-1142

------- Comment #5 From Sune Kloppenborg Jeppesen 2004-12-15 04:01:05 0000 -------
Opening this is public now.

------- Comment #6 From Sune Kloppenborg Jeppesen 2004-12-15 04:01:56 0000 -------
*** Bug 74466 has been marked as a duplicate of this bug. ***

------- Comment #7 From Thierry Carrez (RETIRED) 2004-12-15 05:04:37 0000 -------
Really opening it

------- Comment #8 From Thierry Carrez (RETIRED) 2004-12-15 07:40:18 0000 -------
Waiting for upstream release...

------- Comment #9 From Eldad Zack (RETIRED) 2004-12-15 14:57:47 0000 -------
released upstream.

testing now.

------- Comment #10 From Eldad Zack (RETIRED) 2004-12-15 15:14:25 0000 -------
x86 stable

------- Comment #11 From Sune Kloppenborg Jeppesen 2004-12-15 15:19:15 0000 -------
Thx Eldad.

Arches please mark stable.

------- Comment #12 From Jason Wever (RETIRED) 2004-12-15 18:18:39 0000 -------
Keep on sparc'in

------- Comment #13 From Jochen Maes (RETIRED) 2004-12-16 00:23:53 0000 -------
stable on ppc 

------- Comment #14 From Bryan Østergaard (RETIRED) 2004-12-16 10:33:18 0000 -------
Alpha stable.

------- Comment #15 From Eldad Zack (RETIRED) 2004-12-17 14:58:10 0000 -------
we need pcc64 as well.

------- Comment #16 From Eldad Zack (RETIRED) 2004-12-17 15:07:45 0000 -------
mobile herd: kismet depends on various ethereal version. Since we are going to
purge every version beside 0.10.8, please update your ebuilds...

------- Comment #17 From Simon Stelling (RETIRED) 2004-12-18 02:12:51 0000 -------
amd64 done

------- Comment #18 From Henrik Brix Andersen 2004-12-18 03:03:46 0000 -------
ppc: please mark net-wireless/kismet-2004.10.1-r1 as 'ppc'.

sparc: please mark net-wireless/kismet-2004.10.1-r1 as '~sparc'.

------- Comment #19 From Michael Hanselmann (hansmi) (RETIRED) 2004-12-18 03:30:43 0000 -------
ppc done.

------- Comment #20 From Markus Rothe 2004-12-18 05:07:23 0000 -------
stable on ppc64

------- Comment #21 From Jason Wever (RETIRED) 2004-12-18 05:31:14 0000 -------
Masked on sparc because it is unknown if this application even works on SPARC
and we do not have an effective way to test it.

------- Comment #22 From Sune Kloppenborg Jeppesen 2004-12-18 05:45:33 0000 -------
Thx Brix for noting the Kismet problem. This one is ready for GLSA.

------- Comment #23 From Eldad Zack (RETIRED) 2004-12-18 05:52:29 0000 -------
what about ia64?

------- Comment #24 From Thierry Carrez (RETIRED) 2004-12-18 06:02:24 0000 -------
ia64 is not a security-supported arch (see security policy at
http://www.gentoo.org/security/en/vulnerability-policy.xml), so we cc them but
they don't block GLSA release. GLSA goes out when all security-supported arches
are ready.

------- Comment #25 From Sune Kloppenborg Jeppesen 2004-12-19 06:42:30 0000 -------
GLSA 200412-15

------- Comment #26 From Akinori Hattori 2004-12-21 03:18:25 0000 -------
stable on ia64

First Last Prev Next    No search results available      Search page      Enter new bug