<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>137626</bug_id>
          
          <creation_ts>2006-06-22 11:05 0000</creation_ts>
          <short_desc>xt_sctp: fix endless loop caused by 0 chunk length (CVE-2006-3085)</short_desc>
          <delta_ts>2009-07-10 23:15:08 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Kernel</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.21</bug_file_loc>
          <status_whiteboard>[linux &lt;2.6.16.21] [linux &gt;=2.6.17 &lt;2.6.17.1]</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>jaervosz@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>agriffis@gentoo.org</cc>
    
    <cc>chrb@gentoo.org</cc>
    
    <cc>gimli@gentoo.org</cc>
    
    <cc>hardened-kernel@gentoo.org</cc>
    
    <cc>johnm@gentoo.org</cc>
    
    <cc>kang@gentoo.org</cc>
    
    <cc>kumba@gentoo.org</cc>
    
    <cc>marineam@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2006-06-22 11:05:17 0000</bug_when>
            <thetext>Fix endless loop in the SCTP match similar to those already fixed in the
    SCTP conntrack helper (was CVE-2006-1527).
    
    Signed-off-by: Patrick McHardy &lt;kaber@trash.net&gt;
    Signed-off-by: Chris Wright &lt;chrisw@sous-sol.org&gt;</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-06-24 13:04:49 0000</bug_when>
            <thetext>dsd: Please bump genpatches-2.6.16 to .21.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>sebastian_ml@gmx.net</who>
            <bug_when>2006-06-26 13:40:44 0000</bug_when>
            <thetext>Hi!

2.6.16.22 is already out in the open, allthough I stumbled over it by accident. Is there an easy way to keep track of these updates? They&apos;re only on the kernel.org frontpage for the latest series (now 2.6.17).

Cheers
Sebastian</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dsd@gentoo.org</who>
            <bug_when>2006-07-01 04:51:58 0000</bug_when>
            <thetext>Fixed in gentoo-sources-2.6.16-r11 / genpatches-2.6.16-23</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-07-02 08:44:07 0000</bug_when>
            <thetext>Maintainers please bump to 2.6.16.23/2.7.17.3 preferably or genpatches-2.6.16-13/genpatches-2.6.17-2:

ck-sources-2.6.16: marineam
ck-sources-2.6.17: marineam
hardened-sources-2.6: johnm, hardened
mips-sources-2.6.16: `Kumba
rsbac-sources-2.6: kang
sh-sources-2.6: vapier
suspend2-sources-2.6: brix
usermode-sources-2.6: dang
xbox-sources-2.6: chrb, gimli
xen-sources-2.6: chrb, agriffis</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dang@gentoo.org</who>
            <bug_when>2006-07-03 11:04:49 0000</bug_when>
            <thetext>usermode-sources done for 2.6.16.  There isn&apos;t a 2.6.17 yet, so it will get the newest genpatches when it&apos;s added.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>henrik@brixandersen.dk</who>
            <bug_when>2006-07-04 11:05:12 0000</bug_when>
            <thetext>Fixed in sys-kernel/suspend2-sources-2.6.16-r10. 

sys-kernel/suspend2-sources-2.6.17* is not yet in portage.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>marineam@gentoo.org</who>
            <bug_when>2006-07-09 16:39:28 0000</bug_when>
            <thetext>Fixed in ck-sources-2.6.16_p12-r1 and ck-sources-2.6.17_p1-r1.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>plasmaroo@gentoo.org</who>
            <bug_when>2006-08-07 14:01:40 0000</bug_when>
            <thetext>All fixed, closing.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>