<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>80267</bug_id>
          
          <creation_ts>2005-01-31 16:12 0000</creation_ts>
          <short_desc>net-misc/dante: FD_SET Overflow Vulnerability</short_desc>
          <delta_ts>2009-07-13 22:35:17 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          <bug_file_loc>http://www.inet.no/dante/announce-1.1.15</bug_file_loc>
          <status_whiteboard>C3 [noglsa] lewk</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>minor</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>lewk@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>agriffis@gentoo.org</cc>
    
    <cc>kaiowas@gentoo.org</cc>

      

      
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2005-01-31 16:12:27 0000</bug_when>
            <thetext>TITLE:
Dante FD_SET Overflow Vulnerability

SECUNIA ADVISORY ID:
SA14071

VERIFY ADVISORY:
http://secunia.com/advisories/14071/

CRITICAL:
Less critical

IMPACT:
DoS

WHERE:
&gt;From local network

SOFTWARE:
Dante 1.x
http://secunia.com/product/4583/

DESCRIPTION:
3APA3A has reported a vulnerability in Dante, which can be exploited
by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to a missing boundary check when
doing &quot;FD_SET()&quot; operations. This can be exploited to cause a buffer
overflow in certain configurations by establishing multiple
concurrent connections.

The vulnerability has been reported in version 1.1. Other versions
may also be affected.

SOLUTION:
Update to version 1.1.15.
http://www.inet.no/dante/

PROVIDED AND/OR DISCOVERED BY:
3APA3A

ORIGINAL ADVISORY:
Inferno Nettverk:
http://www.inet.no/dante/advisory-2005-01-28

3APA3A:
http://www.security.nnov.ru/advisories/sockets.asp</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2005-01-31 16:14:44 0000</bug_when>
            <thetext>agriffis, there is no metadata for this package, and you were the last one to bump it, so please update bump to 1.1.15</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kaiowas@gentoo.org</who>
            <bug_when>2005-02-02 23:39:40 0000</bug_when>
            <thetext>version bumped. please test and mark stable for your arch</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2005-02-03 04:09:19 0000</bug_when>
            <thetext>just works. stable on ppc64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2005-02-03 05:53:58 0000</bug_when>
            <thetext>sparc good.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>tester@gentoo.org</who>
            <bug_when>2005-02-03 09:18:40 0000</bug_when>
            <thetext>x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>kloeri@gentoo.org</who>
            <bug_when>2005-02-04 13:03:57 0000</bug_when>
            <thetext>Stable on alpha.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hansmi@gentoo.org</who>
            <bug_when>2005-02-04 14:05:10 0000</bug_when>
            <thetext>Sorry for the delay. Stable on ppc.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>luckyduck@gentoo.org</who>
            <bug_when>2005-02-04 15:22:05 0000</bug_when>
            <thetext>stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2005-02-06 02:43:35 0000</bug_when>
            <thetext>arm/hppa/ia64/s390 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>koon@gentoo.org</who>
            <bug_when>2005-02-06 09:21:30 0000</bug_when>
            <thetext>Please vote: only very specific conf affected -&gt; NO ?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jaervosz@gentoo.org</who>
            <bug_when>2005-02-06 11:16:02 0000</bug_when>
            <thetext>I vote for no GLSA here as well. Lewk?</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>lewk@gentoo.org</who>
            <bug_when>2005-02-07 05:29:24 0000</bug_when>
            <thetext>Closing without GLSA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>hardave@gentoo.org</who>
            <bug_when>2005-02-17 23:40:40 0000</bug_when>
            <thetext>Stable on mips.</thetext>
          </long_desc>
      
    </bug>

</bugzilla>