Summary: | net-analyzer/wireshark < 0.99.2, net-analyzer/ethereal - multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | ChazeFroy <chazefroy> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | netmon, tcort |
Priority: | High | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Other | ||
URL: | http://www.wireshark.org | ||
Whiteboard: | B2? [glsa] DerCorny | ||
Package list: | Runtime testing required: | --- |
Description
ChazeFroy
2006-07-17 17:27:04 UTC
bumped in cvs Arches, please test and stable wireshark 0.99.2, thank you. Suggest modifying build to use the .tar.bz2 (9.3MB) instead of the tar.gz (12MB). This will save bandwidth on our mirrors. May also want to list other download locations. Sources are available on Sourceforge.net, among others. 1) emerges fine 2) passes test suite 3) passes collision test 4) changed setting, sniffed my network traffic (with and without vpn)-> works Portage 2.1-r1 (default-linux/x86/2006.0, gcc-3.4.6, glibc-2.3.6-r4, 2.6.16-gentoo-r13 i686) ================================================================= System uname: 2.6.16-gentoo-r13 i686 AMD Athlon(tm) XP 2500+ Gentoo Base System version 1.6.15 app-admin/eselect-compiler: [Not Present] dev-lang/python: 2.4.3-r1 dev-python/pycrypto: 2.0.1-r5 dev-util/ccache: [Not Present] dev-util/confcache: [Not Present] sys-apps/sandbox: 1.2.17 sys-devel/autoconf: 2.13, 2.59-r7 sys-devel/automake: 1.4_p6, 1.5, 1.6.3, 1.7.9-r1, 1.8.5-r3, 1.9.6-r2 sys-devel/binutils: 2.16.1-r3 sys-devel/gcc-config: 1.3.13-r3 sys-devel/libtool: 1.5.22 virtual/os-headers: 2.6.11-r2 ACCEPT_KEYWORDS="x86" AUTOCLEAN="yes" CBUILD="i686-pc-linux-gnu" CFLAGS="-O2" CHOST="i686-pc-linux-gnu" CONFIG_PROTECT="/etc /usr/share/X11/xkb" CONFIG_PROTECT_MASK="/etc/env.d /etc/gconf /etc/revdep-rebuild /etc/splash /etc/terminfo" CXXFLAGS="-O2" DISTDIR="/usr/portage/distfiles" FEATURES="autoconfig ccache collision-protect distlocks metadata-transfer parallel-fetch sandbox sfperms strict test" GENTOO_MIRRORS="ftp://sunsite.informatik.rwth-aachen.de/pub/Linux/gentoo/" LANG="de_DE@euro" LC_ALL="de_DE@euro" LINGUAS="de" MAKEOPTS="-j2" PKGDIR="/usr/portage/packages" PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --compress --force --whole-file --delete --delete-after --stats --timeout=180 --exclude='/distfiles' --exclude='/local' --exclude='/packages'" PORTAGE_TMPDIR="/var/tmp" PORTDIR="/usr/portage" PORTDIR_OVERLAY="/usr/local/portage" SYNC="rsync://rsync.informatik.rwth-aachen.de/gentoo-portage" USE="x86 3dnow 3dnowext X Xaw3d a52 alsa artworkextra asf audiofile avi bash-completion beagle berkdb bidi bitmap-fonts bootsplash branding bzip2 cairo cdda cddb cdparanoia cdr cli cracklib crypt css cups curl custom-cflags dbus dga directfb divx4linux dlloader dri dts dvd dvdr dvdread dvi eds emacs emboss encode esd evo exif expat fam fat fbcon fdftk ffmpeg firefox foomaticdb fortran ftp gb gcj gdbm gif gnome gpm gstreamer gtk gtk2 gtkhtml hal icq idn imagemagick imap imlib ipv6 isdnlog java javascript jikes jpeg jpeg2k ldap leim libg++ libwww lm_sensors mad maildir matroska mbox mikmod mime mmx mmxext mng mono motif mp3 mpeg mpeg2 mule nautilus ncurses nforce2 nls nocardbus nptl nptlonly nsplugin nvidia ogg opengl pam pcre pdf pdflib perl plotutils pmu png ppds pppd preview-latex print python qt qt3 qt4 quicktime readline reflection reiserfs samba sdk session slang spell spl sse ssl svg svga t1lib tcltk tcpd theora thunderbird tiff truetype truetype-fonts type1-fonts udev usb vcd videos vorbis win32codecs wmf wxwindows xine xml xorg xosd xv xvid zlib elibc_glibc input_devices_mouse input_devices_keyboard kernel_linux linguas_de userland_GNU video_cards_radeon video_cards_vesa video_cards_fbdev" Unset: CTARGET, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LDFLAGS, PORTAGE_RSYNC_EXTRA_OPTS ppc64 stable alpha stable. «amd64 is back.» ppc stable x86 has gone poof ^.^ It is probably worth noting from the versions in the comment 0 that all ethereal versions are vulnerable (<0.99 are ethereal version numbers). Given ethereal.com has no devs working on ethereal (evidence by their cvs email list with last commit on it in May[1] (when their devs left) is very unlikely they will issue a fix. [1] http://www.ethereal.com/lists/ethereal-cvs/200605/ So in the course of three days we assume that upstream is totally dead because they haven't made a commit in two months? I mean, I can think of *lots* of packages in the tree where upstream hasn't made a commit in two months, but it doesn't mean that they're dead. Has anyone tried to contact them? Bleh... it helps if I actually read everything before I comment. I'll shut up now. Leaving "release" on here so I take the time to do the swap in our release snapshot. Sorry for the noise. sparc stable. GLSA 200607-09 ia64 don't forget to mark stable to benifit from the GLSA. ia64 don't worry about this one - see bug 144946 Does not affect current (2008.0) release. Removing release. |